Blockchain investigator ZachXBT says a Chinese organized crime syndicate laundered more than $1 billion stolen by North Korea’s Lazarus Group across multiple crypto exploits. The allegations, detailed in an Oct. 5 thread on X, provide unusually granular detail on how intermediaries may help DPRK-linked funds move through exchanges and other on-chain routes.
ZachXBT claims he infiltrated part of the laundering operation in February 2025—just days after the Bybit hack—by posing as a paying client. He says the information he received helped him identify a cluster of more than $12 million tied to Bybit-linked funds, and that Tether later froze $442,000 in associated USDT.
Key takeaways
- ZachXBT alleges a Chinese network laundered over $1 billion stolen for Lazarus Group, positioning Chinese intermediaries as a key bridge in DPRK-linked crypto flows.
- The investigation centers on a Feb. 2025 undercover approach involving stablecoin orders and an intermediary called “Jimmy Green.”
- ZachXBT says the disclosed leads contributed to identifying Bybit-linked funds and Tether freezing $442,000 in USDt tied to associated activity.
- The broader pattern aligns with prior US and Treasury actions that have targeted Chinese facilitators for converting stolen crypto and bypassing controls.
- Investigators and regulators continue to focus on the links between public messaging channels used by intermediaries and the on-chain routes of stolen funds.
An undercover approach to tracing laundering nodes
According to ZachXBT’s account, he began interacting with the laundering network in February 2025, shortly after the Bybit hack. In the Oct. 5 thread, he said he provided $349,700 in stablecoins and accepted a 5% loss on each order as a way to demonstrate credibility with one of the network’s operators, whom he identified as “Jimmy Green.”
ZachXBT said the operation ran through both Hong Kong and mainland China. He also claimed that information received from the intermediaries allowed him to identify a larger cluster—more than $12 million—in funds linked to the Bybit incident.
The thread further connects the alleged laundering activity to a downstream enforcement mechanism: ZachXBT stated that Tether froze $442,000 in associated USDt (USDT). While the precise criteria behind token freezes aren’t provided in the thread, the outcome suggests that identifiable laundering trails can translate into actionable compliance steps.
Why intermediaries matter for Lazarus-linked crypto
North Korean-linked hackers are widely reported to rely on multi-stage laundering designed to break attribution. ZachXBT described a process in which stolen funds are moved via techniques such as chain-hopping and token swapping across decentralized exchanges, bridges, and other services, making the final origin harder to trace.
In that context, the role of regional intermediaries becomes critical. If funds can be routed through a network of facilitators in financial hubs, it can reduce friction in converting illicit proceeds into assets that are more difficult to associate directly with a specific hack.
ZachXBT’s allegations about Chinese intermediaries fit a pattern seen in earlier enforcement and sanctions actions. In 2020, US prosecutors charged two Chinese nationals with laundering more than $100 million stolen by North Korean hackers from a cryptocurrency exchange in 2018. The case, brought by the US Department of Justice, underscores that law enforcement has previously focused on cross-border facilitators rather than only the initial hack itself.
Similarly, in 2023 the US Treasury’s Office of Foreign Assets Control (OFAC) sanctioned two crypto traders—one from Hong Kong and one from China—over their alleged role in helping the DPRK convert stolen crypto and bypass financial controls. Those measures highlight that regulators view the conversion layer as a key vulnerability in the laundering pipeline.
From Bybit to other alleged laundering targets
ZachXBT’s thread does not limit itself to a single incident. It also references broader alleged activity around other DPRK-linked thefts and the intermediaries reportedly involved.
Separately, ZachXBT said in an X post on Sept. 28 that Chinese actors allegedly laundering funds for North Korean hackers had been openly seeking support in public Discord servers and Telegram channels used by services tied to the laundering workflow. He also alleged that one of the operators had been involved in laundering proceeds from the $292 million Kelp DAO exploit in April.
Those claims matter because they suggest the laundering process may not be conducted entirely in closed channels. If intermediaries are recruiting help on public platforms tied to the operational tooling, that can create additional visibility for investigators—especially when activity is correlated with known hack-linked funds.
ZachXBT also previously linked Chinese actors to laundering funds connected to the $387.5 million Bitget exploit in September, indicating an alleged recurring involvement across different thefts rather than a one-off case.
What investors and compliance teams should watch
If ZachXBT’s allegations are accurate, they point to a recurring architecture: DPRK-linked thefts may be “cleaned” through regionally concentrated intermediaries that facilitate conversion, routing, and eventual blending with legitimate market activity. For traders and compliance-focused firms, the practical implication is that tracing the hack transaction alone may be insufficient; mapping the intermediary and “conversion” layer can be equally important.
The next signal to monitor is whether enforcement and compliance tools continue to respond to identifiable clusters of stolen funds—such as the reported Tether freeze of $442,000 in USDT tied to the alleged Bybit-related activity. Equally important will be whether investigators can consistently link on-chain patterns to off-chain recruiting behavior in public messaging channels, which could strengthen attribution and accelerate mitigation.





Be the first to comment