ZachXBT infiltrates over $1 billion Chinese crypto network
ZachXBT infiltrated a Chinese money laundering network that, according to him, processed over $1 billion in crypto for North Korean hackers from Lazarus.
Blockchain researcher ZachXBT claims to have uncovered an extensive Chinese money laundering network that allegedly processed more than $1 billion in stolen crypto for the North Korean Lazarus Group.
To find out who was behind the operation, he opted for a striking approach. He pretended to be a paying customer for months, wagering hundreds of thousands of dollars of his own money.
The investigation began after the major hack at crypto exchange Bybit. ZachXBT was able to gain the trust of an administrator of the network and thus gained insight into the people and money flows behind the operation.
ZachXBT began its infiltration in February 2025, shortly after the hack at Bybit. He pretended to be a customer who wanted to have large amounts processed by the network.
He used a total of $349,700 in stablecoins for this. These are crypto coins that are designed to maintain a stable value, usually by linking to a traditional currency such as the US dollar.
The investigator deliberately accepted a loss of about five percent in transactions. In doing so, he tried to gain the trust of one of the administrators of the network, known as‘ Jimmy Green ’.
According to him, that strategy ultimately gave him information about the people and money flows behind the alleged money laundering operation. The network would have been active in Hong Kong and mainland China.
With the information collected, ZachXBT said it was able to trace more than $12 million related to the Bybit hack. Part of it could then be blocked. Tether froze $442,000 of USDT linked to the investigated transactions, according to the investigator.
The research offers a glimpse into how North Korean hackers may be trying to launder stolen crypto. The Lazarus Group and other hackers linked to North Korea have been closely monitored by international law enforcement agencies and blockchain researchers for years.
According to analytics firm Chainalysis, hackers associated with North Korea stole at least $6.75 billion in digital assets through 2025.
Stealing crypto is just the first step. After that, the perpetrators have to move the money without researchers being able to easily find out where it comes from.
This is done, for example, via ‘chain hopping’. In doing so, crypto is moved from one blockchain to another. Stolen coins can also be exchanged via decentralized trading platforms and so-called bridges, with which crypto can be transferred between different blockchains.
Moving and exchanging assets creates a long chain of transactions. This makes it more difficult for criminals to follow the trail to the original hack.
Chinese intermediaries have previously been associated with such practices. U.S. prosecutors accused two Chinese nationals of laundering more than $100 million in 2020. That money would have come from an attack that North Korean hackers carried out on a crypto exchange in 2018.
The US Office of Foreign Assets Control (OFAC) also performed later. The agency imposed sanctions on two traders from Hong Kong and China in 2023. They would have helped North Korea convert stolen digital assets and bypass financial controls.
ZachXBT's findings go beyond just the hack at Bybit. The researcher also linked Chinese actors to money laundering from the hack on Bitget in September. According to him, 387.5 million dollars were stolen.
Remarkably, the people involved would not always have acted cautiously. ZachXBT reported that Chinese actors suspected of laundering money for North Korean hackers openly solicited technical assistance in public Discord servers and Telegram channels of services they used.
In addition, one of the administrators of the network would have previously been involved in money laundering from the attack on Kelp Dao in April. That hack would have taken about $292 million.
According to ZachXBT, this creates an image of a much larger network than just the cash flows around Bybit. North Korean hackers would use external intermediaries to move stolen crypto and disguise its origin. The Chinese network ZachXBT investigated would have laundered more than $1 billion for the Lazarus Group alone.