Blockchain investigator ZachXBT says a Chinese organized crime network helped launder more than $1 billion stolen in multiple crypto exploits tied to North Koreaโs Lazarus Group. The claim comes from an investigation that ZachXBT conducted by infiltrating an alleged money-laundering operation in February 2025, shortly after a major Bybit hack.
In an Oct. 5 post on X, ZachXBT described how he posed as a paying client to gain access to the laundering pipeline. He said he provided $349,700 in stablecoins and accepted a 5% loss on each order to build trust with an operator known as โJimmy Green.โ ZachXBT also said information from the laundering network helped him identify a cluster of more than $12 million linked to Bybit, and that Tether later froze $442,000 in associated USDt.
Key takeaways
- ZachXBT alleges a Chinese intermediary network laundered over $1 billion stolen by Lazarus Group across multiple exploits.
- The investigation described an infiltration attempt that ZachXBT said began in February 2025, days after the Bybit hack.
- ZachXBT says data he received helped flag more than $12 million tied to Bybit activity, with Tether freezing $442,000 of related USDT.
- The story reinforces a broader pattern: North Korea-linked theft often relies on multi-stage laundering involving chain-hopping, token swaps, and external intermediaries.
- Previous U.S. and Treasury actions show regulators have repeatedly targeted alleged crypto traders connected to laundering proceeds from North Korean activity.
Infiltration tied to Bybit proceeds
ZachXBT said the laundering operation involved contacts across Hong Kong and mainland China and that an operator called โJimmy Greenโ was part of the process. According to his account, he deliberately structured his interaction to appear credible to the network, using stablecoins and accepting consistent small losses on orders.
The stated outcome of the infiltration was twofold: first, establishing enough trust to gather information, and second, using that information to trace stolen funds. ZachXBT said the details he received allowed him to identify a cluster of more than $12 million in funds linked to the Bybit hack, and that Tether later froze $442,000 of associated USDt.
While the claims are significant, the practical takeaway for market participants is the reminder that investigations often depend on cooperation with or access to intermediary actorsโespecially when funds have already been routed through swaps, bridges, and other obfuscation services. Freezes like Tetherโs can disrupt liquidity, but tracing and attribution frequently require more than on-chain pattern analysis alone.
Why intermediaries matter in North Korea laundering
North Korea-linked campaigns are often described as running stolen crypto through layered steps intended to reduce traceability. One common approach is chain-hopping and token swapping across decentralized exchanges, bridges, and other services that can fragment transaction histories and complicate attribution.
ZachXBTโs allegation of a Chinese intermediary network fits a wider public record of how regulators and prosecutors have approached similar cases. In 2020, U.S. prosecutors charged two Chinese nationals with laundering more than $100 million stolen by North Korean hackers from a cryptocurrency exchange in 2018. Earlier, that same pattern of intermediaries has also shown up in sanctions actions: in 2023, the U.S. Department of the Treasuryโs Office of Foreign Assets Control (OFAC) sanctioned two crypto tradersโone from Hong Kong and one from Chinaโover their alleged role in helping the DPRK convert stolen crypto and bypass financial controls.
These earlier actions do not prove any specific network involved in the latest allegation, but they help explain why investigators focus on regional intermediary roles. When stolen funds move quickly, attribution often hinges on identifying the nodes that reliably convert or move value between ecosystems.
Context from broader reporting on DPRK-linked theft
The ZachXBT investigation arrives at a time when industry researchers have continued to report substantial DPRK-associated theft. According to Chainalysis, hackers linked to North Korea have stolen at least $6.75 billion in digital assets through 2025.
That figure underscores the operational challenge for exchanges, stablecoin issuers, and compliance teams: the volume of stolen funds, combined with laundering complexity, means that detection and response must operate at multiple levels. On-chain monitoring can flag suspicious activity, but enforcement and remediation often depend on knowing how intermediaries interact with centralized actorsโwhether through deposits, conversions, or other touchpoints.
Earlier allegations involving other exploits and public channels
ZachXBT has also previously linked Chinese actors to laundering activity related to other Lazarus-associated incidents. In a separate X post on Sept. 28, he said Chinese actors allegedly involved in laundering funds connected to a $387.5 million Bitget exploit had been seeking support in public Discord servers and Telegram channels used by services in their laundering process.
In the same vein, ZachXBT said one operator he identified had also been involved in laundering funds from the $292 million Kelp DAO exploit in April. While these claims reflect an investigative narrative rather than a court outcome, they point to a potentially important shift: intermediaries may not always hide entirely. When laundering support networks recruit assistance through public communities, it can expose operational detailsโsuch as messaging workflows, service names, or recurring participantsโthat later become useful to investigators.
For readers, the key question is what changes next. ZachXBTโs latest claim centers on an alleged pipeline that can be traced to a Bybit-connected cluster and a subsequent Tether freeze. The next signals to watch are whether additional issuers or exchanges take action after similar tracing work, and whether regulators expand enforcement tied to the regional intermediary roles highlighted across multiple public cases.
As investigators keep probing the connections between stolen funds, regional facilitators, and stablecoin ecosystems, the most important development to monitor will be whether interdictions and freezes scale beyond isolated clustersโsince thatโs often where deterrence becomes tangible for actors attempting to convert stolen crypto into usable value.






