Chinese crime network laundered over $1B for Lazarus: ZachXBT
Reported by Cointelegraph · AI-assisted summary by ChikoCorp AI News Desk

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.
Summary
Blockchain investigator ZachXBT revealed that a Chinese organized crime syndicate laundered over $1 billion in stolen cryptocurrency for North Korea’s Lazarus Group. ZachXBT infiltrated the laundering network in February 2025 by posing as a client and interacting with an operator known as "Jimmy Green." The laundering operations involved locations in Hong Kong and mainland China and included funds linked to recent hacks such as the Bybit exploit.
Why it matters
The investigation provides rare insight into the intermediaries facilitating the laundering of stolen crypto assets linked to North Korea, a major player in large-scale crypto thefts. Understanding these networks is crucial for tracking illicit funds and enhancing regulatory or enforcement responses. The source does not elaborate further on broader market or policy impacts.
Key context
North Korean hackers have stolen at least $6.75 billion in digital assets through 2025, typically employing complex multi-stage laundering methods including chain-hopping and token swaps. Chinese actors have previously been identified as critical facilitators in laundering stolen crypto, with US prosecutions and sanctions targeting such intermediaries. ZachXBT also linked Chinese networks to laundering funds from other significant exploits including Bitget and Kelp DAO hacks.
Key numbers and entities
ZachXBT (blockchain investigator), Lazarus Group (North Korean hacking group), $1 billion laundered, $6.75 billion in total North Korean crypto thefts, $349,700 stablecoins used to infiltrate network, $12 million Bybit-linked cluster identified, $442,000 frozen by Tether, $387.5 million Bitget exploit, $292 million Kelp DAO exploit. U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) is noted for previous sanctions.
What remains unclear
The source does not specify the full scope of the syndicate’s structure, how many individuals are involved, or details on potential law enforcement actions resulting from this infiltration. It also does not explain the broader implications for international sanctions enforcement or changes in crypto exchange policies.