MABOnChain
Educational content only. Nothing on this site is financial advice.
Home / Scam Alerts / ZachXBT Exposes Chinese Syndicate That Laundered $1B+ for North Korea's Lazarus Group
Scam Alerts

ZachXBT Exposes Chinese Syndicate That Laundered $1B+ for North Korea's Lazarus Group

By MABOnChain Desk · Published · Updated · 4 min read

Editorial digital-art illustration of a hooded detective before a cracked North Korean emblem, with red flagged wallet nodes and BTC, ETH and Solana symbols dissolving into pixels

Published October 6, 2026, 14:55 UTC. Based on a 12-post thread by on-chain investigator ZachXBT on X, and reporting by Cointelegraph and The Crypto Times.

On-chain investigator ZachXBT said on October 5 that he spent months posing as a paying client inside a Chinese organized crime syndicate that, he says, laundered more than $1 billion in stolen crypto across multiple exploits for North Korea’s Lazarus Group. The undercover work began in February 2025, days after the $1.5 billion Bybit hack, and the investigator says it produced fund freezes and wallet attributions that he had to withhold until now because the case was still live.

The undercover operation: $349,700 and “Jimmy Green”

ZachXBT said he noticed more than 15 accounts in public Telegram and Discord groups openly seeking help processing orders tied to stolen funds after the February 2025 Bybit breach, according to The Crypto Times. He contacted several, and began dealing with a Telegram operator using the alias “Jimmy Green.” To build trust, he fronted $349,700 in stablecoins and accepted a 5% loss on every order, he wrote.

On March 6, 2025, he funded a fresh Ethereum address with 349,700 USDC and began swapping that USDC for USDT on Tron with Jimmy, according to the thread. ZachXBT says the addresses Jimmy used were funded with gas by a wallet directly traceable to Bybit exploit funds and listed on the public Bybit exploit blacklist. He also says Jimmy described moves of Bybit funds for a North Korean client before they happened, including a next-day transfer to Solana that then occurred, and gave him a basic account of the network’s operations in Hong Kong and mainland China.

The $12 million wallet cluster and the $442,000 freeze

From three Solana addresses Jimmy shared, ZachXBT says he opened up a cluster of more than $12 million in Bybit exploit funds moving across Bitcoin, Ethereum, Solana and Tron. The thread matches the operator’s screenshots against on-chain activity, including a THORChain order created within minutes of a bridge screenshot Jimmy sent, according to The Crypto Times. Tether later froze 442,000 USDT linked to that cluster inside a Uniswap V2 WAFF-USDT liquidity pool, the thread says.

ZachXBT also says one operator he dealt with was separately involved in laundering funds from the $387.5 million Bitget exploit in September, a connection he first flagged on September 28, and from the $292 million Kelp DAO exploit in April, according to Cointelegraph. Another lead in the chats, about roughly $3 million in fraud proceeds handled for a different client, was traced to a hot wallet of Huione Guarantee, which FinCEN identified on May 1, 2025 as a financial institution of primary money laundering concern under Section 311 of the USA PATRIOT Act.

What it reveals about North Korea’s playbook

The investigation offers a rare look at the intermediaries between North Korean hackers and clean money. The FBI attributed the February 21, 2025 Bybit theft, roughly $1.5 billion, to North Korean actors it tracks as TraderTraitor, overlapping with Lazarus Group activity, according to an FBI public service announcement cited by The Crypto Times. Chainalysis data cited by Cointelegraph puts the total stolen by North Korea-linked hackers at no less than $6.75 billion through 2025.

The method, as described, is chain-hopping: stolen funds are token-swapped and bridged across decentralized exchanges and networks to obscure their trail, with Chinese intermediaries moving funds through Hong Kong and the mainland. U.S. prosecutors charged two Chinese nationals in 2020 with laundering more than $100 million stolen by North Korean hackers in 2018, and in 2023 the Treasury’s Office of Foreign Assets Control sanctioned two crypto traders from Hong Kong and mainland China for helping North Korea convert stolen crypto, according to Cointelegraph.

What remains unconfirmed

Several claims in the thread lack independent verification. No law enforcement agency has publicly confirmed ZachXBT’s findings, though he says he shared them with private-sector investigators and agencies assigned to the case, according to The Crypto Times. The thread does not break down how the $1 billion figure in the opening post was calculated, and one operator’s claim that his team handled most of the $1.5 billion in Bybit funds was described by ZachXBT as consistent with patterns he had already been watching, not independently quantified. ZachXBT says the work has helped freeze more than $75 million tied to North Korean incidents since 2022, at the cost of the 5% spread on the money he fronted, and personal risk he did not detail.

This article is news reporting and is not investment advice.

Sources

Not financial advice. This content is for information and education only. See our disclaimer, editorial policy and disclosures.

MABOnChain Daily Brief

The key crypto and markets stories in one short, plain-language email. Free. Unsubscribe any time.

Loading the signup form…

Prefer chat? Join us on Telegram

Keep reading