ZachXBT Exposes Chinese Syndicate That Laundered $1B+ for North Korea's Lazarus Group
Published October 6, 2026, 14:55 UTC. Based on a 12-post thread by on-chain investigator ZachXBT on X, and reporting by Cointelegraph and The Crypto Times.
On-chain investigator ZachXBT said on October 5 that he spent months posing as a paying client inside a Chinese organized crime syndicate that, he says, laundered more than $1 billion in stolen crypto across multiple exploits for North Korea’s Lazarus Group. The undercover work began in February 2025, days after the $1.5 billion Bybit hack, and the investigator says it produced fund freezes and wallet attributions that he had to withhold until now because the case was still live.
The undercover operation: $349,700 and “Jimmy Green”
ZachXBT said he noticed more than 15 accounts in public Telegram and Discord groups openly seeking help processing orders tied to stolen funds after the February 2025 Bybit breach, according to The Crypto Times. He contacted several, and began dealing with a Telegram operator using the alias “Jimmy Green.” To build trust, he fronted $349,700 in stablecoins and accepted a 5% loss on every order, he wrote.
On March 6, 2025, he funded a fresh Ethereum address with 349,700 USDC and began swapping that USDC for USDT on Tron with Jimmy, according to the thread. ZachXBT says the addresses Jimmy used were funded with gas by a wallet directly traceable to Bybit exploit funds and listed on the public Bybit exploit blacklist. He also says Jimmy described moves of Bybit funds for a North Korean client before they happened, including a next-day transfer to Solana that then occurred, and gave him a basic account of the network’s operations in Hong Kong and mainland China.
The $12 million wallet cluster and the $442,000 freeze
From three Solana addresses Jimmy shared, ZachXBT says he opened up a cluster of more than $12 million in Bybit exploit funds moving across Bitcoin, Ethereum, Solana and Tron. The thread matches the operator’s screenshots against on-chain activity, including a THORChain order created within minutes of a bridge screenshot Jimmy sent, according to The Crypto Times. Tether later froze 442,000 USDT linked to that cluster inside a Uniswap V2 WAFF-USDT liquidity pool, the thread says.
ZachXBT also says one operator he dealt with was separately involved in laundering funds from the $387.5 million Bitget exploit in September, a connection he first flagged on September 28, and from the $292 million Kelp DAO exploit in April, according to Cointelegraph. Another lead in the chats, about roughly $3 million in fraud proceeds handled for a different client, was traced to a hot wallet of Huione Guarantee, which FinCEN identified on May 1, 2025 as a financial institution of primary money laundering concern under Section 311 of the USA PATRIOT Act.
What it reveals about North Korea’s playbook
The investigation offers a rare look at the intermediaries between North Korean hackers and clean money. The FBI attributed the February 21, 2025 Bybit theft, roughly $1.5 billion, to North Korean actors it tracks as TraderTraitor, overlapping with Lazarus Group activity, according to an FBI public service announcement cited by The Crypto Times. Chainalysis data cited by Cointelegraph puts the total stolen by North Korea-linked hackers at no less than $6.75 billion through 2025.
The method, as described, is chain-hopping: stolen funds are token-swapped and bridged across decentralized exchanges and networks to obscure their trail, with Chinese intermediaries moving funds through Hong Kong and the mainland. U.S. prosecutors charged two Chinese nationals in 2020 with laundering more than $100 million stolen by North Korean hackers in 2018, and in 2023 the Treasury’s Office of Foreign Assets Control sanctioned two crypto traders from Hong Kong and mainland China for helping North Korea convert stolen crypto, according to Cointelegraph.
What remains unconfirmed
Several claims in the thread lack independent verification. No law enforcement agency has publicly confirmed ZachXBT’s findings, though he says he shared them with private-sector investigators and agencies assigned to the case, according to The Crypto Times. The thread does not break down how the $1 billion figure in the opening post was calculated, and one operator’s claim that his team handled most of the $1.5 billion in Bybit funds was described by ZachXBT as consistent with patterns he had already been watching, not independently quantified. ZachXBT says the work has helped freeze more than $75 million tied to North Korean incidents since 2022, at the cost of the 5% spread on the money he fronted, and personal risk he did not detail.
This article is news reporting and is not investment advice.
Sources
- ZachXBT, 12-post investigation thread on X (Oct. 5, 2026), primary source
- Cointelegraph, Chinese Network Laundered $1B for North Korea: ZachXBT (Oct. 5, 2026)
- The Crypto Times, ZachXBT Posed as a Client to Map a Syndicate Laundering Bybit Hack Funds (Oct. 5, 2026)
- FBI, PSA I-022625-PSA, attribution of the Bybit theft to North Korea’s TraderTraitor (Feb. 26, 2025)
MABOnChain Daily Brief
The key crypto and markets stories in one short, plain-language email. Free. Unsubscribe any time.
Prefer chat? Join us on Telegram
Keep reading
Salus Flags Revenue Over USDG Permit Wallet Drains
Security firm Salus says Revenue, which markets X Money to crypto swaps, is tied to permit signatures that let attackers drain users' USDG in one transaction.
EU Puts Crypto Wallet Makers on 24-Hour Breach Reporting Clock
The EU's Cyber Resilience Act, in force since October 2, requires crypto hardware and software wallet makers to report actively exploited vulnerabilities within 24 hours, with fines up to 15 million euros.
FlashLoop, GoldPesa, MALT: A Week of Smaller DeFi Exploits
Three smaller DeFi exploits from Oct. 1 to 3 cost about $490K combined. Each hit add-on code: a Safe module, a Uniswap v4 hook and a swap function.


