A Chinese crime network laundered more than $1 billion for Lazarus Group, the North Korean hacking syndicate, according to the blockchain investigator ZachXBT. The finding emerged from a months-long infiltration in which the researcher posed as a customer to gain access to the network's operations.
The laundered funds include money traced from the $1.5 billion Bybit hack, one of the largest cryptocurrency thefts on record. ZachXBT's work helped follow the money through a web of Chinese-speaking facilitators who move stolen crypto for a fee.
How the researcher got inside
ZachXBT didn't crack the network with code. He pretended to be a client. By posing as someone looking to cash out or move large sums, he got the network's members to talk — sharing wallet addresses, payment methods, and details about how they handle dirty coins. That access let him map connections between the launderers and Lazarus Group, the hacking team linked to North Korea's government.
The network operates like a shadow banking service for cybercriminals. Clients send stolen cryptocurrency; the network returns clean funds, often through Chinese over-the-counter (OTC) brokers, crypto exchanges, and peer-to-peer traders. The fee is typically a percentage of the total, which adds up quickly when you're moving hundreds of millions.
The Bybit hack and the money trail
In February 2025, attackers hit Bybit, a major crypto exchange, and walked away with $1.5 billion in Ethereum and other tokens. It was the biggest crypto heist ever, and the stolen assets were quickly funneled into laundering pipelines. ZachXBT's infiltration helped trace a portion of those funds to the Chinese network, which then mixed and moved them across borders.
The $1 billion figure tied to Lazarus Group is separate from the Bybit haul. It represents the total volume the network laundered for the syndicate over time, according to ZachXBT's findings. That means the group has been a long-standing partner for North Korea's crypto theft operations, not just a one-off accomplice after Bybit.
What this means for crypto crime fighting
Blockchain analysis firms and law enforcement have long known that Chinese money laundering networks are a key piece of the puzzle for stolen crypto. But getting inside one is rare. ZachXBT's undercover approach worked because the network is built on trust and reputation among criminals. Once he was in, he could see how they communicated, which services they used, and how they tried to hide their tracks.
The findings add pressure on Chinese authorities, who have cracked down on crypto trading but still struggle to police underground financial channels. They also give Bybit and its partners more leads to chase. The exchange has been working with investigators to freeze and recover funds, but only a small fraction of the $1.5 billion has been recovered so far.
For Lazarus Group, the exposure is another blow. The syndicate is already sanctioned by the U.S. Treasury and wanted by the FBI. But sanctions haven't stopped the hacks, and arrests of North Korean IT workers abroad haven't stopped the money flow. The network ZachXBT infiltrated may now go quiet or change tactics, but the demand for laundering services remains.
ZachXBT hasn't said whether he handed his evidence to law enforcement. He published his findings on social media, as he often does, prompting fresh scrutiny of the Chinese laundering ecosystem. Whether that scrutiny leads to arrests or seizures is unclear. What is clear: the $1.5 billion Bybit hack wasn't just a theft — it was a test of how quickly stolen crypto can vanish into a system built to clean it.




