A Chinese organized crime syndicate laundered more than $1 billion stolen in several crypto exploits for North Korea’s Lazarus Group, blockchain investigator ZachXBT said.
In an October 5 thread of posts on X, pseudonymous blockchain investigator ZachXBT said that in February 2025, just days after the Bybit hack, he posed as a customer able to pay in order to infiltrate a money-laundering network. He provided $349,700 in stablecoins and agreed to take a 5% loss on each order to gain the trust of one of the network’s operators, known as “Jimmy Green.”
ZachXBT said the operations spanned Hong Kong and mainland China, and that information provided by a money launderer helped him identify a cluster of funds worth more than $12 million linked to Bybit; Tether later froze $442,000 in related USDt (USDT).
The investigation offers a rare glimpse into the alleged intermediaries serving North Korean hackers, who have stolen cryptocurrency. According to Chainalysis, hackers linked to the country had stolen at least $6.75 billion in digital assets by 2025.
How North Korea moves stolen cryptocurrency
North Korean hackers are known to use a multistep money-laundering process. One method involves moving between blockchains and swapping tokens through decentralized exchanges, bridges, and other services to conceal the movement of funds.
Chinese intermediaries have become an important link in this process. In 2020, U.S. prosecutors charged two Chinese nationals with laundering more than $100 million stolen by North Korean hackers from a cryptocurrency exchange in 2018.

Source: ZachXBT
In 2023, the U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) sanctioned two crypto traders—one from Hong Kong and the other from China—for their role in helping North Korea convert stolen cryptocurrency and evade financial controls.
Chinese participants allegedly launder Bitget funds
ZachXBT also linked Chinese participants to money laundering following the $387.5 million Bitget exploit in September.
In a September 28 post on X, ZachXBT said Chinese participants allegedly laundering funds on behalf of North Korean hackers openly sought support on public Discord servers and Telegram channels operated by services they used. ZachXBT said one of the operators was also involved in laundering funds following the $292 million Kelp DAO exploit in April.