ZachXBT Says Chinese Network Laundered $1B for Lazarus

ZachXBT Says Chinese Network Laundered $1B for Lazarus

Blockchain investigator ZachXBT says he infiltrated an alleged Chinese organized crime network that laundered more than $1 billion across multiple crypto exploits for North Korea-linked actors. In an October 5 disclosure on X, he said he posed as a customer after identifying more than 15 accounts seeking assistance with transactions connected to stolen funds. The $1 billion figure is ZachXBT’s assessment of the network’s activity, rather than an independently confirmed law-enforcement total.

The investigation centered partly on proceeds from the February 2025 Bybit breach. The FBI officially attributed that theft to North Korean TraderTraitor actors, placing the value at approximately $1.5 billion and warning that the stolen assets were being dispersed across multiple blockchains for laundering. That official attribution supports the North Korean connection to the underlying Bybit theft, but not every broader allegation ZachXBT makes about the laundering network.

$349,700 Operation Exposed Bybit-Linked Wallets

ZachXBT said he funded a fresh Ethereum address with 349,700 USDC on March 6, 2025 and began exchanging funds with an operator using the alias “Jimmy Green.” He said he accepted losses of roughly 5% on individual transactions to build trust and obtain wallet information. The $349,700 represents capital he put at risk during the operation, not the final economic cost of the investigation. According to his account, there was no guarantee the counterparty would return the funds.

The investigator said one address supplied by Green had been funded for gas by a wallet directly traceable to the Bybit exploit and included on Bybit’s public blacklist. Green also allegedly discussed future movements of Bybit funds before they appeared onchain, including a planned transfer toward Solana. Those advance details gave ZachXBT a way to compare private claims against subsequent blockchain activity rather than relying solely on the operator’s statements.

One of the strongest examples involved three Solana addresses that ZachXBT said exposed a cluster containing more than $12 million in Bybit-linked funds. The assets moved across Bitcoin, Ethereum, Solana and TRON, while Tether later froze 442,000 USDT associated with the cluster. The $12 million represents traced funds in the identified cluster, while $442,000 is the amount ZachXBT says was ultimately frozen in that specific case. The distinction mirrors broader questions around Tether’s ability to freeze USDT at the issuer level.

Private Investigators Fill Attribution Gaps

ZachXBT said the network operated through contacts in Hong Kong and mainland China and used multiple assets and chains to move illicit proceeds. He also connected statements from the same operator to a previously frozen 332,000 USDC cluster associated with the Poloniex exploit and to another $3 million flow that he traced to a Huione Guarantee hot wallet. The picture is of a service layer that allegedly handled stolen funds for multiple clients rather than a wallet cluster tied to a single exploit.

The case highlights why blockchain tracing increasingly combines public transaction data with offchain intelligence. Similar investigations have relied on wallet attribution, transaction timing and behavioral evidence, including ZachXBT’s work tracing the GANA Payment exploit. At the enforcement layer, disputes such as the $71 million frozen ETH case involving alleged North Korean-linked funds show that identifying suspicious assets and determining their legal disposition are separate processes. Onchain attribution can identify probable flows, but recovery, seizure and ownership still depend on custodians, issuers and legal authorities.

ZachXBT said he shared his findings with law enforcement and delayed publication because of the investigation’s sensitivity. He also claimed to have helped facilitate more than $75 million in freezes connected to North Korean incidents since 2022. For the newly disclosed operation, however, the strongest publicly specified result is narrower: a $12 million-plus Bybit-linked cluster and a subsequent 442,000 USDT freeze. That makes the disclosure significant for understanding laundering infrastructure, while leaving the broader $1 billion estimate dependent on ZachXBT’s attribution and evidence.

Follow Us

Ads

Main Title

Sub Title

It is a long established fact that a reader will be distracted by the readable

Ads
banner 900px x 170px