A Chinese Network Laundered More Than $1 Billion for North Korea’s Lazarus Group, Says ZachXBT
A blockchain investigator went undercover inside a laundering operation tied to North Korea's most notorious hacking crew, and what he uncovered reveals a vulnerability that puts every crypto holder on an exchange at risk.
In a revealing report, blockchain investigator ZachXBT claims that a Chinese crime network laundered more than $1 billion for North Korea’s Lazarus Group. This figure includes a significant portion of the roughly $1.5 billion in Ethereum (CRYPTO:ETH) and other tokens stolen from the Bybit exchange back in February 2025. ZachXBT presented his findings in a detailed 12-part thread on X on October 5, 2026.
ZachXBT went beyond merely analyzing blockchain data; he spent months posing as a client of the laundering network. He shared his findings with law enforcement prior to going public, although authorities have yet to announce any charges.
While $1 billion is staggering, most people keep their crypto in exchange accounts or mobile wallets, so they may not directly interact with a compromised platform. So, what does it mean for the safety of your crypto when there’s a laundering network linked to North Korean hackers?
How ZachXBT Went Undercover Inside the Lazarus Laundering Network

In March 2025, just weeks after the Bybit theft, ZachXBT funded a new Ethereum wallet with 349,700 USDC and hired the network to move it. To appear as a genuine customer and gain the operators’ trust, he accepted a 5% loss on each transaction.
Through this process, he compared the operators’ private messages with public blockchain records. One wallet used by the network received transaction fees from addresses associated with the Bybit hack, and the timing and amounts of transfers through the THORChain bridge matched what the operators had revealed to him. This alignment turned chat screenshots into verifiable evidence for anyone to check on the blockchain.
As a result of his investigations, funds have already been frozen. Tether blocked 442,000 USDT linked to this network, and ZachXBT claims his work has led to the freezing of more than $75 million connected to North Korean hacks since 2022.
How the Network Laundered Lazarus Group’s Stolen Crypto

Every crypto transaction is recorded on a public ledger, which means stolen coins leave a clear trail back to the original theft. Crypto exchanges actively screen incoming deposits and can freeze coins linked to known hacks as soon as they detect them.
This visibility forces thieves to rely on networks like the one ZachXBT described. The operators converted funds from Bitcoin to Ethereum, Solana, and Tron, using the THORChain bridge while parking some of the money in low-volume token pools on Uniswap. This makes it harder to trace the funds before they are cashed out.
Since North Korea has extremely limited access to the global banking system, the Lazarus Group cannot simply open a bank account to withdraw laundered money. Instead, they rely on outside operators to convert traceable coins into usable cash, which helps explain how their laundering activities could reach over $1 billion. These stolen funds largely come from a steady stream of exchange hacks that affect countless users at once.
What the $1.5 Billion Bybit Hack Shows About Exchange Risk

In February 2025, the FBI linked the Bybit theft to North Korea under the operation code name TraderTraitor. The breach occurred within Bybit’s own systems, resulting in significant losses for the platform rather than individual wallet holders.
This scenario illustrates the risk inherent in using crypto exchanges. Funds kept on a platform face not only price volatility risks but also security vulnerabilities. Users typically have no insight into how exchanges protect their private keys or how swiftly they respond to security breaches. For instance, Bitget suffered a $388 million hack in September, raising similar concerns about crypto safety on exchanges.
What Does the ZachXBT Lazarus Report Mean for Your Crypto?
ZachXBT’s report underscores North Korea’s hackers’ reliance on a laundering network to convert stolen crypto into spendable cash. Importantly, the same public ledger that lets them move funds also lets investigators track them and exchanges freeze the assets. For ordinary holders, the main risk comes from the platforms storing their coins, as a single hacking incident can drain the accounts of all users involved.
The full impact of these findings may deepen if authorities charge individuals in the network or identify the exchanges that facilitated the cash-out. Meanwhile, crypto holders should assess how much of their assets depend on third-party security versus the risks of self-custody. Balancing these factors is essential for anyone holding cryptocurrency.
Contact [email protected] for any questions or corrections.








