By Interestana AI Editorial — AI-drafted, human-overseen. How we report
ZachXBT Traces $1B Laundering by Chinese Network for Lazarus

Blockchain investigator ZachXBT has uncovered a sophisticated Chinese criminal network responsible for laundering over $1 billion for the North Korean state-sponsored hacking group Lazarus. ZachXBT detailed his findings in a series of posts on X (formerly Twitter), explaining how he infiltrated the network by posing as a potential customer. This infiltration allowed him to gather crucial information that helped trace illicit funds, particularly those originating from the massive $1.5 billion hack of cryptocurrency exchange Bybit. The investigation revealed that the network utilized a complex web of shell companies and cryptocurrency transactions to obscure the origins of the stolen funds and move them through various jurisdictions, making them difficult for law enforcement to track. ZachXBT's work highlights the persistent challenges in combating cryptocurrency-enabled money laundering, especially when sophisticated state-sponsored actors like Lazarus are involved. Lazarus Group is known for its extensive cybercriminal activities, including ransomware attacks and cryptocurrency theft, often used to fund North Korea's nuclear weapons program. The group has been linked to numerous high-profile hacks, including the 2014 Sony Pictures Entertainment breach and the 2017 WannaCry ransomware attack. The scale of the laundering operation, exceeding $1 billion, underscores the significant financial resources Lazarus Group can acquire through its illicit activities and the critical role of independent investigators like ZachXBT in exposing these operations. The investigation involved meticulously analyzing transaction data on the blockchain, cross-referencing it with information obtained through social engineering tactics, and identifying key individuals and entities involved in the money laundering process. ZachXBT's methodology demonstrates a powerful combination of on-chain analysis and off-chain intelligence gathering. The findings are expected to provide valuable leads for international law enforcement agencies attempting to dismantle Lazarus Group's financial infrastructure and hold those involved accountable. The report also implicitly points to the ongoing need for enhanced regulatory oversight and improved cooperation between cryptocurrency exchanges, financial institutions, and law enforcement to prevent and detect such large-scale illicit financial flows. The Bybit hack, which occurred in late 2022, saw attackers steal approximately $1.5 billion in various cryptocurrencies. The subsequent laundering of a significant portion of these funds through the identified Chinese network represents a major success for Lazarus Group in converting stolen assets into usable funds. ZachXBT's detailed exposition of the network's operations provides a rare glimpse into the mechanics of modern cryptocurrency money laundering and the actors who facilitate it. The investigator's commitment to transparency and public disclosure of these findings aims to raise awareness and encourage further action against cybercrime.
Original source — read the full reporting at the publisher:
Read on CoinTelegraphGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.