By Interestana AI Editorial — AI-drafted, human-overseen. How we report
ZachXBT Posed as Client to Expose Lazarus Launderers

On-chain investigator ZachXBT revealed on March 13, 2024, that he posed as a client of a Chinese crime syndicate to track funds laundered for the North Korean state-sponsored hacking group, Lazarus Group. This elaborate sting operation involved ZachXBT fronting $349,700 in cryptocurrency and incurring a 5% fee on each transaction to gain real-time insights into the syndicate's money laundering activities. The investigation aimed to expose the methods used by the syndicate to obscure the origin of stolen cryptocurrency, particularly funds linked to Lazarus Group's illicit activities, including the $625 million Ronin Bridge hack in March 2022 and the $100 million Horizon Bridge hack in June 2022.
ZachXBT's investigation focused on a specific Chinese money laundering operation that was facilitating the movement of illicit funds, primarily from cryptocurrency exchanges like Bybit. By acting as a customer, ZachXBT was able to observe the syndicate's processes firsthand, including how they managed customer accounts, processed deposits and withdrawals, and ultimately laundered the cryptocurrency. The 5% fee structure indicated a significant operational cost for the launderers, which ZachXBT was willing to absorb to gather actionable intelligence. This approach allowed him to map the flow of funds in real-time, providing a level of detail rarely achieved in cryptocurrency investigations.
The Lazarus Group, designated as a malicious cyber actor by the U.S. Department of the Treasury, is known for its sophisticated hacking operations and has been linked to numerous high-profile cryptocurrency thefts. The group's ability to launder these stolen funds effectively is crucial to their continued operations and is a primary target for law enforcement and cybersecurity researchers. ZachXBT's investigation provided a rare glimpse into the mechanics of these laundering operations, highlighting the role of intermediaries and specialized syndicates in facilitating the movement of illicit digital assets. The findings are expected to aid in future efforts to disrupt such networks and recover stolen funds.
This investigation underscores the evolving tactics employed by both cybercriminals and those working to counter them. ZachXBT's willingness to engage directly with suspected criminal elements, albeit under controlled conditions, demonstrates a proactive approach to uncovering sophisticated financial crimes. The data gathered is crucial for understanding the vulnerabilities within the cryptocurrency ecosystem and for developing more effective countermeasures against state-sponsored hacking groups and their financial facilitators. The syndicate's use of Bybit as a platform for moving Lazarus Group's loot is a significant detail that could lead to further scrutiny of the exchange's anti-money laundering (AML) and know-your-customer (KYC) procedures.
Original source — read the full reporting at the publisher:
Read on DecryptGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.