Thedefiant ZachXBT Exposes Chinese Laundering Operation for Lazarus Group
Article Content
- •ZachXBT infiltrated a Chinese syndicate laundering over $1 billion for North Korea.
- •He lost 5% on each transaction while posing as a client to gain trust.
- •The investigation led to the freezing of funds linked to the Bybit hack.
Blockchain investigator ZachXBT infiltrated a Chinese money-laundering syndicate linked to North Korea's Lazarus Group, which allegedly laundered over $1 billion, including funds from the $1.5 billion Bybit hack in February 2025. Posing as a client, he fronted $349,700 and lost 5% on each transaction to gain the trust of the launderers. His investigation led to the freezing of Bybit-linked funds and the identification of illicit on-chain flows. The FBI attributed the Bybit theft to a North Korean faction known as TraderTraitor. ZachXBT's interactions revealed operational details of the laundering process, including the division of labor among the crew and the movement of funds through various cryptocurrencies. His findings were shared in a detailed thread on X, showcasing the laundering patterns and the crew's methods.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Lazarus Group, TraderTraitor and Bybit in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What was the scale of the laundering operation?
How did ZachXBT gain access to the laundering crew?
What actions were taken as a result of ZachXBT's investigation?
Continue Reading
Bitget Suffers $388M Hack Attributed to North Korean Lazarus Group On September 24, 2026, Bitget reported a significant security breach resulting in the theft of approximately $388 million from its hot and warm wallets. The attackers exploited a vulnerability in a third-party security product to gain internal access credentials and issued fraudulent withdrawal commands. Bitget's cold…