A large, open vault door in a dimly lit room
Crypto

ZachXBT alleges $1B+ Lazarus laundering ring and links it to Bybit funds and a USDT freeze

He says launderer intel surfaced a $12M+ Bybit-linked cluster and Tether later froze $442,000 in associated USDT.

By Marcus Hale5 min read

Blockchain investigator ZachXBT alleges a Chinese organized crime syndicate laundered more than $1 billion from multiple crypto exploits for North Korea’s Lazarus Group. He also says launderer-supplied information helped identify more than $12 million in Bybit-linked funds and preceded a $442,000 USDT freeze by Tether.

ZachXBT Claims a $1B+ Lazarus Laundering Pipeline—and Ties It to Bybit Funds

ZachXBT alleged on Oct. 5 that a Chinese organized crime syndicate laundered more than $1 billion in stolen crypto for North Korea’s Lazarus Group. The packet provides no independent documentation for the $1 billion-plus total, and the claim sits entirely on ZachXBT’s account of what he saw and learned.

The trader-relevant detail is the sequence he describes. ZachXBT said launderer-supplied information helped him identify a cluster of more than $12 million in Bybit-linked funds, and that Tether later froze $442,000 in associated USDt (USDT). That is the practical risk surface: funds can go from “movable” to “stuck” quickly when a stablecoin issuer acts, even if the broader allegation remains unadjudicated.

ZachXBT framed the activity as tied to post-exploit flows, saying his access came days after the Bybit hack. The packet references a “$1.5 billion Bybit hack” but does not provide a date or additional primary documentation for the incident, so the timing and linkage should be treated as unconfirmed beyond ZachXBT’s description.

How the Undercover Access Allegedly Worked, and What It Suggests About Intermediaries

ZachXBT said he infiltrated the laundering network in February 2025 by posing as a paying client. He said he put up $349,700 in stablecoins and accepted a 5% loss on each order to build trust with an operator he identified as “Jimmy Green.” That reads less like an ad hoc mixer trail and more like a fee-driven service where access is purchased and reliability is the product.

He said the operation spanned Hong Kong and mainland China. The packet also places the alleged network inside a familiar laundering playbook tied to North Korea-linked activity: multi-stage movement that uses chain-hopping, token swapping via decentralized exchanges, and bridges to blur provenance.

ZachXBT further linked Chinese actors to laundering tied to a $387.5 million Bitget exploit in September, and said one operator was also involved in laundering funds from a $292 million Kelp DAO exploit in April. The packet does not specify the years for those exploits beyond their placement in the narrative, and it does not provide corroborating documentation for the exploit figures or the operator linkage.

The enforcement backdrop matters because it is the channel through which these stories become market structure. The packet cites that US prosecutors charged two Chinese nationals in 2020 with laundering more than $100 million stolen by North Korean hackers from a cryptocurrency exchange in 2018. It also cites that the US Treasury’s Office of Foreign Assets Control sanctioned two crypto traders in 2023, one from Hong Kong and one from China, for helping the DPRK convert stolen crypto and bypass financial controls.

Why This Matters for Traders: USDT Freeze Risk, Counterparty Exposure, and Sanctions Spillover

The immediate takeaway is issuer control. USDT can be frozen at specific addresses by Tether, and ZachXBT’s claimed chain of events ends with $442,000 frozen. Even if the $1 billion-plus laundering figure is never corroborated, the freeze itself is the kind of event that can abruptly change the usability of funds tied to a hack narrative.

The second-order effect is counterparty selection. If laundering rails are operating like OTC-style intermediaries, the “who benefits” is the service operator collecting spread and fees, while the end-user takes taint risk that can surface later at deposit, withdrawal, or redemption. That risk does not stay contained to the original thief. It can spill into market makers, OTC desks, and venues that touch the flow.

Scale is why the market keeps repricing this theme. Chainalysis estimates hackers linked to North Korea have stolen at least $6.75 billion in digital assets through 2025. That historical loss volume is large enough that any fresh detail about intermediaries or enforcement can tighten compliance, fragment liquidity, and widen spreads in the places that matter.

The forward signals are concrete, not narrative-driven. Follow-on freezes or a public confirmation tied to the Bybit-linked cluster would raise the probability that more addresses get tagged. Law-enforcement or OFAC actions referencing Hong Kong or mainland China facilitators would be the step-change, because designations and seizures tend to propagate quickly into exchange policy and compliance-provider alerts. On-chain, the key is whether the more than $12 million cluster ZachXBT cited starts chain-hopping, bridging, or routing through DEX swaps in patterns consistent with multi-stage laundering, because that is where deposit acceptance and withdrawal friction usually shows up first.

My Read: Treat the Allegation as a Risk Map, Not a Court Filing

The threshold that matters is not the $1 billion-plus headline number. It is whether the Bybit-linked cluster ZachXBT described keeps getting operationally constrained, either through additional USDT freezes beyond the cited $442,000 or through address-level flagging that changes how venues handle deposits.

If issuer actions and compliance advisories start clustering around the same set of addresses, the setup starts to look structural rather than narrative-driven. That is when “taint” becomes a liquidity problem instead of a headline.

Sources