North Korea: how Lazarus launders billions of dollars from crypto hacks
The Bybit hack, which took place in February 2025, remains one of the most significant episodes in the history of cryptocurrencies. The loss is estimated at $1.5 billion. The attack was quickly attributed by the FBI to “TraderTraitor,” a cell directly linked to North Korea. To understand how these enormous sums are laundered, on-chain investigator ZachXBT infiltrated a Chinese money-laundering network that allegedly worked on behalf of the Lazarus group.
Bybit: a historic hack in Lazarus’s shadow
The Bybit case goes beyond a simple hack. With $1.5 billion diverted, it stands as a major event in the crypto ecosystem. Suspicion quickly fell on North Korea and its Lazarus group, through the “TraderTraitor” cell. ZachXBT set out to trace the financial flows and understand the laundering machinery that had been put in place.
Telegram and Discord: the first entry points for laundering
Shortly after the attack, ZachXBT noticed a pattern he describes as recurring. In public groups on Telegram and Discord, more than fifteen accounts asked for help with operations tied to the funds stolen from Bybit. Those requests concerned orders directly connected to the loot.
The investigator then decided to reply to several of these accounts. He made contact in particular with a Telegram user known under the alias “Jimmy Green.”
ZachXBT’s infiltration: 349,700 USDC to gain trust
To carry out the infiltration, ZachXBT funded an Ethereum address with 349,700 USDC. He then completed several transactions with Jimmy Green. Green sent him an address to receive stablecoins, then returned USDT on the Tron network.
From this first exchange, ZachXBT noticed a crucial detail: the address provided by Jimmy Green had received the funds needed to pay gas fees from another address. That source can be traced directly back to the funds stolen in the Bybit hack. It is also among the addresses publicly blacklisted in connection with the hack.
Jimmy Green, an increasingly talkative contact
After several transfers, ZachXBT managed to build a climate of trust. Jimmy Green then spoke about Bybit fund movements carried out on behalf of North Korea. He also gave general information about how the network is organized in Hong Kong and mainland China.
According to him, his team would have laundered most of the $1.5 billion stolen. ZachXBT says he agreed to lose 5% on each order in order to keep the operation going and gather as much usable intelligence as possible.
On-chain evidence and Solana addresses
Jimmy Green eventually sent ZachXBT a screenshot of a transfer in progress through a bridge. The investigator readily tied that operation to the Bybit hack.
He also obtained three Solana addresses. They revealed a cluster of more than $12 million originating from the hack. The funds were being swapped in real time along this path: BTC, then ETH, then SOL, then Tron. Tether ultimately froze 442,000 USDT linked to this cluster.
Uniswap, illiquid tokens and other laundering techniques
The investigation also uncovered a newer laundering method. It uses Uniswap liquidity pools paired with illiquid tokens. Jimmy Green also mentioned a $332,000 freeze in 2024, later tied to the Poloniex hack.
He also referred to the laundering of $3 million from a fraud carried out for another client. ZachXBT linked that sum to a hot wallet of the illicit marketplace Huione Guarantee.
More than $75 million frozen since 2022
All of the data collected was passed to law enforcement. ZachXBT’s work is said to have contributed to freezing more than $75 million in funds linked to incidents involving North Korea. Lazarus has also been on the U.S. Treasury sanctions lists since 2019.
The investigator now hopes to keep receiving grants from foundations and donations from individuals. That funding would allow him to continue investigating crypto laundering networks.
What to remember
- The Bybit hack, estimated at $1.5 billion, is attributed to Lazarus and its TraderTraitor cell.
- Laundering networks are organized in part on Telegram and Discord.
- ZachXBT infiltrated a Chinese network using 349,700 USDC.
- The funds move in particular through BTC, ETH, SOL and Tron.
- Tether froze 442,000 USDT, and more than $75 million has been frozen since 2022.
- Uniswap pools and illiquid tokens appear as newer laundering channels.
FAQ
Who is Lazarus?
Lazarus is a cyberattack group attributed to North Korea. Its “TraderTraitor” cell is associated with large-scale cryptocurrency thefts.
How does North Korea launder stolen crypto?
The regime uses networks organized on Telegram and Discord, stablecoins, bridges, on-chain swaps and DeFi pools to hide the origin of the funds.
What was ZachXBT’s role?
He infiltrated a laundering network, documented the on-chain flows and passed his evidence to the authorities.
Why is the Bybit hack historic?
Because of its size: $1.5 billion. It is one of the largest losses ever recorded in the crypto ecosystem.
Conclusion
ZachXBT’s investigation shows that cryptocurrency laundering linked to North Korea relies on a sophisticated organization spread across messaging apps, stablecoins, bridges and DeFi. For cybersecurity, cooperation between independent investigators, platforms and authorities remains essential to freeze the funds and disrupt Lazarus’s networks.