How did ZachXBT track Lazarus Group’s Bybit loot through Chinese crypto launderers?

On-chain sleuth ZachXBT successfully tracked stolen Bybit funds by posing as a client of a Chinese crime syndicate, fronting nearly $350,000 to infiltrate their laundering network. By paying a 5% fee on transactions, he was able to monitor the Lazarus Group's movement of assets in real time, providing a rare look at North Korean off-ramping tactics.
How did ZachXBT track Lazarus Group’s Bybit loot through Chinese crypto launderers?

ZachXBT tracked the North Korean Lazarus Group’s stolen Bybit loot by posing as a customer of their primary Chinese laundering syndicate, fronting $349,700 of his own capital to gain access. To maintain his cover and receive real-time data on the flow of funds, the investigator accepted a 5% loss on every transaction, effectively paying the launderers to reveal their internal processing routes. This undercover operation allowed for the direct mapping of how state-sponsored hackers convert stolen digital assets into liquid capital through specialized Chinese over-the-counter (OTC) desks.

The operation highlights the sophisticated infrastructure supporting the Lazarus Group in 2026, which relies heavily on Chinese-based crime syndicates to bypass international sanctions. These syndicates act as a buffer, taking stolen crypto and providing clean assets in return, often using high-volume OTC platforms that lack rigorous Know Your Customer (KYC) protocols. By sacrificing capital to act as a participant, ZachXBT bypassed the typical delays in on-chain forensics, catching the movement of funds before they could be fully obfuscated by mixers or cross-chain bridges.

From a geopolitical perspective, this incident places renewed pressure on international regulators to address the role of Chinese OTC traders in the North Korean cyber-warfare machine. Despite ongoing US Treasury sanctions, these laundering networks have proven resilient by shifting their operations across various Asian jurisdictions. The fact that a private investigator had to front significant personal capital to achieve this level of transparency suggests that current automated monitoring tools are still struggling to keep pace with state-level obfuscation techniques.

Market participants should watch for potential new sanctions against the specific wallet addresses and entities identified in ZachXBT’s report, which could lead to localized liquidity freezes on certain exchanges. As the Lazarus Group continues to evolve its methods, the industry may see a shift toward more aggressive, active-participation forensic methods. The success of this undercover sting demonstrates that while the blockchain is transparent, uncovering the human actors behind the addresses increasingly requires high-risk, real-world intelligence gathering.

Editorial method

This report is based on the linked source and is labeled with its publication date, provider, category and market-impact assessment. Market interpretation is informational, not investment advice.