A Chinese crime organization is alleged to have laundered over $1 billion of cryptocurrency obtained by North Korea’s Lazarus Group.

Infiltration of the laundering network

A blockchain analyst posing as a client entered the illicit operation in early 2025. By depositing roughly $350,000 in stablecoins and deliberately taking a small loss on each transaction, the analyst earned the trust of an operator known only as “Jimmy Green.” This approach allowed the analyst to trace the flow of funds and map the network’s reach across Hong Kong and mainland China.

Size and scope of the operation

The probe identified a group of assets exceeding $12 million that were linked to the Bybit hack earlier that year. After the analysis, the issuer of Tether froze close to $442,000 of the associated USD-T tokens. The total amount laundered for Lazarus, according to the investigation, surpasses $1 billion, adding to an estimated $6.75 billion of crypto stolen by North Korean actors through 2025, as reported by independent analytics.

Laundering techniques and historical context

North Korean hackers typically employ a multi-step process that includes hopping between blockchains, swapping tokens on decentralized exchanges, and using cross-chain bridges to conceal origins. Chinese intermediaries have become a pivotal link in this chain. In 2020, U.S. prosecutors charged two Chinese nationals for moving more than $100 million stolen in a 2018 exchange breach. In 2023, the U.S. Treasury’s sanctions office targeted two crypto traders—one based in Hong Kong and another in China—for facilitating the conversion of stolen assets and evading financial controls.

Links to other high-profile exploits

The analyst also connected Chinese actors to the laundering of proceeds from the September 2023 breach of the Bitget platform, which involved $387.5 million, as well as to funds from the Kelp DAO theft earlier that year, valued at $292 million. Public chat groups on Discord and Telegram were reportedly used by these operators to solicit assistance and coordinate transfers.

Why it matters

The findings highlight the enduring involvement of Asian crime networks in the global pipeline that turns illicit crypto into usable money. They also demonstrate the challenges regulators face in tracking assets that move through decentralized services and encrypted communication channels. Continued exposure of such pathways may prompt tighter enforcement actions and encourage the development of more robust tracing tools, which are essential for curbing the financing of illicit state-sponsored cyber activities.