Independent DeFi security desk · Status: operationalMethodology & corrections · Submit an incident
DeFi Safety · Fact checked

Chinese crime network laundered over $1B for Lazarus: ZachXBT

ZachXBT says he infiltrated the network by posing as a customer, gaining information that helped trace funds from the $1.5 billion Bybit hack.

This article may contain affiliate links. Commercial relationships are disclosed in the affiliate policy.

DeFi Safety — illustration keyed to this article's identifier. Source documents are listed under Sources and are not reproduced here.

What happened

ZachXBT says he infiltrated the network by posing as a customer, gaining information that helped trace funds from the $1.5 billion Bybit hack.

Reported details

  • ZachXBT says a $349,700 undercover operation exposed an alleged $1B Lazarus laundering network and helped trace $12M in Bybit funds.

Why this matters

Chinese is an infrastructure change, not a market event: the thing to verify is whether the underlying record moved, or only the wrapper around it. A tokenized claim is unchanged if the ledger, custodian, and redemption terms are unchanged, however the announcement is framed.

Evidence boundary

The scope is limited to what the linked reports state, and where two of them diverge both positions are recorded without either being picked in advance.

What to verify

Verify Chinese on the chain: the deployed contract address and version, and whether the ledger of record changed or only the interface that reads it.

Sources and editorial check time

This information is educational and is not financial, legal, or tax advice.

Sources