mt logoMyToken
ETH Gas
Tiếng việt

ZachXBT Exposes Chinese Criminal Network Laundering Over $1 Billion for North Korea's Lazarus, Linked to Stolen Bybit Funds

sưu tầmcollect
đăng lạishare

According to Cointelegraph, on-chain investigator ZachXBT has disclosed that a Chinese criminal network laundered more than $1 billion in crypto assets for North Korea's Lazarus organization, with the funds linked to the $1.5 billion theft from Bybit exchange. After the disclosure, the incident was classified as a major security and compliance event, drawing high industry attention. The disclosure does not point to a single on-chain transfer or an ordinary hacking attack; rather, it connects key elements such as the Chinese criminal network, the Lazarus organization, and the stolen Bybit funds, expanding the case from an exchange theft to the level of money laundering networks and compliance risk.

In terms of parties involved, the incident involves at least four key roles. ZachXBT is the main source of the disclosure, and his investigation forms the current information basis; the Chinese criminal network is alleged to provide money laundering services for North Korea's Lazarus; North Korea's Lazarus organization is linked to the $1.5 billion Bybit hack; and Bybit is drawn into the related money laundering investigation narrative because of the stolen funds. Although the roles of the parties have been made public, the specific organizational structure, personnel composition, and operational details have not yet entered the public information domain.

The core amounts currently confirmed include two: first, the Chinese criminal network laundered more than $1 billion for North Korea's Lazarus; second, the incident involves the $1.5 billion Bybit hack. Both amounts point to the same type of risk: funds obtained from hacking may be laundered through specific networks, and the stolen Bybit funds are part of this linked chain. It should be emphasized that public information does not specify the exact proportional relationship between the more than $1 billion laundered and the $1.5 billion stolen from Bybit; it can only be confirmed that the two are related.

Against the case background, ZachXBT's disclosure places multiple entities within the same security and compliance event. The Chinese criminal network is alleged to play the role of money laundering service provider, North Korea's Lazarus is alleged to be the party demanding money laundering services, and the stolen Bybit funds become a related funding clue. This structure indicates that the flow of funds after crypto assets are stolen is not an isolated step and may involve a more complex cross-border money laundering network. For the industry, the focus is no longer limited to the Bybit case itself; it also includes on-chain fund tracing, exchange risk control, anti-money laundering reviews, and compliance cooperation among different jurisdictions.

In terms of security impact, the incident is classified as a major security and compliance event and has drawn high industry attention. From an industry observation perspective, its potential impact is reflected at least at three levels. First, the link between the $1.5 billion Bybit hack and the Lazarus money laundering network may increase the complexity of handling stolen exchange funds; relevant parties need to more fully identify fund flow paths and face more participants and cross-border steps in the recovery process. Second, ZachXBT's disclosure involves a Chinese criminal network, indicating that money laundering services may be carried out through networks in multiple locations, increasing the difficulty of cross-border tracing and compliance reviews. Third, the more than $1 billion money laundering scale and the $1.5 billion hack amount mirror each other, reflecting the pressure the crypto industry faces in anti-money laundering, on-chain monitoring, and cross-border compliance. The above judgments are industry observations and do not constitute additional factual findings or determinations of responsibility for any entity.

From the boundary of public information, more specific transaction addresses, fund paths, individuals involved, judicial progress, institutional responses, or timelines have not yet been disclosed. Reporting on the incident should be strictly limited to the disclosed scope. Confirmed content includes: ZachXBT exposed that a Chinese criminal network laundered more than $1 billion for North Korea's Lazarus; the related funds involve stolen Bybit funds; the incident links the $1.5 billion Bybit hack with the Lazarus money laundering network; and the incident is classified as a major security and compliance event with high industry attention. Beyond that, inferences about the final destination of funds, behind-the-scenes organizational division of labor, or regulatory penalties still lack public basis. This information boundary itself also shows that crypto security incidents often require cross-source and cross-institution information piecing together; a single-point disclosure can only present part of the picture, and subsequent updates may change the current understanding of the case scope.

For exchanges and compliance departments, the stolen Bybit funds and the Lazarus money laundering network have been placed within the same incident framework, and ZachXBT's disclosure provides a connecting point. From an industry observation perspective, such incidents will strengthen the need to review the flow of stolen funds; money laundering allegations involving Lazarus and a Chinese criminal network will raise anti-money laundering attention; and for the on-chain analytics industry, ZachXBT's exposure has an information-triggering effect and may drive further screening of related address clusters and fund paths. The above impacts are based on descriptions of the nature of the incident and do not involve judgments about specific institutional operations or market prices.

Directions to watch going forward include: whether ZachXBT's disclosure prompts follow-up from more independent sources; whether the link between the stolen Bybit funds and the Lazarus money laundering network is further confirmed; whether more public information emerges on the specific role of the Chinese criminal network in the money laundering chain; and how the industry will respond at the security and compliance levels. Before public information is further updated, objective tracking should be maintained, and unconfirmed information should not be treated as established fact. The incident already has the basic characteristics of a major security and compliance event, and subsequent developments will continue to affect market attention to exchange risk control, on-chain tracing, and anti-money laundering cooperation.

Tuyên bố từ chối trách nhiệm: Bản quyền của bài viết này thuộc về tác giả gốc và không đại diện cho MyToken(www.mytokencap.com)Ý kiến ​​và vị trí; vui lòng liên hệ với chúng tôi nếu bạn có thắc mắc về nội dung
community_x_prefix
X(https://x.com/MyTokencap)
community_tg_prefixcommunity_tg_name
(https://t.me/mytokenGroup)
Đọc liên quan