ZachXBT, the pseudonymous blockchain investigator, has published an account of posing as a customer of a Chinese organised crime network he alleges launders stolen cryptocurrency for North Korea's Lazarus Group.

Everything that follows is his account. He works under a pseudonym, the figures are his, and no court or agency has tested them. That is worth stating once at the top rather than hedging every sentence afterwards.

How he found it

He says he started after noticing a pattern: more than 15 accounts across Telegram and Discord groups asking for help with orders tied to stolen funds, in the period after the February 2025 Bybit exploit that took about 1.5 billion dollars.

Rather than watch, he became a client. He funded a new Ethereum address with 349,700 USDC and placed orders through a vendor using the pseudonym Jimmy Green, with, in his words, no guarantee the counterparty would not simply disappear with the money.

That is the part worth pausing on. The intelligence here was bought, at personal risk, by one person with their own capital.

The fee is the finding

He reports losing roughly five percent per order.

Five percent is the price of turning stolen cryptocurrency into clean cryptocurrency at volume, and it is the single most useful number in the account, because it describes an industry rather than an incident.

Run it against the figures. If the network handled the amounts he alleges — more than a billion dollars across multiple Lazarus operations, including most of the 1.5 billion from Bybit — then the laundering service earned something in the order of tens of millions of dollars in fees. Not a favour between criminals. A business with a margin, a customer service channel and a rate card.

It also sets the recovery problem. Freezing stolen funds competes with a counterparty who is paid promptly, in volume, to move them faster. Five percent is what the defenders are bidding against.

What the access produced

He says the orders let him map a cluster of more than 12 million dollars in Bybit-linked funds, swapped across Bitcoin, Ethereum, Solana and Tron, and that the information contributed to freezing 442,000 dollars in USDT from it. He puts the total frozen in connection with North Korean incidents since 2022 at around 75 million.

One detail carries the credibility of the rest: he describes the vendor saying a day in advance that funds would move to Solana, and the funds moving to Solana the next day. Knowing the route before it happens is the difference between watching a chain and being inside the operation.

Set the two numbers beside each other, though. He fronted 349,700 dollars. The freeze attributed to this work was 442,000. The margin between what an investigator risks and what the public recovers is thin enough to be uncomfortable, and nothing about that arrangement is funded by anyone with a mandate.

Who is doing this work

That is the uncomfortable finding underneath the headline.

The capability on display — noticing a pattern in chat groups, posing as a buyer, funding it personally, tracing across four blockchains, and getting an exchange to act — belongs to a pseudonymous individual rather than to an agency. It is unpaid and self-financed, it accepts legal and personal risk that an institution would never sign off, and it is not reproducible by anybody with a compliance department.

It also sits in genuinely awkward territory. Paying a laundering service, even to understand it, is transacting with the thing being investigated, and nothing in the account suggests a legal authority sanctioned it. Those questions do not make the findings less real; they make the model unrepeatable.

What this all funds is the same machinery we wrote about last week, when Google documented North Korean operators hiding malware in smart contracts to steal from developers and crypto firms. The theft and the laundering are one pipeline, and the second half is a commercial service with a published rate.

What to do

  • If you run an exchange or a custodian, the actionable part is speed. Freezes work when they arrive before the next hop, and this account describes a counterparty that moves within a day.
  • Treat chat-group intelligence as a real source. The network advertised itself in Telegram and Discord, which is where it was found.
  • Do not copy the method. Funding a laundering service to study it is not a technique anyone with an employer should imitate.
  • For everyone else, the lesson is upstream. This service exists because the thefts succeed, and the thefts mostly start with a developer being phished.

What is not established

  • Whether any of it is accurate beyond ZachXBT's own reporting. None of it has been tested in court, and no agency has confirmed his figures.
  • Who the network actually is. Jimmy Green is a pseudonym attached to a vendor, not an identified person or organisation.
  • Whether the alleged billion-plus is one network or several he has grouped together.
  • What law enforcement has done with the information, beyond the freezes he describes.