ZachXBT Sting and Bitget Laundering Trace Expose Lazarus-Linked Crypto Network

52 minute ago 2 sources negative

Key takeaways:

  • RUNE’s fee reliance on hack laundering raises regulatory scrutiny for THORChain’s liquidity providers.
  • Repeated Tether freezes may deter illicit flows but also highlight stablecoin centralization risks for traders.
  • Watch exchange compliance news as Lazarus laundering across BTC, ETH, SOL, TRX pressures sentiment.

Independent blockchain tracing has exposed new details about how funds stolen in two major cryptocurrency exchange hacks were laundered across multiple chains, while one researcher’s undercover operation linked a Chinese network to North Korea’s Lazarus Group.

Research shared by Andrey Sergeenkov on Oct. 6 found that protocols and services used to move funds from the $387.5 million Bitget hack collected $761,725 in fees. THORChain liquidity providers received $573,226, MetaMask collected $149,417, Chainflip received $26,751 and CoW EthFlow received $12,332. Sergeenkov separately traced $259,718 in THORChain affiliate fees to seven addresses with additional financial links to wallets involved in the stolen fund swaps. The largest linked address received $177,499, with part of the RUNE fee income later converted to USDT and eventually transferred to an address labeled as an OKX hot wallet. Another $206,196 went to affiliate recipients without established links. The analysis followed the Sept. 24 theft from Bitget’s hot and warm wallets.

In a separate investigation, ZachXBT said he spent 349,700 USDC posing as a paying client to infiltrate an alleged Chinese money-laundering network that moved more than $1 billion for North Korea-linked hackers. The operation helped trace more than $12 million in Bybit-linked funds moving across Bitcoin, Ether, Solana and Tron, and prompted Tether to freeze 442,000 USDT. The February 2025 Bybit theft was valued at about $1.46 billion, including 401,347 ETH, and the FBI attributed it to North Korean actors tracked as TraderTraitor. ZachXBT said an operator known as 'Jimmy Green' sent a screenshot matching a THORChain swap that traced back to Bybit-linked funds and later claimed that almost all of the 1.5 billion ETH was laundered by their team.

Tether’s public records show larger freezes tied to Bybit, including nearly $9 million announced by the T3 Financial Crime Unit in March 2025 and $19 million in T3-related cases by October 2025, but do not break out the 442,000 USDT figure. ZachXBT also linked the contact to other illicit flows, including 332,000 USDC from the 2023 Poloniex hack and $3 million associated with Huione Guarantee. Chainalysis said on Oct. 1 it was working with Bitget and law enforcement after the September 2026 theft, which pushed North Korea-linked crypto thefts above $1 billion in 2026.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.