CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

ZachXBT Infiltrates Lazarus Laundering Network: AML Lessons for Firms

CryptaCount Editorial · · 8 min read
AML / KYC / LICENSING ZachXBT Infiltrates Lazarus LaunderingNetwork: AML Lessons for Firms

On-chain investigator ZachXBT has published details of an undercover operation in which he posed as a money-laundering client to gather intelligence inside a Chinese organized crime syndicate believed to have processed over one billion dollars in crypto for North Korea's Lazarus Group. The findings have already produced real enforcement outcomes: funds linked to the $1.5 billion Bybit hack were frozen, and transactions were connected to Huione Guarantee, a sanctioned criminal conglomerate. For accounting firms, auditors, and CFOs with digital asset exposure, the episode is a live-fire demonstration of how illicit flows actually move across chains and what that means for compliance programs right now.

ZachXBT Infiltrates Lazarus Laundering Network: AML Lessons for Firms

How the Undercover Operation Unfolded

The investigation began after ZachXBT identified Chinese Telegram and Discord accounts actively recruiting help to launder proceeds from September's $387 million Bitget hack. He made contact with one operator, referred to as "Jimmy Green," and presented himself as a prospective laundering client.

The mechanics of the engagement

To maintain cover and gather usable intelligence, ZachXBT sent real funds to Jimmy Green across multiple transactions. He reports fronting close to $350,000 in total, with each order carrying a five percent fee that he knew he would lose. He acknowledged there was no guarantee Jimmy Green would not simply disappear with any given transfer, and that dealing directly with the syndicate carried an unquantifiable personal risk. Those are not small trade-offs, and they underscore how seriously he treated the operation.

During the engagement, Jimmy Green disclosed that his team was responsible for laundering the majority of funds stolen in the $1.5 billion Bybit hack, which took place in 2025. He also described the use of THORSwap as a bridging mechanism, referencing specific exploiter addresses in the process. That level of operational detail, volunteered in what the syndicate apparently assumed was a private business conversation, gave investigators a thread they could pull.

Connecting the syndicate to known enforcement targets

The intelligence ZachXBT collected was subsequently shared with private investigators and law enforcement. It contributed directly to freezing funds tied to the Bybit hack. Separately, when Jimmy Green mentioned laundering three million dollars for another client, ZachXBT was able to trace those funds to Huione Guarantee, a sanctioned conglomerate that regulators have identified as operating a multi-billion-dollar criminal marketplace. He also linked a $100,000 freeze targeting Jimmy Green's transactions, which occurred in 2024, to the $100 million hack of the Poloniex exchange. Each connection reinforces how a single node in a laundering network can carry forensic fingerprints pointing to multiple prior offences.

What the Syndicate's Methods Reveal About On-Chain Risk

The operational picture that emerges from ZachXBT's account is instructive for anyone building or auditing a digital asset compliance program. Several patterns stand out.

Cross-chain bridging as an obfuscation layer

The use of THORSwap to move funds between chains is a deliberate friction-reduction strategy. Cross-chain bridges complicate transaction-monitoring because the originating chain's history does not automatically follow the asset to the destination chain. Standard screening tools that work well within a single blockchain ecosystem can lose the trail at a bridge hop. This is not a theoretical gap; it is the method a billion-dollar laundering operation was actively using.

Recruitment through open messaging platforms

The syndicate was openly advertising on Telegram and Discord for laundering clients. That accessibility cuts both ways: it made it possible for ZachXBT to make contact, but it also means that any business interacting with counterparties found through those channels faces a genuine sanctions exposure risk. Enhanced due diligence on counterparties discovered via encrypted or pseudonymous messaging platforms is not a nice-to-have; at this scale of criminal activity, it is essential.

The five percent fee as a red flag

A consistent five percent haircut on each transaction is precisely the kind of structured fee pattern that should trigger suspicion in a well-calibrated transaction-monitoring system. When a counterparty consistently accepts a fixed loss on outgoing transfers with no apparent commercial rationale, that pattern warrants investigation. Firms whose crypto accounting software or bookkeeping workflows are not configured to flag recurring fee structures like this are leaving an obvious signal unread.

AML and Accounting Implications for Firms

ZachXBT's operation is, in effect, a privately funded stress test of the laundering infrastructure surrounding some of the largest crypto thefts on record. The results have direct consequences for how accounting firms and CFOs should approach their digital asset compliance obligations. For context on how AI-driven tracing connected the Bitget hack to North Korea in the first place, see our earlier coverage of how AI-driven tracing connected the Bitget hack to North Korea.

Sanctions screening must extend to counterparty networks

Huione Guarantee appearing in this chain is a reminder that sanctions exposure does not always arrive through a direct transaction with a listed entity. Funds can pass through multiple intermediaries before a sanctioned party's wallet appears in the trail. Under US Office of Foreign Assets Control rules, strict liability applies to sanctions violations regardless of whether the firm knew the ultimate counterparty was listed. That standard demands screening that looks beyond the immediate transaction and considers the broader counterparty graph.

Transaction monitoring needs cross-chain coverage

If your transaction-monitoring program stops at the boundary of one blockchain, it has a structural gap that this case illustrates clearly. Any digital asset accounting software or compliance stack deployed by a firm handling client crypto assets should be capable of following a transaction across bridge hops and flagging activity linked to known illicit addresses on the destination chain, not just the origin.

The CFO's disclosure and reporting duty

For CFOs at businesses holding digital assets on the balance sheet, the question is not only whether their own transactions are clean. Auditors are increasingly asking how management has satisfied itself that counterparties and custodians are not connected to illicit networks. A robust audit trail, supported by reliable crypto bookkeeping software that logs counterparty wallet data at the time of each transaction, will become a baseline expectation. The inability to produce that audit trail when a regulator or auditor asks is itself a compliance failure.

Law enforcement collaboration and information-sharing obligations

ZachXBT explicitly noted that he delayed publishing his findings because of ongoing sensitive investigations with private investigators and law enforcement. That sequencing reflects a principle that compliance-oriented firms should internalize: when suspicious activity is identified, the relevant Suspicious Activity Report must be filed, and further disclosure should be managed in coordination with legal counsel and, where appropriate, law enforcement, rather than disclosed publicly in a way that compromises an investigation. The Bank Secrecy Act's tipping-off prohibition is the statutory framework here for US-based firms.

For a broader view of how international regulators are tightening the screws on crypto-linked sanctioned entities, the analysis of Japan's Garantex sanctions and what they mean for compliance teams is worth reading alongside this case.

Practical Steps for Compliance and Finance Teams

The ZachXBT investigation does not create new legal obligations, but it does surface specific operational weaknesses that regulators and auditors are likely to scrutinize more closely in its wake.

Immediate actions to consider

First, review whether your transaction-monitoring solution tracks assets across cross-chain bridge transactions. If it does not, that gap should be raised with your compliance technology provider or documented in your risk register with a remediation timeline. Second, audit your counterparty onboarding process for clients or business partners identified through Telegram, Discord, or similar channels. The syndicate in this case was operating openly on those platforms. Third, confirm that your sanctions screening database is updated at a frequency appropriate for the pace at which OFAC and equivalent bodies designate new addresses. Static lists that are refreshed monthly are not adequate for real-time transaction environments. Finally, verify that your crypto accounting software captures and retains wallet-level counterparty data at the point of each transaction. A record that shows only a net balance movement, without the on-chain address from which funds originated, will not satisfy a detailed AML examination.

ZachXBT Infiltrates Lazarus Laundering Network: AML Lessons for Firms

Frequently Asked Questions

What is the Lazarus Group and why does it matter for accounting firms?

The Lazarus Group is a state-sponsored hacking collective attributed by US and allied government agencies to North Korea. It has been linked to several of the largest crypto thefts on record. Firms that transact with counterparties connected to Lazarus-linked wallets face strict-liability sanctions exposure under OFAC rules, meaning intent is not a defence.

What is Huione Guarantee and is it currently sanctioned?

Huione Guarantee is a conglomerate that regulators have identified as operating a large-scale criminal marketplace facilitating fraud, money laundering, and other illicit activity. It has been the subject of sanctions designations. Firms should ensure it and its associated wallet addresses appear in their screening lists and that any historical transactions are reviewed for potential exposure.

Does THORSwap's involvement create liability for firms that have used it?

Using a cross-chain bridge protocol is not inherently a sanctions violation. Liability arises when a firm transacts with a counterparty that is itself designated, or when funds can be traced to a sanctioned source. The key obligation is to conduct adequate due diligence and screening at the time of each transaction, and to retain the records that would allow that screening to be evidenced later.

What should a firm do if it discovers a historical transaction linked to a now-sanctioned address?

The firm should consult legal counsel immediately. In the US, a voluntary self-disclosure to OFAC is generally treated as a significant mitigating factor. The firm will also likely need to file a Suspicious Activity Report with FinCEN under the Bank Secrecy Act. Documentation of the discovery process and the remediation steps taken is critical.

How does this case affect the AML program review cycle for crypto firms?

Cases like this one are the kind of typology that regulators use to update examination guidance. Firms should treat this as a signal to bring forward any scheduled review of their transaction-monitoring rules, particularly those covering cross-chain activity and counterparties operating through encrypted messaging platforms. Documenting that review, and any rule changes made, demonstrates a proactive compliance posture.

Source: Protos

GLOBALUSGeneralEnforcementAML/KYC & Licensing

Related articles

AML/KYC & Licensing
Treasury Sanctions Hamas Crypto Fundraising Network Spanning Europe and Gaza
AML/KYC & Licensing
Japan Sanctions Garantex: What Firms Need to Know
AML/KYC & Licensing
AI, Terrorism, and Crypto Financing: What Firms Must Know
AML/KYC & Licensing
OFAC Sanctions Tren de Aragua Crypto Laundering Network