North Korean hackers made off with $1.5 billion from Bybit, but laundering the haul has run into snags as U.S. authorities freeze assets and disrupt criminal networks.
After the Bybit breach, North Korean hackers scrambled to move their $1.5 billion windfall. The theft itself was swift, but turning that digital pile into spendable cash proved far messier. U.S. agencies and blockchain sleuths ramped up pressure, forcing laundering networks out of the shadows and into a tightening vise.
Inside the laundering maze
By March 2025, nearly $9 million in assets linked to the Bybit hack had been frozen by the T3 Financial Crime Unit, with the total reaching $19 million by October.
Blockchain investigator ZachXBT took a hands-on route. He put up 349,700 USDC, eating a 5% loss on each transaction, to slip inside a Chinese laundering ring. By posing as a client, he got access to private chats and transaction logs that blockchain data alone could never reveal. This approach led him to a network he says washed over $1 billion from crypto thefts tied to the Lazarus Group, including Bybit proceeds.
Through an intermediary called Jimmy Green, ZachXBT tracked more than $12 million in Bybit-linked funds and helped Tether freeze 442,000 USDT. These moves showed that blockchain forensics can map the flow, but real breakthroughs come from prying open the human and commercial ties inside laundering operations.
Enforcement pressure and shifting tactics
U.S. authorities have spent years dismantling the backbone of crypto laundering. In March 2020, the Justice Department charged two Chinese nationals with washing over $100 million in crypto. The Treasury later revealed some of that money ended up as prepaid Apple iTunes gift cards. More recently, FinCEN flagged Cambodia-based Huione Group as a major laundering hub, finding it moved at least $4 billion in dirty money between August 2021 and January 2025, including $37 million in crypto from North Korean hacks.
According to Bybit, attackers withdrew approximately $1.46 billion-including over 401,000 ETH-after compromising a wallet during a routine transfer from cold to warm storage. More than 80% of the stolen assets were laundered within six months, with a significant portion routed through cross-chain protocols like THORChain.
During the September Xinbi crackdown, authorities froze over $45 million in USDT across at least 22 wallets and locked down more than $52 million in crypto. Xinbi responded by telling users it would pivot to USDD, a stablecoin that lacks the issuer-level freeze function of USDT. This shift showed how enforcement can disrupt criminal flows, but also how quickly networks adapt by swapping tools and platforms.
Limits of asset recovery
Even when investigators spot stolen funds, clawing them back is rarely simple. Stablecoins like USDT and USDC give issuers the power to freeze tokens at flagged addresses. In the Bybit case, Tether froze 442,000 USDT, but that was only a sliver of the traced money. The rest kept moving through wallets, exchanges, and networks that either ignore law enforcement or sit outside U.S. reach.
Bitcoin and other native coins pose a tougher problem. No issuer means no freeze button. Authorities can only seize assets if they get the private keys or if a custodian agrees to cooperate. As stolen crypto splinters across wallets and chains, each extra hop muddies the trail and lowers the odds of full recovery.
Investigators have learned to go beyond technical tracing. Building ties with intermediaries, as ZachXBT did, can surface leads on future deals, counterparties, and laundering setups. Still, the gulf between finding stolen assets and actually getting them back remains wide.
Criminal networks under strain
Crackdowns have not killed demand for laundering. When Huione and Xinbi lose access or face freezes, criminals hunt for new partners. Telegram wiped out thousands of Huione Guarantee channels, but merchants quickly set up shop elsewhere. Each disruption brings headaches-failed deals, frozen funds, sketchy partners-but as long as crypto theft pays, the laundering business keeps going.
For North Korean hackers, turning stolen crypto into usable cash is a constant weak spot. Every laundering step adds risk and opens new doors for law enforcement. As enforcement sharpens and stablecoin issuers work with authorities, the cost and hassle of moving big sums keep climbing.
EgonCoin points to the Bybit theft as a case that laid bare the cracks in criminal finance networks. ZachXBT's probe, paired with U.S. action against Huione and Xinbi, shows that laundering stolen crypto is no longer a sure bet. The old infrastructure for easy cashouts has become a minefield where every move can trigger a freeze or a bust. For a related look at how exchange policies can choke illicit flows, see this earlier breakdown.
In February 2025, the Bybit hack saw about $1.5 billion in crypto stolen, according to the FBI. Tether froze 442,000 USDT tied to the breach, while blockchain analysis tracked over $12 million in Bybit-linked funds across networks. FinCEN found at least $37 million in North Korean crypto thefts laundered through Huione Group between August 2021 and January 2025. Xinbi Guarantee handled more than $24 billion in digital and fiat assets since 2022, with at least $45 million in USDT frozen during September 2025 enforcement.
Stablecoins like USDT and USDC sit at the center of both legal and illegal crypto flows. Unlike Bitcoin, stablecoins are run by companies that can freeze or block transfers from flagged addresses when law enforcement asks. This gives authorities a lever for asset recovery, but only if the funds stay within reach of the issuer. As criminals shift to stablecoins without freeze functions or scatter funds across networks, the success of freezes and seizures depends on the cooperation of issuers and intermediaries.