ZachXBT Reveals Involvement of Chinese OTC Trader in Lazarus Cyber Attacks

23

On October 23, blockchain investigator ZachXBT disclosed on X that Chinese over-the-counter (OTC) trader Yicong Wang, who operates under various pseudonyms such as ‘Seawang,’ ‘Greatdtrader,’ and ‘BestRhea977′, has been assisting North Korea’s infamous Lazarus Group in laundering millions of dollars in illicit cryptocurrency.

ZachXBT’s probe revealed that Wang has been engaged in crypto laundering since 2022, converting it into cash via bank transfers.

ZachXBT Strikes Again: Unmasking Chinese OTC Trader’s Connection to Lazarus Hacks

The investigation into Wang’s unlawful activities commenced when a trader reported that their account had been frozen after a peer-to-peer transaction with Wang. Further inquiry connected Wang to numerous stolen assets, including cryptocurrency from significant hacks.

Importantly, $17 million from over 25 Lazarus-related hacks was funneled through an Ethereum address, which was partially blacklisted by Tether in November 2023, resulting in the freezing of 374,000 .

1/ Meet Yicong Wang (王逸聪), a Chinese OTC trader who has helped Lazarus Group convert tens of millions of stolen crypto to cash from various hacks via bank transfers since 2022. pic.twitter.com/ARcwC7r3Xr

— ZachXBT (@zachxbt) October 23, 2024

Following the blacklisting, the remaining assets were laundered through Tornado Cash, where substantial amounts of were subsequently withdrawn and aggregated into another wallet.

In December 2023, $45,000 was transferred to Tron and distributed across several addresses directly associated with Wang. His wallet activity indicates extensive ties to Lazarus Group operations, including breaches of prominent crypto projects such as Alex Labs, Irys, EasyFi, and Bondly.

From Paxful Ban to Offsite Operations: How Wang Stays in the Game Despite Crackdowns

Wang’s wallet was linked to the $4.5 million hack of Alex Labs in May 2024, one of many assaults executed by Lazarus Group. Blockchain data also indicated that Wang facilitated the transfer of stolen cryptocurrency associated with other breaches, including those involving Irys co-founder, EasyFi, Bondly, and Maverick.

“While Yicong Wang has been banned from Paxful and Noones on multiple accounts (Seawang/Greatdtrader/BestRhea977) for laundering funds, he has since moved to conducting business offsite,” ZachXBT noted. “It’s evident from on-chain data that he has continued to actively assist Lazarus Group in recent weeks.”

The Lazarus Group, linked to North Korea, has been associated with numerous high-profile , including the $625 million breach of the Ronin blockchain.

In early September, the United States Federal Bureau of Investigation (FBI) issued a warning regarding the North Korean hacker group Lazarus, which has resorted to sophisticated social engineering tactics to target decentralized finance () and cryptocurrency firms.

According to the FBI’s alert on September 3, these malicious actors pilfered funds by conducting thorough research on cryptocurrency-related exchange-traded funds (ETFs).

ZachXBT previously reported that between 2020 and 2023, the Lazarus Group laundered over $200 million from more than 25 crypto-related hacks.

Lazarus is recognized as one of the most notorious groups of crypto hackers. It first emerged in 2009 and has stolen over $3 billion in crypto assets in the six years leading up to 2023.

The post ZachXBT Exposes Chinese OTC Trader’s Role in Lazarus Hacks appeared first on Cryptonews.