Summary
- ZachXBT disclosed he invested $349,700 USDC on March 6, 2025, accepting a 5% loss per transaction while pretending to be a client of a Chinese money laundering operation.
- This initiative revealed over $12 million in funds linked to a Bybit hack, leading to Tether freezing 442,000 USDT associated with the case.
- Since 2022, ZachXBT claims to have facilitated over $75 million in asset freezes related to incidents involving North Korea, funding his efforts through grants and donations.
Unlike most blockchain analysts who observe crypto thefts from the sidelines, the pseudonymous investigator ZachXBT actively engaged by sending $349,700 of his own capital to those involved in laundering stolen funds.
"By posing as a client, I gathered intelligence that enabled asset freezes related to the February 2025 Bybit exploit and tracked illicit activities on the blockchain," he stated on X. He identified the group as a Chinese criminal organization connected to North Korea.
Myriad: Predict Ethereum's next move.The exploit in question resulted in a staggering $1.5 billion loss for the crypto exchange Bybit, with the FBI attributing the incident to North Korean hackers known as TraderTraitor. ZachXBT noted that the alleged launderers were not particularly discreet.
ZachXBT is a prominent figure in the realm of on-chain investigations, having dedicated years to tracking down stolen cryptocurrency and identifying individuals behind scams and breaches. Despite facing legal challenges, including a lawsuit from a previous target in 2023, he has continued his efforts.
1/ How I infiltrated a Chinese organized crime syndicate that has laundered over $1 billion across multiple exploits for the Lazarus Group.
By posing as a client, I gathered intelligence that helped facilitate freezes related to the February 2025 Bybit exploit and attribute illicit activities on-chain. pic.twitter.com/jauRRt8875
— ZachXBT (@zachxbt) October 5, 2026
In February 2025, shortly after the Bybit hack, ZachXBT noticed a trend of over 15 accounts seeking assistance with orders directly linked to stolen funds in public Telegram and Discord groups.
He observed similar activity following the $387 million Bitget hack, which blockchain tracing firms and Bitget's CEO have also connected to North Korea.
ZachXBT's track record concerning North Korea is noteworthy. On the day of the Bybit breach, he used on-chain data to connect it to the Lazarus Group, a finding later corroborated by the FBI. His investigations also revealed that wallets utilized for laundering Bybit funds were associated with past Lazarus attacks, including those against Phemex and BingX.
His tracing of approximately 4,100 BTC stolen from a Genesis creditor in 2024 aided in arrests. In February 2025, he was hired by Paradigm as an incident response advisor, with co-founder Matt Huang stating he had successfully returned over $350 million to victims of scams and hacks. ZachXBT disclosed that he finances his work through grants and individual donations, allowing him to tackle more precarious investigations like this one.
In 2025, ZachXBT began communicating with accounts complaining about Bybit-related orders, one of which was identified as "Jimmy Green" on Telegram.
Screenshot of a conversation between ZachXBT and "Jimmy Green." Image: ZachXBT"On March 6, 2025, I funded a new address with 349.7K USDC on Ethereum to prepare for several transactions with Jimmy Green," he recounted. Jimmy provided an address to which the USDC was sent, in exchange for USDT on the Tron network.
ZachXBT noted that the address was funded by a wallet directly traceable to Bybit exploit funds, listed on the public blacklist for the Bybit exploit. He continued conducting transactions to build trust.
Eventually, Jimmy started discussing plans to transfer Bybit funds for North Korea, sharing basic operational details about their activities in Hong Kong and mainland China.
The evidence ZachXBT collected was compelling. He noted that one day before a planned fund transfer to Solana, the transaction occurred as predicted.
Realizing the financial risk involved, he acknowledged the potential for losing 5% on each order while gathering actionable intelligence rapidly.
"For this investigation, I invested $349.7K and incurred a 5% loss on each order, with the risk of Jimmy disappearing with the funds and the dangers associated with engaging the syndicate," he explained.
Jimmy remained persistent, reaching out frequently until ZachXBT feigned distrust in their business dealings. In response, Jimmy claimed, "the team has prepared $1 million and is ready to start work at any time!"
Screenshot of a conversation between ZachXBT and "Jimmy Green." Image: ZachXBTIn another exchange, Jimmy detailed the structure of their operation: "We have different divisions of labor. We take the u and distribute it to different acceptors." The "u" presumably refers to USDT, the stablecoin from Tether.
ZachXBT's investigations yielded results on-chain. On March 12, 2025, he matched a screenshot from Jimmy of himself transferring funds to an order created shortly after, corroborated by amounts and timing on the Thorchain explorer, a public record of swaps across blockchains.
Jimmy also shared three Solana addresses, revealing a network of over $12 million in Bybit stolen assets being exchanged in real-time, transitioning from Bitcoin to Ether, then to Solana, and finally to Tron. Subsequently, Tether froze 442,000 USDT linked to this network.
Jimmy provided verifiable information as well. He mentioned a team he knew had around $300K frozen in 2024, and ZachXBT successfully traced this to a freeze on-chain. The actual amount was 332,000 USDC, linked to the Poloniex exploit, a November 2023 hack that resulted in over $100 million stolen from the exchange, also attributed to North Korea's Lazarus Group.
The investigation also revealed connections to Cambodia. Jimmy mentioned laundering $3 million in fraud proceeds for another client, which ZachXBT traced to a hot wallet associated with Huione Guarantee, a marketplace on Telegram for laundering services and stolen data.
Huione Guarantee is part of the Huione Group, which has been targeted by the U.S. Treasury's FinCEN for allegedly laundering at least $4 billion. The marketplace was banned by Telegram in May 2025, and Chinese authorities arrested former Huione Group chairman Li Xiong after he was deported from Cambodia.
Not all discussions were focused on illicit activities. "During our conversations, Jimmy and I engaged in casual discussions alongside laundering topics," ZachXBT noted. "He shared personal stories about playing mahjong, hunting wild rabbits, family life, and vacations at Disney."
This investigation is not a standalone event. "Since 2022, I have assisted in facilitating over $75 million in asset freezes linked to North Korean incidents," ZachXBT stated. He emphasized that his findings were promptly shared with trusted private-sector investigators and law enforcement, and the sensitive nature of the investigation delayed his public disclosure.
