Blockchain investigator ZachXBT spent months posing as a scammer on Telegram to get inside a Chinese money-laundering crew that he says handled most of the $1.5 billion stolen from Bybit in February 2025 — a haul tied to North Korea. He fronted $349,700 of his own money for the operation and collected a 5% fee on every order, meaning the people he was investigating were paying him.
The evidence he gathered helped authorities freeze funds and attribute the Bybit flows. The public thread landed 19 months after the hack because he handed everything to private investigators and law enforcement first.
How the cover story worked
ZachXBT's entry point was a simple, ugly problem: he told the crew he had marked ETH from the privacy tool Railgun that needed to become clean USDT on Tron. That's a common headache for launderers, and the crew bought it.
One of the launderers used the alias "Jimmy Green" and posted a stuck transaction in THORChain's 10,845-member community chat. Jimmy Green's Telegram bio advertised processing of flagged BTC, ETH, SOL and TRX through a mixing service — a fairly open pitch for a business that lives or dies on not being noticed. His account carried a US phone number with a Virginia area code.
Jimmy Green quoted the going rate: 5%. An early test order came back as 23,750 USDT, a 5% haircut on $25,000.
Brags, wallets, and a trip through Solana
The launderer wasn't shy. He referred to Kim Jong-un by name, treating the North Korean leader like a moody supplier. He claimed his team had washed almost all of Bybit's $1.5 billion in ETH — though that figure remains his own claim, not a verified number.
More useful for investigators were the times he announced what North Korea's work would involve. He said it would start "tomorrow" and that Bitcoin would return to Solana. The next day, funds moved to Solana.
On March 12, 2025, Jimmy Green sent a screenshot of himself bridging 1.192 BTC into ETH. ZachXBT matched it to a THORChain order created minutes later. That kind of sloppy timing is exactly what sinks these operations.
Jimmy Green also handed over three Solana addresses. Those exposed a cluster of $12 million or more in Bybit funds cycling through BTC, ETH, SOL and Tron. Tether later froze 442,000 USDT linked to that cluster.
He mentioned a team with around $300,000 frozen in 2024. ZachXBT found it on-chain: 332,000 USDC from the Poloniex exploit. A separate brag about washing $3 million in fraud proceeds led to a hot wallet at Huione Guarantee, the Cambodian marketplace that has since been sanctioned and whose former chairman was arrested.
The human details that gave him away
Jimmy Green sent photos of meals, asked if ZachXBT could play Chinese mahjong, and shared personal details. One photo showed his phone displaying a wallet holding about 1.2 million USDT, with a laptop behind it running Google Translate.
ZachXBT identified 15 or more accounts in public Telegram and Discord groups seeking help with orders tied to stolen funds. The crew wasn't hiding in dark corners — it was asking for business in open channels.
Why the thread is late — and what's next
The Bybit hack happened in February 2025. The full account went public only this week because ZachXBT chose to route it to private investigators and law enforcement before publishing. That's a 19-month gap between the theft and the public reckoning, and it explains why some of the trail has already been cleaned up — or frozen.
What's unresolved is how much of the $1.5 billion actually moved through this specific crew. Jimmy Green's claim that his team handled nearly all of it is just that: a claim from a man who wanted to look big. The verified pieces are narrower — the frozen 442,000 USDT, the $12 million cluster, the 332,000 USDC linked to Poloniex. Law enforcement hasn't said whether the Virginia number or the "Jimmy Green" alias has led to a real identity.




