Loading market data...

ZachXBT Posed as Crypto Client to Infiltrate Chinese Laundering Syndicate Tied to $1B in Hacks

Blockchain investigator ZachXBT says he spent months posing as a cryptocurrency client to infiltrate a Chinese money-laundering syndicate that moved more than $1 billion tied to North Korea's Lazarus Group, including funds from last year's Bybit hack. He fronted 349,700 USDC on Ethereum to build trust with a contact using the alias Jimmy Green, then traded stablecoins back and forth while the contact volunteered details about moving stolen funds.

The investigation began after the February 2025 Bybit exploit, when ZachXBT noticed at least 15 accounts in public Telegram and Discord groups asking for help with orders he linked to stolen assets. On March 6, 2025, he funded a new Ethereum address with the USDC, setting up an arrangement where he sent his funds on Ethereum in exchange for the contact's USDT on Tron. He says he lost 5% on each order.

The trades that opened doors

The repeated exchanges were not just about moving money. According to ZachXBT, they led to private conversations about shifting funds stolen from Bybit, and the contact began discussing movements of those assets for North Korea before they happened. The talks also touched on operations in Hong Kong and mainland China.

The contact told him funds would move to Solana, and the transfer happened the following day. On March 12, 2025, the contact sent a screenshot of a cross-blockchain transfer. ZachXBT matched it to a THORChain transaction explorer order. That contact also supplied three Solana addresses, which exposed a cluster moving more than $12 million in Bybit exploit funds through Bitcoin, Ethereum, Solana and Tron.

Tether later froze 442,000 USDT linked to that cluster. ZachXBT also says the contact mentioned a team whose funds had been frozen in 2024, matching an on-chain freeze of 332,000 USDC tied to the Poloniex exploit.

What the FBI has confirmed

The FBI's public attribution is narrower than ZachXBT's full findings. In a Feb. 26, 2025 alert, the bureau said North Korea stole approximately $1.5 billion in virtual assets from Bybit on or about Feb. 21, calling the activity TraderTraitor. Some stolen assets were converted into Bitcoin and other virtual assets and dispersed across thousands of addresses on multiple blockchains, according to the FBI. The agency urged private-sector services to block transactions connected to the laundering addresses.

The syndicate's total haul and the links to Jimmy Green remain ZachXBT's findings, separate from the FBI's attribution of the theft itself. Allegations involving a Chinese over-the-counter trader surfaced in October 2024, but the full picture of the network described this week comes from the investigator's own tracing.

Funding for higher-risk work

ZachXBT said intelligence from these trades helped freeze funds tied to the Bybit exploit. He has appealed for continued foundation grants and individual donations to support higher-risk investigations, a model he has used before to keep independent tracing work going.

The public record now includes the FBI's TraderTraitor alert from February 2025 and ZachXBT's account of a months-long operation that ran from March 2025 into this year. What remains unresolved is whether law enforcement will act on the specific cluster and addresses he identified, and whether Tether's 442,000 USDT freeze is the last word on those funds or the start of a broader seizure effort.