In a daring undercover operation, blockchain investigator ZachXBT has exposed a sophisticated money laundering network with ties to North Korea’s notorious Lazarus Group. His findings, detailed in a thread on X, highlight the alarming extent of crypto-related crime and the lengths to which investigators must go to uncover the truth.
Beginning in February 2025, just days after the Bybit hack, ZachXBT posed as a client in a Chinese organized crime syndicate, investing $349,700 in stablecoins to infiltrate the network. His commitment to the operation was both strategic and costly, as he accepted a 5% loss on each trade to build trust with an operator known only as Jimmy Green.
Inside the Laundering Operation
ZachXBT described the network as a sprawling operation that spanned Hong Kong and mainland China, allegedly laundering over $1 billion across multiple exploits for Lazarus Group. The operator provided insights that revealed the extent of the network’s involvement in moving funds stolen from various crypto exchanges, including Bybit.
His first clue emerged from a trade route, where a receiving wallet was funded by an address already blacklisted by Bybit. This led to a series of conversations that allowed ZachXBT to match illicit fund movements with public blockchain transactions, gathering critical intel on the laundering process.
In a key moment, the operator shared screenshots of a transaction involving the swap of 1.192 Bitcoin for 51.73 Ether, which ZachXBT was able to trace back to a THORChain transaction linked to the Bybit funds.
Tracing Wallets and Freezing Funds
As the operation progressed, ZachXBT uncovered three Solana addresses holding over $12 million in funds linked to Bybit. This significant discovery prompted Tether to freeze 442,000 USDT associated with these wallets—a move confirmed by Tether’s T3 Financial Crime Unit.
By October 2025, Tether had frozen a total of $19 million related to the Bybit theft, although the specific figure of 442,000 USDT had not been publicly disclosed prior to this revelation. ZachXBT’s findings also pointed to other hacks, including funds from the 2023 Poloniex breach and a batch related to Huione Guarantee.
The FBI had attributed the Bybit hack to North Korea shortly after the attack, identifying the perpetrators as TraderTraitor, who reportedly stole around $1.5 billion in assets. Bybit acknowledged that compromised credentials from a developer were exploited to facilitate the breach.
Throughout the operation, ZachXBT maintained communication with investigators and law enforcement, strategically waiting until October 2026 to publish his findings due to the sensitivity of the case. While public records from the FBI, Treasury, and Tether have yet to confirm the identity of Jimmy Green, the details shared by ZachXBT paint a grim picture of the intersection between crypto crime and organized international hacking.
As Chainalysis reports that North Korean hackers stole $2.02 billion in cryptocurrency during 2025, the implications of this investigation extend beyond just financial losses. They underscore the urgent need for enhanced security measures and international cooperation to combat the rising tide of crypto-related crime.
