ZachXBT Says He Infiltrated Chinese Crypto Laundering

Network Linked to Lazarus

Pseudonymous blockchain investigator ZachXBT says he spent months posing as a customer to infiltrate a Chinese organized-crime network that allegedly laundered more than $1 billion in crypto for North Korea-linked Lazarus Group.

According to his October 5 disclosure, the operation also helped identify more than $12 million in funds linked to the $1.5 billion Bybit hack, with 442,000 USDT later frozen by Tether. 

How the Undercover Operation Started

ZachXBT said he noticed more than 15 accounts in Telegram and Discord groups seeking assistance with transactions connected to the February 2025 Bybit exploit.

He eventually contacted an operator using the alias “Jimmy Green” and presented himself as a customer looking to exchange potentially flagged cryptocurrency for cleaner funds.

To build credibility, ZachXBT says he ultimately committed approximately $349,700 of his own USDC, accepting losses of about 5% on each transaction. 

Key Figures

Metric Reported figure
Funds ZachXBT says he committed ~$349,700
Alleged laundering volume $1B+
Bybit exploit ~$1.5B
Bybit-linked wallet cluster identified $12M+
USDT later frozen 442,000 USDT
DPRK-related freezes ZachXBT says he helped action since 2022 $75M+

Tracking the Bybit Funds

The investigation combined private conversations with public blockchain transactions.

ZachXBT said the operator provided wallet addresses and information about upcoming transfers. He then compared those details with on-chain transactions across Ethereum, Bitcoin, Solana and Tron.

In one example, information supplied by the operator reportedly matched a transaction routed through THORChain, helping connect the private communications with funds associated with the Bybit exploit. 

ZachXBT said the resulting investigation identified a cluster containing more than $12 million in Bybit-linked funds.

Tether Froze 442,000 USDT

One of the reported outcomes was the freezing of approximately 442,000 USDT connected to the wallet cluster.

ZachXBT said the intelligence was shared with private investigators and law-enforcement officials while the investigation was ongoing. He did not publish the details until October 2026, citing the sensitivity of the investigation.

A freeze does not necessarily mean the funds have been returned to victims. It prevents the identified tokens from being moved while further investigations or legal processes can take place.

Operator Allegedly Claimed Role in Bybit Laundering

According to ZachXBT's account, “Jimmy Green” claimed that his team had handled a substantial portion of the cryptocurrency stolen from Bybit.

ZachXBT said some of the operator's claims could be compared against blockchain activity, including transfers across multiple networks.

However, these statements remain allegations from the undercover investigation. Public reporting has not independently established the operator's real identity or confirmed the entire $1 billion-plus laundering figure.

Links to Other Crypto Hacks

The investigation also allegedly connected the network to funds from other major crypto incidents.

ZachXBT said the operator described laundering roughly $3 million in fraud proceeds, which he subsequently traced toward infrastructure associated with Huione Guarantee.

The investigation also reportedly identified connections to funds associated with the 2023 Poloniex hack, which has previously been linked by researchers and authorities to North Korean actors. 

Why Lazarus Remains a Major Crypto Threat

North Korea's Lazarus-linked hacking operations have become one of the crypto industry's largest illicit-finance concerns.

The FBI previously attributed the February 2025 Bybit theft to North Korean actors it tracks as TraderTraitor. The incident resulted in approximately $1.5 billion in stolen cryptocurrency.

More recent investigations have also continued to identify North Korean-linked activity targeting crypto exchanges and moving stolen assets across multiple blockchain networks. 

Blockchain Transparency Helped Trace the Funds

The case highlights an unusual advantage of public blockchains: although criminals can move assets through multiple networks, the transactions remain permanently recorded.

Investigators can combine:

  • Wallet addresses
  • Transaction timing
  • Transfer amounts
  • Cross-chain movements
  • Exchange deposit addresses
  • Private communications
  • Known illicit-wallet clusters

This can allow investigators to connect seemingly unrelated transactions and identify laundering patterns.

What Is Confirmed vs. Alleged?

It is important to separate the different claims surrounding the investigation.

Established background:

  • The Bybit hack occurred in February 2025.
  • The FBI attributed the theft to North Korean actors.
  • Blockchain investigators have traced portions of the stolen funds.
  • Tether can freeze USDT held at identified addresses.

Claims from ZachXBT's investigation:

  • The Chinese network laundered more than $1 billion for Lazarus.
  • “Jimmy Green” was involved in the network.
  • The group processed most of the Bybit funds.
  • ZachXBT's undercover work directly contributed to the 442,000 USDT freeze.

The latter claims have not been independently confirmed in full by law enforcement, according to reporting reviewed for this article. 

What Crypto Traders Should Watch

The investigation could have broader implications for crypto compliance and on-chain intelligence.

Key areas to watch include:

  • Further freezes of Bybit-linked assets
  • Law-enforcement identification of the alleged operators
  • Tether's response to additional wallet addresses
  • Movement of remaining Lazarus-linked funds
  • Cross-chain laundering methods
  • New sanctions or enforcement actions against crypto infrastructure

The case also demonstrates why stablecoins and cross-chain bridges remain important areas of focus for blockchain investigators.

FAQ

How much money did ZachXBT spend on the investigation?

He says he committed approximately $349,700 in USDC while posing as a customer. 

How much did the alleged network launder?

ZachXBT estimates the network processed more than $1 billion for Lazarus-linked operations. This remains an investigator's assessment rather than a publicly confirmed law-enforcement figure. 

How much Bybit-linked crypto was identified?

ZachXBT said his investigation identified a wallet cluster containing more than $12 million connected to the Bybit exploit. 

Did Tether freeze the funds?

ZachXBT says 442,000 USDT connected to the identified cluster was subsequently frozen. 

Final Take

ZachXBT's latest disclosure offers an unusual look inside the infrastructure allegedly used to move stolen cryptocurrency for North Korea-linked hackers.

The investigator says he risked nearly $350,000 to gain access to the network, eventually identifying a $12 million-plus Bybit-linked wallet cluster and helping facilitate freezes. The broader claim that the network laundered more than $1 billion for Lazarus, however, remains an allegation from the investigation and should not be treated as a final law-enforcement finding.