TL;DR
- ZachXBT infiltrated a Chinese criminal network that laundered over $1 billion in stolen funds linked to North Korea’s Lazarus Group.
- The investigator risked $349,700 in USDC by posing as a client, losing 5% per transaction with no guarantee of recovering the funds.
- The undercover operation allowed frozen funds from the February 2025 Bybit hack to be traced across multiple blockchains.
Onchain investigator ZachXBT revealed that he infiltrated a Chinese criminal network linked to North Korea’s Lazarus Group, posing as a client to gather intelligence that allowed frozen funds from the February 2025 Bybit hack — valued at $1.5 billion — to be identified.
The undercover operation began when ZachXBT detected more than 15 accounts in public Telegram and Discord groups soliciting help to process orders directly linked to the stolen funds.
On March 6, 2025, the investigator funded a new Ethereum address with 349,700 USDC to execute multiple transactions with a vendor operating under the pseudonym “Jimmy Green.” Jimmy’s receiving address had been gas-funded by a wallet directly traceable to the Bybit exploit funds and appeared on the exchange’s public blacklist.
2/ In Feb 2025, shortly after the $1.5B Bybit exploit attributed to the DPRK-linked group 'TraderTraitor', I observed a pattern of 15+ accounts asking for help with orders directly tied to stolen funds in public groups on Telegram and Discord.
Last week I shared how illicit… pic.twitter.com/EKLeuzOOXT
— ZachXBT (@zachxbt) October 5, 2026
ZachXBT Has Helped Freeze Over $75 Million Since 2022
As the operations progressed, Jimmy shared details about the group’s activity in Hong Kong and mainland China. A day before it happened, he informed ZachXBT that funds would be moved to Solana — and they were. He also claimed his team had laundered most of the $1.5 billion stolen from Bybit, a statement ZachXBT noted as consistent with the laundering patterns he had observed.
On March 12, 2025, Jimmy shared a screenshot showing himself bridging funds. ZachXBT cross-referenced that image with a transaction on the THORChain explorer using amounts and timestamps. Three Solana addresses provided by Jimmy also revealed a cluster holding over $12 million in exploit funds, which had been swapped across Bitcoin, Ethereum, Solana, and Tron. Tether subsequently froze $442,000 in USDT linked to that cluster.
The investigation also traced another $3 million in funds to a Huione Guarantee hot wallet — an entity that has since been sanctioned — along with roughly $300,000 frozen in 2024 that matched funds from the Poloniex exploit.
ZachXBT acknowledged that the operation involved a personal financial risk: he put approximately $349,700 on the line with no guarantee that Jimmy would not disappear with the money. The findings were immediately shared with private sector investigators and authorities, though the sensitivity of the case prevented their publication until now. Since 2022, the investigator has contributed to freezing more than $75 million linked to incidents attributed to North Korea.






