NewsCryptoZachXBT infiltrates Chinese laundering network tied to Bybit and Bitget hacks

ZachXBT infiltrates Chinese laundering network tied to Bybit and Bitget hacks

Author: Cryptopolitan·

Key Takeaways

  • •ZachXBT infiltrated a Chinese laundering syndicate as an undercover client, gathering intelligence on a network that has processed more than $1 billion in stolen funds for North Korea's Lazarus Group.
  • •ZachXBT personally sent $3.497 million in USDC to a blacklisted Ethereum wallet tied to the Bybit on March 6, 2025, accepting roughly a 5% loss risk on each investigative transaction.
  • •An operator known as 'Jimmy Green' revealed three Solana addresses holding over $12 million in Bybit funds, and Tether later froze approximately 442,000 USDT linked to those wallets.
  • •Analytics firm Elliptic connected the $387.5 million September 2026 Bitget hack to laundering routes used after the Bybit theft, lifting suspected North Korean crypto thefts above $1 billion in 2026.
  • •Wallets tied to the Bitget hack moved about $3.9 million in Zcash into the Ironwood shielded pool, where concealed transaction details make tracing considerably more difficult.
ZachXBT infiltrates Chinese laundering network tied to Bybit and Bitget hacks

On-chain investigator ZachXBT says he spent months posing as a paying client inside a Chinese money-laundering syndicate that has moved more than $1 billion in stolen funds on behalf of North Korea's Lazarus Group.

Intelligence gathered during the undercover work helped freeze proceeds from the February 2025 Bybit breach, in which the exchange lost roughly $1.5 billion to attackers — one of the largest thefts in crypto history. The operation also offers a rare first-hand look at how stolen exchange funds travel through informal broker networks, where every hop across public blockchains leaves a traceable record.

Inside the Bybit laundering pipeline

After Bybit lost about1.5 billion in February 2025, ZachXBT says he identified more than 15 accounts in open Telegram and Discord channels offering to help process money tied to the theft. In a long thread posted on X (1, 2, 3), he revealed that he approached one operator using the handle "Jimmy Green" and spent weeks building trust through a series of real transactions.

On March 6, 2025, ZachXBT sent $3.497 million in USDC to an Ethereum address publicly known as a blacklisted hack wallet that is also linked back to the Bybit hack. He said the roughly $3.5 million came out of his own pocket and that he accepted a loss risk of about 5% on each transaction made during the investigation.

Through those interactions, Jimmy handed over three Solana addresses holding more than $12 million in Bybit funds. ZachXBT watched the funds hop in real time from Bitcoin into Ether, then Solana, and then Tron. Tether later froze about 442,000 USDT linked to those wallets. Because stablecoins like USDT can be blacklisted at the contract level, that on-chain visibility can translate directly into frozen funds.

Other tips picked up along the way allowed ZachXBT to verify older claims. Jimmy mentioned a team that had roughly $300,000 frozen in 2024, and ZachXBT located the freeze on-chain. Jimmy also boasted about laundering $3 million in fraud money, which led ZachXBT to discover wallets connected to Huione Guarantee, a marketplace already sanctioned by the United States. ZachXBT said investigators and law enforcement were informed as early as possible, and that since 2022 his work has helped freeze more than $75 million tied to North Korea-linked incidents. With law enforcement informed, whether the flagged wallets draw further freezes is the immediate development to watch.

The conversations were not limited to business. ZachXBT wrote that Jimmy also described playing mahjong, hunting wild rabbits, his diet meals, family life, and holidays at Disney.

North Korean links to the Bitget hack

The findings also touch the September 2026 Bitget hack, in which about $387.5 million was lost to attackers. Following the incident, Bitget CEO Gracy Chen named North Korea as the likely culprit.

Blockchain analytics firm Elliptic said the stolen Bitget funds were linked to addresses used to launder money from the 2025 Bybit theft. The firm described the reuse of the same laundering routes as a common pattern for North Korean hackers and said the Bitget attack pushed suspected North Korean crypto thefts above $1 billion in 2026. The reuse matters because infrastructure flagged in one heist can be watched for the next.

ZachXBT flagged five accounts in the Bitget laundering effort, including one account called "lolo" that also handled proceeds from the $292 million Kelp DAO exploit in April.

Separately, Cryptopolitan reported that wallets tied to the Bitget hack pushed about $3.9 million in Zcash into the Ironwood shielded pool. Zcash's shielded pools are designed to conceal transaction details, making funds that enter them considerably harder to trace.