NewsCryptoZachXBT Says He Posed as a Customer to Infiltrate Chinese Network Laundering North Korea-Linked Bybit Funds

ZachXBT Says He Posed as a Customer to Infiltrate Chinese Network Laundering North Korea-Linked Bybit Funds

Author: Crypto Adventure·

Key Takeaways

  • •ZachXBT risked $349,700 of his own USDC to pose as a paying customer of a Chinese laundering network allegedly handling stolen cryptocurrency for North Korea-linked operators, publishing the operation's details on October 5.
  • •The FBI attributed the approximately $1.5 billion February 2025 Bybit theft, the largest crypto theft on record, to North Korean actors it tracks as TraderTraitor.
  • •According to ZachXBT, the wider network has processed over $1 billion across exploits connected to the Lazarus Group, although that aggregate figure has not been independently confirmed by law enforcement.
  • •Conversations with a Telegram operator using the alias 'Jimmy Green' exposed more than $12 million in Bybit-linked assets moving through Bitcoin, Ethereum, Solana, and Tron.
  • •A connected USDT address holding roughly 442,000 USDT was frozen on March 14, 2025, and ZachXBT says his DPRK-related work has helped action more than $75 million in asset freezes since 2022.
ZachXBT Says He Posed as a Customer to Infiltrate Chinese Network Laundering North Korea-Linked Bybit Funds

Blockchain investigator ZachXBT says he spent weeks posing as a paying customer of a Chinese money-laundering network that handles stolen cryptocurrency for North Korea-linked operators, risking $349,700 of his own USDC to gain access to the group. He published details of the undercover operation on X on October 5, nearly 18 months after the February 2025 Bybit breach that set the investigation in motion.

According to ZachXBT, the wider network has processed more than $1 billion across multiple exploits connected to the Lazarus Group, although that aggregate figure has not been independently confirmed by law enforcement. The scale matters because North Korea-linked crews rank among the most prolific theft actors in crypto, and U.S. government assessments have repeatedly described such proceeds as a funding source for the regime.

The FBI attributed the Bybit theft of approximately $1.5 billion — the largest crypto theft on record — to North Korean actors it tracks as TraderTraitor on February 26, 2025, warning at the time that the stolen assets were already being dispersed across thousands of addresses and multiple blockchains.

$349,700 Used to Build Trust

ZachXBT said he identified more than 15 accounts in public Telegram and Discord groups that were seeking help with transactions he linked to stolen Bybit funds. After contacting several, he established an ongoing relationship with a Telegram operator using the alias "Jimmy Green."

On March 6, 2025, ZachXBT funded a fresh Ethereum address with 349,700 USDC and began exchanging funds with the operator for USDT on Tron. Each order carried a cost of roughly 5%, he said, with no assurance that the counterparty would return the money. Investigations typically rely on tracing funds after the fact; here, direct participation surfaced operational details that public chain data alone cannot show.

The risk produced evidence. One Ethereum address supplied during the transactions had received gas from a wallet ZachXBT traced directly to Bybit exploit proceeds. Bybit had already created a public blacklist system to distribute identified attacker addresses to investigators and recovery partners.

The access also yielded advance information about fund movements. ZachXBT said Green told him Bybit-linked assets would move into Solana one day before the corresponding transactions appeared onchain.

Chats Exposed a $12 Million Bybit Fund Cluster

A March 12 exchange gave ZachXBT another point of comparison. Green sent a screenshot of a cross-chain transfer, and the transaction amount and timing matched a THORChain order created within minutes of the message.

Three Solana addresses supplied during the conversations then exposed more than $12 million in Bybit-linked assets moving through Bitcoin, Ethereum, Solana, and Tron. The routing fits the cross-chain laundering pattern previously observed after the Bybit theft, when THORChain became a major conduit for stolen funds; moving value across chains in this way is a common technique for obscuring the trail between theft and cash-out.\nA USDT address connected to the identified cluster was frozen on March 14, 2025. ZachXBT placed the affected balance at approximately 442,000 USDT, and BlockSec's onchain tracker confirms the address entered Tether's frozen state. Stablecoin freezes of this kind are among the few interventions that can directly immobilize stolen funds once they have been converted into tokens like USDT.

The broader laundering problem has continued into 2026. ZachXBT recently linked wallets from the September Bitget exploit to suspected North Korean actors, while separate Lazarus-linked wallets moved more than $30 million through Hyperliquid earlier this year.

ZachXBT said he waited roughly 18 months before publishing details of the undercover operation because related investigations remained active. He added that his work on DPRK-linked cases has helped action more than $75 million in asset freezes since 2022. With those investigations still open, further disclosures, address blacklisting, or freezes could follow as more of the network's infrastructure comes into view.

Source: Crypto Adventure