TLDR
- On-chain investigator ZachXBT invested $349,700 in an undercover operation, posing as a customer to penetrate a suspected Chinese crypto laundering operation.
- The syndicate allegedly processed over $1 billion in stolen cryptocurrency for North Korea’s Lazarus Group through numerous hacking incidents.
- The investigation helped locate more than $12 million in digital wallets tied to the $1.5 billion Bybit breach.
- Tether subsequently froze 442,000 USDT associated with the wallet cluster identified during the probe.
- According to Chainalysis, North Korean cyber criminals extracted $2.02 billion in digital assets throughout 2025, bringing their cumulative total beyond $6.75 billion.
An on-chain sleuth known as ZachXBT has revealed spending several months working undercover to uncover a cryptocurrency money laundering operation allegedly connected to North Korean state-sponsored hackers. He published his investigation results in a detailed X thread on October 5.
According to ZachXBT, he began operating as a paying client in February 2025, merely days following the Bybit security breach. He discovered contacts through public Telegram and Discord channels where individuals were requesting assistance with transferring illicitly obtained cryptocurrency.
The investigator explained that he loaded an Ethereum wallet with $349,700 worth of stablecoins. To establish credibility with an operator using the pseudonym Jimmy Green, he willingly absorbed a 5% loss on every transaction.
Inside the money laundering operation
ZachXBT characterized the organization as a Chinese organized crime network. According to his findings, the operation maintained a presence across Hong Kong and mainland China.
He asserted that the network processed more than $1 billion through various cryptocurrency exploits on behalf of the Lazarus Group. The operator purportedly informed him that nearly all assets from the Bybit incident passed through their laundering infrastructure.
ZachXBT’s initial breakthrough came through one specific transaction route. He discovered that a destination wallet had received funding from an address already listed on Bybit’s publicly available blacklist.
Subsequent communications provided him with advance intelligence regarding upcoming fund transfers. He cross-referenced these messages against publicly visible blockchain activity to verify the information.
On March 12, the operator transmitted a screenshot displaying an exchange of 1.192 Bitcoin for 51.73 Ether. ZachXBT successfully matched this transaction to activity on THORChain connected to Bybit-related funds.
Digital wallet analysis triggers asset freezes
Three Solana wallet addresses disclosed during their exchanges revealed a cluster containing over $12 million in assets linked to the Bybit compromise. ZachXBT noted the funds circulated between Bitcoin, Ether, Solana and Tron networks.
He reported that Tether subsequently froze 442,000 USDT associated with these wallets. Tether has independently verified larger freeze actions related to the Bybit incident through its T3 Financial Crime Unit.
By October 2025, T3-related enforcement had frozen $19 million connected to the Bybit theft, based on Tether’s disclosures. The specific 442,000 USDT freeze was not referenced in those prior public announcements.
ZachXBT additionally stated that the same intermediary provided intelligence about other incidents. This encompassed stolen assets from the 2023 Poloniex breach and a set of funds associated with Huione Guarantee.
The FBI publicly attributed the Bybit attack to North Korean actors just five days after the incident occurred. The bureau indicated that threat actors it designates as TraderTraitor made off with approximately $1.5 billion in digital assets.
Bybit explained that compromised login credentials belonging to a developer enabled the attacker to penetrate its systems. The platform stated that internal audits revealed no compromise of its fundamental infrastructure.
ZachXBT disclosed that he provided his intelligence to investigators and law enforcement agencies throughout the active investigation. He explained the delay in publishing until October 2026 was necessary given the case’s sensitive nature.
Official documentation from the FBI, Treasury Department and Tether has not identified the individual operating under the alias Jimmy Green. No court documents have substantiated the complete scope of the laundering network outlined in the investigator’s thread.
Chainalysis reports that North Korean-linked hackers stole $2.02 billion in cryptocurrency throughout 2025. The analytics firm indicates investigators continue tracing proceeds from the $387 million Bitget breach that occurred in September 2026.





