Key facts
- ZachXBT fronted $349,700 in USDC on March 6, 2025, posing as a client of a Chinese laundering syndicate.
- He accepted a 5% loss on each order to gather intelligence.
- The operation exposed over $12 million in Bybit exploit funds.
- Tether froze 442,000 USDT linked to the Bybit exploit funds.
- ZachXBT has helped action over $75 million in freezes tied to North Korean incidents since 2022.
- The Bybit exploit in February 2025 caused $1.5 billion in losses and was attributed to North Korean hackers.
Pseudonymous crypto investigator ZachXBT revealed on October 5, 2026, that he infiltrated a Chinese organized crime syndicate working for North Korea's Lazarus Group. Posing as a client, ZachXBT fronted $349,700 in USDC on March 6, 2025, accepting a 5% loss on each transaction to gather intelligence. This operation helped expose over $12 million in funds stolen from the Bybit exchange in February 2025, leading to Tether freezing 442,000 USDT linked to the exploit.
The Bybit exploit, which resulted in $1.5 billion in losses, was attributed by the FBI to North Korean hackers tracked as TraderTraitor. ZachXBT stated that the alleged launderers were not actively hiding their activities. He observed patterns of accounts seeking help with orders tied to stolen funds on Telegram and Discord shortly after the exploit.
ZachXBT's work has been instrumental in tracing stolen crypto. He has helped action over $75 million in freezes related to North Korean incidents since 2022. His investigations, funded by grants and donations, rely on publicly available blockchain data. He previously helped trace the theft of approximately 4,100 BTC from a Genesis creditor, which led to arrests. Paradigm hired him as an incident response advisor in February 2025.
During his infiltration, ZachXBT communicated with an individual named "Jimmy Green" within the syndicate. He sent USDC to an address that was traceable to the Bybit exploit blacklist. After building trust through several transactions, Jimmy began discussing moving Bybit funds for North Korea, providing details about their operations in Hong Kong and mainland China. ZachXBT noted that the funds were moved to Solana the day after Jimmy stated they would be.
ZachXBT also observed that the syndicate was moving funds from Bitcoin to Ether, then to Solana and finally to Tron, exposing over $12 million in stolen funds in real-time. He found that a team mentioned by Jimmy had $300,000 frozen in 2024, which he traced to the Poloniex exploit, a hack also linked to Lazarus Group. Additionally, Jimmy mentioned laundering $3 million in fraud proceeds for another client, which ZachXBT traced to Huione Guarantee, a Telegram marketplace targeted by the U.S. Treasury for alleged money laundering.
