How ZachXBT Infiltrated a Crypto Laundering Network Handling Bybit and Other Stolen Funds

by Joseph Rees

ZachXBT is back with another major crypto expose. This time, the onchain investigator said he infiltrated a Chinese organized crime syndicate that has laundered more than $1 billion across multiple exploits for the notorious Lazarus Group.

After posing as a client, ZachXBT said that he gathered information that helped action freezes linked to the February 2025 Bybit exploit.

Inside the Chinese Crime Syndicate

The investigation started shortly after the $1.5 billion Bybit exploit. The attack was attributed to the DPRK-linked group TraderTraitor. ZachXBT noticed more than 15 accounts on public Telegram and Discord groups asking for help with orders tied directly to the stolen funds. He contacted several of those accounts. One of them used the alias “Jimmy Green” on Telegram.

On March 6, 2025, ZachXBT funded a new Ethereum address with 349,700 USDC, which he planned to use for several transactions with the individual.

Jimmy gave him an address to send USDC to in exchange for USDT on Tron. The investigator then found that the address had been funded with gas by another wallet that could be directly traced to funds from the Bybit exploit. He then continued making trades with Jimmy to build trust.

That eventually led to Jimmy sharing more information about the operation. According to ZachXBT, the alleged launderer talked about moving Bybit funds for DPRK actors and gave basic details about the group’s operations in Hong Kong and mainland China. In one example, Jimmy told ZachXBT one day before it happened that funds would be moved to Solana. The next day, the funds were indeed moved to Solana.

Jimmy also claimed that his team had laundered most of the $1.5 billion stolen from Bybit. ZachXBT said this was consistent with the laundering patterns he had observed. On March 12, 2025, Jimmy shared a screenshot showing himself bridging funds. The onchain sleuth then matched the screenshot to a transaction on the THORChain explorer using the amounts and timing.

Jimmy later shared three Solana addresses, which revealed a cluster containing more than $12 million in Bybit exploit funds. The funds were swapped across Bitcoin, Ethereum, Solana, and Tron in real time. Around $442,000 in USDT linked to the cluster was later frozen by Tether. ZachXBT also identified a laundering method involving Uniswap liquidity pools and illiquid tokens. The investigation uncovered other activity too.

ZachXBT was told that a team Jimmy knew had around $300,000 frozen in 2024, which was later identified as being from the Poloniex exploit. Jimmy also talked about laundering $3 million in fraud proceeds for another client. Those funds were traced to a hot wallet linked to Huione Guarantee, which has since been sanctioned.

The conversations were not always about laundering money. Jimmy also talked about mahjong, hunting wild rabbits, food, family life, and vacations to Disney. ZachXBT said Jimmy’s awkward grammar could be explained by the use of a translator.

Costly Operation

The investigation came with a financial risk for ZachXBT. He said he fronted 349,700 USDC and lost 5% on each order. There was also no guarantee that the launderer would not disappear with the funds.

Since 2022, ZachXBT has helped freeze more than $75 million related to DPRK incidents. He said the findings from this case were immediately shared with trusted investigators in the private sector and law enforcement assigned to the case. Due to the sensitivity of the investigation, he said he could not publish the findings sooner.

The post How ZachXBT Infiltrated a Crypto Laundering Network Handling Bybit and Other Stolen Funds appeared first on CryptoPotato.

Source: https://cryptopotato.com/how-zachxbt-infiltrated-a-crypto-laundering-network-handling-bybit-and-other-stolen-funds/

You may also like

Leave a Comment