Newsroom
5 October, 2026 / News / AI / Tags: zachxbt, bybit, jimmy, lazarus, green

On-chain investigator ZachXBT spent nearly $350,000 of his own funds posing as a client to gather intelligence on a money-laundering network linked to the $1.5 billion Bybit theft
Blockchain investigator ZachXBT has detailed an undercover operation in which he posed as a customer of a Chinese organized crime syndicate accused of laundering more than $1 billion in stolen cryptocurrency for actors tied to North Korea’s Lazarus Group. The effort, which required him to risk hundreds of thousands of dollars, produced actionable intelligence that supported freezes of funds connected to the February 2025 Bybit exchange hack valued at approximately $1.5 billion.
Shortly after the Bybit incident, which the FBI attributed to the North Korea-linked group known as TraderTraitor, ZachXBT noticed more than 15 accounts in public Telegram and Discord groups seeking assistance with transactions involving the stolen assets. He initiated contact with one operator using the alias Jimmy Green and presented himself as a potential client seeking to process funds.
On March 6, 2025, ZachXBT funded a new address with 349,700 USDC on Ethereum to begin transactions. The operator directed him to send the USDC in exchange for USDT on the Tron network. The receiving address had previously received gas fees from a wallet directly traceable to Bybit exploit proceeds. To establish credibility, ZachXBT completed multiple additional transfers, accepting roughly 5 percent losses on each order.
As trust developed, Jimmy Green began sharing advance details about planned movements of Bybit-linked funds, including operations based in Hong Kong and mainland China. The operator claimed his team had handled the bulk of the stolen assets from the exchange breach. ZachXBT cross-checked these statements against blockchain records and identified a matching wallet cluster holding more than $12 million in Bybit-related funds.
The laundered funds moved across multiple blockchains, including Bitcoin, Ethereum, Solana, and Tron, in an apparent effort to obscure their origins. In one instance, information provided by the operator about an impending bridge transfer aligned with activity recorded on THORChain. On March 12, 2025, a screenshot shared by Jimmy Green of a bridging transaction corresponded in amount and timing to an order visible on the protocol’s public explorer.
Jimmy Green later supplied three Solana addresses that further mapped the cluster of more than $12 million in exploit proceeds being swapped in real time. The investigator also confirmed a separate freeze of 332,000 USDC tied to the earlier Poloniex hack, which researchers have connected to Lazarus Group activity. Jimmy Green had referenced a roughly $300,000 freeze from 2024 involving a team he knew; on-chain data matched the actual amount.
Tether subsequently froze approximately $442,000 in USDT linked to the identified wallet cluster. ZachXBT stated that intelligence from the operation was shared promptly with private-sector investigators and the law enforcement agencies assigned to the Bybit case.
The probe extended beyond the Bybit incident. Jimmy Green described laundering about $3 million in fraudulent proceeds for another client. ZachXBT traced those funds to a hot wallet associated with Huione Guarantee, a Cambodian Telegram marketplace that offered laundering services. Huione Group, the parent entity, was designated by the U.S. Treasury’s FinCEN in May 2025 as a financial institution of primary money-laundering concern over alleged activity involving at least $4 billion. Telegram later banned the marketplace, and Chinese authorities arrested a former Huione Group chairman after his deportation from Cambodia.
ZachXBT reported that the Chinese syndicate had processed more than $1 billion across multiple exploits on behalf of Lazarus-linked actors. He noted that conversations with the operator also included ordinary topics such as mahjong, hunting, meals, family, and vacations.
Since 2022, ZachXBT has assisted in the freezing of more than $75 million connected to North Korea-related cryptocurrency incidents. He funds higher-risk work of this nature through grants from foundations and donations from individuals. The investigator has previously linked wallets used in the Bybit laundering process to earlier Lazarus-associated attacks, including those on Phemex and BingX. On the day of the Bybit breach itself, his on-chain analysis pointed to Lazarus Group, an attribution later supported by the FBI.
The disclosure of the undercover work came on October 5, 2026. ZachXBT indicated that sensitivity surrounding the investigation delayed public discussion of the details. The operation carried both financial cost and personal risk, with no assurance that the counterpart would not abscond with the funds transferred during the engagement.









