ZachXBT Went Undercover With $349,700 to Follow Stolen Bybit Crypto
TLDR
- ZachXBT says he spent $349,700 posing as a client of an alleged Chinese laundering network tied to North Korea’s Lazarus Group.
- He says the operation helped trace more than $12 million in Bybit-linked funds across several blockchains.
- According to ZachXBT, Tether froze 442,000 USDT tied to wallets he uncovered.
- The FBI blamed North Korea’s TraderTraitor actors for the $1.5 billion Bybit theft in February 2025.
- Authorities have not publicly confirmed the operator “Jimmy Green” or the network’s alleged $1 billion in laundering.
Blockchain investigator ZachXBT says he spent $349,700 on an undercover operation inside an alleged Chinese crypto laundering network. He says the group moved more than $1 billion for North Korea-linked hackers.
His work helped trace funds from the $1.5 billion Bybit theft in February 2025. He shared the details in a thread on X on Oct. 5, 2026.
ZachXBT said he found more than 15 accounts in public Telegram and Discord groups asking for help with transactions tied to the Bybit hack. That led him to an operator using the name “Jimmy Green.”
How the Undercover Operation Worked
ZachXBT contacted the operator in late February 2025. He posed as a customer holding flagged crypto and asked to swap it for USDT on the Tron network.
By March 6, he had put 349,700 USDC into a new Ethereum address. He accepted a 5% loss on each order to build trust with the group.
He called the group a “Chinese organized crime syndicate.” He said it had “laundered $1B+ across multiple exploits for Lazarus Group.”
The first on-chain link came from a payment route. ZachXBT said the receiving address got its gas funding from a wallet tied to the Bybit exploit and listed on Bybit’s public blacklist.
On March 12, the operator sent a screenshot showing a swap of 1.192 BTC for 51.73 ETH. ZachXBT matched it to a THORChain transaction that led back to Bybit-linked funds.
The operator later claimed his team laundered “almost all the 1.5 billion eth.” Law enforcement has not confirmed that claim.
Wallets, Freezes and Official Records
Three Solana addresses shared during the chats revealed a wallet cluster holding more than $12 million in Bybit-linked funds. ZachXBT said the money moved from Bitcoin to Ether, then to Solana and Tron.
He said Tether later froze 442,000 USDT linked to the cluster. Tether’s own public releases reported $19 million in Bybit-related freezes by Oct. 31, 2025, but did not break out that amount.
The same contact pointed to other illicit flows. These included 332,000 USDC from the 2023 Poloniex hack and a $3 million batch traced to a wallet linked to Huione Guarantee.
The FBI said North Korea’s TraderTraitor actors carried out the Bybit theft on Feb. 21, 2025. Bybit said hackers used stolen credentials from a Safe developer to trick signers into approving a harmful transaction.
Chainalysis estimates North Korean hackers stole a record $2.02 billion in crypto during 2025. The Bybit breach made up $1.5 billion of that total.
ZachXBT said he shared his findings with private investigators and law enforcement while the operation was active. He says he has helped secure more than $75 million in freezes tied to North Korea-linked incidents since 2022.
Public records from the FBI, U.S. Treasury and Tether do not name “Jimmy Green.” No public criminal charge names the operator.
North Korea-linked thefts continue. Chainalysis said on Oct. 1 that investigators are working with Bitget after $387 million was stolen from the exchange on Sept. 24, 2026. The firm said the attack pushed North Korea’s 2026 crypto haul above $1 billion.
The post ZachXBT Went Undercover With $349,700 to Follow Stolen Bybit Crypto appeared first on Blockonomi.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0
Comments (0)