ZachXBT says he fronted $349,700 to infiltrate alleged Chinese launderers tied to Lazarus, Bybit hack
Posing as a client, the onchain sleuth said he gathered intelligence that helped action freezes tied to the $1.5 billion Bybit hack and attribute illicit activity onchain.

Quick Take
- Onchain sleuth ZachXBT said he infiltrated a Chinese organized crime network that laundered over $1 billion across multiple Lazarus Group-linked crypto exploits.
- Posing as a client, the sleuth said he gathered intelligence that helped action freezes tied to the $1.5 billion Bybit hack and attribute illicit activity onchain.
Blockchain investigator ZachXBT said he infiltrated a Chinese organized crime network and gathered intelligence that helped action freezes tied to the 2025 Bybit hack.
In a detailed thread on X, ZachXBT alleged that the Chinese crime syndicate laundered over $1 billion across multiple exploits for North Korea's Lazarus Group.
The onchain sleuth said he began investigating after he noticed a pattern involving more than 15 accounts in Telegram and Discord groups seeking help with orders tied to stolen funds following the Bybit exploit in February 2025.
Posing as a client, ZachXBT funded a new address with 349,700 USDC on Ethereum to conduct multiple transactions with a vendor who went by the pseudonym "Jimmy Green."
In March 2025, Jimmy provided ZachXBT with the receiving address "0xbaa5" to exchange USDC for USDT on Tron. The sleuth said that Jimmy's receiving address was gas-funded by a wallet that was "directly traceable to Bybit exploit funds" and appeared on Bybit's public exploit blacklist.
ZachXBT also said that Jimmy discussed plans to move Bybit funds for North Korea before the transactions occurred and shared details about the group's operation in Hong Kong and mainland China.
"One day prior, he stated funds would be moved to Solana and the next day they were," ZachXBT said. "He stated his team laundered most of the $1.5 billion from Bybit, which was consistent with the laundering patterns I observed."
Repeated pattern
ZachXBT said other claims made by Jimmy showed similar ties to illicit funds.
Among those operations, a March 12 bridge screenshot shared by Jimmy matched a THORChain order created within minutes, according to ZachXBT. Three Solana addresses Jimmy shared also helped identify a cluster of over $12 million in Bybit exploit funds that had been swapped across BTC, ETH, SOL, and Tron, he said. Tether later froze 442,000 USDT linked to the cluster.
Two other claims in their conversations were also checkable, he said. Jimmy's mention of roughly $300,000 frozen in 2024 matched 332,000 USDC from the Poloniex exploit.
Jimmy also claimed to have laundered $3 million in fraud proceeds for another client. ZachXBT said he traced those funds to a hot wallet of Huione Guarantee, which has been sanctioned.
"Throughout our conversations, Jimmy and I had a lot of small talk in between discussing laundering for DPRK," said ZachXBT. "He talked about playing mahjong, hunting wild rabbits, food, his fat-reducing meal, family life, and vacations at Disney."
ZachXBT noted that he ultimately fronted $349,700 and lost about 5% per order, "with no guarantee Jimmy wouldn't disappear with the funds." He said he continued trading with the group in an effort to "gamble on capturing as much actionable intel as quickly as possible."
The investigator said he immediately shared his findings with law enforcement but was unable to disclose details sooner due to sensitivity around the investigation. He added that he has helped facilitate the freezing of $75 million in funds related to North Korean incidents since 2022.

