0x218da6f7218d…218da6f4
ZachXBT Posed as Client to Expose Bybit Hack Laundering Syndicate
Pseudonymous investigator ZachXBT mapped a Chinese laundering ring tied to the $1.5B Bybit hack by posing as a buyer, according to a Crypto Times report.

Outputs
ZachXBT mapped a Chinese-organized laundering network tied to the February 2025 Bybit hack by posing as a buyer, per The Crypto Times
Bybit confirmed approximately $1.5 billion in ether and ether-related tokens were drained from a cold wallet in February 2025
The exploit was attributed to TraderTraitor, a North Korean state-linked group also known as Lazarus Group
Cash-out points reportedly extended across Chinese cities including Hong Kong and Macau
The mapped network could trigger OFAC designations, mainland China or Hong Kong prosecutions, or U.S. DOJ seizures
Pseudonymous blockchain investigator ZachXBT mapped a Chinese-organized laundering network handling proceeds from the February 2025 Bybit exchange hack by posing as a client, according to a report published by The Crypto Times.
The undercover operation produced an on-chain map of how stolen assets from one of the largest exchange exploits on record were moved through the syndicate. Bybit confirmed in February 2025 that approximately $1.5 billion in ether and ether-related tokens had been drained from one of its cold wallets in an exploit later attributed to TraderTraitor, the North Korean state-linked group also known as Lazarus Group.
What did the investigation reveal?
ZachXBT's investigation, summarized in The Crypto Times report, leveraged social-engineering tradecraft rather than pure on-chain forensics. By adopting the role of a buyer, the investigator obtained documentation and identifying details that tied specific over-the-counter desks and money-service operators in China to the laundering pipeline.
The Crypto Times summary does not yet enumerate specific addresses or transaction counts. It indicates the network extended across multiple Chinese cities and used cash-out points in Hong Kong and Macau to convert stolen crypto into fiat. The method echoes previous laundering patterns documented after the Harmony Bridge and Ronin Bridge exploits, both of which were also attributed to Lazarus Group.
Why does the undercover tactic matter?
Forensic-only investigations typically trace transactions to a cluster of wallets, then stall when funds hit a swap service or OTC desk. Posing as a customer produces something those data sources cannot: a name, a face, a bank account, a WeChat handle, or a physical address. Each becomes a separate lead for law enforcement.
Chainalysis, TRM Labs and Elliptic have increasingly coordinated with undercover work rather than relying solely on graph analytics. Pseudonymous researchers have used variations of the technique in previous cases, including a 2022 follow-on tracing of stolen Axie Infinity funds and a 2023 investigation into a Southeast Asian pig-butchering ring.
What are the regulatory consequences?
Identifying the cash-out network strengthens the case for sanctions designations by the U.S. Office of Foreign Assets Control (OFAC) and the United Nations Security Council Panel of Experts on North Korea. North Korea's evasion revenue funds its weapons programs, which is the explicit basis for those sanctions. Each newly identified entity creates a fresh designation candidate.
Exchanges that serviced those OTC desks now face potential enforcement exposure under the Bank Secrecy Act and equivalent regimes in Singapore and the European Union, depending on whether they failed to file suspicious activity reports on the relevant transaction volumes.
What remains unverified
The Crypto Times summary does not yet detail the size of the funds the mapped syndicate handled, the number of individuals implicated, or whether any arrests or asset seizures followed. The original publication has not been linked from ZachXBT's verified social channels in publicly available coverage at the time of writing, which limits third-party verification of the specific findings.
ZachXBT, who has previously assisted law enforcement on cases including the 2022 Bored Ape Yacht Club phishing investigation and the 2023 suspected Mango Markets insider case, has emerged as a recurring source for tracing chronically underreported individuals within the North Korean laundering pipeline.
The next operational milestone will be whether the mapped network triggers OFAC designations, prosecutions in mainland China or Hong Kong, or additional seizures by the U.S. Department of Justice, which has historically followed similar leads with a multi-year lag.
via Google News - Crypto Hack Exploit (Source)
More from Daniel Okafor
Show full bio
Correspondent covering industry trends and analytics at Mempool Brief.
435 articles