0x12058f401205…12058f3d
ZachXBT Says Chinese Syndicate Laundered $1B for Lazarus Group
ZachXBT alleged in an Oct. 5 disclosure that he infiltrated a Chinese laundering network that moved more than $1 billion for Lazarus Group, fronting 349,700 USDC to build trust with a contact known as Jimmy Green.
Outputs
ZachXBT alleged on Oct. 5 that the network laundered more than $1 billion for Lazarus Group
ZachXBT fronted 349,700 USDC on Ethereum and absorbed a 5% loss on each order to build trust with contact 'Jimmy Green'
FBI's Feb. 26, 2025 PSA attributed the approximately $1.5 billion Bybit theft on Feb. 21, 2025 to malicious activity labeled 'TraderTraitor'
Tether froze 442,000 USDT linked to a traced cluster exceeding $12 million moving through Bitcoin, Ethereum, Solana and Tron
An additional 332,000 USDC tied to the 2024 Poloniex exploit matched information volunteered by the same contact
ZachXBT, a pseudonymous blockchain investigator, alleged in an Oct. 5 social media disclosure that he infiltrated a Chinese laundering network responsible for moving more than $1 billion in stolen crypto for Lazarus Group, North Korea's state-linked hacking unit.
The thread, posted to X, described a months-long operation in which the investigator posed as a stablecoin client to build trust with a contact using the alias Jimmy Green. According to ZachXBT's account, the arrangement required an upfront stake of 349,700 USDC and produced intelligence that helped Tether freeze funds tied to the February 2025 Bybit exchange exploit.
What the intelligence covered
The investigation originated from the Bybit theft of Feb. 21, 2025. In a Feb. 26 public service announcement, the FBI attributed that theft—approximately $1.5 billion in virtual assets—to malicious activity the bureau labels TraderTraitor. The FBI said some stolen assets had been converted into Bitcoin and dispersed across thousands of addresses on multiple blockchains, urging private-sector services to block transactions tied to the listed laundering addresses.
ZachXBT's thread adds what he presented as primary-source intelligence drawn from inside the pipeline.
On March 6, 2025, he funded a new Ethereum address with 349,700 USDC, exchanging it for the contact's USDT on Tron. He completed additional trades and absorbed a 5% loss on each order to build credibility. Over time, the contact began volunteering operational details, including advance notice that funds would move to Solana—a shift that occurred the following day, according to ZachXBT.
On March 12, 2025, the contact sent a screenshot of a cross-blockchain transfer. ZachXBT matched its amounts and timing to a transaction on the THORChain explorer created within minutes of the message. The contact also supplied three Solana addresses that, per ZachXBT, exposed a cluster exceeding $12 million in Bybit exploit funds moving through Bitcoin, Ethereum, Solana, and Tron.
Tether separately froze 442,000 USDT linked to that cluster, according to ZachXBT. The freeze sits inside a larger traced total that he did not fully itemize.
A broader operational footprint
The contact's disclosures extended past Bybit. ZachXBT said the same Telegram handle referenced a team whose funds had been frozen in 2024, a figure that matched an on-chain freeze of 332,000 USDC tied to the Poloniex exploit. The overlap suggests the syndicate was active well before the latest exchange hack.
Allegations involving a Chinese over-the-counter trader first surfaced in October 2024. The Oct. 5 thread documents how ZachXBT obtained fresh information by becoming a trading counterparty himself—a blend of human-source work and on-chain forensics that few investigators have attempted at that scale.
The syndicate's total and the links to Jimmy Green remain ZachXBT's findings, distinct from the FBI's formal TraderTraitor attribution of the Bybit theft. The in-channel details he described—named chains, advance notice of fund shifts, references to operations in Hong Kong and mainland China—nonetheless align with the bureau's pattern of professionalized, state-sponsored laundering.
The cost of access was concrete. ZachXBT said he fronted 349,700 USDC for the case and absorbed the spread on each order without quantifying his net loss.
What's next
ZachXBT used the disclosure to appeal for foundation grants and individual donations to underwrite higher-risk operations. He argued that intelligence from these trades had already yielded frozen funds and that his personal financial exposure was not sustainable without external support.
With Tether's freeze actions and the FBI's TraderTraitor designation already on record, the enforcement window for the syndicate's known on-chain identifiers now depends on whether additional exchanges and off-ramps adopt the same blocking posture across Tron, Solana, Ethereum and Bitcoin before the addresses are rotated out of active use.
via x.com (Original)
More from Daniel Okafor
Show full bio
Correspondent covering industry trends and analytics at Mempool Brief.
435 articles