0x25b395d625b3…25b395d3

ConfirmedSecurity568 vB146 sat/vB3 min decode

ZachXBT Says He Fronted $349,700 to Infiltrate Laundering Network

ZachXBT says he deployed $349,700 of personal funds to infiltrate an alleged Chinese laundering ring tied to Lazarus Group, with addresses linked to a $12M Bybit cluster and a 442,000 USDT Tether freeze.

Outputs

  1. ZachXBT says he fronted $349,700 of personal funds to infiltrate an alleged Chinese laundering network between March and October 2025

  2. He credits three Solana addresses with exposing a cluster of more than $12 million in Bybit hack proceeds and enabling a 442,000 USDT freeze by Tether

  3. He alleges the network laundered more than $1 billion across Bitcoin, Ethereum, Solana and Tron for North Korea's Lazarus Group

  4. The FBI attributed the approximately $1.5 billion Bybit hack on or about February 21, 2025 to the DPRK, branding it 'TraderTraitor'

  5. Separately, ZachXBT says approximately $170,000 connected to the Bitget exploit was frozen at a service on Hyperliquid

Blockchain investigator ZachXBT says he deployed $349,700 of personal capital to infiltrate an alleged Chinese laundering network, supplying three Solana addresses he credits with enabling Tether to freeze 442,000 USDT connected to the February 2025 Bybit hack.

In a 12-post X thread dated October 5, 2025, ZachXBT outlined how he posed as a money-laundering client to gather intelligence on operations he tied to North Korea's Lazarus Group. He alleged the network moved more than $1 billion from multiple exploits, and that he absorbed a 5% haircut on every transaction to establish credibility with the counterparty.

"Due to sensitivity around the investigation, I was unable to publish sooner," he wrote.

How did ZachXBT build the case?

According to the thread, the probe began weeks after the Bybit breach, when ZachXBT spotted at least 15 Telegram and Discord accounts seeking assistance processing orders he believed stemmed from stolen exchange funds. He approached several of those accounts, including one operating under the alias "Jimmy Green."

On March 6, 2025, ZachXBT funded a fresh Ethereum address to transact with the contact. Etherscan records show that address received approximately 349,720 USDC that same day. The initial swap, he said, was USDC on Ethereum exchanged for USDT on Tron — a routine corridor for cross-chain laundering.

Repeated deals eventually earned him a higher level of visibility. According to ZachXBT, his contact began disclosing planned movements of Bybit-related funds before settlement, including a transfer routed through Solana a full day in advance. That advance notice, he argued, is what allowed investigators and Tether to stage the freeze.

What did Tether actually freeze?

ZachXBT identified the Ethereum address 0x652d7f9edaaa8891be2de74ea568d70af823d89e as the freeze target. As of Etherscan's last public state, that address holds roughly 442,399 USDT and is labeled as a Uniswap V2 liquidity pool. An on-chain balance alone cannot confirm a freeze or identify the controlling party; the freeze claim rests on ZachXBT's attribution.

The three Solana addresses he provided, he said, exposed a cluster of more than $12 million in proceeds routed through Bitcoin, Ethereum, Solana and Tron.

Who is behind the network?

ZachXBT alleged that the network serviced North Korean state hackers. The Federal Bureau of Investigation attributed the Bybit attack — roughly $1.5 billion drained on or about February 21, 2025 — to the DPRK and branded the campaign "TraderTraitor." The Defiant has reported on the laundering operation, including concerns that large hauls were splintered into smaller transactions to evade automated detection.

What else surfaced?

Separately, in an October 5 reply on X, ZachXBT said approximately $170,000 linked to the Bitget exploit was recently frozen at a service operating on Hyperliquid. He added that his findings were shared immediately with private-sector investigators and law enforcement assigned to the case — a standard protocol for voluntary cooperation that typically precedes any public disclosure by weeks or months.

What remains unverified?

On-chain balances confirm only the volume of stablecoins sitting at the named addresses. They do not, on their own, confirm a freeze, attribution to Lazarus, or the real-world identity of "Jimmy Green." Any conviction or seizure will require law enforcement to formalize the trail ZachXBT has mapped.

The next material milestone will be any government action naming the alleged network's operators, since private freezes alone do not unwind the broader $1 billion in flows now scattered across four major chains.

via x.com (Original)

More from Elena Vasquez

Elena Vasquez

Show full bio

Staff writer covering marketplaces and e-commerce at Mempool Brief.

439 articles