0x32dd686c32dd…32dd686f
ZachXBT Says He Spent $349,700 Undercover to Expose Lazarus Launderers
ZachXBT says he wired $349,700 to pose as a client of a Lazarus-linked Chinese laundering ring, exposing $12M+ in Bybit funds and prompting a 442K USDT freeze by Tether.
Outputs
ZachXBT fronted $349,700 in USDC on March 6, 2025, accepting a 5% loss per order to pose as a laundering client.
The operation exposed a $12M+ cluster of Bybit exploit funds; Tether later froze 442,000 USDT linked to it.
The Feb 2025 Bybit exploit caused $1.5 billion in losses; the FBI attributed it to TraderTraitor (North Korea).
ZachXBT says he has helped action $75M+ in freezes tied to DPRK incidents since 2022.
Leads connected the syndicate to Huione Guarantee, targeted by FinCEN over alleged laundering of at least $4 billion.
Pseudonymous on-chain investigator ZachXBT says he fronted $349,700 of his own money to pose as a client of a Chinese laundering syndicate working for North Korea's Lazarus Group, an operation that exposed a cluster of more than $12 million in stolen Bybit funds and led Tether to freeze 442,000 USDT.
In a detailed post on X, ZachXBT said he wired 349,700 USDC on March 6, 2025, and accepted a 5% loss on each transaction to maintain his cover — with no guarantee the counterparty, who went by "Jimmy Green" on Telegram, would not simply vanish with the funds.
"Posing as a client, I gathered intel that helped action freezes for the Feb 2025 Bybit exploit and attribute illicit activity onchain," he wrote.
How did the operation begin?
The investigation started in the aftermath of the February 2025 Bybit exploit, which caused $1.5 billion in losses and which the FBI attributed to North Korean hackers it tracks as TraderTraitor. ZachXBT attributed the hack to Lazarus Group using on-chain data on the day of the incident; the FBI backed that attribution days later.
"In Feb 2025, shortly after the $1.5B Bybit exploit attributed to the DPRK-linked group 'TraderTraitor,' I observed a pattern of 15+ accounts asking for help with orders directly tied to stolen funds in public groups on Telegram and Discord," he wrote. He said he saw the same pattern last week following the $387 million Bitget hack, which Bitget's CEO and the tracing firms Elliptic and Chainalysis have linked to North Korea.
The alleged launderers were operating in plain sight, ZachXBT said. He identified the group as a Chinese syndicate that he says has laundered more than $1 billion across multiple exploits for Lazarus Group, with operations based in Hong Kong and mainland China.
What did the undercover transactions reveal?
Jimmy instructed ZachXBT to send USDC on Ethereum to a designated address in exchange for USDT on Tron. That address, ZachXBT wrote, had been funded with gas by a wallet "directly traceable to Bybit exploit funds" and labeled on the public Bybit exploit blacklist site.
After several transactions built trust, Jimmy began discussing moving Bybit funds for the DPRK in advance of the movements. ZachXBT verified the claim: "One day prior he stated funds would be moved to Solana and the next day they were."
"For this case, I fronted $349.7K and lost 5% on each order, with no guarantee Jimmy wouldn't disappear with the funds, and an unknown amount of personal risk from dealing with the syndicate," he said.
The breakthrough came on March 12, 2025, when ZachXBT matched a screenshot Jimmy sent of a bridge transaction to an order created within minutes of the message, using amounts and timing visible on the Thorchain explorer. Jimmy then shared three Solana addresses that exposed a cluster of more than $12 million in Bybit funds being swapped in real time — moving from Bitcoin to Ether to Solana and finally to Tron.
Where did the leads lead?
Jimmy's disclosures produced verifiable on-chain corroboration beyond Bybit. He mentioned a team that had roughly $300,000 frozen in 2024; ZachXBT located the freeze on-chain and found the actual figure was 332,000 USDC stolen in the November 2023 Poloniex exploit, a hack that drained more than $100 million and that researchers have tied to Lazarus Group.
Jimmy also claimed he had laundered $3 million in fraud proceeds for another client. ZachXBT traced those funds to a hot wallet used by Huione Guarantee, the Telegram marketplace banned in May 2025, whose parent conglomerate the U.S. Treasury's FinCEN targeted over alleged laundering of at least $4 billion. Chinese authorities arrested former Huione Group chairman Li Xiong after Cambodia deported him.
ZachXBT said he passed his findings immediately to trusted private-sector investigators and to law enforcement assigned to the case, and that sensitivity around the investigation prevented him from publishing sooner.
Is this a one-off?
No. ZachXBT says he has helped action more than $75 million in freezes tied to North Korean incidents since 2022. Paradigm hired him as an incident response advisor in February 2025, with co-founder Matt Huang crediting him with returning more than $350 million to victims of hacks and scams. He funds his riskier cases through grants from foundations and individual donations.
With the Bitget hack showing the same laundering pattern re-emerging in public Telegram and Discord groups, pressure is likely to grow on stablecoin issuers and exchanges to shorten the window between attribution and freezes.
via trmlabs.com (Original)
More from Daniel Okafor
Show full bio
Correspondent covering industry trends and analytics at Mempool Brief.
435 articles