Blockchain investigator ZachXBT says he infiltrated a Chinese cryptocurrency laundering network allegedly connected to North Korea's Lazarus Group following the $1.5 billion Bybit hack.
According to the investigator, his operation combined private conversations with publicly available blockchain data to identify individuals involved in moving stolen cryptocurrency.
He also said his findings helped cryptocurrency companies freeze stolen funds and provided intelligence to investigators and law enforcement.
The claims represent ZachXBT's assessment based on his investigation and have not been independently confirmed in full by law enforcement.
Crypto Laundering Network Processed More Than $1 Billion
In an October 5 disclosure on X, ZachXBT said the syndicate had laundered more than $1 billion across multiple cryptocurrency exploits.
The figure is an estimate attributed to the investigator rather than a confirmed total from law enforcement.
Following the February 2025 Bybit theft, ZachXBT said he identified more than 15 accounts seeking assistance with transactions involving stolen Bybit funds in public Telegram and Discord communities.
He eventually approached an operator using the alias "Jimmy Green" while posing as a potential client.
The investigation allowed ZachXBT to gain access to conversations in which the operator allegedly discussed cryptocurrency transfers and laundering services.
Undercover Operation Traced Crypto Transfers
On March 6, 2025, ZachXBT said he funded a new Ethereum wallet with approximately 349,700 USDC.
He then began exchanging USDC for USDT on the Tron network.
According to his account, he accepted losses of approximately 5% per transaction to establish credibility with the operators and maintain access to the network.
The operator subsequently shared wallet addresses, screenshots, and information about planned cryptocurrency transfers.
ZachXBT said "Jimmy Green" claimed that his team had processed a significant portion of the stolen Bybit funds and operated from Hong Kong and mainland China.
However, those statements came from private conversations and do not independently establish the operator's identity or physical location.
Matching Private Chats With Blockchain Transactions
One of the most important parts of the investigation involved comparing statements made in private chats with publicly recorded blockchain transactions.
ZachXBT reported that the operator's receiving wallet obtained cryptocurrency for transaction fees from an address associated with the Bybit theft.
A screenshot shared on March 12 reportedly matched a THORChain transaction based on both its timing and amount.
The investigation also identified a Telegram account identifier appearing in separate screenshots, which ZachXBT said helped connect the operator's private profile with activity in a public THORChain group.
This combination of off-chain intelligence and on-chain transaction data allowed the investigator to build stronger links between individual accounts and cryptocurrency wallets.
More Than $12 Million in Bybit Funds Traced
ZachXBT said three Solana addresses helped identify a wallet cluster containing more than $12 million in funds connected to the Bybit theft.
The cryptocurrency moved across multiple blockchain networks, including:
- Bitcoin
- Ethereum
- Solana
- Tron
Moving assets between different blockchain networks can make investigations more complicated by introducing additional transactions and wallets.
However, investigators can still correlate transactions using characteristics such as:
- Transfer amounts
- Transaction timing
- Wallet relationships
- Cross-chain swaps
- Funding sources
- Exchange activity
In this case, ZachXBT said these correlations helped connect transactions across multiple networks.
Tether Froze $442,000 in USDT
According to ZachXBT, Tether later froze approximately 442,000 USDT associated with the identified wallet cluster.
The investigator also said he shared intelligence with investigators and law enforcement to support additional attempts to freeze stolen cryptocurrency.
The available reporting does not include a separate Tether statement independently confirming ZachXBT's role in that specific freeze.
Asset freezing is an important part of cryptocurrency investigations because stolen funds can potentially be blocked before they are converted into fiat currency or moved through additional laundering services.
FBI Links Bybit Theft to North Korea
The FBI attributed the February 21, 2025, Bybit theft to North Korea.
In its February 26 advisory, the agency referred to the activity as TraderTraitor and warned that stolen cryptocurrency was being rapidly dispersed across thousands of addresses across multiple blockchain networks.
The FBI said the stolen assets were being converted and moved through multiple cryptocurrency ecosystems in an effort to conceal their origins.
The Bybit incident became one of the largest cryptocurrency thefts ever recorded, with approximately $1.5 billion in digital assets stolen.
Blockchain Tracing Remains a Critical Investigative Tool
The investigation demonstrates how public blockchain records can be combined with traditional intelligence-gathering techniques to investigate cryptocurrency laundering operations.
Although blockchain transactions are publicly visible, identifying the people controlling individual wallets can be significantly more difficult.
Investigators can improve attribution by combining:
- Blockchain transaction analysis
- Cryptocurrency exchange data
- Messaging-platform intelligence
- Wallet clustering
- Cross-chain transaction analysis
- Undercover interactions
- Open-source intelligence
The combination can reveal relationships that would not necessarily be visible from blockchain transactions alone.
ZachXBT Says His Investigations Helped Freeze More Than $75 Million
ZachXBT said his investigations have contributed to the freezing of more than $75 million associated with North Korean cryptocurrency incidents since 2022.
His latest investigation has also prompted calls for greater support for independent blockchain investigators, who can face financial and personal risks while investigating organized cryptocurrency theft and laundering operations.
However, the claims and attribution described in the investigation still require further independent confirmation.
Freezing Stolen Cryptocurrency Is Not the Same as Recovery
While freezing cryptocurrency can prevent criminals from moving or liquidating stolen assets, it does not automatically mean that the funds will be returned to victims.
The recovery process can involve exchanges, stablecoin issuers, law enforcement agencies, courts, and other organizations.
Nevertheless, quickly identifying wallet clusters can significantly improve the chances of preventing stolen assets from disappearing into additional laundering channels.
Key Takeaway
The ZachXBT investigation highlights the growing importance of blockchain intelligence, cross-chain tracing, and cryptocurrency transaction analysis in investigations involving major cybercrime operations.
The case also demonstrates that attackers attempting to hide stolen cryptocurrency can still leave valuable investigative clues through transaction timing, wallet relationships, cross-chain transfers, and interactions on messaging platforms.
Following the Bybit theft, the ability to connect private communications with public blockchain activity reportedly helped investigators identify wallet clusters and freeze portions of the stolen funds.
For cryptocurrency platforms and organizations exposed to digital-asset threats, real-time blockchain monitoring and rapid wallet attribution can be critical for disrupting laundering operations before stolen funds move beyond recovery.