Investigator Traces $12 Million from Bybit Hack Using Undercover Tactics
On-chain investigator ZachXBT uncovered a significant trail of funds linked to the $1.5 billion Bybit hack in February 2025 by posing as a customer. He traced over $12 million in funds and contributed to freezing some of them. ZachXBT began his investigation after the hack, monitoring more than 15 accounts on Telegram and Discord that were seeking help with transactions involving stolen funds. This led him to a China-based criminal network allegedly connected to the Lazarus Group, known for laundering over $1 billion from various attacks.
To gather information, ZachXBT transferred 349,700 USDC to a new Ethereum wallet, posing as a customer. He conducted multiple transactions with an individual using the alias “Jimmy Green,” risking about $350,000 in the process. Despite the risk of losing the funds, ZachXBT continued his investigation, comparing transaction details shared with on-chain activity. In March 2025, he identified a recipient address linked to the Bybit hack, which was also on Bybit’s blacklist.
Three Solana addresses provided by Jimmy helped ZachXBT identify a cluster of over $12 million in Bybit-linked funds moved across Bitcoin, Ethereum, Solana, and Tron. Tether subsequently froze 442,000 USDT tied to this cluster. ZachXBT noted that Jimmy’s claims about laundering most of the stolen $1.5 billion were consistent with the observed activity. Although the investigation’s details are now public, ZachXBT had shared his findings with law enforcement earlier due to the sensitive nature of the case.
ZachXBT also revealed that he had helped freeze a total of $75 million in funds across various North Korea-linked incidents since 2022. His efforts highlight the critical role of on-chain investigators in tracking and recovering stolen cryptocurrency assets.