ZachXBT Exposes $1 Billion Chinese Laundering Network Tied to North Korea
Blockchain investigator ZachXBT spent months undercover, posing as a client to infiltrate a Chinese money laundering network allegedly linked to North Korea’s Lazarus Group. He reported that the network laundered over $1 billion across multiple crypto exploits, including the $1.5 billion Bybit hack in February 2025. ZachXBT funded an Ethereum address with $349,700 in stablecoins to gain the trust of an operator known as Jimmy Green, who shared details about the group’s operations.
ZachXBT traced over $12 million in wallets connected to the Bybit hack, leading to the freezing of 442,000 USDT by Tether. The investigation also uncovered links to other hacks, such as the 2023 Poloniex hack and funds tied to Huione Guarantee. Tether’s T3 Financial Crime Unit had previously frozen $19 million related to the Bybit theft, though the 442,000 USDT figure was not publicly disclosed until now.
The FBI attributed the Bybit theft to North Korea, stating that actors tracked as TraderTraitor were responsible. ZachXBT shared his findings with law enforcement during the investigation but waited until October 2026 to publish details due to the case’s sensitivity. Public records from the FBI, Treasury, and Tether have not named the operator called Jimmy Green, and no court filings confirm the full scale of the laundering network.
Chainalysis reported that North Korean hackers stole $2.02 billion in crypto during 2025, bringing their total past $6.75 billion. Investigators are still tracing funds from the $387 million Bitget hack that occurred in September 2026.