ZachXBT Exposes Chinese Launderers Tied to Lazarus Group and Bybit Hack
Blockchain investigator ZachXBT revealed on Monday that he infiltrated a Chinese money-laundering group linked to North Korea’s Lazarus Group. Over several weeks, ZachXBT posed as a client to gather intelligence on the crew, which he claims has laundered over $1 billion, including a significant portion of the $1.5 billion stolen from Bybit in February 2025. To gain the group’s trust, he invested $349,700 of his own money, losing 5% on every order.
ZachXBT identified key figures within the group, including an individual using the alias “Jimmy Green” on Telegram. Through conversations, ZachXBT discovered that the group was responsible for laundering much of the Bybit hack funds. Jimmy provided insights into the group’s operations, such as the movement of funds and their laundering methods. ZachXBT’s findings led to the freezing of Bybit-linked funds and helped attribute other illicit flows.
The investigation also uncovered new laundering techniques, including the use of Uniswap liquidity pools seeded with illiquid tokens. ZachXBT shared his findings with private-sector investigators and law enforcement, contributing to over $75 million in DPRK-related freezes since 2022. The real identity of Jimmy Green remains undisclosed, and no law-enforcement agency has commented publicly.