ZachXBT exposes Chinese laundering crew linked to Bybit and Bitget thefts
Crypto investigator ZachXBT recently revealed that he spent months posing as a client within a Chinese money-laundering syndicate, uncovering a network that has moved over $1 billion in stolen funds for North Korea’s Lazarus Group. His findings played a crucial role in freezing proceeds from the February 2025 Bybit breach, which saw approximately $1.5 billion stolen. ZachXBT identified more than 15 accounts in Telegram and Discord channels offering to process money tied to the theft. He established contact with an operator using the handle “Jimmy Green” and built trust through real transactions.
On March 6, 2025, ZachXBT sent $3.497 million in USDC to a blacklisted Ethereum address linked to the Bybit hack, accepting a 5% loss risk on each transaction. Through his interactions, Jimmy provided three Solana addresses holding over $12 million in Bybit funds. ZachXBT tracked these funds as they moved across Bitcoin, Ether, Solana, and Tron. Tether later froze about 442,000 USDT tied to those wallets. Other tips led ZachXBT to verify older claims, including a $300,000 freeze in 2024 and wallets connected to Huione Guarantee, a U.S.-sanctioned marketplace.
ZachXBT also uncovered details about the September 2026 Bitget hack, where $387.5 million was stolen. The blockchain firm Elliptic linked the stolen Bitget funds to addresses used in the 2025 Bybit theft, suggesting North Korean hackers reused the same laundering routes. ZachXBT flagged five accounts involved in the Bitget laundering effort, including one called “lolo,” who also handled proceeds from the $292 million Kelp DAO exploit in April. Since 2022, ZachXBT’s work has helped freeze over $75 million tied to North Korea-linked incidents.