ZachXBT Exposes Chinese Network Laundering North Korean Hack Funds
Blockchain investigator ZachXBT infiltrated a Chinese laundering network handling stolen cryptocurrency for North Korea-linked operators. Posing as a customer, he risked $349,700 of his own USDC to gain access to the group. The operation began after the February 2025 Bybit breach, which the FBI attributed to North Korean actors. ZachXBT alleges the network processed over $1 billion across multiple exploits connected to the Lazarus Group, though this figure has not been independently confirmed.
ZachXBT identified more than 15 accounts in public Telegram and Discord groups seeking help with transactions linked to stolen Bybit funds. He established an ongoing relationship with a Telegram operator using the alias “Jimmy Green.” On March 6, 2025, ZachXBT funded a fresh Ethereum address with 349,700 USDC and began exchanging funds for USDT on Tron. Each order cost roughly 5%, with no guarantee the counterparty would return the funds.
One Ethereum address supplied during the transactions had received gas from a wallet ZachXBT traced directly to Bybit exploit proceeds. The access soon produced advance information about fund movements. ZachXBT claims Green told him Bybit-linked assets would move into Solana one day before the corresponding transactions appeared onchain.
A March 12 exchange gave ZachXBT another point of comparison. Green sent a screenshot of a cross-chain transfer, and the transaction amount and timing matched a THORChain order created within minutes of the message. Three Solana addresses supplied during the conversations then exposed more than $12 million in Bybit-linked assets moving through Bitcoin, Ethereum, Solana, and Tron.
The laundering problem has continued into 2026. ZachXBT recently linked wallets from the September Bitget exploit to suspected North Korean actors, while separate Lazarus-linked wallets moved more than $30 million through Hyperliquid earlier this year. ZachXBT waited roughly 18 months before publishing details of the undercover operation while related investigations remained active.