ZachXBT exposes Chinese syndicate laundering $1.5B from Bybit hack
Blockchain investigator ZachXBT revealed how he infiltrated a Chinese crypto money laundering syndicate linked to the $1.5 billion Bybit hack in 2025. The operation began after North Korean hackers, known as the Lazarus Group, stole the funds. ZachXBT posed as a customer, fronting $350,000 of his own money in USDC to gain the trust of a key figure named Jimmy Green. The goal was to track the illicit flow of funds and gather actionable intelligence.
Through his undercover work, ZachXBT discovered that Green’s group was responsible for laundering nearly all of the $1.5 billion in Ethereum stolen from Bybit. Green boasted that the team’s methods ensured the funds wouldn’t be frozen, claiming they were “professional in making partitions.” The investigator also traced $12 million in Bybit exploit funds as they were swapped between BTC, ETH, SOL, and TRX. Additionally, he linked Green’s operations to a $3 million laundering job for another customer through Huione Guarantee, a peer-to-peer marketplace known for handling over $70 billion in crypto over five years.
The intelligence ZachXBT gathered helped freeze $75 million in stolen funds, including 442,000 USDT frozen by Tether. Despite the risks, losing 5% on every completed exchange and risking exposure, ZachXBT emphasized the importance of his work. He called for support from foundations and individuals to continue his investigations, stressing that his operation was self-funded and highly sensitive.