ZachXBT Exposes Chinese Syndicate Laundering $1B in DPRK-Linked Crypto
Blockchain investigator ZachXBT has revealed an undercover operation targeting a Chinese crime syndicate linked to over $1 billion in crypto laundering for North Korea's Lazarus Group. The investigation, which began after the $1.5 billion Bybit exploit in February 2025, involved ZachXBT posing as a client to gather intelligence on the syndicate's operations.
ZachXBT contacted a suspect, identified by the Telegram alias Jimmy Green, who provided cryptocurrency addresses for laundering stolen funds. ZachXBT transferred 349.7K USDC to Jimmy Green's addresses, tracing them to Bybit exploit funds. The investigation uncovered Solana addresses holding over $12 million in Bybit exploit funds, with 442K USDT later frozen by Tether.
Jimmy Green also disclosed details about laundering $3 million in fraud proceeds for another client, traced to a hot wallet belonging to the sanctioned Huione Guarantee. ZachXBT's findings were shared with law enforcement, leading to over $75 million in freezes connected to DPRK incidents since 2022. The operation highlighted the syndicate's use of multiple blockchain networks and laundering techniques, including Uniswap liquidity pools.
ZachXBT's work was supported by grants and donations, enabling high-risk investigations. The investigator emphasized the personal risks involved in dealing with the syndicate but noted the importance of exposing such operations to support law enforcement efforts.