ZachXBT Exposes Chinese Syndicate Laundering Bybit Hack Funds for North Korea
On-chain investigator ZachXBT revealed on October 5, 2026, that he spent weeks in early 2025 posing as a client of a Chinese laundering syndicate linked to North Korean exploit proceeds, including the February 2025 Bybit hack. The FBI had previously attributed the $1.5 billion Bybit hack to North Korea, referring to the activity as TraderTraitor.
ZachXBT traced $1.5 billion in stolen funds through multiple blockchain transactions, identifying a cluster of $12 million moving across BTC, ETH, Solana, and Tron. He funded a new Ethereum address with 349,700 USDC, swapped it for USDT on Tron, and identified gas-funder 0xbcb4 as the source of the exploit. The investigation led to the freezing of 442,000 USDT in a Uniswap V2 USDT/WAFF pool.
ZachXBT interacted with an alias named Jimmy Green, who provided details about the laundering operations, including a next-day transfer to Solana that matched a THORChain order. Jimmy also claimed his team laundered most of the $1.5 billion, a claim ZachXBT did not independently verify but found consistent with his observations. The investigation also linked addresses to the Poloniex exploit and a sanctioned hot wallet of Huione Guarantee.
The sensitivity of the case kept the findings private until October 5, 2026. ZachXBT mentioned that since 2022, he has helped action more than $75 million in freezes tied to North Korean incidents, though this case cost him the 5% spread on fronted money and personal risks he did not detail.