Skip to content
Back to Guavy Wire
Crypto

ZachXBT Exposes Chinese Syndicate Laundering Millions for North Korea's Lazarus Group

Instruments
BTC ETH USDT SOL USDC
Share

ZachXBT, a well-known blockchain investigator, spent months posing as a client within a Chinese organized crime syndicate that laundered over $1 billion in stolen cryptocurrency for North Korea's Lazarus Group. His investigation, detailed in an Oct. 5 thread on X, involved funding an Ethereum address with $349,700 in USDC and accepting a 5% loss on each transaction to build trust with a syndicate operator named "Jimmy Green." ZachXBT's infiltration began shortly after the February 2025 Bybit breach, which resulted in the theft of roughly $1.5 billion, attributed to North Korean hackers.

During his undercover operation, ZachXBT observed more than 15 accounts in public Telegram and Discord channels seeking help in processing orders tied to stolen funds. On March 6, 2025, he funded a new address with 349,700 USDC on Ethereum to conduct transactions with Jimmy Green. The address provided by Jimmy had been linked to the Bybit exploit funds, as labeled on a public Bybit exploit blacklist site. ZachXBT completed several transactions to build trust, during which Jimmy began discussing the movement of Bybit funds for North Korea and sharing details about their operations in Hong Kong and mainland China.

The intelligence gathered from these chats proved valuable. On March 12, 2025, ZachXBT matched a screenshot Jimmy sent of himself bridging funds to an order created within minutes of the message, using amounts and timing visible on the Thorchain explorer. Jimmy later shared three Solana addresses that exposed a cluster of more than $12 million in Bybit loot being swapped in real time. The investigator watched as the funds moved from Bitcoin to Ether, then to Solana, and finally to Tron. Tether later froze 442,000 USDT linked to this cluster.

The syndicate's operations were not limited to the Bybit breach. ZachXBT also linked Chinese actors to laundering proceeds from the $387.5 million Bitget exploit in September 2026. The investigation further revealed a Cambodia connection, with Jimmy admitting to laundering $3 million in fraud proceeds for a different client. ZachXBT traced these funds to a hot wallet used by Huione Guarantee, a Telegram marketplace banned in May 2025 for selling laundering services and stolen data.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc