ZachXBT Exposes Crypto Laundering Network Linked to Bybit Exploit
ZachXBT, a well-known onchain investigator, has uncovered a major crypto laundering operation linked to the Lazarus Group. The investigation began after the $1.5 billion Bybit exploit in February 2025, which was attributed to the DPRK-linked group TraderTraitor. ZachXBT infiltrated a Chinese organized crime syndicate by posing as a client, fronting $349,700 in USDC for the undercover operation.
During the investigation, ZachXBT connected with an individual using the alias “Jimmy Green” on Telegram. Jimmy provided details about laundering Bybit funds for DPRK actors and shared information about the group’s operations in Hong Kong and mainland China. The investigator also learned about the movement of funds to Solana, which was confirmed the following day. Jimmy claimed his team had laundered most of the $1.5 billion stolen from Bybit, a claim consistent with ZachXBT’s observations.
ZachXBT identified a cluster containing more than $12 million in Bybit exploit funds, which were swapped across Bitcoin, Ethereum, Solana, and Tron. Around $442,000 in USDT linked to the cluster was later frozen by Tether. The investigation also uncovered laundering methods involving Uniswap liquidity pools and illiquid tokens. Additionally, ZachXBT discovered connections to the Poloniex exploit and fraud proceeds linked to Huione Guarantee, a sanctioned entity.
The operation was financially risky for ZachXBT, who lost 5% on each order and faced the possibility of the launderer disappearing with the funds. Since 2022, ZachXBT has helped freeze over $75 million related to DPRK incidents. The findings were shared with trusted investigators and law enforcement, but due to the sensitivity of the case, the details could not be published sooner.