ZachXBT Infiltrates Chinese Laundering Syndicate Tied to North Korea
In a daring undercover operation, crypto investigator ZachXBT posed as a client of a Chinese laundering syndicate to expose a major crypto exploit. On March 6, 2025, ZachXBT fronted 349.7K USDC, accepting a 5% loss on each transaction, to gather intelligence on a group laundering funds for North Korea's Lazarus Group. This operation helped freeze $12M+ in Bybit exploit funds and led to Tether freezing 442K USDT linked to the cluster.
ZachXBT's investigation targeted a group working for North Korea, identified as 'TraderTraitor' by the FBI. The group, operating through Telegram and Discord, was openly soliciting clients to launder stolen funds. By posing as a client, ZachXBT built trust with a key member named 'Jimmy Green' and uncovered details about their operations in Hong Kong and mainland China.
The investigation revealed a network of over 15 accounts involved in laundering funds from multiple exploits, including the $1.5B Bybit hack and the $387M Bitget hack. ZachXBT's findings have led to over $75M in freezes related to North Korean incidents since 2022. His work is funded through grants and donations, allowing him to take on high-risk cases like this one.
Throughout the operation, ZachXBT engaged in small talk with 'Jimmy Green,' discussing topics like mahjong, hunting, and family life. Despite the personal risk and financial loss, ZachXBT's efforts have significantly contributed to the tracking and freezing of illicit crypto funds.