ZachXBT Infiltrates Crime Syndicate Laundering $1B+ for North Korea
Independent blockchain investigator ZachXBT (ZachXBT) recently infiltrated a Chinese organized crime group by posing as a client, using approximately $349,700 in USDC to gather intelligence. The group is suspected of laundering over $1 billion in cryptocurrency stolen by North Korea’s Lazarus Group from multiple hacks. The investigation was triggered by the February 2025 Bybit exploit, where about $15 billion in assets were stolen, an incident linked to another North Korean hacker group, TraderTraitor.
ZachXBT began the investigation by identifying over 15 accounts on Telegram and Discord offering to assist in moving stolen funds. Pretending to be a customer, ZachXBT engaged with one account, using the alias Jimmy Green, to facilitate transactions. Through these exchanges, ZachXBT traced the stolen funds across multiple blockchains, including Ethereum, Tron, and Solana.
The investigator confirmed the group’s involvement in laundering the Bybit stolen funds by cross-referencing on-chain data with information provided by Jimmy Green. Key evidence included screenshots of transactions and the movement of over $12 million in assets. ZachXBT also shared critical intelligence with law enforcement and private investigators, leading to the freezing of 442,000 USDT by Tether.
ZachXBT has previously contributed to freezing over $75 million in funds linked to North Korean cybercrime since 2022. Despite risks, including potential scams and personal danger, the investigator’s undercover work helped expose the group’s operations and disrupted its illicit activities.