ZachXBT infiltrates laundering ring with $349,700 USDC stake
Blockchain investigator ZachXBT took an unconventional approach to tracking stolen funds, directly engaging with a suspected laundering ring linked to North Korea’s Lazarus Group. On October 5, 2026, ZachXBT revealed he had fronted $349,700 in USDC to gain trust with a contact inside a Chinese organized crime syndicate. The group is believed to have laundered funds stolen from the Bybit exchange in February 2025, where approximately $1.5 billion was taken.
The operation began on March 6, 2025, when ZachXBT connected with an individual using the alias “Jimmy Green.” By providing USDC upfront, ZachXBT earned Jimmy Green’s confidence, who then shared specific Solana addresses. This intelligence helped ZachXBT trace funds across blockchains, leading to the identification of a wallet cluster holding over $12 million tied to the Bybit hack. Tether subsequently froze 442,000 USDT linked to these funds.
The syndicate’s operations reportedly spanned Hong Kong and mainland China, playing a key role in laundering the stolen Bybit funds. ZachXBT’s undercover work carried significant risks, but it resulted in the freezing of more than $75 million in North Korea-linked assets since 2022. This case highlights the challenges and potential impacts of independent investigators working outside traditional law enforcement channels.
Stablecoins like USDT serve as a critical choke point in laundering routes. Tether’s ability to freeze funds at the issuer level adds a layer of risk for criminals relying on stablecoins. While the frozen amount represents a small fraction of the $1.5 billion Bybit hack, it underscores the importance of stablecoins in disrupting illicit financial flows.