ZachXBT Traces $12 Million from Bybit Exploit to Chinese Laundering Syndicate
Investigative journalist ZachXBT has traced over $12 million in funds linked to the Bybit exploit in 2025. In a post dated October 5, ZachXBT detailed how he infiltrated a Chinese money laundering syndicate by posing as a crypto client. The network is alleged to have laundered more than $1 billion from various exploits, including those associated with the Lazarus group.
ZachXBT's investigation began on March 6, 2025, when he sent 349,700 USDC from a new Ethereum address to a contact using the alias Jimmy Green. By building trust with this contact, he gained insights into upcoming movements of stolen Bybit funds, including warnings about transfers to Solana. On March 12, 2025, ZachXBT linked a screenshot of a cross-chain bridge to a transaction recorded in the THORChain explorer.
The investigator identified a cluster of addresses on Solana, Bitcoin, Ethereum, and Tron containing over $12 million from the Bybit exploit. Additionally, Tether froze 442,000 USDT connected to these movements. ZachXBT also mentioned a team whose funds were frozen in 2024, coinciding with an on-chain freeze of 332,000 USDC linked to the Poloniex exploit.
The broader context of the case involves an FBI alert dated February 26, 2025, which reported that North Korea stole approximately $1.5 billion in virtual assets from Bybit around February 21. The FBI labeled the malicious activity as TraderTraitor and advised blocking transactions tied to the addresses used in the laundering.