ZachXBT Traces Bybit Hack Funds to Lazarus-Linked Laundering Network
Blockchain investigator ZachXBT has uncovered a Chinese laundering network linked to North Korea’s Lazarus Group, which allegedly moved over $1 billion for hackers. In an undercover operation costing $349,700, ZachXBT posed as a client and traced more than $12 million in Bybit-linked funds across multiple blockchains. His efforts led Tether to freeze 442,000 USDT connected to the network.
ZachXBT’s investigation began after he found accounts in Telegram and Discord groups seeking help with transactions tied to the Bybit hack. He identified an operator using the alias “Jimmy Green,” whose chats and wallet details helped map Bybit-linked funds. The group claimed responsibility for laundering nearly all of the $1.5 billion stolen from Bybit in the February 2025 attack, though this has not been independently confirmed by law enforcement.
The FBI previously attributed the Bybit theft to North Korea’s state-backed TraderTraitor actors. Chainalysis estimated that North Korean hackers stole $2.02 billion in crypto during 2025, a record high. ZachXBT shared his findings with private-sector investigators and law enforcement, facilitating over $75 million in freezes tied to North Korea-linked incidents since 2022.
As of October 2026, no public criminal charges or court filings have named “Jimmy Green” or independently confirmed the alleged network’s size and identity. Fresh North Korea-linked thefts, including a $387 million breach at Bitget in September 2026, remain under active tracing.