ZachXBT uncovers $1 billion laundering network behind Bybit and Bitget hacks
Crypto investigator ZachXBT has exposed a Chinese money-laundering syndicate linked to North Korea’s Lazarus Group, which has moved over $1 billion in stolen funds. ZachXBT spent months posing as a client within the network, gathering intelligence that helped freeze proceeds from the February 2025 Bybit breach, where approximately $1.5 billion was stolen.
ZachXBT identified more than 15 accounts in Telegram and Discord channels offering to launder money tied to the Bybit hack. He contacted an operator using the handle “Jimmy Green” and built trust through real transactions. On March 6, 2025, ZachXBT sent $3.497 million in USDC to a blacklisted Ethereum address linked to the Bybit hack, accepting a 5% loss risk on each transaction.
Through his interactions, Jimmy provided three Solana addresses holding over $12 million in Bybit funds. ZachXBT tracked these funds as they moved between Bitcoin, Ether, Solana, and Tron. Tether later froze about 442,000 USDT tied to those wallets. Additionally, ZachXBT verified older claims, such as a $300,000 freeze in 2024, and discovered wallets connected to Huione Guarantee, a marketplace sanctioned by the U.S.
Following the September 2026 Bitget hack, where $387.5 million was stolen, CEO Gracy Chen named North Korea as the likely culprit. Blockchain firm Elliptic linked the stolen Bitget funds to addresses used in the 2025 Bybit theft, noting a common pattern among North Korean hackers. ZachXBT flagged five accounts in the Bitget laundering effort, including one called “lolo,” who also handled proceeds from the $292 million Kelp DAO exploit in April.