ZachXBT uncovers $1B crypto laundering network tied to Lazarus Group
Blockchain investigator ZachXBT went undercover to expose a crypto laundering syndicate linked to the Lazarus Group, allegedly moving over $1 billion in stolen funds. In October 2023, ZachXBT disclosed his investigation, claiming he infiltrated the network by posing as a client and funding repeated stablecoin trades. He provided 349,700 USDC to build trust with a contact using the alias Jimmy Green, who later shared details about moving stolen funds from the Bybit exploit in 2025.
The investigation began after the February 2025 Bybit hack, where ZachXBT noticed multiple accounts seeking help with orders linked to stolen funds. After contacting Jimmy Green, he funded an Ethereum address with 349,700 USDC for exchanges involving USDT on Tron. Over time, the contact shared information about moving Bybit funds, including a cross-blockchain transfer to Solana, which ZachXBT verified through THORChain transactions. The investigator traced a cluster of over $12 million in Bybit exploit funds moving across Bitcoin, Ethereum, Solana, and Tron.
ZachXBT also reported that Tether froze 442,000 USDT linked to the cluster. The syndicate's activities extended beyond Bybit, with references to a team whose funds were frozen in 2024, matching an on-chain freeze of 332,000 USDC tied to the Poloniex exploit. The FBI had previously attributed the Bybit theft to North Korea, estimating $1.5 billion in stolen assets. ZachXBT's findings, however, remain separate from the FBI's official attribution.
ZachXBT emphasized the risks and costs of his investigation, losing 5% on each order while fronting 349,700 USDC. He appealed for continued support to fund high-risk investigations, stating that intelligence from these trades helped freeze funds tied to the Bybit exploit.