ZachXBT Undercover Sting Traces Bybit Hack Funds to Lazarus-Linked Network
Blockchain investigator ZachXBT conducted an undercover operation to trace funds stolen in the February 2025 Bybit hack, which was attributed to North Korean hackers linked to the Lazarus Group. ZachXBT posed as a client and transferred 349,700 USDC to an Ethereum address to infiltrate a suspected money-laundering network. The operation helped uncover a wallet cluster containing over $12 million in Bybit-linked funds, prompting Tether to freeze 442,000 USDT connected to the cluster.
ZachXBT contacted a network operator known as “Jimmy Green” through public Telegram and Discord groups. The investigator shared details of the operation in an X thread on Oct. 5, 2026, revealing that the sensitivity of the work delayed its publication. The operation involved tracking transactions across Bitcoin, Ethereum, Solana, and Tron, with the operator claiming to have laundered nearly all of the stolen $1.5 billion ETH, a claim not independently confirmed.
The FBI attributed the Bybit theft to North Korean actors, with Chainalysis estimating that North Korean hackers stole $2.02 billion in 2025. The operation also revealed other illicit flows, including 332,000 USDC from the 2023 Poloniex hack and $3 million traced to a wallet associated with Huione Guarantee, a group later sanctioned by the U.S. Treasury for laundering North Korean cyber heists.
The investigation highlights the challenges of tracking stolen crypto assets across multiple blockchains. While Bybit reported that 77% of the stolen funds remained traceable, attribution to specific operators remains difficult. As of Oct. 6, no law enforcement agencies have named the operator or independently confirmed the scale of the alleged laundering network.