ZachXBT’s Sting Operation Reveals North Korean Crypto Laundering Network
ZachXBT, a well-known on-chain investigator, took an unusual approach to tracking stolen cryptocurrency by posing as a client of a Chinese laundering group linked to North Korea. He wired $349,700 of his own money to gather intel that helped freeze funds tied to the February 2025 Bybit exploit, which caused $1.5 billion in losses. The FBI attributed the exploit to North Korean hackers known as TraderTraitor. ZachXBT identified the launderers as a Chinese gang working for North Korea, noting they were not particularly discreet in their operations.
ZachXBT began his investigation shortly after the Bybit hack by messaging accounts on Telegram and Discord that were offering to help move stolen funds. One of these individuals, going by "Jimmy Green," agreed to facilitate transactions in exchange for a fee. ZachXBT sent 349.7K USDC to an address provided by Jimmy, which was later traced to the Bybit exploit funds. Over several transactions, Jimmy revealed details about their operation, including plans to move funds to Solana and the involvement of a team based in Hong Kong and mainland China.
The investigation led to the freezing of 442,000 USDT linked to the laundered funds. ZachXBT also uncovered connections to other hacks, such as the Poloniex exploit and the Bitget hack, which was linked to North Korea. Additionally, he traced funds to Huione Guarantee, a Telegram marketplace involved in laundering services, which was later banned and linked to a Cambodian conglomerate under U.S. Treasury scrutiny.
ZachXBT's efforts have resulted in over $75 million in fund freezes related to North Korean incidents since 2022. His findings were shared with law enforcement and private-sector investigators, contributing to the broader understanding of cybercrime in the crypto space.