How ZachXBT traced Bybit hack funds to a Lazarus-linked network
Blockchain investigator ZachXBT has said an undercover operation costing him $349,700 exposed an alleged Chinese laundering network that moved more than $1 billion for North Korea-linked hackers and helped trace funds from Bybit’s $1.5 billion 2025 theft.
- ZachXBT says he spent $349,700 posing as a client inside an alleged Lazarus-linked laundering network.
- His investigation identified more than $12 million in Bybit-linked funds moving across several public blockchains.
- ZachXBT says Tether later froze 442,000 USDT connected to wallets uncovered during his undercover operation.
- The FBI previously attributed the $1.5 billion Bybit theft to North Korea’s state-backed TraderTraitor actors.
- Chainalysis estimates North Korean hackers stole $2.02 billion in crypto during 2025, a new record.
ZachXBT said in an Oct. 5 X thread that he posed as a paying customer after finding more than 15 accounts in public Telegram and Discord groups seeking help with transactions tied to the Bybit hack. He said the work led him to an operator using the alias “Jimmy Green,” whose chats and wallet details later helped map Bybit-linked funds across several networks.
ZachXBT says a $349,700 sting opened the Bybit trail
After contacting the operator in late February 2025, ZachXBT said he presented himself as a customer holding marked crypto and asked to exchange funds for USDT on Tron. By March 6, he had funded a fresh Ethereum address with 349,700 USDC and accepted a 5% loss on each order while building trust. He described the group as a “Chinese organized crime syndicate” and said it had “laundered $1B+ across multiple exploits for Lazarus Group.”
The first on-chain link came from the payment route used for one of those trades, according to his account. ZachXBT said the receiving address had been funded for gas by a wallet traceable to the Bybit exploit and listed on Bybit’s public blacklist. Later conversations produced advance details about where stolen assets would move, allowing him to compare private messages with public transaction times and amounts.
On March 12, the operator sent a screenshot showing a swap of 1.192 BTC for 51.73 ETH, according to reports reviewing the thread. ZachXBT matched the timing and amount to a THORChain transaction that traced back through intermediary wallets to Bybit-linked funds. The operator later claimed, “This time, almost all the 1.5 billion eth was laundered by our team,” a statement that has not been independently confirmed by law enforcement.
More than $12 million in wallets led to a USDT freeze claim
Three Solana addresses provided during the conversations exposed a wallet cluster containing more than $12 million in Bybit-linked funds, ZachXBT said. His tracing showed assets moving from Bitcoin to Ether, then Solana and Tron while the transactions were occurring. He said Tether later froze 442,000 USDT connected to the cluster
Tether has separately confirmed larger freezes tied to the Bybit theft. On March 26, 2025, the T3 Financial Crime Unit, a partnership involving Tether, TRON and TRM Labs, announced that it had frozen nearly $9 million connected to the hack. By Oct. 31, 2025, Tether said T3-related cases had frozen $19 million linked to the Bybit incident. Neither public release broke out the 442,000 USDT amount described by ZachXBT or linked it to the “Jimmy Green” operation.
The investigator said information from the same contact pointed to other illicit flows. One case involved 332,000 USDC from the 2023 Poloniex hack that had been frozen in 2024, while another $3 million batch was traced to a wallet associated with Huione Guarantee. U.S. Treasury records later described Huione Group as a critical laundering node for proceeds from North Korean cyber heists and cut the Cambodia-based group off from the U.S. financial system in 2025.
Official records confirm North Korea behind the Bybit hack
The FB said North Korea was responsible for the Feb. 21, 2025 Bybit theft in a public notice issued five days after the attack. The agency said actors it tracks as TraderTraitor stole approximately $1.5 billion in virtual assets, converted part of the haul into Bitcoin and other assets, and spread funds across thousands of addresses on multiple blockchains. The FBI asked exchanges, bridges, analytics firms and other crypto services to block transactions connected to listed attacker addresses.
Bybit said in its forensic update that compromised credentials belonging to a Safe developer allowed the attacker to gain unauthorized access to Safe infrastructure and deceive signers into approving a malicious transaction. Reviews by Verichains and Sygnia Labs found no evidence that Bybit’s core infrastructure had been compromised, according to the exchange. Its incident timeline put the loss at $1.46 billion, including 401,347 ETH and several liquid-staking tokens.
ZachXBT submitted evidence to Arkham linking the attack to Lazarus Group shortly after the breach and received a 50,000 ARKM bounty. A later crypto.news report tracking the stolen Bybit funds cited CEO Ben Zhou as saying 77% remained traceable on March 4, while 20% had gone dark and 3% had been frozen. Zhou said 83% of the stolen assets had been converted into Bitcoin, with a large portion moving through THORChain.
Chainalysis later estimated that North Korean hackers stole $2.02 billion in crypto during 2025, pushing their cumulative total to at least $6.75 billion. The firm said the Bybit breach accounted for $1.5 billion of the year’s stolen funds and identified Chinese-language laundering services, bridges and mixing services among recurring tools in North Korea-linked fund movements.
What happens next depends on law enforcement follow-up
ZachXBT said he shared the Bybit findings with private-sector investigators and law-enforcement officers assigned to the case while the operation was still active. He said the sensitivity of the work kept him from publishing the details until Oct. 5, 2026. His public account says he has helped facilitate more than $75 million in freezes tied to North Korea-linked incidents since 2022.
Public releases from the FBI, U.S. Treasury and Tether reviewed as of Oct. 6 do not identify “Jimmy Green” or independently confirm that one Chinese network laundered more than $1 billion for Lazarus Group. No public criminal charge or court filing located in those records names the operator described in ZachXBT’s thread, leaving the alleged network size and identity attributed to his investigation.
Fresh North Korea-linked thefts remain under active tracing. Chainalysis said on Oct. 1 that investigators were working with Bitget and law-enforcement partners after $387 million was stolen from the exchange on Sept. 24, 2026. The firm attributed that attack to North Korean actors, said the theft pushed their 2026 crypto haul above $1 billion, and stated that investigators would keep monitoring the stolen funds and sharing intelligence with partners in the coming weeks.