ZachXBT Says He Spent $349,700 of His Own Money to Pose as a Client of an Alleged Bybit Laundering Network

ZachXBT Says He Spent $349,700 of His Own Money to Pose as a Client of an Alleged Bybit Laundering Network

On October 5, 2026, blockchain investigator ZachXBT said he put $349,700 of his own money into a fake identity to pose as a customer of an alleged cryptocurrency laundering network. He says the intelligence he gathered was shared with law enforcement and that it was linked to a freeze of 442,000 USDT by Tether.

USDT is a stablecoin, meaning a digital token built to track the U.S. dollar. Blocking funds means an issuer or exchange stops them from being moved or cashed out.

Everything about the network itself comes from ZachXBT. He has not named the people involved, and the claims have not been confirmed publicly.

The numbers in ZachXBT's account

  • $349,700 of his own money used to pose as a client, according to ZachXBT.
  • A 5% loss on each order he accepted to build trust, he said.
  • More than $12 million in Bybit hack proceeds he says he traced through three Solana addresses he was given.
  • A 442,000 USDT freeze by Tether, which he described as the clearest result of the investigation.
  • More than $1 billion laundered across several hacks for North Korea's Lazarus Group, which he alleged.

What his 12-part thread on X says

ZachXBT posted a 12-part account on X on October 5. He said the operation started after he noticed at least 15 accounts in public Telegram and Discord groups asking for help with orders he linked to funds stolen in the February 2025 Bybit hack. He said he contacted several of them, including one person using the Telegram alias "Jimmy Green."

He said he funded a new Ethereum wallet on March 6, 2025, to trade with that contact. Ethereum is a blockchain, meaning a public ledger that records transactions. The starting deal, he said, was to send USDC on Ethereum in exchange for USDT on Tron. Both tokens are dollar-linked digital assets.

He said he took a 5% loss on each order to earn trust. After repeated trades, he said the contact began telling him about planned movements of Bybit funds before they happened, including a move to Solana one day ahead of time.

In a separate post on October 5, he said roughly $170,000 connected to the Bitget exploit had recently been frozen on the Hyperliquid platform, which runs its own blockchain. That claim is also his alone.

ZachXBT said he passed his findings immediately to private-sector investigators and law enforcement working the case. "Due to sensitivity around the investigation, I was unable to publish sooner," he wrote.

What the blockchain records show

An Ethereum transaction recorded on the public blockchain explorer Etherscan shows the address ZachXBT identified receiving about 349,720 USDC on March 6, 2025. That record is public and matches the amount he described.

Etherscan also shows about 442,399 USDT at the Ethereum address he linked to the freeze. The address is labeled as a Uniswap V2 liquidity pool, which is a pool of funds used for trading on a decentralized exchange. A wallet balance by itself does not show that funds were frozen or who controls them, so the freeze and the link to Bybit remain ZachXBT's attribution.

The Bybit hack and the FBI's finding

The FBI attributed the theft of roughly $1.5 billion from Bybit, which happened on or about February 21, 2025, to North Korea. The agency called the operation "TraderTraitor." Bybit is a centralized cryptocurrency exchange, meaning a company that holds customers' funds and matches buyers and sellers.

The Defiant has previously reported that North Korean hackers moved more than $1 billion of the stolen Bybit funds, and that security researchers were concerned the funds were being split into many smaller transactions to make tracking harder.

What is confirmed and what is not

Supported by public records: an Ethereum address ZachXBT named received about 349,720 USDC on March 6, 2025, and holds about 442,399 USDT today. The FBI's attribution of the Bybit hack to North Korea is an official finding.

Not independently confirmed: the size of the laundering network, its nationality, its role for the Lazarus Group, the $12 million cluster traced through three Solana addresses, the 442,000 USDT freeze, the $170,000 Bitget freeze, and the claim that his findings caused any of it. ZachXBT has shared no names, no arrest records, and no public confirmation from Tether or law enforcement.

Why undercover work matters here

Stolen crypto moves quickly and crosses chains. ZachXBT described tracking funds across Bitcoin, Ethereum, Solana and Tron. Each hop makes it harder to follow, which is why investigators say laundering networks split funds into smaller pieces.

His account also shows a method that does not depend on catching someone in the act: posing as a customer to learn planned movements before they happen. If his description is accurate, that timing is what makes a freeze possible.

Sources

Newisty Editorial Team
Written by

Newisty Editorial Team

Technology · Crypto · Digital Economy
View all posts

Newisty Editorial Team covers technology, cryptocurrency, digital products, online platforms, developer tools and the wider digital economy. Our content is researched from official sources, company announcements, public documentation, market data and other primary or reputable sources. Articles are reviewed and edited before publication for clarity, accuracy and useful context.

Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!