ZachXBT says posing as a client exposed a $1 billion crypto laundering syndicate

ZachXBT says posing as a client exposed a $1 billion crypto laundering syndicate

Investigator says he entered a laundering ring as a paid fake client

On October 5, on-chain investigator ZachXBT published an account of how he joined a Chinese syndicate that he says laundered more than $1 billion stolen in hacks tied to Lazarus Group, the hacking group linked to North Korea. His method was simple and unusual: he posed as a customer and put real money into trades to earn the group's trust.

ZachXBT said he provided 349,700 USDC to build a working relationship with a contact who uses the Telegram name Jimmy Green. USDC and USDT are stablecoins, which are crypto tokens designed to track the price of a traditional currency such as the dollar. He said he gave up 5% on every order he made as part of the investigation.

Key numbers in the disclosure

  • More than $1 billion: what ZachXBT says the syndicate laundered across multiple hacks tied to Lazarus Group.
  • 349,700 USDC: the amount he says he fronted as a fake client.
  • 5%: what he says he lost on each order.
  • More than $12 million: the size of the Bybit-linked cluster he says he traced across Bitcoin, Ethereum, Solana and Tron.
  • 442,000 USDT: the amount he says Tether later froze in connection with that cluster.
  • 332,000 USDC: an earlier freeze he says matched a 2024 exploit of the Poloniex exchange.

How he says he gained access to private conversations

ZachXBT said his investigation started after the February 2025 exploit of the Bybit exchange, when he noticed at least 15 accounts asking for help with orders in public Telegram and Discord groups. Those requests, he said, matched stolen funds he could see on the public blockchain ledger, where every transaction is permanently recorded.

He contacted several of those accounts. One turned out to be Jimmy Green. On March 6, 2025, he said, he funded a new Ethereum address with 349,700 USDC. The arrangement was to send his USDC on Ethereum in exchange for the contact's USDT on Tron, a different blockchain. He then made more of these swaps to build trust.

As the relationship deepened, he said the contact began discussing planned movements of Bybit funds for North Korea before those movements happened. The conversations also covered operations in Hong Kong and mainland China. In one example, the contact told him money would move to Solana, and the move happened the next day.

On March 12, 2025, the contact sent a screenshot of a transfer that crossed blockchains, which is money or data moving from one blockchain network to another. ZachXBT said he matched the amounts and timing to an order on the THORChain transaction explorer, created within minutes of the message. The contact also gave him three Solana addresses, which he says exposed a cluster of more than $12 million in Bybit hack funds moving through Bitcoin, Ethereum, Solana and Tron.

The FBI's account of the Bybit theft

In a public alert dated February 26, 2025, the FBI said North Korea stole about $1.5 billion in virtual assets from Bybit on or around February 21, 2025. The agency named the specific malicious activity TraderTraitor. At the time, it said some stolen assets had been turned into Bitcoin and other assets spread across thousands of addresses on several blockchains, and it urged private companies to block transactions tied to the laundering addresses.

Earlier reporting in October 2024 had described allegations involving a Chinese over-the-counter trader linked to laundering money for North Korean hackers. ZachXBT's latest account differs in method: it describes how he obtained information by becoming a trading counterparty himself.

What is confirmed and what is still unproven

Two things are supported by official records. ZachXBT did publish a disclosure on October 5. And the FBI has publicly said that North Korea took roughly $1.5 billion from Bybit in February 2025 and asked industry services to help block the addresses.

The rest rests on ZachXBT's account. The claim that the syndicate handled more than $1 billion, the identification of the contact as Jimmy Green, and the connection to Lazarus Group are his own findings. The supplied material notes these conclusions are separate from the FBI's attribution of the theft. The reported 442,000 USDT freeze is also described by ZachXBT; the supplied material includes no statement from Tether confirming it.

The freeze amount is specific to that part of the investigation. The larger $12 million figure represents funds he says he traced, and should not be read as the total value frozen.

Why getting inside the group could matter

Tracing stolen crypto usually works from public blockchain records. But payments made outside those records, and private chats about them, are not visible to anyone watching the chain. ZachXBT's account shows a second route: becoming a participant in the activity in order to learn the plans directly.

His approach also has a cost. He said the 349,700 USDC he provided is separate from his overall loss, which he did not quantify, and that he ended the case with less money than he started with.

He is asking for funding to continue

ZachXBT said information gathered through these trades helped freeze funds connected to the Bybit hack. He also asked for continued grants and individual donations so he can take on investigations he describes as higher risk.

Sources

Newisty Editorial Team
Written by

Newisty Editorial Team

Technology · Crypto · Digital Economy
View all posts

Newisty Editorial Team covers technology, cryptocurrency, digital products, online platforms, developer tools and the wider digital economy. Our content is researched from official sources, company announcements, public documentation, market data and other primary or reputable sources. Articles are reviewed and edited before publication for clarity, accuracy and useful context.

Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!