Blockchain investigator ZachXBT says an undercover operation that cost him $349,700 helped expose an alleged Chinese laundering network linked to North Korean hackers and trace more than $12 million in funds connected to the $1.5 billion Bybit hack.
According to ZachXBT, he spent the money while posing as a customer inside a laundering network that he claims had moved more than $1 billion across multiple crypto exploits linked to the Lazarus Group.
He said the investigation began after he found more than 15 accounts on public Telegram and Discord groups offering services connected to funds from the Bybit hack. He eventually made contact with an operator using the alias “Jimmy Green.”
ZachXBT said he approached the group as a paying customer and offered to exchange marked cryptocurrency for USDT on Tron. By March 6, 2025, he had funded a new Ethereum address with $349,700 in USDC and accepted a 5% loss on each transaction while building trust with the operators.
The first major connection to the Bybit hack reportedly came through the payment route used during one of the trades. ZachXBT said the receiving wallet had received gas from an address connected to the Bybit exploit and listed on Bybit’s blacklist.
Further conversations reportedly gave him information about where stolen funds would move. He was then able to compare the private information with public blockchain transactions and match wallet movements, transaction amounts, and timing.
On March 12, the operator reportedly sent a screenshot showing a swap of 1.192 BTC for 51.73 ETH. ZachXBT said he matched the transaction to a THORChain transfer that eventually traced back to funds connected to the Bybit hack.
The investigation later identified three Solana addresses that ZachXBT said were connected to a wallet cluster holding more than $12 million in Bybit-linked funds. The funds moved across several blockchains, including Bitcoin, Ethereum, Solana, and Tron.
ZachXBT also said Tether later froze 442,000 USDT connected to wallets identified during his investigation.
Tether has separately confirmed several larger freezes involving funds linked to the Bybit attack. However, its public announcements did not specifically confirm the 442,000 USDT freeze described by ZachXBT or publicly connect it to the “Jimmy Green” operation.
The investigator also said information from the same network helped identify other suspicious transactions, including funds connected to the 2023 Poloniex hack and wallets associated with Huione Guarantee.
The Bybit hack itself has been officially attributed to North Korea. The FBI said North Korean actors known as TraderTraitor were responsible for the Feb. 21, 2025 attack and stole approximately $1.5 billion in virtual assets.
Bybit previously said the attacker gained access through compromised credentials connected to Safe’s infrastructure and tricked signers into approving a malicious transaction. The exchange said there was no evidence that its own core infrastructure had been compromised.
ZachXBT had also previously provided evidence linking the attack to the Lazarus Group and helped track the stolen assets as they moved between different blockchains and services.
The scale of North Korean crypto theft has continued to grow. Chainalysis estimated that North Korean hackers stole around $2.02 billion in cryptocurrency during 2025, bringing their cumulative stolen amount to at least $6.75 billion.
While ZachXBT’s investigation provides additional information about how some of the stolen funds may have been moved, the claims about the identity and full scale of the alleged laundering network have not been independently confirmed by law enforcement or through public court records.
The investigation highlights how blockchain transactions can remain traceable even after stolen funds are moved through multiple wallets, blockchains, and conversion services. It also shows the growing role of private blockchain investigators in helping exchanges, stablecoin issuers, and authorities identify and freeze illicit crypto funds.








