TLDR
- On-chain investigator ZachXBT invested $349,700 while operating undercover to penetrate a suspected Chinese cryptocurrency laundering operation.
- The operation allegedly processed over $1 billion in stolen digital assets for North Korea’s Lazarus Group through various cyberattacks.
- ZachXBT’s investigation uncovered more than $12 million in digital wallets connected to the $1.5 billion Bybit breach.
- Tether froze approximately 442,000 USDT tied to the wallet network he identified.
- According to Chainalysis, North Korean cybercriminals extracted $2.02 billion in cryptocurrency throughout 2025, bringing their cumulative total above $6.75 billion.
On-chain detective ZachXBT revealed he conducted an extended undercover investigation to uncover a cryptocurrency money laundering operation connected to North Korean threat actors. He published his comprehensive findings through a detailed X thread on October 5.
According to ZachXBT, he assumed the role of a paying client beginning in February 2025, mere days following the Bybit security breach. He discovered accounts advertising fund-moving services within public Telegram and Discord communities.
ZachXBT stated he loaded an Ethereum wallet with $349,700 worth of stablecoins. To establish credibility with an operator using the pseudonym Jimmy Green, he willingly absorbed a 5% fee on every transaction.
Inside the money laundering infrastructure
The investigator characterized the operation as a Chinese organized crime enterprise. According to his findings, the network maintained activities throughout Hong Kong and mainland Chinese territories.
ZachXBT asserted the network processed upwards of $1 billion from numerous cryptocurrency exploits for the Lazarus Group. The contact purportedly disclosed that nearly all proceeds from the Bybit incident passed through their laundering infrastructure.
A specific transaction pathway provided ZachXBT with his initial breakthrough. He noted that a recipient wallet had received funding from an address previously listed on Bybit’s public blacklist.
Subsequent communications provided him with advance intelligence about upcoming fund transfers. He cross-referenced these messages against on-chain transaction data to verify alignment.
On March 12, the operator transmitted a screenshot depicting an exchange of 1.192 Bitcoin for 51.73 Ether. ZachXBT successfully matched this activity to a THORChain transaction associated with Bybit assets.
On-chain analysis results in asset freezes
Three Solana wallet addresses disclosed during their exchanges revealed a cluster containing over $12 million in Bybit-related assets. ZachXBT observed the funds circulating across Bitcoin, Ether, Solana, and Tron networks.
According to the investigator, Tether subsequently froze 442,000 USDT associated with these digital wallets. Tether has independently verified additional freezes related to the Bybit incident through its T3 Financial Crime Unit.
By October 2025, T3-affiliated investigations had frozen $19 million connected to the Bybit theft, Tether reported. The specific 442,000 USDT freeze was absent from those prior public announcements.
ZachXBT additionally revealed the same intermediary provided intelligence regarding separate incidents. These included proceeds from the 2023 Poloniex compromise and a collection tied to Huione Guarantee.
The FBI formally attributed the Bybit attack to North Korean actors five days post-incident. The bureau identified the perpetrators as a group they monitor under the designation TraderTraitor, responsible for extracting approximately $1.5 billion in digital assets.
Bybit explained that compromised developer credentials enabled the attacker to penetrate its systems. The platform maintained that internal audits revealed no compromise of its fundamental infrastructure.
ZachXBT confirmed he provided his intelligence to investigators and law enforcement agencies throughout the active operation. He explained he postponed publishing the complete details until October 2026 because of the case’s sensitive nature.
Official documentation from the FBI, Treasury Department, and Tether has not identified the individual operating under the alias Jimmy Green. No court documents have substantiated the complete extent of the laundering network outlined in his disclosure.
Chainalysis data indicates North Korean cybercriminals stole $2.02 billion in cryptocurrency throughout 2025. The analytics firm notes investigators continue tracking funds from the $387 million Bitget breach that occurred in September 2026.


