Blockchain investigator ZachXBT exposes Chinese syndicate laundering North Korean-stolen cryptocurrency
A blockchain investigator’s undercover operation has exposed a Chinese money-laundering syndicate handling North Korean-stolen cryptocurrency, providing law enforcement with operational details and on-chain evidence of fund flows that conventional analysis might miss. The case demonstrates both the investigative power of direct infiltration and the persistent challenge of tracking stolen assets across multiple blockchains in real time.
- ZachXBT infiltrated a laundering network by posing as a client, funding 349,700 USDC in stablecoin trades with a contact using the alias Jimmy Green.
- The syndicate allegedly laundered more than $1 billion across exploits attributed to North Korea’s Lazarus Group, with the $1.5 billion Bybit theft occurring in February 2025.
- ZachXBT traced over $12 million in Bybit funds through Bitcoin, Ethereum, Solana and Tron, leading to a 442,000 USDT freeze by Tether on linked addresses.
- $1.5B Virtual assets North Korea stole from Bybit on February 21, 2025
- 349,700 USDC ZachXBT fronted to build trading relationship with syndicate contact
- $12M+ Bybit exploit funds ZachXBT traced across four major blockchains
- 442,000 USDT frozen by Tether on addresses linked to the cluster
Blockchain investigator ZachXBT disclosed on October 5 (Monday) that he had infiltrated a Chinese laundering syndicate by posing as a cryptocurrency trader, providing new operational details about how stolen assets from the Bybit exchange are being processed and distributed. CryptoSlate reported that ZachXBT’s operation began after the February 2025 theft from Bybit, when the FBI attributed the $1.5 billion virtual asset heist to North Korea in an alert using the designation “TraderTraitor.” ZachXBT said he identified at least 15 accounts in public Telegram and Discord groups seeking help moving funds he believed were stolen, and he contacted one operator known as Jimmy Green to initiate a relationship.
ZachXBT funds undercover trades to gain operational intelligence
Starting on March 6, 2025, ZachXBT funded a new Ethereum address with 349,700 USDC and began executing repeated stablecoin swaps with his contact, exchanging USDC on Ethereum for USDT on Tron. He incurred a 5 percent loss on each transaction to build trust and establish himself as a legitimate trader. As the relationship deepened over subsequent weeks, the contact began disclosing the timing and destinations of fund movements tied to the Bybit theft before those transfers occurred.
On March 12, 2025, the contact sent ZachXBT a screenshot of a cross-blockchain transfer, which ZachXBT matched to a transaction recorded on the THORChain explorer within minutes of the message. The contact subsequently provided three Solana addresses that ZachXBT said exposed a cluster containing more than $12 million in Bybit exploit funds moving through Bitcoin, Ethereum, Solana and Tron. Tether later froze 442,000 USDT on addresses connected to the cluster, according to ZachXBT’s account.
FBI attribution and broader criminal network connections
The FBI released a public service announcement on February 26, 2025 confirming that North Korea was responsible for the theft of approximately $1.5 billion in virtual assets from Bybit on or about February 21, 2025. The bureau stated that TraderTraitor actors had converted some stolen assets to Bitcoin and other cryptocurrencies dispersed across thousands of addresses on multiple blockchains, with expectations that remaining assets would be further laundered and eventually converted to fiat currency.
ZachXBT’s findings extend beyond the Bybit theft. His contact mentioned a team whose funds had been frozen in 2024, which ZachXBT said matched an on-chain freeze of 332,000 USDC tied to the Poloniex exploit. ZachXBT characterized the broader syndicate he infiltrated as having laundered more than $1 billion across multiple exploits, though the syndicate’s total and its direct connection to Lazarus Group are ZachXBT’s own findings, separate from the FBI’s formal attribution of the Bybit theft.
Investigator seeks funding for continued infiltration operations
ZachXBT appealed for continued foundation grants and individual donations to support higher-risk investigations of this kind, stating that intelligence obtained through his undercover trades helped facilitate the freezes of funds tied to the Bybit exploit.
The investigator’s approach reveals a gap between what law enforcement attribution and blockchain analysis can establish from on-chain data alone, and what direct operational intelligence can reveal about the timing, routing decisions and organizational structure of criminal money-laundering networks. However, ZachXBT’s account remains a single investigator’s findings and has not been independently verified by law enforcement or published in a formal forensic report.
The BlockWest read. ZachXBT’s willingness to risk capital and operational security to infiltrate a North Korean-linked laundering operation highlights a structural challenge: public blockchains allow forensic analysis of past flows but offer limited visibility into live decision-making, counterparty relationships, and routing strategies. Law enforcement and blockchain firms may increasingly rely on investigators who can embed themselves in criminal networks, not just analyze their traces.
The FBI’s TraderTraitor alert published a list of 47 Ethereum addresses tied to North Korean actors and encouraged private-sector entities including exchanges, bridges, and blockchain analytics firms to block transactions connected to those addresses. ZachXBT’s identification of additional addresses, fund flows, and syndicate participants could inform whether law enforcement expands the official list or initiates new enforcement actions against the Chinese over-the-counter traders he identified.
BlockWest is a news publication. Nothing here is investment advice. Read our disclaimer and editorial policy.
