ZachXBT infiltrated syndicate tied to Lazarus laundering

Blockchain investigator ZachXBT says he posed as a client, fronted 349,700 USDC, traced a Bybit-linked cluster of more than $12 million and reports Tether froze 442,000 USDT.

Blockchain investigator ZachXBT reports he infiltrated a Chinese cryptocurrency laundering syndicate by posing as a client and fronting 349,700 USDC. He attributes the group’s activity to laundering more than $1 billion for the Lazarus Group, a North Korea-linked hacking collective, based on his tracing of transfers across multiple exploits.

The operation began after a February 2025 exploit of the Bybit exchange. He contacted accounts offering trading help on Telegram and Discord and established a relationship with a contact using the alias Jimmy Green. On March 6, 2025, he funded a new Ethereum address with 349,700 USDC to act as a trading counterparty.

He exchanged USDC on Ethereum for the contact’s USDT on Tron in repeated trades to build credibility. He reports losing about 5% on each order while fronting liquidity to obtain access to the network.

As trust grew, the contact shared operational details and screenshots of transfers before they occurred. He matched a March 12 screenshot to an order on the THORChain transaction explorer created minutes after the message.

Using those details, he mapped three Solana addresses and a cluster he traces to more than $12 million in funds that originated from the Bybit exploit and moved across Bitcoin, Ethereum, Solana and Tron. Tether froze 442,000 USDT linked to that cluster, according to his account.

He also matched a reference to a team whose funds were frozen in 2024 to an on-chain freeze of about 332,000 USDC tied to a Poloniex exploit.

In a Feb. 26, 2025 alert, the FBI said North Korea stole roughly $1.5 billion in virtual assets from Bybit in an operation it labeled TraderTraitor and that some stolen assets were converted and dispersed across thousands of addresses. ZachXBT’s attributions are presented as his findings and separate from the FBI’s public attribution of the theft.

He has appealed for foundation grants and individual donations to support similar on-the-ground investigations. He reports the intelligence gathered through his participation contributed to enforcement actions that led to the Tether freeze.

Articles by this author