Crypto Sleuth ZachXBT Fronted $350K to Pose as Client of Lazarus’ Chinese Launderers
This post was originally published on this site
Blockchain investigator ZachXBT says he spent nearly $350,000 of his own money to infiltrate an alleged Chinese money-laundering network connected to North Korea’s Lazarus Group, an operation that helped expose more than $12 million in funds linked to the $1.5 billion Bybit hack.
In a detailed post on X published October 5, the pseudonymous investigator said he posed as a client of the network in early 2025, deliberately accepting losses on transactions in exchange for information about how the group moved stolen cryptocurrency.
“Posing as a client, I gathered intel that helped action freezes for the Feb 2025 Bybit exploit and attribute illicit activity onchain,” ZachXBT said.
The Bybit attack, which took place in February 2025, remains one of the largest cryptocurrency thefts on record. The FBI attributed the theft of approximately $1.5 billion in digital assets to North Korean hackers it tracks as TraderTraitor, saying the stolen funds were rapidly moved across thousands of blockchain addresses in an effort to obscure their origin.

ZachXBT’s status on X
Going undercover with $349,700
ZachXBT said his investigation began after he noticed more than 15 accounts in public Telegram and Discord groups seeking assistance with transactions involving funds connected to the Bybit exploit.
One of those contacts used the alias “Jimmy Green.”
Rather than simply tracking the wallets from the outside, ZachXBT decided to pose as a potential customer. On March 6, 2025, he funded a new Ethereum address with 349,700 USDC and began conducting transactions with Green.
The arrangement involved sending USDC in exchange for USDT on the Tron network. ZachXBT said the wallet provided by Green had itself received gas from an address directly traceable to Bybit exploit funds and listed on a public Bybit blacklist.
He continued making transactions to establish credibility with the alleged laundering operation.
The strategy came at a cost. ZachXBT said he lost around 5% on each order, while also facing the possibility that the counterparty could simply disappear with his money.
“At this point, I realized I needed to continue losing 5% per order and gamble on capturing as much actionable intel as quickly as possible,” he wrote.
According to ZachXBT, Green eventually began discussing plans to move funds connected to North Korea and provided details about the network’s operations in Hong Kong and mainland China.

A conversation between ZachXBT and “Jimmy Green.” (Source: ZachXBT)
The blockchain evidence followed
The conversations became more valuable when Green began providing information that ZachXBT could independently verify on-chain.
In one instance, Green sent a screenshot showing a transaction involving funds being bridged between networks. ZachXBT said he was able to match the screenshot with a corresponding THORChain transaction that had been created within minutes of the conversation.
Green later shared three Solana addresses. ZachXBT said those addresses helped him identify a cluster containing more than $12 million in Bybit-linked funds, which were being moved between Bitcoin, Ethereum, Solana and Tron.
Tether subsequently froze 442,000 USDT connected to the wallet cluster, according to ZachXBT and reports detailing his investigation.
The alleged laundering network also appeared to have knowledge of other major crypto thefts.

The blockchain evidence followed
Green reportedly mentioned approximately $300,000 that had previously been frozen. ZachXBT traced the figure to 332,000 USDC linked to the 2023 Poloniex exploit, which researchers have associated with North Korean hacking activity.
Green also claimed to have laundered around $3 million in fraud proceeds for another client. ZachXBT said those funds could be traced to a wallet associated with Huione Guarantee, a marketplace that has been linked to cryptocurrency laundering and illicit services.
A broader network behind the laundering
The investigation suggests the operation was not simply a single broker moving money for individual criminals.
ZachXBT alleged that the Chinese network had laundered more than $1 billion across multiple exploits linked to Lazarus Group, including a substantial portion of the funds stolen from Bybit. The claims are based on a combination of private conversations, wallet movements and transaction timing.
The alleged organization reportedly operated through different divisions, with individuals responsible for receiving and distributing stablecoins to other participants.
That structure highlights a critical weakness in crypto laundering operations: stolen funds may move through dozens of wallets and blockchains, but they still need intermediaries willing to convert, exchange or transfer them.
For investigators, those intermediaries can become valuable sources of intelligence.
ZachXBT’s growing role in North Korea investigations
The operation also builds on ZachXBT’s previous work tracking cryptocurrency stolen by North Korean-linked hackers.
He said he has helped facilitate more than $75 million in freezes connected to DPRK-related incidents since 2022. His investigation into the Bybit attack also preceded the FBI’s public attribution of the theft to North Korea.
The investigator has become one of the most prominent independent figures in crypto incident response, using publicly available blockchain data to trace stolen assets and identify connections between seemingly unrelated hacks.
His work has also attracted controversy and personal risk. ZachXBT was previously sued and doxxed by a former target, yet has continued investigating major cryptocurrency thefts.
He said grants from foundations and donations from individuals have helped fund more difficult investigations, including the undercover operation.
For this particular case, however, he personally fronted the money.
The operation was not without danger. ZachXBT said he had no guarantee that Green would continue cooperating or return the funds, while direct contact with an organized laundering network created an unknown level of personal security risk.
He ultimately kept the investigation private while passing the information to law enforcement and other trusted investigators.
The case illustrates how cryptocurrency laundering has evolved alongside blockchain surveillance. Even as criminals move stolen assets across multiple chains, stablecoins, bridges and decentralized exchanges, investigators can sometimes use the same transparent infrastructure to reconstruct the trail.
ZachXBT’s operation took that approach one step further: instead of merely following the money, he says he stepped inside the network moving it.
The post Crypto Sleuth ZachXBT Fronted $350K to Pose as Client of Lazarus’ Chinese Launderers appeared first on NFT Plazas.