Blockchain Investigator ZachXBT Exposes Billion-Dollar Crypto Laundering Network Tied to North Korea

ZachXBT said he began the operation after the February 2025 Bybit exploit, which the FBI identified as the work of the North Korea-linked group TraderTraitor. The FBI attribution is separate from any public confirmation of ZachXBT’s investigation.
Before contacting the alleged launderers, ZachXBT said he observed more than 15 accounts in public Telegram and Discord groups seeking help with orders tied to stolen funds.
ZachXBT identified one contact as “Jimmy Green” and said he completed additional transactions to build trust. He also alleged that an address used by the contact had received gas funding from an address traceable to Bybit exploit proceeds and listed on a public Bybit exploit blacklist.
The reporting places the alleged network’s activity in a wider pattern: ZachXBT had previously named five aliases he said were laundering funds from the $387.5 million Bitget exploit and said he had tracked similar activity across multiple TraderTraitor-attributed exploits.
Blockchain investigator ZachXBT claims he posed undercover as a client to infiltrate a Chinese money-laundering network that moved over $1 billion tied to North Korea's Lazarus Group, including proceeds from the February 2025 Bybit hack Decrypt. ZachXBT said he spent roughly $350,000 in personal funds during the operation and shared findings with private-sector investigators and law enforcement to help freeze stolen assets Protos.
The investigator identified one key contact as "Jimmy Green" and completed multiple transactions to build trust within the network Cyber Kendra. However, no U.S. law enforcement agency has publicly confirmed ZachXBT's investigation findings, and some reported transaction details remain unverified by independent sources.
ZachXBT said he began tracking the network after the Bybit hack in February 2025. The FBI attributed that hack to TraderTraitor, the Lazarus Group's cybercriminal arm Decrypt. ZachXBT observed more than 15 accounts in public Telegram and Discord groups openly seeking help moving stolen funds.
To infiltrate the operation, ZachXBT posed as a customer needing money-laundering services. He completed multiple transactions with the contact "Jimmy Green," spending around $350,000 of his own money to establish credibility Decrypt. He traced one address linked to Jimmy Green back to funds from the Bybit exploit using public blacklists.
ZachXBT's work connects the Bybit breach to a wider pattern of Lazarus Group crimes. The investigator previously identified five aliases allegedly laundering $387.5 million stolen from the Bitget exploit Cryptopolitan. He said he tracked similar money-moving activity across multiple TraderTraitor-attributed heists.
The scale suggests a highly organized operation. Over $1 billion in stolen crypto has flowed through the alleged Chinese criminal network, according to ZachXBT's analysis Protos. The laundering crew appears to specialize in processing North Korean hacker proceeds into usable assets.
ZachXBT reported a specific 349,700-USDC transaction as part of his findings Decrypt. However, independent researchers have not confirmed all details of his investigation. The lack of public law enforcement statements makes verification difficult for outside parties.
ZachXBT is known as crypto's most prolific on-chain investigator Decrypt. His past work has identified theft patterns and frozen assets. But his latest claims rely partly on unverified undercover work and closed-source intelligence shared only with select authorities and private sector partners.
Publishers
12
Articles
3
Reach
15