ZachXBT Says He Infiltrated $1B Lazarus Laundering Network
ZachXBT says an undercover operation connected private conversations with blockchain records to trace Bybit exploit funds and help secure a USDT freeze. Archival stock photo of a laptop displaying code under blue and pink lighting. Photo: Daniil Komov / Unsplash
Technology & Security

ZachXBT Says He Infiltrated $1B Lazarus Laundering Network

ZachXBT says he risked $349,700 to infiltrate an alleged Lazarus laundering network, identify more than $12 million in stolen funds and help secure a USDT freeze.

Make us preferred on Google

Key Notes

  • ZachXBT says he infiltrated a Chinese network that laundered more than $1 billion across exploits for North Korea’s Lazarus Group.
  • He advanced 349,700 USDC and accepted a 5% loss on each order to obtain information about planned movements of Bybit funds.
  • The investigation identified a cluster with more than $12 million in stolen assets, with 442,000 USDT later frozen by Tether, according to his account.

Blockchain investigator ZachXBT says he infiltrated a Chinese money-laundering network that processed more than $1 billion for North Korea’s Lazarus Group, putting nearly $350,000 of his own funds at risk to gain access to its operations.

In an October 5 thread, he described posing as a client during an undercover investigation in March 2025. The operation combined conversations with an alleged laundering intermediary and blockchain tracing, eventually identifying a cluster containing more than $12 million in Bybit exploit funds.

The case followed the roughly $1.5 billion theft from Bybit in February 2025. The FBI attributed that attack to North Korea, referring to the malicious activity as TraderTraitor. ZachXBT’s newly published account concerns the subsequent laundering operation, rather than a new breach at the exchange.

A Client’s Cover Opens the Door

ZachXBT said his starting point was an unusually public trail: more than 15 accounts asking for help with orders tied to stolen Bybit funds in Telegram and Discord groups. He began contacting several of those accounts, looking for a connection between their requests and the movement of the missing assets.

One contact used the Telegram alias “Jimmy Green.” The name is an online identity described in the investigation, rather than a verified legal identity. Through that contact, ZachXBT said he gained access to an operation involving Hong Kong and mainland China.

On March 6, 2025, he funded a new Ethereum address with 349,700 USDC in preparation for several transactions. The contact supplied an address to receive the funds. ZachXBT said the wallet’s transaction-fee funding could be traced back to Bybit exploit proceeds and was linked to an address on the exchange’s public blacklist.

That connection gave him more than a suspicious conversation to work with. It provided an onchain link between the person handling his orders and the stolen assets he was already tracking. Additional transactions helped build trust and kept the conversation going.

Taking a 5% Loss to Gain Advance Intelligence

The access came at a cost. ZachXBT said he lost 5% on each order and continued accepting those losses to gather actionable information. He also faced the risk that the contact could simply disappear with the funds he had advanced.

The $349,700 figure describes the capital he fronted, rather than his total loss. His disclosure does not provide a complete order count or cumulative loss calculation, so the amount should not be treated as money entirely spent or stolen during the investigation.

As the relationship developed, the contact began discussing planned movements of Bybit funds before they occurred. In one example, he said the assets would move to Solana; ZachXBT said they did so the following day.

The contact also claimed his team had laundered most of the $1.5 billion stolen from Bybit. ZachXBT said that statement was consistent with the patterns he observed. It remains a claim reported from the conversation, distinct from a court finding about the team’s responsibilities.

Conversations Lead to a $12 Million Cluster

A more specific connection emerged on March 12, 2025, when the contact shared a screenshot of a bridging transaction. ZachXBT said he matched its amount and timing against the THORChain explorer, identifying an order created within minutes of the message.

The contact subsequently shared three Solana addresses. Those addresses, ZachXBT said, revealed a cluster containing more than $12 million in Bybit exploit funds moving across Bitcoin, Ethereum, Solana and Tron.

The investigation illustrates how private communications can add context to a public transaction trail. A blockchain record shows movements between addresses; a contemporaneous conversation can help an investigator connect those movements to an operator and test whether advance statements match what happens next.

ZachXBT said Tether later froze 442,000 USDT linked to the cluster. That freeze concerned a portion of the identified funds. It does not establish that the entire $12 million cluster was blocked, or that the frozen tokens have been returned to Bybit.

An Etherscan listing identifies the address he cited for the freeze as a Uniswap V2 WAFF–USDT liquidity pool. It held approximately 442,400 USDT when checked for this article. ZachXBT also said the cluster used illiquid tokens through Uniswap liquidity pools as part of its laundering activity.

Tether’s published freezing policy provides broader context for such interventions: the issuer announced in December 2023 that it would extend sanctions-related wallet controls to the secondary market. That policy announcement is separate from ZachXBT’s account of this specific freeze.

Why the Findings Stayed Private Until Now

ZachXBT said he immediately shared his findings with trusted private-sector investigators and law enforcement personnel assigned to the case. He attributed the delay in publishing to the investigation’s sensitivity, explaining why an operation conducted in March 2025 is being disclosed in October 2026.

He also said he has helped bring about more than $75 million in freezes connected to North Korean incidents since 2022. That cumulative figure covers multiple cases, rather than this operation alone, and describes assets frozen rather than a confirmed total returned to victims.

The disclosure follows his September report about suspected laundering of Bitget exploit funds through publicly accessible support groups. CoinScreamer’s Bitget coverage examined the exchange’s limited recovery outlook and the distinction between freezing assets and recovering them. The Bitget incident is a separate case from the FBI-attributed Bybit theft.

Today’s thread provides transaction references and excerpts from conversations supporting ZachXBT’s account. It does not announce arrests or a completed prosecution of the network. The central result he describes is actionable intelligence passed to investigators, with a documented tracing claim and a reported stablecoin freeze, while the wider enforcement outcome remains undisclosed.

Disclaimer: CoinScreamer is an independent media brand owned and operated by NuvexMedia LLC, publishing news, research, and market insights on digital assets and related technologies. NuvexMedia LLC invests in and collaborates with companies across the digital asset, blockchain, and technology sectors. These relationships do not influence CoinScreamer’s editorial coverage, and the publication maintains full editorial independence to provide accurate, timely, and objective information. © 2025 NuvexMedia LLC. All rights reserved. This content is for informational purposes only and should not be considered legal, tax, investment, financial, or other professional advice.

News, Technology & Security