Researcher Infiltrates Chinese Crime Syndicate Laundering Crypto for Lazarus Group
ZachXBT says he infiltrated a Chinese syndicate laundering Bybit proceeds for North Korea’s Lazarus Group.
Blockchain investigator ZachXBT said he posed as a customer inside a Chinese laundering syndicate he links to North Korea’s Lazarus Group and TraderTraitor. After the February 2025 Bybit theft, which he estimated at $1.5 billion, he contacted Telegram intermediary “Jimmy Green” and spent 349,700 USDC on test swaps. He matched wallets and advance tips to Bybit proceeds, including a Solana cluster above $12 million, and said Tether froze 442,000 USDT; he also reported 332,000 USDC tied to Poloniex. The article says the syndicate attribution and about $1 billion total are his unverified claims.
- ZachXBT posed as a customer of intermediary Jimmy Green after the February 2025 Bybit theft.
- He linked the intermediary wallet’s gas funding to blacklisted Bybit exploit proceeds.
- A disclosed Solana cluster held over $12 million; Tether froze 442,000 USDT.
- Conversations also tied 332,000 USDC to the 2024 Poloniex exploit.
- Syndicate identity and the roughly $1 billion total remain unverified ZachXBT claims.
Full article527 words · extracted from gbhackers.com · click to collapse
Blockchain investigator ZachXBT has revealed that he infiltrated a Chinese organized crime syndicate believed to have laundered over $1 billion through cryptocurrency exploits linked to North Korea’s Lazarus Group.
In a disclosure on October 5, 2026, he said he posed as a customer to gather intelligence that helped freeze stolen assets and link criminal conversations to observable blockchain transactions.
Researcher Infiltrates Lazarus Group’s Crypto
The investigation began after the February 2025 Bybit exploit, which ZachXBT described as a $1.5 billion theft attributed to the DPRK-linked TraderTraitor group.
He identified more than 15 accounts seeking help with orders connected to stolen funds in public Telegram and Discord communities. These support requests served as an entry point into the suspected money laundering network without needing access to its private infrastructure.
ZachXBT reached out to several participants, including a Telegram user named “Jimmy Green,” whose username was long_991 and numeric account ID was 7635649994.
On March 6, 2025, the investigator funded a new Ethereum address with 349,700 USDC to prepare for transactions designed to build credibility with the suspected intermediary.
Jimmy offered to exchange the investigator’s Ethereum-based USDC for USDT on Tron, directing the payment to an Ethereum address abbreviated as 0xbaa5.
According to ZachXBT, this wallet had received transaction gas funding from 0xbcb4, an address directly linked to proceeds from the Bybit exploit and listed on the public Bybit blacklist. This relationship provided an additional on-chain connection between the intermediary’s wallet and the stolen assets.
After completing further exchanges, ZachXBT noted that Jimmy began discussing planned movements of Bybit funds for North Korean clients, as well as operations in Hong Kong and mainland China.

For instance, Jimmy allegedly predicted a transfer to Solana a day before it occurred. Such advance disclosures allowed the investigator to compare private statements with subsequent blockchain activity.
On March 12, 2025, Jimmy shared a screenshot of a bridging transaction. ZachXBT matched its amount and timing to an order created on THORChain explorer within minutes of receiving the message.
Three Solana addresses Jimmy later disclosed revealed a cluster containing over $12 million in Bybit proceeds moving across BTC, ETH, SOL, and Tron. Tether subsequently froze 442,000 USDT associated with that cluster, according to the investigator.
Additionally, the conversations led to discoveries beyond Bybit. Jimmy mentioned a team whose funds had been frozen in 2024; ZachXBT identified 332,000 USDC linked to the Poloniex exploit.
The investigator stated that he personally funded 349,700 USDC and incurred a five percent loss on each exchange while building trust.
These findings highlight how public support channels, gas-funding relationships, cross-chain transaction timing, and undercover engagement can together expose money laundering operations.
However, the syndicate attribution, aggregate laundering total, and described outcomes remain claims from ZachXBT’s disclosure; the accessible thread does not independently establish the identity of every participant or provide complete transaction records for each allegation.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.