ZachXBT Says He Infiltrated Lazarus-Linked Crypto Laundering
ZachXBT says he posed as a client inside a Chinese syndicate laundering Bybit proceeds he links to North Korea's Lazarus Group.
Blockchain investigator ZachXBT said he infiltrated a Chinese organized-crime syndicate he links to North Korea's Lazarus Group by posing as a client of Telegram intermediary "Jimmy Green" after the February 2025 Bybit cryptocurrency theft. Cyber Security News reported that the FBI attributed the February 21, 2025 theft, estimated at $1.5 billion, to North Korea under the name TraderTraitor, while GBHackers treated the $1.5 billion figure, the syndicate's identity, and a roughly $1 billion laundering total as ZachXBT's unverified claims. He said he spent 349,700 USDC in March 2025, took about 5% losses per order, and matched operator chats and wallets to Bybit proceeds across Bitcoin, Ethereum, Solana, and Tron, including gas funding tied to blacklisted exploit funds. Both outlets reported that Tether froze 442,000 USDT connected to a Solana cluster above $12 million; GBHackers also cited 332,000 USDC tied to the 2024 Poloniex exploit, and Cyber Security News said ZachXBT claims his work has helped freeze more than $75 million since 2022. Jimmy Green allegedly claimed his team processed most stolen Bybit funds. The reports agree the central allegations still need independent confirmation, and Cyber Security News noted that freezing assets does not return them to victims.
- ZachXBT said he posed as a client of Telegram intermediary "Jimmy Green" inside a Chinese syndicate he links to North Korea's Lazarus Group.
- Cyber Security News said the FBI attributed the February 21, 2025 Bybit theft, estimated at $1.5 billion, to North Korea's TraderTraitor activity.
- He reported using 349,700 USDC in March 2025 for test swaps and absorbing roughly 5% losses per order, matching chats to transfers on Bitcoin, Ethereum, Solana, and Tron.
- Both reports said Tether froze 442,000 USDT tied to a Solana wallet cluster holding more than $12 million.
- GBHackers also reported 332,000 USDC tied to the 2024 Poloniex exploit and gas funding linked to blacklisted Bybit proceeds.
- GBHackers called the syndicate identity and roughly $1 billion laundering total unverified ZachXBT claims; Cyber Security News added that Jimmy Green allegedly said his team processed most Bybit funds and that ZachXBT claims freezes of…
Coverage timelineoldest first · each row is one article
- · 3d agoResearcher Infiltrates Lazarus Group’s Crypto Laundering Network After $1.5B Bybit Hack
Cyber Security News· 62
Investigator ZachXBT infiltrated a Chinese laundering syndicate processing $1B+ for Lazarus Group, enabling Tether freezes of stolen Bybit funds.
- · 2d agoResearcher Infiltrates Chinese Crime Syndicate Laundering Crypto for Lazarus Group
GBHackers· 66
ZachXBT says he infiltrated a Chinese syndicate laundering Bybit proceeds for North Korea’s Lazarus Group.