Blockchain AcademicsBlockchain Academics
ZachXBT Went Undercover Inside a Chinese Syndicate Laundering $1B+ for North Korea

ZachXBT Went Undercover Inside a Chinese Syndicate Laundering $1B+ for North Korea

Blockchain investigator ZachXBT posed as a client inside a Chinese organized crime syndicate that has laundered more than $1 billion for North Korea's Lazarus Group, and the intelligence he gathered helped freeze funds from the 2025 Bybit exploit.

Hadi GhadbanEdited by Wael RajabOctober 5, 20265 min read
Share

ZachXBT Went Undercover Inside a Chinese Syndicate Laundering $1B+ for North Korea

Blockchain investigator ZachXBT posed as a client inside a Chinese organized crime syndicate that laundered stolen cryptocurrency for North Korea's Lazarus Group, a covert operation that produced wallet freezes, on-chain attribution, and an unusually detailed window into how DPRK-linked actors move stolen funds across multiple blockchains.

In a 12-part thread published Monday on X, ZachXBT disclosed the full scope of the operation. It centered on funds stolen in the February 2025 Bybit exploit, which drained about $1.5 billion and was attributed to the DPRK-linked group "TraderTraitor." He tied it to a pattern he flagged last week after the September 2026 Bitget exploit, in which illicit actors laundering $387 million on behalf of the alleged DPRK attackers openly asked for help with their orders in public channels.

How I infiltrated a Chinese organized crime syndicate that has laundered $1B+ across multiple exploits for Lazarus Group. Posing as a client, I gathered intel that helped action freezes for the Feb 2025 Bybit exploit and attribute illicit activity onchain.

ZachXBT, via X thread

The Undercover Operation

The operation began in the immediate aftermath of the Bybit breach, when ZachXBT observed more than 15 accounts in public Telegram and Discord groups seeking help with orders directly tied to stolen funds. He made contact with one of them, a person operating under the alias "Jimmy Green" on Telegram. On March 6, 2025, ZachXBT funded a fresh Ethereum address with 349,700 USDC to begin transacting with Green, exchanging USDC on Ethereum for USDT on Tron. The gas wallet Green used to fund his receiving address was traceable on the public Bybit exploit blacklist to funds taken directly in the breach.

Over subsequent weeks, ZachXBT completed multiple transactions to build trust, absorbing a 5% fee on each order with no guarantee Green would not simply vanish with the capital. The personal financial exposure was real, and so was the operational risk.

I fronted $349.7K and lost 5% on each order, with no guarantee Jimmy wouldn't disappear with the funds, and an unknown amount of personal risk from dealing with the syndicate.

ZachXBT, via X thread

Intelligence and Advance Warning

The intelligence Green provided was operationally specific. One day before Bybit funds were moved to Solana, Green told ZachXBT it would happen. The next day, it did. On March 12, 2025, Green shared a screenshot of himself executing a bridge transaction; ZachXBT matched it by amount and timestamp to a THORChain transaction (hash: 81a85130b36057428e64b6f97215f77b5a197776a8f1b3a61c8cd0ee1ebfa8c1) created within minutes of the message.

Green also provided three Solana addresses that revealed a cluster of more than $12 million in Bybit exploit funds being rotated across Bitcoin, Ethereum, Solana, and Tron in real time. Tether later froze 442,000 USDT linked to that cluster. The same cluster deployed what ZachXBT described as a novel laundering method: Uniswap liquidity pools seeded with illiquid tokens.

Green told ZachXBT his team laundered most of the $1.5 billion taken from Bybit, a claim ZachXBT said was consistent with the laundering patterns he independently observed.

He stated his team laundered most of the $1.5B from Bybit, which was consistent with the laundering patterns I observed.

ZachXBT, via X thread

Additional Threads and Connections

The investigation surfaced additional threads. Green mentioned that a team he knew had roughly $300,000 frozen in 2024; ZachXBT traced that on-chain to a freeze of 332,000 USDC from the Poloniex exploit. Green also described laundering $3 million in fraud proceeds for a separate client. ZachXBT traced those funds to a hot wallet for Huione Guarantee, a platform that has since been sanctioned and whose former chairman was arrested. Green also shared basic details about the syndicate's operation in Hong Kong and mainland China.

The Bitget Pattern

The same pattern ZachXBT documented in the Bybit aftermath reappeared after the September 2026 Bitget exploit. Illicit actors laundering funds from that $387 million breach were openly filing support tickets in public Discord servers and Telegram channels, with funds being chain-hopped via bridges and deposited into mixing services including Wasabi. ZachXBT identified five aliases involved in that operation, publishing their Discord IDs, Telegram handles, and associated transaction hashes.

Methodological Limits and Track Record

The methodological limits of the investigation deserve acknowledgment. Jimmy Green's identity and reliability rest on ZachXBT's account alone. Wallet clustering and cross-chain attribution carry inherent false-positive risk. The thread does not describe any charges resulting from the intelligence. ZachXBT says sensitivity around the investigation kept him from publishing sooner, so the public account arrives about 19 months after the onchain activity it describes.

Still, the aggregate track record is notable. ZachXBT states that since 2022 he has helped action more than $75 million in freezes tied to DPRK-linked incidents. The Tether freeze of 442,000 USDT linked to the Bybit cluster is a concrete, verifiable output. The strongest support for his account is the advance notice Green gave of fund movements that then played out as described.

Since 2022, I have helped action $75M+ in freezes related to DPRK incidents.

ZachXBT, via X thread

Professionalized Infrastructure

The broader picture the investigation draws is of a professionalized laundering infrastructure. Chinese organized crime syndicates serving as intermediaries for state-linked North Korean hackers, using cross-chain bridges, mixing services, and novel DeFi mechanisms to layer stolen funds, is not a new hypothesis. But rarely has an independent investigator documented it from the inside, with transaction hashes and timestamps that can be checked against public explorers.

ZachXBT said his findings were shared immediately with trusted investigators in the private sector and with law enforcement assigned to the case. He also disclosed that he is currently sitting on significant findings from other ongoing investigations that he cannot yet publish.

Discussion

Loading comments...