Key Takeaways:
- According to ZachXBT, he had successfully penetrated a Chinese laundering structure that facilitated billions of dollars for North Korea-backed Lazarus.
- He gambled $349,700 of USDC to advance the scheme and took 5% losses in transactions with the supposed “Jimmy Green” operator.
- The investigation assisted in the tracing of over $12 million of funds linked to Bybit, including $442,000 in USDT which was ultimately frozen.
Blockchain investigator ZachXBT says he spent months posing as a customer inside a Chinese organized crime network that allegedly laundered more than $1 billion tied to Lazarus Group-linked crypto hacks.
1/ How I infiltrated a Chinese organized crime syndicate that has laundered $1B+ across multiple exploits for Lazarus Group.
Posing as a client, I gathered intel that helped action freezes for the Feb 2025 Bybit exploit and attribute illicit activity onchain. https://t.co/jauRRt8875
— ZachXBT (@zachxbt) October 5, 2026
The operation started soon after an exploit on Bybit in February 2025, noticing many people in public Telegram and Discord groups asking for assistance with transactions linked to the stolen funds.
Read More: ZachXBT Turns Unwanted Meme Coin Into $30K Venezuela Quake Relief Donation
ZachXBT Put $349,700 at Risk to Enter the Network


ZachXBT reported that he reached out to various accounts about transactions associated with the Bybit hack and later started communicating with a Telegram user who used the nickname “Jimmy Green.”
ZachXBT funded a new address and started to transact with the operator on March 6, 2025 using 349,700 tokens of USDC. He stated that the trades include swapping USD with ETH and USDT with Tron.
The investigator intentionally made several trades with a near 5% loss on each trade to establish credibility. That approach enabled him to learn about the network’s alleged “laundering” activity in Hong Kong and mainland China.
ZachXBT reported that Jimmy later spoke about intended transfers of assets linked to the Bybit exploit, leading to some transactions on-chain.
$12M Cluster Traced Across Bitcoin, Ethereum, Solana and Tron
The major development happened when an alleged cross-chain transfer screenshot was shared around by Jimmy. ZachXBT stated that he matched in terms of quantum and time to a THORChain transaction that was created within minutes of the message.
The operator also gave out a number of Solana addresses. From those addresses, a vast concentration of over $12 million was detected in Bybit’s funds that were transferred among Bitcoin, Ethereum, Solana, and Tron.
Later, ZachXBT reported that the funds, worth $442,000 (in USDT), were frozen by Tether after the cluster.
He added that he noticed a newer laundering approach among Uniswap liquidity pools and illiquid tokens as well.
Read More: Echo Protocol Hack Sparks $76M Panic After Hacker Mints Fake eBTC and Drains ETH
Bybit Funds Were Not the Only Crypto Trail


There were reports that the investigation revealed other illicit crypto traffic connections. ZachXBT reported that Jimmy had previously spoken about the amount of USD 300,000 which was previously frozen. According to onchain analysis, the money was linked to 332,000 USDC still reportedly stolen out of the Poloniex exploit.
A second conference included approximately $3 million in fraud funds identified as a Huione Guarantee hot wallet. The investigator stated that his results were shared with “trusted private investigators and law enforcement members.
He says his work has helped lock away over $75 million in freezes since 2022. Building on the discovery of the stolen crypto, which was claimed in a recent operation, he says how it can traverse intermediaries long after the original exploit happened.





Be the first to comment