ZachXBT infiltrates $1B crypto syndicate to expose Lazarus Group
Blockchain investigator ZachXBT stated he infiltrated a Chinese laundering syndicate by posing as a cryptocurrency shopper and funding repeated stablecoin trades.
In an Oct. 5 disclosure, he alleges the community laundered greater than $1 billion throughout exploits for Lazarus Group.
He stated he fronted 349,700 USDC to construct a relationship with a contact utilizing the alias Jimmy Green. According to his account, the repeated exchanges led to personal conversations about transferring funds stolen from Bybit in 2025.
He reported tracing a cluster involving greater than $12 million in Bybit funds and a later 442,000 USDT freeze by Tether.
Becoming a shopper
ZachXBT stated the investigation started after the February 2025 Bybit exploit, when he seen a minimum of 15 accounts asking for assist with orders he linked to stolen funds in public Telegram and Discord teams.
He contacted a number of of these accounts. One was Jimmy Green, the Telegram alias of the individual with whom he subsequently exchanged funds.
On March 6, 2025, ZachXBT stated he funded a brand new Ethereum deal with with 349,700 USDC in preparation for transactions with the contact. The association concerned sending his USDC on Ethereum in trade for the contact’s USDT on Tron. He then accomplished extra transactions to construct belief.
As he constructed belief by repeat exchanges, ZachXBT stated the contact started discussing actions of Bybit funds for North Korea earlier than they occurred. The conversations additionally included particulars about operations in Hong Kong and mainland China.
In one instance, he stated the contact informed him funds would transfer to Solana, and the motion occurred the next day.
On March 12, 2025, ZachXBT stated the contact despatched a screenshot of a cross-blockchain switch. He matched its quantities and timing to an order on the THORChain transaction explorer created inside minutes of the message.
According to ZachXBT, the contact additionally equipped three Solana addresses. He stated these uncovered a cluster involving greater than $12 million in Bybit exploit funds transferring by Bitcoin, Ethereum, Solana and Tron.
He individually reported that Tether later froze 442,000 USDT linked to the cluster. That is the particular freeze quantity described on this a part of his investigation; the bigger cluster determine represents funds he stated he traced.
The account additionally reaches past Bybit. ZachXBT stated the contact talked about a crew whose funds had been frozen in 2024. He stated that matched an on-chain freeze of 332,000 USDC tied to the Poloniex exploit.
The Bybit backdrop and the price of entry
In a Feb. 26, 2025 alert, the FBI stated North Korea stole roughly $1.5 billion in digital belongings from Bybit on or about Feb. 21. It known as the particular malicious exercise TraderTraitor.
At the time, the FBI stated some stolen belongings had been transformed into Bitcoin and different digital belongings dispersed throughout hundreds of addresses on a number of blockchains. It urged private-sector companies to block transactions linked to the laundering addresses.
The syndicate’s complete and the hyperlinks to Jimmy Green stay ZachXBT’s findings, separate from the FBI’s attribution of the theft.
Allegations involving a Chinese over-the-counter trader surfaced in October 2024. The newest account describes how ZachXBT obtained info by changing into a buying and selling counterparty himself.
ZachXBT stated he fronted 349,700 USDC for the case and misplaced 5% on every order. The quantity superior is distinct from his web loss, which he didn’t quantify within the disclosed figures.
He appealed for continued basis grants and particular person donations to help higher-risk investigations. He stated intelligence from these trades helped freeze funds tied to the Bybit exploit.
The submit ZachXBT infiltrates $1B crypto syndicate to expose Lazarus Group appeared first on CryptoSlate.
