How ZachXBT Infiltrated a Crypto Laundering Network Handling Bybit and Other Stolen Funds
ZachXBT is again with one other main crypto expose. This time, the onchain investigator mentioned he infiltrated a Chinese organized crime syndicate that has laundered greater than $1 billion throughout a number of exploits for the infamous Lazarus Group.
After posing as a consumer, ZachXBT mentioned that he gathered info that helped motion freezes linked to the February 2025 Bybit exploit.
Inside the Chinese Crime Syndicate
The investigation started shortly after the $1.5 billion Bybit exploit. The assault was attributed to the DPRK-linked group TraderTraitor. ZachXBT noticed greater than 15 accounts on public Telegram and Discord teams asking for assist with orders tied on to the stolen funds. He contacted a number of of these accounts. One of them used the alias “Jimmy Green” on Telegram.
On March 6, 2025, ZachXBT funded a new Ethereum tackle with 349,700 USDC, which he deliberate to make use of for a number of transactions with the person.
Jimmy gave him an tackle to ship USDC to in trade for USDT on Tron. The investigator then discovered that the tackle had been funded with fuel by one other pockets that could possibly be straight traced to funds from the Bybit exploit. He then continued making trades with Jimmy to construct belief.
That finally led to Jimmy sharing extra details about the operation. According to ZachXBT, the alleged launderer talked about shifting Bybit funds for DPRK actors and gave fundamental particulars concerning the group’s operations in Hong Kong and mainland China. In one instance, Jimmy instructed ZachXBT in the future earlier than it occurred that funds can be moved to Solana. The subsequent day, the funds had been certainly moved to Solana.
Jimmy additionally claimed that his workforce had laundered a lot of the $1.5 billion stolen from Bybit. ZachXBT mentioned this was in step with the laundering patterns he had noticed. On March 12, 2025, Jimmy shared a screenshot displaying himself bridging funds. The onchain sleuth then matched the screenshot to a transaction on the THORChain explorer utilizing the quantities and timing.
Jimmy later shared three Solana addresses, which revealed a cluster containing greater than $12 million in Bybit exploit funds. The funds had been swapped throughout Bitcoin, Ethereum, Solana, and Tron in actual time. Around $442,000 in USDT linked to the cluster was later frozen by Tether. ZachXBT additionally recognized a laundering technique involving Uniswap liquidity swimming pools and illiquid tokens. The investigation uncovered different exercise too.
ZachXBT was instructed that a workforce Jimmy knew had round $300,000 frozen in 2024, which was later identified as being from the Poloniex exploit. Jimmy additionally talked about laundering $3 million in fraud proceeds for an additional consumer. Those funds had been traced to a scorching pockets linked to Huione Guarantee, which has since been sanctioned.
The conversations weren’t at all times about laundering cash. Jimmy additionally talked about mahjong, searching wild rabbits, meals, household life, and holidays to Disney. ZachXBT mentioned Jimmy’s awkward grammar could possibly be defined by means of a translator.
Costly Operation
The investigation got here with a monetary danger for ZachXBT. He mentioned he fronted 349,700 USDC and misplaced 5% on every order. There was additionally no assure that the launderer wouldn’t disappear with the funds.
Since 2022, ZachXBT has helped freeze greater than $75 million associated to DPRK incidents. He mentioned the findings from this case had been instantly shared with trusted investigators within the personal sector and regulation enforcement assigned to the case. Due to the sensitivity of the investigation, he mentioned he couldn’t publish the findings sooner.
The publish How ZachXBT Infiltrated a Crypto Laundering Network Handling Bybit and Other Stolen Funds appeared first on CryptoPotato.
