Build with CoinStats’ all-in-one API. Learn more

Deutsch한국어日本語中文EspañolFrançaisՀայերենNederlandsРусскийItalianoPortuguêsTürkçePortfolio TrackerCryptocurrenciesPricingCrypto APIMCPIntegrationsNewsRWA MarketEarnBlogNFTWidgetsDeFi Portfolio TrackerDerivativesETF FlowsCrypto GamingPrediction Markets24h ReportPress KitAPI Docs

ZachXBT Infiltrates Chinese Syndicate Laundering North Korean Hack Funds

bullish:

0

bearish:

0

ZachXBT Infiltrates Chinese Syndicate Laundering North Korean Hack Funds

Blockchain investigator ZachXBT says he spent weeks posing as a paying customer of a Chinese laundering network handling stolen crypto for North Korea-linked operators, putting $349,700 of his own USDC at risk to gain access to the group.

The October 5 disclosure details an undercover operation that began after the February 2025 Bybit breach. ZachXBT alleges the wider network processed more than $1 billion across multiple exploits connected to Lazarus Group, although that aggregate figure has not been independently confirmed by law enforcement.

The FBI attributed the Bybit theft of approximately $1.5 billion to North Korean actors it tracks as TraderTraitor on February 26, 2025. The agency warned that the stolen assets were already being dispersed across thousands of addresses and multiple blockchains.

$349,700 Used to Build Trust

ZachXBT identified more than 15 accounts in public Telegram and Discord groups seeking help with transactions he linked to stolen Bybit funds. He contacted several before establishing an ongoing relationship with a Telegram operator using the alias “Jimmy Green.”

On March 6, 2025, ZachXBT funded a fresh Ethereum address with 349,700 USDC and began exchanging funds with the operator for USDT on Tron. He says each order cost roughly 5%, with no assurance that the counterparty would return the funds.

One Ethereum address supplied during the transactions had received gas from a wallet ZachXBT traced directly to Bybit exploit proceeds. Bybit had already created a public blacklist system to distribute identified attacker addresses to investigators and recovery partners.

The access soon produced advance information about fund movements. ZachXBT says Green told him Bybit-linked assets would move into Solana one day before the corresponding transactions appeared onchain.

Chats Exposed a $12M Bybit Fund Cluster

A March 12 exchange gave ZachXBT another point of comparison. Green sent a screenshot of a cross-chain transfer, and the transaction amount and timing matched a THORChain order created within minutes of the message.

Three Solana addresses supplied during the conversations then exposed more than $12 million in Bybit-linked assets moving through Bitcoin, Ethereum, Solana and Tron. The routing fits the cross-chain laundering pattern previously seen after the Bybit theft, when THORChain became a major route for stolen funds.

A USDT address connected to the identified cluster was frozen on March 14, 2025. ZachXBT placed the affected balance at approximately 442,000 USDT, while BlockSec’s onchain tracker confirms the address entered Tether’s frozen state.

The same broader laundering problem has continued into 2026. ZachXBT recently linked wallets from the September Bitget exploit to suspected North Korean actors, while separate Lazarus-linked wallets moved more than $30 million through Hyperliquid earlier this year.

ZachXBT waited roughly 18 months before publishing details of the undercover operation while related investigations remained active. He says his work on DPRK-linked cases has helped action more than $75 million in asset freezes since 2022.

The post ZachXBT Infiltrates Chinese Syndicate Laundering North Korean Hack Funds appeared first on Crypto Adventure.

bullish:

0

bearish:

0

Manage all your crypto, NFT and DeFi from one place

Securely connect the portfolio you’re using to start.