A pseudonymous blockchain investigator says he spent months posing as a paying client inside a Chinese organized crime syndicate that laundered more than $1 billion in stolen cryptocurrency for North Korea's Lazarus Group, an operation that yielded real-time intelligence on the movement of funds from the Bybit and Bitget hacks.
ZachXBT, one of the most prolific on-chain sleuths in the crypto industry, published his findings in an Oct. 5 thread on X. He described funding an Ethereum address with $349,700 in USDC and accepting a 5% loss on every transaction to build trust with a syndicate operator using the handle "Jimmy Green."
"Posing as a client, I gathered intel that helped action freezes for the Feb 2025 Bybit exploit and attribute illicit activity onchain," he wrote.
The infiltration began just days after the February 2025 Bybit breach, in which hackers stole roughly $1.5 billion from the exchange. The FBI attributed that incident to North Korean actors it tracks as TraderTraitor, a designation that overlaps with Lazarus Group activity. ZachXBT said he observed more than 15 accounts in public Telegram and Discord channels openly asking for help processing orders tied to stolen funds.
On March 6, 2025, he funded a new address with 349,700 USDC on Ethereum to conduct transactions with Jimmy Green. The address Jimmy provided for receiving the stablecoin had been funded with gas by a wallet directly traceable to Bybit exploit funds and labeled on the public Bybit exploit blacklist site.
"I completed several additional transactions with him in order to build up trust," ZachXBT said. "After that, Jimmy began to talk about moving Bybit funds for DPRK in advance of it happening, along with basic details about their operation in Hong Kong and mainland China."
The trust-building came at a cost. ZachXBT said he "fronted $349.7K and lost 5% on each order, with no guarantee Jimmy wouldn't disappear with the funds, and an unknown amount of personal risk from dealing with the syndicate."
The intelligence gathered from the chats paid off on-chain. On March 12, 2025, ZachXBT matched a screenshot Jimmy sent of himself bridging funds to an order created within minutes of the message, using amounts and timing visible on the Thorchain explorer, a public log of swaps on the decentralized protocol that moves coins directly across blockchains.
Jimmy subsequently shared three Solana addresses that exposed a cluster of more than $12 million in Bybit loot being swapped in real time. ZachXBT watched the funds hop from Bitcoin to Ether, then to Solana, and finally to Tron. Tether later froze 442,000 USDT linked to the cluster.
The investigator said the syndicate's operations spanned Hong Kong and mainland China. North Korean hackers are known to use a multi-stage laundering process involving chain-hopping and token swapping through decentralized exchanges, bridges, and other services to obscure the flow of funds.
The Bybit breach was not the only incident tied to the network. ZachXBT said Chinese actors were also involved in laundering proceeds from the $387.5 million Bitget exploit in September 2026. Bitget CEO Gracy Chen named North Korea as the likely culprit, and blockchain tracing firm Elliptic said the stolen funds were linked to addresses used to launder the Bybit theft. The firm noted that reusing the same laundering routes is a common pattern for North Korean hackers and that the Bitget attack pushed suspected North Korean crypto thefts above $1 billion for 2026.
ZachXBT flagged five accounts in the Bitget laundering effort, including one operating as "lolo" that also handled proceeds from the $292 million Kelp DAO exploit in April 2026. Some operators had been openly seeking support in public Discord servers and Telegram channels operated by services they used.
The involvement of Chinese intermediaries in North Korean crypto laundering is not a new allegation. In 2020, U.S. prosecutors charged two Chinese nationals with laundering more than $100 million stolen by North Korean hackers from a cryptocurrency exchange in 2018. In 2023, the U.S. Treasury Department's Office of Foreign Assets Control sanctioned two crypto traders, one from Hong Kong and the other from China, for helping the Democratic People's Republic of Korea convert stolen crypto and bypass financial controls.
ZachXBT's investigation also surfaced a Cambodia connection. Jimmy told him he had laundered $3 million in fraud proceeds for a different client, and ZachXBT traced those funds to a hot wallet used by Huione Guarantee, a Telegram marketplace where criminals sold laundering services and stolen data. Huione Guarantee is part of Huione Group, the Cambodian conglomerate targeted by the U.S. Treasury's FinCEN over alleged laundering of at least $4 billion. Telegram banned the marketplace in May 2025, and Chinese authorities arrested former Huione Group chairman Li Xiong after Cambodia deported him.
Chainalysis estimates that hackers linked to North Korea have stolen at least $6.75 billion in digital assets through 2025.
Implications for Compliance and Enforcement
The investigation offers a rare look at the professional intermediaries who handle stolen crypto for state-sponsored actors. If the network operated at the scale described, it would represent a significant compliance failure across multiple touchpoints, including exchanges, OTC desks, and fiat offramps that may have accepted deposits without knowing the original source.
Blockchain's transparent ledger makes retroactive tracing possible, which is precisely what ZachXBT's methodology relies on. But real-time screening at the point of transaction remains the more effective intervention. For exchanges and payment processors, wallet provenance screening and transaction monitoring are not optional for any entity touching funds that may have moved through Lazarus-adjacent infrastructure.
The broader pattern aligns with a documented trend of state-sponsored actors using professional third-party networks to distance stolen funds from their origin. Law enforcement recoveries in crypto fraud cases have increased as on-chain tracing tools improve, but prosecutions lag investigations by months or years. ZachXBT's work accelerates the public identification phase; the legal phase depends on jurisdictional cooperation that does not always materialize quickly when alleged actors are based in countries with limited extradition agreements with the United States.
ZachXBT said his findings went immediately to trusted private-sector investigators and to law enforcement assigned to the case. Since 2022, he wrote, his work has helped freeze more than $75 million tied to North Korea-linked incidents. He said grants from foundations and donations from individuals allowed him to take on riskier cases like this one.
"Throughout our conversations, Jimmy and I had a lot of small talk in between discussing laundering for DPRK," ZachXBT said. "He talked about playing mahjong, hunting wild rabbits, food, his fat reducing meal, family life, and vacations at Disney."
The allegations have not been adjudicated by any court or confirmed by law enforcement as of publication.
Once added, BigGo Finance appears first in Google Search Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.