Advertise

Ethereum

ZachXBT Fronted $349,700 USDC on Ethereum (ETH) to Infiltrate Lazarus Launderers

ZachXBT fronted $349,700 in USDC to pose as a laundering client, exposing a Chinese syndicate that moved over $1 billion for North Korea's Lazarus Group.

Be a creator
October 5, 2026, 07:31 PM UTC4 min read
AI SummaryAI
  • ZachXBT fronted 349,700 USDC on Ethereum on March 6, 2025 to pose as a laundering client.
  • Tether froze 442,000 USDT tied to a $12 million cluster of Bybit exploit funds.
  • The Chinese syndicate allegedly laundered over $1 billion across exploits for North Korea's Lazarus Group.
  • The February 2025 Bybit exploit drained $1.5 billion and was attributed to TraderTraitor.
gate.com

On-chain investigator ZachXBT says he went inside a Chinese organized crime syndicate that has laundered more than $1 billion in stolen crypto for North Korea's Lazarus Group, and it cost him $349,700 of his own money to do it. In a thread published on October 5, 2026, he wrote that posing as a client let him gather intelligence later used to action freezes for the February 2025 Bybit exploit and attribute illicit activity on-chain.

The sequence began shortly after the $1.5 billion Bybit hack, when he spotted more than 15 accounts in public Telegram and Discord groups asking for help with orders tied to stolen funds. One operator used the alias “Jimmy Green.” On March 6, 2025, ZachXBT funded a fresh address on Ethereum (ETH) with 349,700 USDC, the stablecoin issued by Circle Internet Group, and began transacting with Jimmy, who swapped the USDC for USDT on Tron. That destination address had received gas from a wallet directly traceable to Bybit exploit funds and labeled on the public Bybit exploit blacklist.

Every completed order lost him 5%, and he concedes there was no guarantee Jimmy would not vanish with the funds, alongside an unknown amount of personal risk. The payoff came in intelligence: Jimmy discussed Bybit fund movements for the DPRK before they happened, along with operational details in Hong Kong and mainland China. By March 10 he was pressing for more orders; when the fake persona balked, he answered that the team had $1 million ready to start work at any time. On March 12, 2025, ZachXBT matched a screenshot Jimmy sent of himself bridging funds to an order logged minutes earlier on the Thorchain explorer, a public record of swaps on the cross-chain protocol. Jimmy then shared three Solana addresses that exposed a cluster of more than $12 million in Bybit loot hopping from Bitcoin to Ether to Solana and finally to Tron. Tether later froze 442,000 USDT linked to that cluster.

From Bybit Loot to Huione

The Bybit record underpins the case. ZachXBT linked the February 2025 exploit, which drained $1.5 billion from the exchange, to Lazarus Group using on-chain data on the day of the attack, and the FBI confirmed the attribution days later, assigning it to the cluster it tracks as TraderTraitor. He also showed that wallets laundering the Bybit funds tied back to earlier Lazarus attacks at Phemex and BingX. In a follow-up post, Jimmy claimed his team had laundered most of the Bybit proceeds and shared exploiter addresses plus an example of bridging through THORSwap.

The cross-checks mattered as much as the chatter. Jimmy mentioned a team with roughly $300,000 frozen in 2024; on-chain, the freeze was 332,000 USDC stolen in the November 2023 Poloniex exploit, a breach of more than $100 million that researchers have tied to Lazarus. When Jimmy said he had laundered $3 million in fraud proceeds for another client, ZachXBT traced the funds to a hot wallet used by Huione Guarantee, the Telegram marketplace tied to Cambodian conglomerate Huione Group, which the U.S. Treasury's FinCEN targeted over alleged laundering of at least $4 billion. Telegram banned the marketplace in May 2025, and Chinese authorities arrested former Huione Group chairman Li Xiong after Cambodia deported him.

The method is repeatable, too. Last week, after the $387 million Bitget hack, which Bitget's CEO and tracing firms Elliptic and Chainalysis have linked to North Korea, he again surfaced multiple Chinese accounts soliciting laundering help. ZachXBT says he has helped action more than $75 million in freezes tied to DPRK incidents since 2022. Paradigm hired him as an incident response advisor in February 2025, with co-founder Matt Huang saying he had returned more than $350 million to victims of hacks and scams, and he funds riskier work through foundation grants and individual donations.

What the Sting Changes

COINOTAG's read: the disclosure is less about the money than about method. A private investigator financing an operation out of pocket, eating a 5% loss on every order, produced verifiable on-chain anchors that issuers and law enforcement could act on, from the 442,000 USDT freeze to the $75 million in cumulative DPRK-linked freezes since 2022. The findings matter more for enforcement than for Ethereum (ETH) price direction. The sensitivity ZachXBT describes, holding publication until private-sector investigators and assigned law enforcement finish their work, means results surface late and in bulk, as this one did, roughly 19 months after the Bybit exploit and only after the freezes were already in place.

Readers tracking the market in real time can follow live spot and futures prices on Gate.

Primary sources

COINOTAG's editorial and research desk.

AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.