Loading prices…
🩸BEARISH

ZachXBT Exposes Alleged $1B Lazarus Laundering Network

The investigation links Bybit exploit funds to alleged laundering operations and highlights how blockchain tracing can support freezes, even when investigators must risk funds to gather evidence.

Blockchain investigator ZachXBT says he spent $349,700 in USDC to infiltrate a Chinese crime network allegedly laundering funds for North Korea’s Lazarus Group, including proceeds tied to the 2025 Bybit hack. He says the group claimed to have laundered most of the $1.5 billion stolen from Bybit, and that its operations were consistent with patterns he traced across more than 15 online accounts.

Why it matters

ZachXBT said he posed as a client and exchanged USDC for USDT through a vendor using the name “Jimmy Green.” An address provided by the vendor was funded by a wallet he linked to the Bybit exploit and that appeared on Bybit’s public blacklist. The investigator also said the vendor discussed moving Bybit funds to Solana before the funds moved.

He said three Solana addresses helped identify a cluster containing more than $12 million in Bybit exploit funds, swapped across BTC, ETH, SOL and Tron. Tether later froze 442,000 USDT linked to that cluster. ZachXBT also linked a separate roughly $300,000 freeze claim to 332,000 USDC from the Poloniex exploit, and traced another alleged $3 million laundering operation to a Huione Guarantee hot wallet.

Market impact

The case shows how transaction tracing and coordination with law enforcement and issuers can turn blockchain evidence into freezes. ZachXBT said he lost about 5% per order while funding the operation, with no guarantee the vendor would not disappear with the money.

He said he shared his findings with law enforcement and has helped facilitate freezes of $75 million tied to North Korean incidents since 2022. The allegations underscore the ongoing challenge of tracing stolen funds across chains and converting intelligence into action.

Related tokens
$USDC $USDT $BTC $ETH $SOL

Frequently asked questions

  1. How did ZachXBT say he gained access to the alleged laundering network?

    He said he posed as a client and funded an address with $349,700 in USDC to conduct transactions with a vendor using the name “Jimmy Green.”

  2. What evidence did ZachXBT link to the Bybit exploit?

    He said the vendor’s receiving address was funded by a wallet traceable to Bybit exploit funds and listed on Bybit’s public exploit blacklist.

  3. How much of the traced Bybit-linked funds did Tether freeze?

    Tether froze 442,000 USDT linked to a cluster containing more than $12 million in Bybit exploit funds, according to ZachXBT.

  4. Which blockchain assets were involved in the identified Bybit fund cluster?

    ZachXBT said funds in the cluster were swapped across BTC, ETH, SOL and Tron.

  5. What financial risk did ZachXBT say he took during the operation?

    He said he lost about 5% per order and had no guarantee the vendor would not disappear with the funds.

Source attribution
Aggregated from TheBlock · Verified · Last refreshed 51m ago
Open original →