Blockchain investigator ZachXBT has revealed details of an undercover operation in which he spent $349,700 of his own funds to infiltrate an alleged Chinese organized crime syndicate that laundered more than $1 billion for North Korea's Lazarus Group. The disclosure, published on X on Oct. 5, 2026, explains how he posed as a client to trace funds stolen in the $1.5 billion Bybit hack of February 2025.
According to ZachXBT, he contacted an operator using the alias "Jimmy Green" in late February 2025 after finding more than 15 accounts in public Telegram and Discord groups offering help with transactions tied to the Bybit exploit. By March 6, he had funded a fresh Ethereum address with 349,700 USDC and accepted a 5% loss per order to build trust. The first on-chain link reportedly came from a payment route where the receiving address had been funded for gas by a wallet traceable to the Bybit exploit and listed on Bybit's public blacklist.
The investigation eventually identified more than $12 million in Bybit-linked funds moving across several public blockchains, with assets shifting from Bitcoin to Ether and then to Solana and Tron. ZachXBT said Tether later froze 442,000 USDT connected to wallets uncovered during the operation. He also shared findings with private-sector investigators and law enforcement while the work was still active. The FBI had previously attributed the Bybit theft to North Korea's state-backed TraderTraitor actors, and Chainalysis estimates North Korean hackers stole a record $2.02 billion in crypto during 2025.
ZachXBT says he has helped facilitate more than $75 million in freezes tied to North Korea-linked incidents since 2022. While no public criminal charge names the operator described in his thread, the investigation highlights how on-chain analysis and undercover work can trace illicit flows across major blockchain networks and stablecoin rails.