ZachXBT says he paid $350K into a North Korea-linked laundering ring to trace it from the inside
On-chain investigator ZachXBT says he sent $349,700 of his own money to a Chinese syndicate laundering for North Korea, posing as a client to trace Bybit hack proceeds and trigger freezes.
The pseudonymous on-chain investigator ZachXBT published a thread on X on October 5, 2026, describing a tactic that goes well beyond the usual armchair blockchain tracing: he says he wired $349,700 of his own funds to a Chinese organized-crime syndicate that launders money for North Korea's Lazarus Group, posing as a paying customer to gather intelligence in real time. Decrypt reported the thread.
By his account, the operation began in February 2025, shortly after the roughly $1.5 billion Bybit exploit the FBI attributed to a DPRK-linked group it tracks as TraderTraitor. ZachXBT says he spotted 15-plus accounts in public Telegram and Discord groups seeking help moving funds tied to the hack, and began messaging one operator going by "Jimmy Green." On March 6, 2025, he says, he funded a fresh Ethereum address with 349,700 USDC to trade with Jimmy, swapping it for USDT on Tron and absorbing a 5% loss on every order to build trust and keep the intelligence flowing. The deposit address, he wrote, had been gas-funded by a wallet traceable to Bybit exploit funds on the public blacklist.
ZachXBT says the chats and matching on-chain activity exposed a cluster of more than $12 million in Bybit proceeds being swapped across Bitcoin, Ether, Solana and Tron, and that Tether later froze 442,000 USDT linked to it. He says Jimmy also volunteered checkable details — a prior ~$332,000 USDC freeze from the November 2023 Poloniex hack, and $3 million in fraud proceeds traceable to a Huione Guarantee hot wallet, the Cambodian marketplace FinCEN targeted over at least $4 billion in alleged laundering.
Key facts
- Amount fronted: 349,700 USDC, sent March 6, 2025; 5% lost per order — ZachXBT via X/Decrypt.
- Bybit exploit: ~$1.5B, Feb 2025, attributed to DPRK "TraderTraitor" — FBI, per Decrypt.
- Cluster exposed: $12M+ in Bybit funds; 442,000 USDT frozen by Tether — ZachXBT.
- Claimed lifetime impact: $75M+ in freezes tied to DPRK incidents since 2022 — ZachXBT.
- Funding model: foundation grants and individual donations; Paradigm hired him as an incident-response advisor in Feb 2025 — Decrypt.
The real-world read
Nearly every specific here comes from one interested party — ZachXBT's own thread — so treat the figures as his claims, not independently confirmed. That said, his attribution record is checkable: he tied the Bybit hack to Lazarus on day one and the FBI concurred days later, and several of his sting details (the Poloniex freeze, the Huione link) point at publicly documented events. What's unverified is the sting's framing: the dollar amounts, the 5% losses, and the "Jimmy" chats are self-reported, and no law-enforcement body has publicly corroborated this specific operation. He also says sensitivity delayed publication — convenient, but not inherently suspect. Decrypt is reputable secondary reporting; the underlying source is ZachXBT.
Not financial advice.
Sources
- Decrypt (Tier 2, secondary), Oct 5, 2026 — reported and quoted ZachXBT's X thread, plus background on his prior work, Paradigm's hiring, and the Huione/Poloniex context. Not sponsored.
- ZachXBT on X (primary, interested party) — the self-reported account of the sting, figures, and chat logs, as quoted by Decrypt.