cleartext

Independent, sourced crypto news. No paid placements.

lazarus

ZachXBT says he spent $349,700 posing as a client to infiltrate a laundering ring tied to the Bybit hack

Onchain investigator ZachXBT says he posed as a client and fronted $349,700 in stablecoins to infiltrate a Chinese laundering network he alleges moved over $1 billion for North Korea's Lazarus Group, including funds from the $1.5 billion Bybit hack.

Onchain investigator ZachXBT said he spent months undercover inside an alleged Chinese organized-crime network, posing as a paying client and fronting $349,700 in stablecoins, to gather intelligence on a group he says laundered more than $1 billion for North Korea's Lazarus Group — including proceeds of the February 2025 Bybit hack, the largest crypto theft on record at roughly $1.5 billion.

In a detailed thread on X, as reported by The Block, ZachXBT said he began digging after spotting more than 15 accounts across Telegram and Discord seeking help with orders tied to stolen Bybit funds. Posing as a client, he funded a fresh address with 349,700 USDC on Ethereum and began transacting with a vendor using the pseudonym "Jimmy Green."

In March 2025, ZachXBT said, Jimmy supplied a Tron receiving address beginning "0xbaa5" to swap USDC for USDT. That address, he said, was gas-funded by a wallet "directly traceable to Bybit exploit funds" and already on Bybit's public exploit blacklist. Jimmy allegedly discussed moving Bybit funds for North Korea before the transfers happened — on one occasion saying a day in advance that funds would move to Solana, which ZachXBT said they then did — and claimed his team had laundered most of the $1.5 billion.

Several of Jimmy's claims were independently checkable against the chain, ZachXBT said: a March 12 bridge screenshot matched a THORChain order created minutes later; three Solana addresses helped surface a cluster of over $12 million in Bybit funds swapped across BTC, ETH, SOL and Tron, after which Tether froze 442,000 USDT; a reference to roughly $300,000 frozen in 2024 matched 332,000 USDC from the Poloniex exploit; and $3 million Jimmy claimed to have laundered for another client traced to a hot wallet of the sanctioned Huione Guarantee. ZachXBT said he passed his findings to law enforcement, lost about 5% per order with no guarantee Jimmy wouldn't vanish with the money, and has helped freeze $75 million tied to North Korean incidents since 2022.

Key facts

  • $349,700 in USDC fronted by ZachXBT to infiltrate the network (ZachXBT via The Block).
  • Network allegedly laundered $1 billion-plus across Lazarus-linked exploits; Bybit hack ~$1.5 billion (ZachXBT via The Block).
  • 442,000 USDT frozen by Tether on a >$12M Bybit cluster; 332,000 USDC matched to Poloniex; $3M traced to Huione Guarantee (ZachXBT via The Block).
  • $75 million frozen across DPRK incidents since 2022 (ZachXBT via The Block).

The real-world read

Every allegation here — the $1 billion figure, the DPRK links, Jimmy's boasts — originates from a single party: ZachXBT's own X thread. The Block is reporting his account, not independently verifying it, and ZachXBT is an interested party who has been inside the operation. His case rests on onchain corroboration (the blacklisted gas wallet, the THORChain timing, the Tether freeze), which is checkable, versus Jimmy's unverifiable chatter about mahjong, Disney trips and who laundered what. Treat the verifiable chain movements as the solid part and the attributed quotes as claims. "Jimmy Green" is a pseudonym; no arrests, charges, or law-enforcement confirmation have been disclosed, and the "helped action freezes" framing is ZachXBT's characterization of his own contribution.

This is news coverage, not financial advice.

Sources

  • The Block (Tier 2, secondary), 2026-10-06 — reported ZachXBT's X thread and the specific figures, addresses, and freezes cited above. The underlying primary source is ZachXBT's own public thread on X; no marketing or sponsored material was used.