He talked mahjong, restaurants and a Disney trip with a man who called himself "Jimmy Green." What he was actually doing was mapping how North Korea launders stolen billions.
Blockchain investigator ZachXBT says that in the spring of 2025 he infiltrated a Chinese money-laundering network serving North Korea's Lazarus Group. He set up a fake client account and ran $349,700 in USDC through it on Ethereum, knowingly eating a roughly 5% loss on every transfer just to keep an operator named Jimmy Green trusting him.
The bet paid off. Jimmy didn't just convert USDC to USDT on Tron and route the rest to Solana — he admitted his team had laundered most of the $1.5 billion stolen from Bybit in February 2025. That heist has long been attributed to Lazarus Group, the unit Chainalysis says has stolen at least $6.75 billion from crypto since it started operating.
The addresses ZachXBT gathered let him trace more than $12 million tied to the Bybit hack across several blockchains, and Tether froze 442,000 USDT linked to that wallet cluster. By his own account, the broader network — straddling Hong Kong and mainland China — may have laundered over $1 billion from various Lazarus exploits since 2022, the year he first helped freeze $75 million in North Korea-linked funds.
For now, the bigger numbers rest on one investigator's account and an anonymous middleman's admissions — there's no court ruling or official probe backing them yet. But the 442,000 USDT freeze is proof that even a laundering operation built over years still leaves a trail someone can follow.



