ZachXBT Posed as a Client to Infiltrate Lazarus Group's Laundering Ring

iEXExchanger
ZachXBT Posed as a Client to Infiltrate Lazarus Group's Laundering Ring

Investigator ZachXBT fronted $349,700 to pose as a client of a Chinese laundering ring tied to North Korea's hackers — and helped Tether freeze $442,000 linked to the Bybit hack.

He talked mahjong, restaurants and a Disney trip with a man who called himself "Jimmy Green." What he was actually doing was mapping how North Korea launders stolen billions.

Blockchain investigator ZachXBT says that in the spring of 2025 he infiltrated a Chinese money-laundering network serving North Korea's Lazarus Group. He set up a fake client account and ran $349,700 in USDC through it on Ethereum, knowingly eating a roughly 5% loss on every transfer just to keep an operator named Jimmy Green trusting him.

The bet paid off. Jimmy didn't just convert USDC to USDT on Tron and route the rest to Solana — he admitted his team had laundered most of the $1.5 billion stolen from Bybit in February 2025. That heist has long been attributed to Lazarus Group, the unit Chainalysis says has stolen at least $6.75 billion from crypto since it started operating.

The addresses ZachXBT gathered let him trace more than $12 million tied to the Bybit hack across several blockchains, and Tether froze 442,000 USDT linked to that wallet cluster. By his own account, the broader network — straddling Hong Kong and mainland China — may have laundered over $1 billion from various Lazarus exploits since 2022, the year he first helped freeze $75 million in North Korea-linked funds.

For now, the bigger numbers rest on one investigator's account and an anonymous middleman's admissions — there's no court ruling or official probe backing them yet. But the 442,000 USDT freeze is proof that even a laundering operation built over years still leaves a trail someone can follow.

Questions and answers

Frequently asked questions about this article

Who is ZachXBT?

A pseudonymous blockchain investigator who has tracked stolen crypto since 2022 and helped exchanges and stablecoin issuers freeze funds linked to North Korea.

What exactly did he do?

In the spring of 2025 he posed as a paying client of a Chinese laundering network, sent an operator nicknamed Jimmy Green $349,700 in USDC, and knowingly took a roughly 5% loss on each deal to earn trust.

How is this connected to the Bybit hack?

In February 2025, hackers stole $1.5 billion from Bybit; the attack is attributed to Lazarus Group. Jimmy Green admitted to ZachXBT that his team laundered most of that money.

What did Tether do, and how big is the whole network?

Based on addresses ZachXBT gathered, Tether froze 442,000 USDT from a wallet cluster tied to the Bybit hack. By the investigator's own estimate, the syndicate operating between Hong Kong and mainland China may have laundered over $1 billion from various Lazarus exploits since 2022 — though that figure isn't confirmed by a court or an independent probe.