ZachXBT Says He Infiltrated Chinese Laundering Network Tied to Lazarus
- ZachXBT spent months posing as a customer to infiltrate a Chinese criminal network allegedly responsible for laundering more than US$1 billion for North Korea’s Lazarus Group.
- The investigation began after the US$1.5 billion Bybit hack, when suspicious accounts openly sought laundering assistance through Telegram and Discord.
- Wallet addresses and transaction records helped ZachXBT trace millions in stolen funds, including a cluster linked to 442,000 USDT subsequently frozen by Tether.
- Having helped secure freezes involving more than US$75 million in DPRK-linked funds since 2022, ZachXBT is seeking funding for further investigations.
Nothing screams criminal mastermind like a money launderer swapping stories about rabbit hunting and Disney holidays. Yet that’s what ZachXBT says he got from a man calling himself Jimmy Green.
ZachXBT spent months undercover, gaining the trust of suspected Chinese money launderers allegedly responsible for processing more than US$1 billion (AU$1.43 billion) in stolen crypto linked to North Korea’s Lazarus Group. He detailed his findings in a thread on 5 October.
Public Groups, Public Mistakes
It began in February 2025, shortly after the US$1.5 billion (AU$2.15 billion) Bybit hack. More than 15 accounts caught his attention, with users openly discussing transactions involving stolen Bybit funds on Telegram and Discord.
He approached several accounts, and Jimmy responded. On 6 March, ZachXBT funded a fresh wallet with 349,700 USDC (approx. AU$501,697) to trade for Jimmy’s USDT on Tron. The wallet Jimmy used to send the funds had received gas from an address linked to the Bybit hack, one that was already on a public blacklist.
Read more: Australia Opens AFCA Complaints Path for Digital Asset Users
More trades followed to build trust, each costing ZachXBT roughly 5%.
Then Jimmy got chatty. He’d flag transactions before they happened. Funds were heading to Solana one day and, sure enough, they turned up the next. Jimmy also claimed his team had laundered most of the stolen Bybit funds.
[…] Jimmy began to talk about moving Bybit funds for DPRK in advance of it happening, along with basic details about their operation in HK and mainland China.
ZachXBT The evidence began piling up. A screenshot Jimmy shared of a bridging transaction matched an order on THORChain. Three Solana addresses he provided exposed a cluster holding more than US$12 million (AU$17.2 million), with funds moving between BTC, ETH, SOL and Tron in real time.
Tether subsequently froze 442,000 USDT (approx. AU$634,179) linked to the cluster.
The group had also experimented with another laundering method, using Uniswap liquidity pools filled with illiquid tokens.
Some of Jimmy’s claims appeared to check out, too. ZachXBT traced a US$3 million (AU$4.3 million) batch of fraud proceeds to a Huione Guarantee hot wallet. The company has since been sanctioned, while its former chairman was arrested.
Who’s Paying for This?
There was no guarantee Jimmy wouldn’t simply disappear with the money. ZachXBT also acknowledged taking “an unknown amount of personal risk” during the investigation.
His findings were shared with private-sector investigators and law enforcement, which explains why he’s only now making the details public.
Since 2022, ZachXBT says he’s helped secure freezes involving more than US$75 million (AU$107.6 million) in DPRK-linked funds. He is now publicly seeking grants and donations to finance investigations involving greater personal and financial risks.
I hope to continue receiving grants from foundations and donations from individuals, as it enables me to take on higher risk for unique cases that others may not consider viable.
ZachXBT And there’s more to come. ZachXBT plans to release further data in the coming weeks on groups allegedly involved in laundering funds from the US$387 million (AU$555.2 million) Bitget exploit.
Read also: CFTC Moves Ahead With Crypto Rulebook Despite CLARITY Setback