
ZachXBT Lazarus investigation: how he infiltrated a Chinese crypto syndicate and traced laundering linked to the $1.5B Bybit hack.
Author: Kritika Gupta
5th October 2026 – On-chain investigator ZachXBT says he posed as a client to infiltrate a Chinese crypto laundering syndicate that he links to North Korea’s Lazarus Group. He laid out the account in a 12-part thread on X.
High Signal Summary For A Quick Glance
Lavneet Bansal
@lavneetwtf
@zachxbt You have been taking so much risk exposing all these scammers and money launderers. I don't understand why most of the CT acts entitled while asking help from you. Thank you for the great work 🫡.
1/ How I infiltrated a Chinese organized crime syndicate that has laundered $1B+ across multiple exploits for Lazarus Group. Posing as a client, I gathered intel that helped action freezes for the Feb 2025 Bybit exploit and attribute illicit activity onchain. https://t.co/jauRRt8875
12:42 PM·Oct 5, 2026
Chlooe☀️
@chloesnugly
@zachxbt the bio literally says “won’t flow back” like that makes it better. zachxbt doing this out in the open is genuinely insane work and hes still the only one asking to get paid for it
1/ How I infiltrated a Chinese organized crime syndicate that has laundered $1B+ across multiple exploits for Lazarus Group. Posing as a client, I gathered intel that helped action freezes for the Feb 2025 Bybit exploit and attribute illicit activity onchain. https://t.co/jauRRt8875
12:42 PM·Oct 5, 2026
ACHIVX
@ACHIVX_com
@zachxbt the advance warning offered in your second screenshot is partly public, @zachxbt. a usdt blacklist call sits on tether's multisig before it executes, in the open. in our freeze log the median wait is 25 minutes on tron and 44 on ethereum. 13,259 addresses sit frozen today.
1/ How I infiltrated a Chinese organized crime syndicate that has laundered $1B+ across multiple exploits for Lazarus Group. Posing as a client, I gathered intel that helped action freezes for the Feb 2025 Bybit exploit and attribute illicit activity onchain. https://t.co/jauRRt8875
12:34 PM·Oct 5, 2026
Low Attention
Overheated
High attention and emotional sentiment detected.
According to ZachXBT, the syndicate has moved more than $1 billion for Lazarus across several exploits. He also says his intel helped freeze funds tied to the February 2025 Bybit hack. Still, almost every detail rests on his word alone.
ZachXBT runs one of crypto’s best-known independent investigation accounts. After the Bybit hack, he says he spotted more than 15 accounts seeking help to launder stolen funds in public Telegram and Discord groups. So he reached out to several of them.
One used the alias Jimmy Green. On 6 March 2025, ZachXBT funded a fresh wallet with 349,700 USDC. Then he began swapping that USDC for Tron-based USDT with the counterparty.
He says he lost about 5% on each order to stay in the flow. Because of that cost, the trades built trust and kept the chat open. Over the following days, Jimmy shared screenshots, wallet addresses, and advance notice of upcoming moves.
ZachXBT says Jimmy claimed his team laundered most of the $1.5 billion from Bybit. Jimmy also described the operation as based in Hong Kong and mainland China. As a result, ZachXBT labeled it a Chinese crypto laundering syndicate.
The strongest part of the account is the on-chain data, which anyone can check. ZachXBT Lazarus published wallet addresses, one bridge transaction, and three Solana addresses. Block explorers confirm those transactions, though not the identity behind them.
He says Jimmy’s receiving wallet drew its gas from an address already on the Bybit exploit blacklist. Then, on 12 March 2025, a bridging screenshot matched a THORChain transaction by amount and timing. Because the FBI had attributed the hack weeks earlier, the timeline fits.
Three Solana addresses then exposed a cluster of more than $12 million in Bybit funds, according to ZachXBT. The money hopped from Bitcoin to Ethereum to Solana to Tron in real time. He says Tether later froze 442,000 USDT linked to that cluster. He also matched a smaller freeze Jimmy mentioned to a 332,000 USDC seizure from the Poloniex exploit.
Key milestones related to this development
About $625 million was stolen in an exploit later attributed to Lazarus.
About $100 million was stolen in another major exploit later linked to Lazarus.
Roughly $230–235 million was stolen in an attack widely linked to Lazarus.
Attackers stole approximately $1.5 billion in virtual assets in the Bybit breach.
ZachXBT says he funded a wallet with $349.7K USDC and began trading with a counterparty using the alias “Jimmy Green.”
Chat records, transaction screenshots and wallet activity helped ZachXBT trace movements involving Bybit-linked funds.
ZachXBT says intelligence from his investigations contributed to freezes involving DPRK-linked funds, including 442K USDT later frozen by Tether.
Bybit reported $48.4 million recovered and $30.5 million frozen in connection with its lawsuit against the DPRK, Reconnaissance General Bureau and Lazarus Group.
ZachXBT publishes a 12-part thread detailing his alleged infiltration of a Chinese laundering syndicate linked to Lazarus and the Bybit hack.
The underlying hack is well documented, even if this infiltration is not. The FBI said on 26 February 2025 that North Korea stole about $1.5 billion from Bybit. It named the activity TraderTraitor.
Attackers drained more than 400,000 ETH after altering a Safe{Wallet} signing flow. It remains the largest crypto exchange hack on record. Within hours, customers pulled close to $10 billion, about half of Bybit’s deposits. By early March 2025, Bybit said about 20% of the funds had gone dark.
In August 2026, Bybit sued North Korea and Lazarus and reported $48.4 million recovered and $30.5 million frozen. That is roughly 5% of the haul. Those are Bybit’s figures, and the exchange does not tie them to ZachXBT’s operation.
DPRK crews rarely cash out the coins themselves. Instead, Chinese-speaking OTC desks and underground markets convert stolen crypto into USDT or cash for a fee. This cash-out layer is where a Chinese crypto laundering syndicate earns its spread.
The best-documented example is Huione Guarantee. In May 2025, FinCEN moved to call Huione Group a primary money-laundering concern, and Telegram removed it. Its former chairman was later extradited to China, according to Elliptic.
Freezes only work where someone controls a balance. Tether and Circle can freeze their own stablecoins, and exchanges can lock deposits. Native Bitcoin and Ether, by contrast, cannot be frozen at the protocol layer.
How the latest investigation compares with the broader Lazarus laundering activity
So far, no Western wire has matched the reporting, and the first write-ups came from Chinese outlets. BlockBeats reported the fronted amount correctly as $349,700. Odaily and ChainCatcher misstated it as $3.497 million, which his own posts contradict.
The biggest claims still rest on one source. ZachXBT has not shown that his intel caused the 442,000 USDT freeze, and no Tether statement names that wallet. He also has not named Jimmy Green or confirmed any arrest.
Several questions stay open. It is unclear whether law enforcement authorized the trades, or how much he lost after the 5% haircut. For now, his track record is the main reason to take the account seriously.
ZachXBT says he has helped action more than $75 million in DPRK-related freezes since 2022. He also flagged a separate $387.5 million Bitget exploit in September 2026. So this thread likely feeds an ongoing investigation rather than closing one.
Watch for three signals next: a Tether confirmation on the 442,000 USDT, any arrest tied to Jimmy Green, and coverage from major outlets. Until then, treat the $1 billion total as a claim, not a verified figure. This article is reporting, not financial advice.
Our Crypto Talk is committed to unbiased, transparent, and true reporting to the best of our knowledge. This news article aims to provide accurate information in a timely manner. However, we advise the readers to verify facts independently and consult a professional before making any decisions based on the content since our sources could be wrong too. Check our Terms and conditions for more info.
ZachXBT Infiltrated Lazarus Laundering Ring Behind Bybit Hack
Kelsier Ventures As 1,000 Wallets Fell From $300M to $2M in LIBRA
Base Vault Exploit Drains $6M in wstETH Via Whitelist
MetaMask Security Incident Triggers Lido Validator Exits
ZachXBT Infiltrated Lazarus Laundering Ring Behind Bybit Hack
Kelsier Ventures As 1,000 Wallets Fell From $300M to $2M in LIBRA
Base Vault Exploit Drains $6M in wstETH Via Whitelist
MetaMask Security Incident Triggers Lido Validator Exits