ZachXBT: $349,700 sting traced Bybit hack funds to Lazarus-linked network

In this article
Blockchain investigator ZachXBT said he funded a fresh Ethereum address with 349,700 USDC and posed as a paying client to infiltrate an alleged Chinese money-laundering network that moved more than $1 billion for North Korea-linked hackers, according to Crypto.news. The operation helped trace funds linked to Bybit’s $1.5 billion theft in February 2025 and prompted a freeze of 442,000 USDT, he said.
Crypto.news reported that ZachXBT disclosed the operation in an X thread on Oct. 5, 2026, more than 19 months after the hack. He said the sensitivity of the work kept him from publishing the details until then, and that he shared the findings with private-sector investigators and law-enforcement officers assigned to the case while it was still active.
A trade, a screenshot, and a trail across four chains
According to Crypto.news, ZachXBT contacted the operator in late February 2025 after finding more than 15 accounts in public Telegram and Discord groups seeking help with transactions tied to the Bybit hack. By March 6, he had funded the Ethereum address with 349,700 USDC.
PANews, covering the same thread, described that transaction differently: it reported that on March 6, 2025, ZachXBT transferred $3.497 million in USDC to conduct a USDC-to-TRON USDT swap — 10 times the figure Crypto.news published. Both outlets agree the address’s gas funds traced back to the Bybit hack and that it had been publicly flagged on Bybit’s blacklist.
The first on-chain link, per Crypto.news, came from the payment route used for one of the trades. Later conversations produced advance details about where stolen assets would move. On March 12, the operator sent a screenshot showing a swap of 1.192 BTC for 51.73 ETH, which ZachXBT matched by timing and amount to a THORChain transaction that traced back through intermediary wallets to Bybit-linked funds.
He said the operator later claimed that “almost all of the 1.5 billion eth was laundered by our team” — a statement Crypto.news noted has not been independently confirmed by law enforcement. Cointelegraph reported that ZachXBT said the group’s operations spanned Hong Kong and mainland China, and PANews added that the group also attempted to move funds through Uniswap liquidity pools and low-liquidity tokens.
The freeze that Tether’s public records don’t match
Crypto.news reported that Tether later froze 442,000 USDT connected to the wallet cluster ZachXBT identified, but that neither of Tether’s public releases on the Bybit case broke out that figure or linked it to the “Jimmy Green” operation.
Those releases put the confirmed numbers higher and earlier. On March 26, 2025, the T3 Financial Crime Unit — a partnership involving Tether, TRON and TRM Labs — announced it had frozen nearly $9 million connected to the hack. By Oct. 31, 2025, Tether said T3-related cases had frozen $19 million tied to the Bybit incident.
ZachXBT said information from the same contact pointed to other illicit flows. One case involved 332,000 USDC from the 2023 Poloniex hack that had been frozen in 2024; another $3 million batch was traced to a wallet associated with Huione Guarantee. U.S. Treasury records later described Huione Group as a critical laundering node for proceeds from North Korean cyber heists and cut the Cambodia-based group off from the U.S. financial system in 2025, Crypto.news reported.
Why it matters
The thread offers a rare look at the intermediaries that handle North Korea’s stolen crypto — a role U.S. authorities have flagged before, sanctioning Chinese and Hong Kong-based traders in 2023 over DPRK conversion activity. The Bybit recovery picture came largely from this kind of private tracing: Bybit CEO Ben Zhou said on March 4, 2025 that 77% of the stolen funds remained traceable, 20% had gone dark and 3% had been frozen, with 83% converted into Bitcoin. Attribution remains the gap — no public filing names the operator, and the alleged network’s size and identity rest on ZachXBT’s account.
For exchanges, bridges and analytics firms, the case reinforces how quickly stolen assets cross chains the FBI asked them to monitor. Bybit’s forensic update said compromised credentials belonging to a Safe developer let the attacker reach Safe infrastructure and deceive signers into approving a malicious transaction; reviews by Verichains and Sygnia Labs found no evidence Bybit’s core infrastructure had been compromised.
What to watch
Chainalysis said on Oct. 1 that investigators were working with Bitget and law-enforcement partners after $387 million was stolen from the exchange on Sept. 24, 2026 — an attack the firm attributed to North Korean actors and said pushed their 2026 crypto haul above $1 billion. It said investigators would keep monitoring the stolen funds and sharing intelligence with partners in the coming weeks. Whether any agency converts ZachXBT’s findings into a charge or a named suspect is the next test of the operation’s value.
Frequently Asked Questions
Who are the Lazarus Group and TraderTraitor?
The FBI attributed the February 2025 Bybit theft to North Korean state-backed actors it tracks as TraderTraitor, part of the Lazarus Group. Chainalysis estimates North Korean hackers stole $2.02 billion in crypto during 2025.
How much did ZachXBT say he spent on the undercover operation?
ZachXBT said he funded a fresh Ethereum address with 349,700 USDC and accepted a roughly 5% loss on each order to build trust with the network operator known as “Jimmy Green.” PANews reported that the swap involved $3.497 million in USDC, 10 times that amount.
Has Tether’s 442,000 USDT freeze been confirmed?
Tether has confirmed larger freezes tied to the Bybit theft, including nearly $9 million announced by the T3 Financial Crime Unit on March 26, 2025, and $19 million in T3-related cases by Oct. 31, 2025. Neither release broke out the 442,000 USDT figure ZachXBT described or linked it to the operation.
Have law enforcement agencies named the operator?
No. Public releases from the FBI, U.S. Treasury and Tether reviewed as of Oct. 6 do not identify “Jimmy Green” or independently confirm that one Chinese network laundered more than $1 billion for Lazarus Group.
Are North Korea-linked thefts still happening in 2026?
Yes. Chainalysis said on Oct. 1 that it was working with Bitget and law-enforcement partners after $387 million was stolen from the exchange on Sept. 24, 2026, an attack the firm attributed to North Korean actors and said pushed their 2026 haul above $1 billion.
Sources: crypto.news, PANews, Cointelegraph


