Blockchain investigator ZachXBT says he spent nearly $350,000 posing as a customer of a Chinese organized-crime network in an undercover operation that helped trace funds from the $1.5 billion Bybit hack and contributed to the freezing of 442,000 USDT.
In an investigation published October 5, ZachXBT said the network had laundered more than $1 billion across multiple exploits for North Korea’s Lazarus Group. That $1 billion figure is ZachXBT’s assessment and has not been independently confirmed by law enforcement.
The operation began shortly after the February 2025 Bybit hack, when ZachXBT says he identified more than 15 accounts in public Telegram and Discord groups seeking assistance with transactions connected to stolen funds.
He subsequently approached an operator using the alias “Jimmy Green” and posed as a customer who needed cryptocurrency exchanged. On March 6, 2025, ZachXBT funded a new Ethereum wallet with 349,700 USDC and began conducting transactions with the operator, accepting losses of approximately 5% on each deal in order to build trust.
The unusual tactic gave him something conventional blockchain tracing could not: information directly from someone allegedly involved in moving the stolen assets.
A $349,700 Undercover Transaction Opened the Network
According to ZachXBT, Jimmy provided an Ethereum address where USDC could be sent in exchange for USDT on Tron.
ZachXBT traced the gas funding for that address back to a wallet associated with the Bybit exploit and listed on a public Bybit blacklist. He then continued conducting transactions with the operator, gradually collecting additional addresses and information about how the group moved funds.
The relationship eventually produced intelligence that ZachXBT says could be checked against public blockchain activity.
In one instance, Jimmy discussed upcoming movement of Bybit-linked assets before the transfer occurred. In another, he sent a screenshot showing a bridge transaction that ZachXBT matched by amount and timing to activity on THORChain.
Three Solana addresses later supplied by the operator helped expose a cluster containing more than $12 million in Bybit-linked assets that moved across Bitcoin, Ethereum, Solana and Tron.
Tether subsequently froze approximately 442,000 USDT associated with that cluster, according to ZachXBT.
The Bybit Attribution Is Stronger Than the $1B Claim
There are several different levels of evidence in the investigation, and they should not be treated as equally established.
The underlying Bybit attribution is unusually strong. The FBI formally attributed the approximately $1.5 billion February 2025 Bybit theft to North Korea and identified the activity as TraderTraitor.
ZachXBT’s links between individual wallets and the Bybit theft are also based partly on public blockchain data that can be checked independently.
Other claims rely more heavily on what the alleged laundering operator told him. Jimmy reportedly claimed his group had handled most of the stolen Bybit funds and described operations involving Hong Kong and mainland China.
Those statements provide useful investigative leads but do not independently prove the scale or organizational structure of the laundering network.
The same caution applies to ZachXBT’s statement that the syndicate laundered more than $1 billion across multiple Lazarus exploits. His October 5 disclosure does not provide a transaction-by-transaction calculation showing how the $1 billion total was reached.
The Network Appears to Extend Beyond Bybit
The investigation also suggests the laundering infrastructure was not created for a single hack.
ZachXBT says comments from Jimmy helped him connect other transactions with the Poloniex exploit and with Huione Guarantee, the Cambodian financial network that has repeatedly appeared in investigations involving cybercrime and illicit crypto flows.
More recently, ZachXBT said he observed a similar pattern of Chinese-language accounts seeking help with funds associated with September’s Bitget breach.
That matters because DaveFinances has already tracked how North Korea-linked indicators emerged during the Bitget investigation, although Bitget itself has described DPRK involvement as highly likely rather than definitively established.
The stolen Bitget portfolio has since fragmented across numerous laundering routes. Some funds moved through multiple blockchains before reaching Bitcoin and a Wasabi CoinJoin transaction, while thousands of stolen ZEC were later transferred into Zcash’s privacy infrastructure.
That broader pattern supports one of the most important lessons from ZachXBT’s investigation: stealing the cryptocurrency and laundering it are increasingly separate businesses.
Lazarus May Be Buying Laundering as a Service
The traditional image of a state-backed hacking group suggests one organization conducting the intrusion, controlling the stolen wallets and laundering the proceeds itself.
The October 5 investigation points toward a more modular system.
A hacking group can steal the assets while external brokers, OTC operators and organized-crime networks provide the infrastructure required to turn visibly stolen cryptocurrency into assets that are harder to trace or freeze.
That arrangement has obvious advantages for the attacker. Specialized laundering networks already have access to liquidity, accounts, cross-chain routes and counterparties willing to accept risky funds for a fee.
It can also create layers of separation between the hackers and the people who eventually convert the assets.
The apparent 5% fee ZachXBT says he paid is revealing. If similar pricing applies to genuine criminal customers, a laundering network processing hundreds of millions of dollars does not need to steal anything itself to generate significant revenue.
Cross-Chain Liquidity Is Becoming the Battleground
The laundering process also explains why bridges and decentralized liquidity networks repeatedly appear after major crypto thefts.
An attacker holding marked Ether has a tracing problem. Moving into Bitcoin, Solana, Tron or privacy-enhancing infrastructure changes the transaction graph and forces investigators to follow the assets through different systems.
That does not automatically make the money disappear, particularly when swap providers screen addresses or intermediaries can freeze assets.
The tension became especially visible after the Bitget breach, when THORChain and NEAR Intents took sharply different approaches to stolen-fund screening. NEAR Intents said it rejected tens of millions of dollars in attempted Bitget-linked flows, while permissionless protocols face a fundamentally different question about whether they can—or should—intervene.
ZachXBT’s undercover work effectively exploited the same ecosystem from the opposite direction. Rather than merely watching a bridge after stolen funds arrived, he obtained information from a person allegedly arranging the transactions and then used the blockchain to test what he had been told.
The $442,000 Freeze Shows Both the Power and Limits of Stablecoins
The reported Tether freeze demonstrates why stablecoins remain an important choke point in laundering operations.
Bitcoin, Ether and other permissionless assets cannot normally be frozen at the token level. Centralized stablecoins can.
If investigators identify illicit USDT before it moves again, Tether can blacklist the relevant address. That creates a strong incentive for laundering networks to minimize the time stolen value remains in freezeable assets.
The same pressure helps explain the increasing use of privacy tools. In the Bitget case, for example, 2,746 ZEC was moved into Zcash’s Ironwood shielded pool in a single day after much smaller earlier transactions.
The contest is increasingly about speed: investigators need to identify the destination before launderers convert or shield the funds.
The Most Important Asset May Have Been Human Intelligence
Blockchain analytics is often presented as a technical exercise: identify wallets, follow transfers and cluster addresses.
ZachXBT’s investigation shows the limit of that model.
The breakthrough did not apparently come from a new tracing algorithm. It came from persuading an alleged laundering operator that he was a customer.
Private conversations then supplied addresses, expected movements and operational details that could be compared against the public ledger.
That hybrid approach—human intelligence plus blockchain evidence—may become increasingly important as sophisticated laundering networks adopt privacy protocols, cross-chain swaps and rapid asset conversion specifically designed to break straightforward tracing paths.
There is also a substantial risk. ZachXBT says there was no guarantee the operator would not simply disappear with the money, and interacting directly with alleged organized-crime networks creates dangers that extend beyond financial loss.
A Delayed Disclosure May Signal More Investigations Are Still Active
One final detail explains why the October 5 disclosure concerns activity that occurred more than a year earlier.
ZachXBT says he could not publish the investigation while sensitive work involving private investigators and law enforcement remained active.
He says his work has helped action more than $75 million in freezes connected to DPRK incidents since 2022 and indicated that other significant findings remain unpublished.
That makes the thread more than a retrospective account of the Bybit hack.
It provides a rare view into the layer between a major crypto theft and the final conversion of the proceeds—a market of brokers, liquidity providers and criminal intermediaries willing to turn traceable stolen assets into something easier to spend.
The $1 billion figure still needs to be treated as ZachXBT’s estimate rather than an independently established total. But the $12 million Bybit-linked cluster, the cross-chain transaction matches and the 442,000 USDT freeze show why the investigation matters even without accepting every claim at face value.
The hacks may make the headlines. The infrastructure that turns stolen crypto into usable money is increasingly where the real investigative battle begins.
Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.
His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.
Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape.

