Blockchain investigator ZachXBT has published a detailed account of an undercover operation in which he posed as a paying client of a Chinese organized crime syndicate he alleges has laundered more than $1 billion across multiple exploits for North Korea's Lazarus Group.

The disclosure, posted October 5, describes trades and private conversations from 2025 that he says helped trace funds stolen from Bybit and led to a 442,000 USDT freeze by Tether. The syndicate's role and its totals remain the investigator's own allegations — separate from the FBI's official attribution of the Bybit theft itself to North Korean state actors.

Becoming a Customer

ZachXBT said the investigation began after the February 2025 Bybit exploit, when he noticed at least 15 accounts soliciting help with orders in public Telegram and Discord groups that he linked to stolen funds. He contacted several of them, including a figure operating under the Telegram alias "Jimmy Green."

On March 6, 2025, he funded a fresh Ethereum address with 349,700 USDC and began exchanging it for the contact's USDT on Tron — accepting a 5% loss on each order as the cost of building trust, according to his account, which was corroborated in detail by CryptoSlate and crypto.news.

As the relationship deepened, the contact allegedly began discussing movements of Bybit funds for North Korea before they occurred, along with operational details spanning Hong Kong and mainland China. In one instance, the contact said funds would move to Solana — and the movement took place the following day. A March 12 screenshot of a cross-chain transfer was matched to a THORChain explorer order created within minutes of the message.

The Trail: $12M Cluster and a 442K USDT Freeze

Three Solana addresses supplied by the contact exposed a cluster of more than $12 million in Bybit exploit funds moving through Bitcoin, Ethereum, Solana and Tron, ZachXBT said. He separately reported that Tether later froze 442,000 USDT linked to the cluster — the confirmed freeze from this leg of the investigation, distinct from the larger traced total.

The syndicate's reach allegedly extends beyond Bybit. The investigator said the contact mentioned a team whose funds had been frozen in 2024, which he matched to an on-chain freeze of 332,000 USDC tied to the Poloniex exploit.

What Is Confirmed and What Is Alleged

The backdrop is documented: in a February 26, 2025 alert, the FBI said North Korean actors stole approximately $1.5 billion in virtual assets from Bybit, branding the activity "TraderTraitor" and urging private-sector services to block transactions connected to laundering addresses.

The syndicate's $1 billion-plus total and its specific links to "Jimmy Green," however, remain ZachXBT's findings. No government has confirmed them, and no charges tied to the network have been announced. The same distinction applies to the Chinese intermediaries he previously alleged were moving Bitget proceeds in public channels after the September 2026 breach.

ZachXBT, who said he fronted 349,700 USDC of his own funds for the operation, closed the disclosure with an appeal for continued foundation grants and individual donations to support higher-risk investigations. The operational lesson for exchanges is uncomfortable either way: the laundering layer between state-sponsored thieves and liquid crypto is staffed by commercial OTC operators who will take on almost any counterparty — and will talk to one they trust.

TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.