Home / News / ZachXBT Risks $350K to Expose Alleged North Korean Crypto Laundering Network
News 6 min read

ZachXBT Risks $350K to Expose Alleged North Korean Crypto Laundering Network

Key Takeaways

  • ZachXBT says an undercover investigation exposed more than $12 million in funds linked to the Bybit hack.
  • Tether later froze 442,000 USDT associated with the identified cluster, according to his account.
  • He fronted $349,700 to trade with an alleged laundering contact, accepting a 5% loss on each order.

A contact’s private messages gave blockchain investigator ZachXBT a window into where stolen Bybit funds would move next—and helped him identify a crypto trail worth more than $12 million.

ZachXBT says information gathered while posing as a customer of an alleged laundering syndicate helped facilitate freezes connected to the exchange’s $1.5 billion hack.

His latest report describes an investigation that required nearly $350,000 of his own money and repeated dealings with a man allegedly moving funds for North Korea.

Private Messages Exposed Bybit’s Money Trail

The most revealing information came from a Telegram contact named “Jimmy Green,” according to ZachXBT.

Jimmy supplied three Solana addresses, enabling the investigator to identify a cluster holding more than $12 million in proceeds from the Bybit exploit.

ZachXBT said he watched the funds being swapped across Bitcoin, Ethereum, Solana, and Tron.

Tether froze 442,000 USDT linked to that cluster, he said.

Meanwhile, the conversations also allegedly gave ZachXBT advance notice of transactions.

“One day prior he stated funds would be moved to Solana and the next day they were,” he wrote.

A separate message provided another opportunity to connect Jimmy’s claims to blockchain activity.

On March 12, 2025, Jimmy sent a screenshot of himself bridging fund — ZachXBT said the amounts and timing matched a THORChain order created within minutes of the message.

Why ZachXBT Put His Own Money Into the Operation

Obtaining that information required ZachXBT to become a trading counterparty.

According to his Oct. 5 thread, the investigation began after he spotted more than 15 accounts seeking assistance with orders tied to stolen funds in public Telegram and Discord groups following the Bybit hack.

He approached the accounts and established contact with Jimmy.

On March 6, 2025, ZachXBT said he placed 349,700 USDC into a new Ethereum address to prepare for several transactions.

The receiving address supplied by Jimmy had obtained transaction-fee funding from a wallet traceable to Bybit exploit proceeds, according to ZachXBT.

That funding wallet also appeared on Bybit’s public exploit blacklist.

Further trades helped establish the relationship, as Jimmy then began sharing details about operations in Hong Kong and mainland China, along with plans to move Bybit funds.

ZachXBT alleged that the wider Chinese syndicate had laundered more than $1 billion across multiple exploits for Lazarus Group.

The FBI has separately attributed the February 2025 Bybit theft to North Korea, identifying the activity as TraderTraitor.

Poloniex and Fraud Proceeds Added Further Leads

Bybit was not the only case discussed during the exchanges.

Jimmy mentioned that a team he knew had approximately $300,000 frozen in 2024 — ZachXBT said he located an on-chain freeze involving 332,000 USDC from the Poloniex exploit.

Jimmy’s account of a separate $3 million laundering job supplied another lead, which ZachXBT found reached a Huione Guarantee hot wallet.

Between discussions of stolen crypto, the pair even talked about food, family, mahjong, and holidays.

The investigator gained the trust of the scammer | Source: X (@ZachXBT)

“Throughout our conversations, Jimmy and I had a lot of small talk in between discussing laundering for DPRK,” ZachXBT wrote.

He said Jimmy discussed hunting wild rabbits, meals intended to reduce body fat, and vacations at Disney.

The Financial and Personal Cost of Going Undercover

ZachXBT said the investigation depended on accepting repeated trading losses while continuing to gather evidence.

“For this case, I fronted $349.7K and lost 5% on each order, with no guarantee Jimmy wouldn’t disappear with the funds, and an unknown amount of personal risk from dealing with the syndicate.”

According to ZachXBT, trusted private-sector investigators and law enforcement assigned to the case received his findings immediately.

He said the investigation’s sensitivity prevented him from publishing earlier.

“Since 2022, I have helped action $75M+ in freezes related to DPRK incidents,” he wrote.

He appealed for further foundation grants and individual donations, saying that support always allows him to pursue risky cases that others might consider unviable.

Other Cases ZachXBT Has Helped Uncover

A $243M Theft From a Single Crypto Holder

ZachXBT’s September 2024 investigation into a Genesis creditor’s approximately $243 million loss became one of his most prominent cases.

He said the investigation helped secure multiple arrests and more than $9 million in frozen assets.

The resulting criminal case has continued to develop.

On Sept. 8, 2026, the Justice Department announced that Malone Lam pleaded guilty to a racketeering conspiracy involving more than $245 million in stolen and laundered cryptocurrency.

Prosecutors said Lam selected victims and organized other members of the operation, which used social engineering and occasional home break-ins to obtain access to cryptocurrency wallets.

Suspected Theft From U.S. Government Crypto Wallets

An online display of wealth provided the opening for another investigation.

In January 2026, ZachXBT linked wallets used by a person known as “John” or “Lick” to suspicious funds originating from U.S. government-controlled addresses.

TRM Labs said wallet balances and transfers displayed during an online contest helped him identify addresses and examine their transaction histories.

John Daghita was subsequently arrested in Saint Martin in a joint operation involving the French Gendarmerie and the FBI. Authorities accused him of involvement in cryptocurrency theft associated with the U.S. Marshals Service.

Helping an Elderly Scam Victim Recover $275K

His investigations have also produced recoveries for individual victims.

In a separate investigation disclosed in October 2024, scammers impersonating Coinbase support had targeted an elderly American.

ZachXBT said he helped retrieve approximately $275,000 and connected the alleged perpetrators to other cryptocurrency thefts totaling around $5 million.

Was this Article helpful? Yes No
Thank you for your feedback. 0% 0%