en
Back to the list

ZachXBT Posed as a Client to Infiltrate Chinese Syndicate Laundering Bybit Hack Funds

source-logo  thedefiant.io 05 October 2026 15:30, UTC

Onchain investigator ZachXBT spent weeks in early 2025 posing as a client of a Chinese organized crime syndicate he says has laundered more than $1 billion for North Korea's Lazarus Group, and used the access to help freeze funds stolen in the February 2025 Bybit hack, according to a 12-post thread he published on X on Monday.

The thread names the Telegram handle, the wallets and the transaction hash that tie one broker to Bybit money, and it describes the layer that sits between a North Korean exploit and the exchanges where stolen funds re-enter circulation. ZachXBT published none of it at the time. He wrote that the findings went immediately to private-sector investigators and law enforcement assigned to the case, and that sensitivity around the investigation kept them unpublished for roughly 18 months.

He funded a fresh Ethereum address with 349,700 $USDC on March 6, 2025, and traded it for $USDT on Tron at a 5% loss on each order to build trust with the broker. One cluster the broker exposed held more than $12 million in Bybit proceeds moving across Bitcoin, Ether, Solana and Tron in real time. Tether later froze 442,000 $USDT linked to it. ZachXBT said the work was done pro bono, and that he has helped action more than $75 million in freezes tied to North Korean incidents since 2022.

app-logo

Know when your
coins move

Alerts, real-time prices, and market news — all in one app
4.8 based on 40K reviews in the App Store and Google Play

Hackers stole about $1.5 billion from Bybit on Feb. 21, 2025. The Federal Bureau of Investigation, or FBI, attributed the theft to North Korea five days later and named the activity TraderTraitor. More than 80% of the funds had been laundered within six months, much of it bridged through THORChain.

Support Tickets In Public

ZachXBT said he found his way in through the launderers' own customer service habits. In the weeks after the exploit, he counted more than 15 accounts asking for help with orders directly tied to the stolen funds in public Telegram and Discord groups run by the services they were using.

He began contacting them. One used the alias "Jimmy Green" on Telegram, under the handle long_991 and the numeric identifier 7635649994. The account was deleted earlier this year, ZachXBT wrote in a reply, and someone else has since claimed the username. He said a good number of the syndicate's members are based in Fujian, China.

The same pattern surfaced again last month. ZachXBT reported on Sept. 28 that Chinese actors moving proceeds from the $387.5 million Bitget exploit were opening support tickets in public channels. Chainalysis has linked that hack to North Korea.

The Gas Funder Slip

Jimmy Green gave ZachXBT the address 0xbaa551da0ae0c93025d9a983a68025a27dc15337 to receive the $USDC, against $USDT delivered on Tron. That address had been funded with gas by a wallet ZachXBT identified as 0xbcb4, which traces directly to Bybit exploit funds and carries a label on the public blacklist Bybit maintains for the hack.

He ran several more orders through two further addresses and two Tron addresses to establish himself as a repeat customer.

One Day Ahead

Jimmy Green then started describing moves before they happened, along with details of the operation's footprint in Hong Kong and mainland China, according to the thread. In one instance he said the funds would be shifted to Solana, and they were the following day. He told ZachXBT his team had laundered most of the $1.5 billion taken from Bybit, which ZachXBT wrote was consistent with the patterns he had been tracking.

On March 12, 2025, the broker sent a screenshot of himself bridging funds. ZachXBT matched the amounts and timing to a THORChain order created minutes after the message, with the hash 81a85130b36057428e64b6f97215f77b5a197776a8f1b3a61c8cd0ee1ebfa8c1.

"At this point, I realized I needed to continue losing 5% per order and gamble on capturing as much actionable intel as quickly as possible," he wrote.

Frozen In A Liquidity Pool

The three Solana addresses Jimmy Green shared opened up the cluster holding more than $12 million in Bybit proceeds, swapped from Bitcoin to Ether to Solana to Tron while ZachXBT watched. Tether froze 442,000 $USDT tied to it at 0x652d7f9edaaa8891be2de74ea568d70af823d89e.

The Defiant confirmed the freeze onchain. The $USDT contract returns a blacklisted status for that address, which holds 442,399 $USDT. The address is a Uniswap V2 pool, consistent with what ZachXBT described as a laundering method built on liquidity pools for illiquid tokens.

Mahjong And Disney

Jimmy Green also made small talk. ZachXBT said the two discussed mahjong, hunting wild rabbits, food, a diet, family life and vacations at Disney, in between discussions of laundering for North Korea. He attributed the broker's awkward grammar to a translator.

Two of Jimmy Green's offhand remarks checked out onchain. He mentioned a team that had roughly $300,000 frozen in 2024; ZachXBT found the freeze and put the figure at 332,000 $USDC from the Poloniex exploit. He also mentioned laundering $3 million in fraud proceeds for another client, which ZachXBT traced to a hot wallet for Huione Guarantee, the online marketplace run by Cambodia's Huione Group, which the Treasury Department cut off from the U.S. financial system in October 2025.

Eighteen Months Of Silence

ZachXBT fronted the full 349,700 $USDC with no guarantee the broker would not disappear with it, and lost 5% on every order.

"That is one of the frustrations I have with my work," he wrote. "I am not always able to share findings as quickly as I'd like, and I am currently sitting on significant findings from other cases."

He asked for continued grants from foundations and donations from individuals, which he said let him take on higher risk for cases others would not consider viable.

thedefiant.io