Blockchain investigator ZachXBT says he spent months infiltrating a Chinese-language money-laundering network allegedly responsible for processing more than $1 billion in cryptocurrency stolen by North Korea-linked hackers.
In an investigation published on October 5, ZachXBT described how he posed as a paying customer and interacted directly with laundering operators after the $1.5 billion Bybit hack in February 2025, which U.S. authorities attributed to North Korea.
According to ZachXBT, he identified more than 15 accounts openly advertising laundering services through Telegram and Discord communities.
Rather than simply monitoring the accounts, he contacted an operator using the alias “Jimmy Green” and gradually established trust by conducting transactions with the network.
1/ How I infiltrated a Chinese organized crime syndicate that has laundered $1B+ across multiple exploits for Lazarus Group.
— ZachXBT (@zachxbt) October 5, 2026
Posing as a client, I gathered intel that helped action freezes for the Feb 2025 Bybit exploit and attribute illicit activity onchain. pic.twitter.com/jauRRt8875
1/ How I infiltrated a Chinese organized crime syndicate that has laundered $1B+ across multiple exploits for Lazarus Group.
— ZachXBT (@zachxbt) October 5, 2026
Posing as a client, I gathered intel that helped action freezes for the Feb 2025 Bybit exploit and attribute illicit activity onchain. pic.twitter.com/jauRRt8875
Investigator Risked Millions During Operation
ZachXBT said the undercover investigation required him to put substantial capital at risk.
On March 6, 2025, he transferred approximately $3.5 million in USDC to an Ethereum address associated with the laundering operation. He said the money was his own and that transactions during the investigation carried an estimated loss risk of approximately 5%.
The strategy eventually provided access to information about wallets allegedly handling stolen Bybit funds.
According to ZachXBT, Jimmy supplied three Solana addresses holding more than $12 million connected to the Bybit theft. The investigator then monitored funds moving across multiple blockchains.
The assets were reportedly moved from Bitcoin to Ethereum, then Solana and Tron, demonstrating how laundering networks can use cross-chain transfers to complicate asset tracing.
ZachXBT said information gathered during the operation ultimately contributed to Tether freezing approximately 442,000 USDT associated with the identified wallets.
Network Allegedly Processed North Korea-Linked Funds
The investigation also uncovered information ZachXBT says helped connect the operators with other suspicious activity.
During their conversations, Jimmy allegedly discussed a team that had approximately $300,000 frozen during 2024. ZachXBT said he subsequently located the corresponding transaction activity onchain, providing independent support for parts of the operator's account.
Jimmy also allegedly claimed involvement in laundering around $3 million connected to fraud.
Following those leads, ZachXBT identified wallets linked with Huione Guarantee, a Cambodia-based marketplace that U.S. authorities have accused of facilitating extensive illicit financial activity. The U.S. Treasury previously moved to restrict Huione Group's access to the American financial system over money-laundering concerns.
ZachXBT said relevant intelligence was shared with investigators and law enforcement as quickly as possible. He estimates his investigations have contributed to more than $75 million in freezes involving North Korea-linked incidents since 2022.
Bitget Hack Shows Similar Laundering Patterns
The investigation also overlaps with the more recent Bitget security breach in September 2026.
Bitget CEO Gracy Chen publicly attributed the attack to North Korea-linked actors, while blockchain analytics company Elliptic identified connections between wallets used after the Bitget theft and infrastructure previously associated with laundering proceeds from the Bybit hack.
Elliptic said the overlap is consistent with patterns seen in previous North Korean cryptocurrency operations, where laundering infrastructure and services are reused across separate thefts.
The firm estimated that the Bitget incident pushed suspected North Korea-linked crypto theft above $1 billion during 2026.
ZachXBT separately identified five accounts allegedly involved in processing Bitget funds.
One operator using the name “lolo” was also linked by ZachXBT to laundering proceeds associated with the roughly $292 million Kelp DAO exploit in April, suggesting some laundering services may handle funds originating from multiple unrelated attacks.
Hackers Move Funds Across Chains
The movement of funds following the Bitget breach illustrates the increasingly complex methods used to obscure stolen cryptocurrency.
Wallets associated with the attackers moved assets between different blockchains and cryptocurrencies, while approximately $3.9 million in Zcash was reportedly transferred into the Ironwood shielded pool, which can make subsequent transaction tracing considerably more difficult.
Such techniques complement traditional laundering methods involving exchanges, over-the-counter brokers, cross-chain bridges and stablecoins.
The overlap identified between the Bybit and Bitget cases suggests that professional laundering networks can become shared infrastructure for major crypto theft operations, rather than each hacking group independently developing its own cash-out network.
ZachXBT's investigation provides an unusual look inside that ecosystem. Instead of relying exclusively on blockchain analytics, he combined onchain tracing with direct interaction with alleged laundering operators, using their own transactions and disclosures to identify additional wallets.
While some of his claims remain based on his independent investigation rather than court findings, the resulting intelligence reportedly contributed to real asset freezes and provided investigators with new information about how stolen cryptocurrency moves through underground laundering networks.



