ZachXBT Exposes Laundering Network Linked to Bybit and Bitget Hacks

10/6/2026
4min read
Denislav Manolov's Image
by Denislav Manolov
Crypto Expert at Airdrops.com
10/6/2026
4min read
Denislav Manolov's Image
by Denislav Manolov
Crypto Expert

Blockchain investigator ZachXBT says he spent months infiltrating a Chinese-language money-laundering network allegedly responsible for processing more than $1 billion in cryptocurrency stolen by North Korea-linked hackers.

In an investigation published on October 5, ZachXBT described how he posed as a paying customer and interacted directly with laundering operators after the $1.5 billion Bybit hack in February 2025, which U.S. authorities attributed to North Korea.

According to ZachXBT, he identified more than 15 accounts openly advertising laundering services through Telegram and Discord communities.

Rather than simply monitoring the accounts, he contacted an operator using the alias “Jimmy Green” and gradually established trust by conducting transactions with the network.

Investigator Risked Millions During Operation

ZachXBT said the undercover investigation required him to put substantial capital at risk.

On March 6, 2025, he transferred approximately $3.5 million in USDC to an Ethereum address associated with the laundering operation. He said the money was his own and that transactions during the investigation carried an estimated loss risk of approximately 5%.

The strategy eventually provided access to information about wallets allegedly handling stolen Bybit funds.

According to ZachXBT, Jimmy supplied three Solana addresses holding more than $12 million connected to the Bybit theft. The investigator then monitored funds moving across multiple blockchains.

The assets were reportedly moved from Bitcoin to Ethereum, then Solana and Tron, demonstrating how laundering networks can use cross-chain transfers to complicate asset tracing.

ZachXBT said information gathered during the operation ultimately contributed to Tether freezing approximately 442,000 USDT associated with the identified wallets.

Network Allegedly Processed North Korea-Linked Funds

The investigation also uncovered information ZachXBT says helped connect the operators with other suspicious activity.

During their conversations, Jimmy allegedly discussed a team that had approximately $300,000 frozen during 2024. ZachXBT said he subsequently located the corresponding transaction activity onchain, providing independent support for parts of the operator's account.

Jimmy also allegedly claimed involvement in laundering around $3 million connected to fraud.

Following those leads, ZachXBT identified wallets linked with Huione Guarantee, a Cambodia-based marketplace that U.S. authorities have accused of facilitating extensive illicit financial activity. The U.S. Treasury previously moved to restrict Huione Group's access to the American financial system over money-laundering concerns.

ZachXBT said relevant intelligence was shared with investigators and law enforcement as quickly as possible. He estimates his investigations have contributed to more than $75 million in freezes involving North Korea-linked incidents since 2022.

Bitget Hack Shows Similar Laundering Patterns

The investigation also overlaps with the more recent Bitget security breach in September 2026.

Bitget CEO Gracy Chen publicly attributed the attack to North Korea-linked actors, while blockchain analytics company Elliptic identified connections between wallets used after the Bitget theft and infrastructure previously associated with laundering proceeds from the Bybit hack.

Elliptic said the overlap is consistent with patterns seen in previous North Korean cryptocurrency operations, where laundering infrastructure and services are reused across separate thefts.

The firm estimated that the Bitget incident pushed suspected North Korea-linked crypto theft above $1 billion during 2026.

ZachXBT separately identified five accounts allegedly involved in processing Bitget funds.

One operator using the name “lolo” was also linked by ZachXBT to laundering proceeds associated with the roughly $292 million Kelp DAO exploit in April, suggesting some laundering services may handle funds originating from multiple unrelated attacks.

Hackers Move Funds Across Chains

The movement of funds following the Bitget breach illustrates the increasingly complex methods used to obscure stolen cryptocurrency.

Wallets associated with the attackers moved assets between different blockchains and cryptocurrencies, while approximately $3.9 million in Zcash was reportedly transferred into the Ironwood shielded pool, which can make subsequent transaction tracing considerably more difficult.

Such techniques complement traditional laundering methods involving exchanges, over-the-counter brokers, cross-chain bridges and stablecoins.

The overlap identified between the Bybit and Bitget cases suggests that professional laundering networks can become shared infrastructure for major crypto theft operations, rather than each hacking group independently developing its own cash-out network.

ZachXBT's investigation provides an unusual look inside that ecosystem. Instead of relying exclusively on blockchain analytics, he combined onchain tracing with direct interaction with alleged laundering operators, using their own transactions and disclosures to identify additional wallets.

While some of his claims remain based on his independent investigation rather than court findings, the resulting intelligence reportedly contributed to real asset freezes and provided investigators with new information about how stolen cryptocurrency moves through underground laundering networks.

Share with your friends on social media:

Join the community and don't miss a crypto giveaway.

Subscribe for updates by e-mail with the latest research reviews, airdrop news, reward programs, event updates about upcoming airdrops.

By entering your email address you are accepting our Terms & Conditions and Privacy & Cookie Policy.