TL;DR
-
ZachXBT says he infiltrated a Chinese money laundering syndicate, putting up $350,000 of his own money.
-
The launderer's wallet was gas-funded from Bybit's exploit blacklist, and he revealed Bybit fund movements before they happened.
-
The investigation revealed a $12m cluster of stolen money and helped Tether freeze $442,000.
-
The Chinese money launderers are turning out to be the weakest link in the Lazarus hacks.
X user ZachXBT, known for his investigative reports in crypto, says he has infiltrated a Chinese money laundering syndicate. He put up $350,000 of his own money to gain the launderers' trust. ZachXBT was the first to attribute the $1.5 billion Bybit hack to North Korea's Lazarus Group back in February of 2025.
The investigation revealed a $12m cluster of stolen money and helped freeze $442k. He sat on most of the information for a year and a half so that the investigation could go on.
1/ How I infiltrated a Chinese organized crime syndicate that has laundered $1B+ across multiple exploits for Lazarus Group. Posing as a client, I gathered intel that helped action freezes for the Feb 2025 Bybit exploit and attribute illicit activity onchain. https://t.co/jauRRt8875
— ZachXBT (@zachxbt) October 5, 2026
Trading With the Launderer to Build Trust
The whole investigation is revealed in a thread on X. Shortly after the hack, ZachXBT contacted a person off a public Telegram group who was asking for help with orders tied to the stolen funds. Then, on March 6th, 2025, he funded a fresh wallet with $349,700 and started trading with the contact, who called himself Jimmy Green, to build trust.
He found that Jimmy Green's wallet had been gas-funded by a wallet on Bybit's exploit blacklist. That was an indication that he was on the right track. As the two started building a relationship, and ZachXBT kept using Jimmy Green's services, the money launderer started revealing Bybit fund movements before they happened. That was the confirmation.
5/ Jimmy provided his address 0xbaa5 for me to send my USDC to, in exchange for his USDT on Tron. 0xbaa5 was funded with gas by 0xbcb4, which is directly traceable to Bybit exploit funds and is labeled on the public Bybit exploit blacklist site. Jimmy Green addresses: 0xbaa551da0ae0c93025d9a983a68025a27dc15337 TPwXAPwYaDCm7GrzNFiMmNnofrxEVURXRM
— ZachXBT (@zachxbt) October 5, 2026
Laundering Most of the Bybit Money
Green himself claimed that he and his team had laundered most of the money that had come out of the $1.5 billion Bybit hack. This claim fits the on-chain data uncovered by ZachXBT.
Along with all the information ZachXBT managed to uncover, he also found enough evidence for Tether to freeze $442,000 after Green shared addresses exposing a cluster of $12 million of stolen Bybit funds moving BTC to ETH to SOL to Tron.
9/ Jimmy also shared three Solana addresses, which revealed a cluster of $12M+ of Bybit exploit funds being swapped across BTC -> ETH -> SOL -> Tron in real time. 442K USDT linked to the cluster was later frozen by Tether. The cluster also deployed a novel laundering method via Uniswap LPs using illiquid tokens. Jimmy Green addresses 9gSwa2Mew9P21Wxs8nFgDujTurKZx1nBEVRv6K5sJP6e EvZJGsDymrSUQyF23HLKEgUpjfd9XN1GTmm8AG6pFS7H 8S6T5gL2w5z4M9TCehMgQjxVm3Q6R7WDHp6WFfbtZSAy Tether freeze 0x652d7f9edaaa8891be2de74ea568d70af823d89e
— ZachXBT (@zachxbt) October 5, 2026
Before publishing his investigation, his findings went to private-sector investigators and law enforcement. There's still no public response from Bybit, Tether or law enforcement. This thread comes a week after ZachXBT's post on the Bitget hack.
The Chinese money launderers are turning out to be the weakest link in the Lazarus hacks. Still, only a fraction of the Bybit funds have been recovered. Maybe that's just the cost of business for the North Korean hackers.
Check out the full thread here.
Melker Bengtsson