A blockchain investigator spent more than 349,000 dollars of his own money to go undercover inside a money-laundering ring he links to North Korea's hackers. The ZachXBT undercover operation played out over weeks in early 2025, when the investigator posed as a paying client of a Chinese syndicate he says helped wash the proceeds of the 1.5 billion dollar Bybit theft. Details of the sting only became public on October 5, 2026, when ZachXBT published a long thread explaining why he had kept it quiet.
The revelation pulls back the curtain on the middlemen who move stolen crypto for state-backed hackers, according to CoinCodex's report on the ZachXBT undercover operation. After the Bybit exchange was hit in February 2025, ZachXBT said he noticed more than 15 accounts in public Telegram and Discord groups offering to help process transactions tied to the stolen funds. He reached out, and one contact calling himself Jimmy Green became his way in.
How the ZachXBT undercover operation worked
The setup was expensive on purpose. As reported by CryptoRank's account of the ZachXBT undercover operation, ZachXBT funded a fresh Ethereum address with 349,700 USDC and began swapping with the operator, accepting a loss of roughly five percent on each order to look like a real client. That willingness to lose money on every trade is what made the ZachXBT undercover operation convincing to the people he was trying to fool. The financial hit was the price of trust: once the contact believed he was dealing with a genuine laundering customer, the conversations changed.
ZachXBT said Jimmy Green began sharing advance word of where stolen funds would move next. In one case, the operator said funds would move to Solana, and the movement happened the following day. On March 12, 2025, the contact sent a screenshot of a cross-chain swap, and ZachXBT matched its timing and amounts to a transaction on the THORChain explorer that traced back through intermediary wallets to Bybit-linked funds.
Three Solana addresses supplied during the conversations cracked the case wider open, according to CoinCodex. Comparing chat logs with on-chain activity, ZachXBT says he identified a wallet cluster holding more than 12 million dollars in Bybit-linked funds. The money moved across Bitcoin, Ethereum, Solana and Tron as the network tried to blur its trail. The ZachXBT undercover operation also produced at least one hard result: Tether later froze about 442,000 USDT connected to the wallet cluster.
The operator's own claims went further. ZachXBT said the contact told him his team had handled most of the stolen Bybit proceeds, and that the syndicate's reach extended beyond one heist. The investigation also surfaced 332,000 USDC tied to the 2023 Poloniex hack and roughly three million dollars in fraud proceeds traced to a wallet connected with Huione Guarantee, a Cambodian network that United States authorities later targeted over laundering concerns.
What the ZachXBT undercover operation tells us about crypto crime
The thread fills a gap that official reports rarely reach: who actually moves the money after the hack. The FBI attributed the February 2025 Bybit theft to North Korean actors it tracks as TraderTraitor, part of the Lazarus Group. Chainalysis estimated that North Korean hackers stole a record 2.02 billion dollars in crypto during 2025, bringing their cumulative haul to at least 6.75 billion dollars. But attribution usually stops at the hackers, while the laundering networks stay invisible. This account names the layers in between.
For everyday crypto users, the story is a reminder that the exchanges and bridges they use every day sit downstream of these flows. Exchanges and analytics firms raced to flag the stolen funds, and Bybit's own forensic review found that compromised credentials at a vendor let the attacker reach the signing infrastructure and trick approvers into signing a malicious transaction. If laundering pipelines this organized exist, ordinary users feel the consequences in frozen withdrawals, delisted tokens and compliance checks across the industry.
There is also a counterpoint that matters. None of the key claims has been independently confirmed by law enforcement. As reported by CryptoRank, no public release from the FBI, the Treasury or Tether names Jimmy Green or confirms that one Chinese network laundered more than one billion dollars for Lazarus Group. Tether has confirmed larger freezes tied to the Bybit theft, including nearly nine million dollars announced by the T3 Financial Crime Unit in March 2025, but none of those releases break out the 442,000 USDT figure ZachXBT described or link it to his operation.
ZachXBT said he shared his findings with private-sector investigators and law enforcement while the case was still active, which is why he waited until now to publish. Since 2022, he says he has helped freeze more than 75 million dollars tied to North Korea-related crypto incidents. The open question is whether any agency turns the ZachXBT undercover operation into a charge or a named suspect.
The problem he chased has not slowed down. Chainalysis said on October 1, 2026 that it was working with Bitget and law enforcement after 387 million dollars was stolen from that exchange in late September, an attack the firm attributed to North Korean actors. Earlier coverage of the NEAR Intents exploit showed the same pattern: an independent investigator tracing stolen funds across chains while the industry scrambles to react. Whether the ZachXBT undercover operation leads to arrests or simply fades into the archive of crypto's biggest heists depends on what investigators do next. Either way, it stands as one of the boldest examples of what a single investigator with a wallet and a cover story can accomplish. For more on the digital-asset beat, see Crypto.
Comments 0
No comments yet. Be the first to share your thoughts!
Leave a comment
Share your thoughts. Your email will not be published.