BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Altcoins

ZachXBT’s $349K Undercover Operation Exposes Chinese Money Laundering Ring for Lazarus Group

TLDR On-chain investigator ZachXBT invested $349,700 in an undercover operation to penetrate a suspected Chinese money laundering operation. The operation allegedly processed over $1 billion

AnonymousCryptoCompass newsroom
October 6, 2026
4 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for altcoins coverage.

TLDR

  • On-chain investigator ZachXBT invested $349,700 in an undercover operation to penetrate a suspected Chinese money laundering operation.
  • The operation allegedly processed over $1 billion in stolen cryptocurrency for North Korea’s Lazarus Group.
  • His investigation identified more than $12 million in digital wallets connected to the $1.5 billion Bybit breach.
  • Tether subsequently froze 442,000 USDT tied to the wallet network he discovered.
  • According to Chainalysis, North Korean-linked hackers took $2.02 billion in cryptocurrency throughout 2025, bringing their cumulative total beyond $6.75 billion.

Cryptocurrency investigator ZachXBT revealed he conducted an extensive undercover investigation to uncover a digital asset laundering operation connected to North Korean actors. He published his discoveries in a detailed post on X dated October 5.

According to ZachXBT, he began operating undercover in February 2025, shortly following the Bybit security breach. He located profiles on public Telegram and Discord channels offering services to transfer illicit cryptocurrency.

ZachXBT explained that he deposited $349,700 worth of stablecoins into an Ethereum wallet. He deliberately absorbed a 5% fee on every transaction to establish credibility with a contact using the pseudonym Jimmy Green.

Inside the laundering operation’s structure

The investigator characterized the organization as a Chinese-based criminal enterprise. He indicated its activities extended across Hong Kong and the Chinese mainland.

He asserted the network processed more than $1 billion from various cryptocurrency hacks for the Lazarus Group. The contact purportedly revealed that nearly all assets from the Bybit incident passed through their laundering infrastructure.

A specific transaction path provided ZachXBT with his initial breakthrough. He noted that a destination wallet had previously received funding from an address appearing on Bybit’s published blocklist.

Subsequent communications provided him with advance intelligence about upcoming fund transfers. He cross-referenced these messages with on-chain data to verify the information.

On March 12, the operator transmitted a screenshot depicting an exchange of 1.192 Bitcoin for 51.73 Ether. ZachXBT successfully linked this activity to a THORChain swap involving Bybit-related assets.

Blockchain tracking results in asset freezes

Three Solana wallet addresses disclosed during their exchanges revealed a cluster containing over $12 million in funds traced to Bybit. ZachXBT observed the assets flowing across Bitcoin, Ether, Solana and Tron networks.

He reported that Tether subsequently immobilized 442,000 USDT associated with these addresses. Tether has independently announced larger freezes related to the Bybit incident through its T3 Financial Crime Unit.

By October 2025, T3-connected actions had frozen $19 million linked to the Bybit attack, Tether disclosed. The specific 442,000 USDT amount was absent from those earlier public announcements.

ZachXBT additionally stated the same source provided intelligence on separate incidents. These encompassed assets from the 2023 Poloniex compromise and a portion connected to Huione Guarantee.

The FBI assigned responsibility for the Bybit attack to North Korean entities five days following the breach. The bureau identified actors it designates as TraderTraitor as having stolen approximately $1.5 billion worth of digital assets.

Bybit explained that stolen credentials from a developer enabled the attacker to penetrate its systems. The platform stated audits revealed no compromise of its primary infrastructure.

ZachXBT indicated he transmitted his evidence to investigators and law enforcement throughout the ongoing operation. He explained he delayed publishing until October 2026 because of the investigation’s sensitive nature.

Official documentation from the FBI, Treasury and Tether has not identified the individual known as Jimmy Green. No legal proceeding has validated the complete extent of the laundering network outlined in his disclosure.

Chainalysis reports North Korean-affiliated hackers extracted $2.02 billion in cryptocurrency during 2025. The analytics firm notes investigators continue tracing proceeds from the $387 million Bitget breach that occurred in September 2026.

The post ZachXBT’s $349K Undercover Operation Exposes Chinese Money Laundering Ring for Lazarus Group appeared first on Blockonomi.