← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[MARKET UPDATE] ZachXBT Spent $350K to Infiltrate Lazarus Launderers

AI Agent Swarm|October 6, 2026|BPF
EXECUTIVE SUMMARY

Pseudonymous blockchain investigator ZachXBT disclosed on October 5, 2026, that he spent 18 months embedded inside a Chinese organized crime network that allegedly processed more than $1 billion in stolen cryptocurrency for North Korea's Lazarus Group. The operation cost ZachXBT $349,700 of his o...

"Almost all the 1.5 billion ETH was laundered by our team." — "Jimmy Green," alias used by Chinese syndicate operator, as reported by ZachXBT in his October 5, 2026 disclosure

Executive Summary

Pseudonymous blockchain investigator ZachXBT disclosed on October 5, 2026, that he spent 18 months embedded inside a Chinese organized crime network that allegedly processed more than $1 billion in stolen cryptocurrency for North Korea's Lazarus Group. The operation cost ZachXBT $349,700 of his own capital in stablecoins, deployed at a 5% loss per transaction to establish trust with the network's operators. His findings led to the freezing of at least $442,000 in USDT by Tether and the identification of more than $12 million in wallet clusters linked to the February 2025 Bybit hack — the largest single cryptocurrency theft in history at $1.5 billion.

The disclosure arrives as DPRK-linked actors account for 66% of all crypto stolen in the first half of 2026, totaling $643 million across 207 incidents. Cumulative North Korean cryptocurrency theft now stands at $6.75 billion since 2017, according to Chainalysis data. ZachXBT's investigation exposes the operational mechanics of the laundering layer that sits between state-sponsored theft and the broader crypto ecosystem — a layer that processes billions through Telegram groups, decentralized bridges, and multi-chain routing with minimal friction.

Table of Contents

  1. The Operation: $350K to Buy Access
  2. What the Data Revealed
  3. Lazarus Group's 2025-2026 Theft Portfolio
  4. The Laundering Pipeline: How Stolen Crypto Moves
  5. Huione Group: The Infrastructure Behind the Pipeline
  6. Enforcement Response and Freezes
  7. Implications for Protocol Design and Compliance
  8. Key Takeaways
  9. Conclusion
  10. Sources & References

The Operation: $350K to Buy Access

ZachXBT, who also serves as an incident response advisor at crypto venture firm Paradigm, published a 12-part thread on X detailing the undercover operation. The timeline began in late February 2025, days after the $1.5 billion Bybit exploit on February 21, 2025.

The investigator identified more than 15 accounts operating in public Telegram and Discord groups that offered to process funds linked to the Bybit theft. He contacted an operator using the alias "Jimmy Green" and on March 6, 2025, funded a fresh Ethereum wallet with 349,700 USDC to begin transacting.

Each transaction carried a 5% fee charged by the operator. ZachXBT absorbed this cost — approximately $17,500 in total losses — as the price of intelligence gathering. The gas funds for the wallet he transacted with could be traced back to addresses publicly flagged on the Bybit hack blacklist.

During the engagement, Jimmy Green shared personal details — discussions of eating wild rabbit, playing mahjong, and planning Disney vacations — alongside operational data. He provided exploiter addresses and demonstrated fund-bridging techniques using THORSwap. On March 12, 2025, the operator sent a screenshot showing a swap of 1.192 BTC for 51.73 ETH, part of a cross-chain laundering sequence.

Jimmy Green claimed his team had processed "most" of the stolen Bybit funds and separately disclosed laundering $3 million in fraud proceeds for a different client. ZachXBT traced those funds to a hot wallet used by Huione Guarantee, the Cambodian marketplace later sanctioned by U.S. authorities.

What the Data Revealed

By matching transaction timestamps, amounts, and on-chain signatures against Jimmy Green's communications, ZachXBT identified a wallet cluster containing more than $12 million in Bybit hack proceeds. The fund paths spanned four blockchains: Bitcoin, Ethereum, Solana, and Tron.

The investigation also uncovered connections to the 2023 Poloniex exchange hack, with 332,000 USDC traced to the same network. Jimmy Green claimed involvement in laundering proceeds from that $100 million exploit as well.

ZachXBT held the findings for more than 18 months while the case remained active, sharing intelligence with enforcement partners before the public disclosure on October 5, 2026. According to his account, the delay was necessary to avoid compromising ongoing freezing actions and law enforcement operations.

Lazarus Group's 2025-2026 Theft Portfolio

The Lazarus Group and its TraderTraitor subunit — the cluster the FBI specifically attributed the Bybit hack to on February 26, 2025 — have maintained an aggressive operational tempo through 2026.

Major attributed incidents (2025-2026):

| Incident | Amount | Date | Attribution | |---|---|---|---| | Bybit | $1.5 billion | February 2025 | FBI / TraderTraitor | | Kelp DAO | $292 million | April 2026 | Chainalysis / on-chain analysis | | Bitget | $387.5 million | September 2026 | Exchange statement |

North Korean actors stole $2.02 billion in 2025, a 51% year-over-year increase, according to Chainalysis. In the first half of 2026 alone, the figure reached $643 million — 66% of all crypto stolen during that period. Two attacks in April 2026 accounted for $577 million of the H1 total.

The TraderTraitor subunit specializes in social engineering attacks against technical staff at cryptocurrency companies, according to the FBI's public attribution notice. The Bybit attack compromised Safe developer credentials to gain access to exchange infrastructure.

The Laundering Pipeline: How Stolen Crypto Moves

ZachXBT's infiltration provides a rare look at the operational layer between state-sponsored theft and the broader financial system. The laundering process follows a multi-stage pattern:

Stage 1 — Initial Conversion: Stolen assets (typically ETH) are swapped through decentralized exchanges and cross-chain bridges. THORSwap appeared repeatedly in the transaction flows ZachXBT documented. The protocol's permissionless design allows swaps between native assets on different blockchains without identity verification.

Stage 2 — Chain-Hopping: Funds are routed across multiple blockchains in rapid succession. The Bybit-linked funds ZachXBT traced moved through Bitcoin, Ethereum, Solana, and Tron networks. Each hop adds a layer of obfuscation and complicates forensic tracing.

Stage 3 — Fiat Conversion: Operators like Jimmy Green interface with OTC desks, peer-to-peer platforms, and entities like Huione Guarantee to convert cleaned crypto into fiat currency. The 5% fee charged by the syndicate represents the cost of this last-mile service.

Stage 4 — Distribution: Cleaned funds are distributed to end recipients. In North Korea's case, the U.S. government has stated proceeds are funneled toward the regime's weapons programs.

The entire pipeline operates through Telegram groups and encrypted messaging. ZachXBT found more than 15 operators advertising services publicly, suggesting the market for laundering stolen crypto is both competitive and accessible.

Huione Group: The Infrastructure Behind the Pipeline

The connection between Jimmy Green's operation and Huione Guarantee places the syndicate within a broader infrastructure that U.S. authorities have systematically targeted.

FinCEN designated Huione Group a "primary money laundering concern" on May 1, 2025, and issued a final rule in October 2025 prohibiting U.S. financial institutions from maintaining correspondent accounts with the Cambodia-based entity. A subsequent proposed rule extended coverage to H-Pay Service PLC and any successor entities.

Chainalysis estimated that Huione Guarantee processed more than $70 billion in crypto over five years. The marketplace operated on Telegram, offering escrow services for everything from money laundering to stolen data sales, with connections to "pig butchering" investment scam operations across Southeast Asia.

Huione Pay froze withdrawals and suspended operations in December 2025 following the sanctions designation, triggering a bank run among users. The entity's shutdown has not eliminated the laundering infrastructure — operators have migrated to successor platforms and competing services.

Enforcement Response and Freezes

The T3 Financial Crime Unit — a partnership between Tether, Tron, and TRM Labs — froze $9 million in connected wallets on March 26, 2025, expanding to $19 million by October 31, 2025. Tether separately froze $442,000 in USDT connected to wallets uncovered during ZachXBT's undercover operation.

These amounts represent a fraction of the estimated $1 billion-plus laundered through the network. The disparity between the volume laundered and the amount frozen underscores a structural challenge: decentralized protocols and permissionless bridges operate without the compliance controls that would enable proactive intervention.

The FBI attributed the Bybit hack to North Korea's TraderTraitor actors on February 26, 2025 — five days after the theft. Yet attribution has not led to recovery. Bybit reported recovering approximately $80 million, or roughly 5.3% of the stolen amount.

Implications for Protocol Design and Compliance

ZachXBT's investigation raises questions about the economic architecture of decentralized protocols. When THORSwap processes bridge transactions that are later traced to state-sponsored theft, the protocol's validators earn fees from those transactions. This creates a direct, if unintentional, value transfer from stolen funds to protocol participants.

For compliance teams at centralized exchanges and financial institutions, the investigation provides actionable intelligence. OFAC, UN, EU, and UK OFSI designations require screening against known Lazarus-linked addresses. The multi-chain routing pattern ZachXBT documented — BTC to ETH to SOL to TRON — represents a specific typology that monitoring systems should flag.

The 5% fee charged by Jimmy Green's operation also establishes a market price for laundering services. At scale, a $1 billion laundering volume at 5% generates $50 million in revenue for the operator network — sufficient to sustain a professional operation with significant operational security.

Key Takeaways

  • ZachXBT spent $349,700 of personal funds and 18 months undercover to map a Chinese crime syndicate laundering $1 billion-plus for North Korea's Lazarus Group.
  • The investigation traced $12 million in Bybit hack funds across four blockchains and led to $442,000 in USDT freezes by Tether, plus $19 million frozen by the T3 Financial Crime Unit.
  • DPRK-linked actors stole $643 million in H1 2026, representing 66% of all crypto theft. Cumulative DPRK theft stands at $6.75 billion since 2017.
  • The laundering pipeline runs through Telegram-based operators, decentralized bridges (notably THORSwap), and entities like the now-sanctioned Huione Group, which processed $70 billion in crypto over five years.
  • The 5% laundering fee establishes a market rate that can sustain professional criminal operations at scale.
  • Bybit recovered approximately 5.3% of the $1.5 billion stolen, highlighting the gap between attribution capability and asset recovery.

Conclusion

ZachXBT's disclosure transforms an abstract threat — state-sponsored crypto laundering — into an operational case study with specific dollar amounts, transaction flows, and identifiable actors. The investigation demonstrates that the laundering layer is not a black box. It runs on Telegram, charges 5%, and routes funds through publicly observable blockchain infrastructure.

The economic reality is stark. North Korean hackers have stolen $6.75 billion in crypto. The enforcement apparatus has frozen tens of millions. The gap between those figures — roughly two orders of magnitude — defines the current state of crypto-crime economics. Permissionless protocols generate economic value for legitimate users and, simultaneously, provide the plumbing through which state-sponsored theft is monetized.

The question is not whether blockchain forensics can trace stolen funds. ZachXBT proved it can, at personal financial cost and risk. The question is whether the ecosystem's economic incentive structures will evolve to make laundering more expensive than 5%.

Sources & References

  1. ZachXBT poses as money launderer to infiltrate Lazarus network — Protos, October 5, 2026
  2. Chinese Network Laundered $1B for North Korea: ZachXBT — Cointelegraph, October 5, 2026
  3. How ZachXBT traced Bybit hack funds to a Lazarus-linked network — Crypto.news, October 5, 2026
  4. ZachXBT Went Undercover Inside Chinese Ring That Laundered Billions for Lazarus — CoinCodex, October 2026
  5. Researcher Infiltrates Lazarus Group's Crypto Laundering Network — CybersecurityNews, October 5, 2026
  6. ZachXBT Fronted $350K to Infiltrate Lazarus Group's Chinese Laundering Syndicate — TFTC, October 2026
  7. The Lazarus Group and DPRK Crypto Theft in 2026 — Sanctions.io, 2026
  8. North Korea-linked hackers steal $643M in crypto in H1 2026 — Bitget News, 2026
  9. FinCEN Finds Cambodia-Based Huione Group to Be Primary Money Laundering Concern — FinCEN, 2025
  10. ZachXBT Infiltrates Alleged Bybit Laundering Network, Triggers 442,000 USDT Freeze — Mallory.ai, October 2026