Investigator Infiltrates Lazarus Group-Linked Network, Aids in Freezing $75M After Bybit Hack
Blockchain investigator ZachXBT infiltrated a Chinese crypto laundering network tied to North Korea's Lazarus Group, helping to freeze over $75 million in stolen assets following the massive Bybit hack.

Independent blockchain investigator ZachXBT has revealed how he infiltrated a Chinese organized crime syndicate suspected of laundering over $1 billion in cryptocurrency, with direct links to North Korea's notorious Lazarus Group. This operation, which followed the staggering $1.5 billion hack of the Bybit exchange in February 2025, saw ZachXBT pose as a client to gather intelligence that directly contributed to freezing more than $75 million in illicitly obtained funds.
ZachXBT's investigation began shortly after the Bybit exploit, when he identified over 15 accounts in public Telegram and Discord channels seeking assistance with transactions related to the stolen Bybit funds. Posing as a potential client under the alias "Jimmy Green," ZachXBT engaged with an operator who claimed their team had processed a significant portion of the stolen Bybit assets and operated from Hong Kong and mainland China. To gain trust and maintain access, ZachXBT strategically incurred losses of approximately 5% per transaction while exchanging USDC for USDT across different blockchains like Tron.
The critical phase of the investigation involved meticulously cross-referencing the operator's claims with verifiable blockchain transactions. ZachXBT reported that a wallet used by "Jimmy Green" received gas fees from an address directly linked to the Bybit theft. Further evidence, including a screenshot shared on March 12, reportedly matched a THORChain transfer in both timing and amount. The investigator also leveraged a Telegram account identifier found in separate screenshots to link the operator's private profile to activity within a public THORChain group, demonstrating a sophisticated blend of social engineering and technical analysis.
By tracing funds across multiple blockchains, including Bitcoin, Ethereum, Solana, and Tron, ZachXBT identified a cluster of wallets containing over $12 million in Bybit funds. While the use of different networks complicates tracing, matching transfer amounts and times allowed investigators to connect the disparate transactions. As a result of this intelligence, Tether later froze 442,000 USDT associated with this cluster, and ZachXBT shared further insights with law enforcement to support additional asset freezes.
The FBI had previously attributed the February 21, 2025, Bybit theft to North Korea, identifying the activity under the moniker TraderTraitor and warning of the widespread distribution of stolen assets across numerous blockchains. This incident underscores the persistent challenge of tracking and recovering funds stolen in large-scale cryptocurrency heists, often orchestrated by sophisticated state-sponsored or state-affiliated groups.
ZachXBT's work highlights the crucial role of independent investigators in combating sophisticated cybercrime. His efforts since 2022 have reportedly helped freeze over $75 million linked to North Korean incidents alone. While the full extent of the laundered funds and the precise attribution of all illicit activity require further independent confirmation, this operation demonstrates the power of persistent undercover work, advanced blockchain tracing, and timely collaboration with exchanges and law enforcement to disrupt criminal operations and recover stolen assets.