ZachXBT exposes the laundering network behind the Bybit and Bitget hacks

- ZachXBT revealed he went undercover inside a Chinese syndicate that has laundered over $1 billion for North Korea’s Lazarus Group.
- The investigator’s intel helped freeze funds from the February 2025 Bybit hack.
- The same attacker’s methods now connect to the $387.5 million Bitget breach of September 2026.
Crypto investigator ZachXBT says he spent months posing as a paying client inside a Chinese money-laundering syndicate that has moved more than $1 billion in stolen funds for North Korea’s Lazarus Group.
The intelligence gathered by ZachXBT helped freeze proceeds from the February 2025 Bybit breach.
Did ZachXBT help recover the $1.5 billion taken during the Bybit breach?
After Bybit lost about $1.5 billion in February 2025, ZachXBT says he found more than 15 accounts in open Telegram and Discord channels offering to help process money tied to the theft.
In a long thread posted today on X, ZachXBT revealed that he reached out to one of the operators who was using the handle “Jimmy Green” and spent weeks building trust through a series of real transactions.
On March 6, 2025, ZachXBT sent $3.497 million in USDC to an Ethereum address publicly known as a blacklisted hack wallet that is also linked back to the Bybit hack. ZachXBT said the roughly $3.5 million came out of his pocket and that he accepted a loss risk of about 5% on each transaction he made in the course of his investigation.
Through the interactions, Jimmy handed over three Solana addresses that were holding more than $12 million in Bybit funds. ZachXBT watched these funds hop from Bitcoin into Ether, then Solana, then Tron in real time. Tether later froze about 442,000 USDT linked to those wallets.
Other tips picked up during their interactions led ZachXBT to verify older claims. For instance, Jimmy mentioned a team that had roughly $300,000 frozen in 2024 and Zach was able to locate the freeze on-chain.
Jimmy also boasted about laundering $3 million in fraud money, which led ZachXBT to discover wallets connected to Huione Guarantee, a marketplace already sanctioned by the U.S. He said investigators and law enforcement were informed as early as possible, and that since 2022, his work has helped freeze more than $75 million tied to North Korea-linked incidents.
Alongside the talk about money laundering, ZachXBT wrote that Jimmy described playing mahjong, hunting wild rabbits, his diet meal, family life and holidays at Disney.
Was North Korea involved in the Bitget hack?
Following the September 2026 Bitget hack, in which about $387.5 million was lost to attackers, the company’s CEO Gracy Chen named North Korea as the likely culprit.
The blockchain firm Elliptic said the stolen Bitget funds were linked to addresses used to launder the funds from the 2025 Bybit theft. It called reusing the same laundering routes a common pattern for North Korean hackers, and said the Bitget attack pushed suspected North Korean crypto thefts above $1 billion in 2026.
ZachXBT flagged five accounts in the Bitget laundering effort, and one account called “lolo,” who also handled proceeds from the $292 million Kelp DAO exploit in April.
Separately, Cryptopolitan reported that wallets tied to the Bitget hack pushed about $3.9 million in Zcash into the Ironwood shielded pool.
If you're reading this, you’re already ahead. Stay there with our newsletter.
FAQs
How did ZachXBT get inside the laundering group?
He posed as a client, contacting a Telegram operator who used the alias "Jimmy Green" and building trust through transactions, including a $3.497 million USDC swap on March 6, 2025, that he funded with his own money.
What was the result of the investigation?
The intelligence helped freeze Bybit exploit funds, including about 442,000 USDT frozen by Tether, and ZachXBT says his work has helped freeze more than $75 million tied to North Korea-linked incidents since 2022.
How is this connected to the Bitget hack?
Elliptic traced links between the roughly $387.5 million stolen from Bitget on September 24, 2026, and addresses used to launder the 2025 Bybit theft, and ZachXBT flagged overlapping launderers, including one account also tied to the $292 million Kelp DAO exploit.
Disclaimer. The information provided is not trading advice. Cryptopolitan.com holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Hannah Collymore
Hannah is a writer and editor with nearly a decade of blog writing and event reporting experience in the crypto space. At Cryptopolitan, Hannah contributes to the news page, reporting and analyzing the latest developments in DeFi, RWA, crypto regulation, AI and frontier tech industries. She graduated from Arcadia university with a degree in Business Administration.















