
AI-generated summary
The Bybit exploit occurred on or about February 21, 2025, when North Korea-linked Lazarus Group stole approximately $1.5 billion in virtual assets. The FBI attributed the theft to TraderTraitor malware and urged blocking transactions tied to laundering addresses. ZachXBT's investigation began after noticing accounts seeking help with orders linked to stolen funds in public Telegram and Discord groups.
Blockchain investigator ZachXBT said he infiltrated a Chinese laundering syndicate by posing as a cryptocurrency client and funding repeated stablecoin trades.
In an Oct. 5 disclosure, he alleges the network laundered more than $1 billion across exploits for Lazarus Group.
He said he fronted 349,700 USDC to build a relationship with a contact using the alias Jimmy Green. According to his account, the repeated exchanges led to private conversations about moving funds stolen from Bybit in 2025.
He reported tracing a cluster involving more than $12 million in Bybit funds and a later 442,000 USDT freeze by Tether.
Becoming a client
ZachXBT said the investigation began after the February 2025 Bybit exploit, when he noticed at least 15 accounts asking for help with orders he linked to stolen funds in public Telegram and Discord groups.
He contacted several of those accounts. One was Jimmy Green, the Telegram alias of the person with whom he subsequently exchanged funds.
On March 6, 2025, ZachXBT said he funded a new Ethereum address with 349,700 USDC in preparation for transactions with the contact. The arrangement involved sending his USDC on Ethereum in exchange for the contact's USDT on Tron. He then completed additional transactions to build trust.
As he built trust through repeat exchanges, ZachXBT said the contact began discussing movements of Bybit funds for North Korea before they occurred. The conversations also included details about operations in Hong Kong and mainland China.
In one example, he said the contact told him funds would move to Solana, and the movement happened the following day.
On March 12, 2025, ZachXBT said the contact sent a screenshot of a cross-blockchain transfer. He matched its amounts and timing to an order on the THORChain transaction explorer created within minutes of the message.
According to ZachXBT, the contact also supplied three Solana addresses. He said these exposed a cluster involving more than $12 million in Bybit exploit funds moving through Bitcoin, Ethereum, Solana and Tron.
He separately reported that Tether later froze 442,000 USDT linked to the cluster. That is the specific freeze amount described in this part of his investigation; the larger cluster figure represents funds he said he traced.
The account also reaches beyond Bybit. ZachXBT said the contact mentioned a team whose funds had been frozen in 2024. He said that matched an on-chain freeze of 332,000 USDC tied to the Poloniex exploit.
The Bybit backdrop and the cost of access
In a Feb. 26, 2025 alert, the FBI said North Korea stole approximately $1.5 billion in virtual assets from Bybit on or about Feb. 21. It called the specific malicious activity TraderTraitor.
At the time, the FBI said some stolen assets had been converted into Bitcoin and other virtual assets dispersed across thousands of addresses on multiple blockchains. It urged private-sector services to block transactions connected to the laundering addresses.
The syndicate's total and the links to Jimmy Green remain ZachXBT's findings, separate from the FBI's attribution of the theft.
Allegations involving a Chinese over-the-counter trader surfaced in October 2024. The latest account describes how ZachXBT obtained information by becoming a trading counterparty himself.
ZachXBT said he fronted 349,700 USDC for the case and lost 5% on each order. The amount advanced is distinct from his net loss, which he did not quantify in the disclosed figures.
He appealed for continued foundation grants and individual donations to support higher-risk investigations. He said intelligence from these trades helped freeze funds tied to the Bybit exploit.
AI outlook — possibilities, not facts
Tether or other stablecoin issuers may freeze additional funds linked to the traced Bybit exploit cluster as more evidence emerges.
Likely · Within weeks
Law enforcement may increase scrutiny on over-the-counter (OTC) trading desks in Hong Kong and mainland China suspected of facilitating North Korea-linked money laundering.
Possible · Within months

On-chain investigator ZachXBT wired $349,700 of his own funds to pose as a client and infiltrate a North Korean-linked crypto laundering operation, gathering intelligence that led to freezes and attribution of the $1.5 billion Bybit exploit and other hacks, while detailing interactions with launderer 'Jimmy Green' and connections to Huione Guarantee in Cambodia.

Nine suspects, including two Greek servicemen, have been arrested for allegedly running an $8 million cryptocurrency pyramid scheme. The operation, which reportedly targeted 10,000 investors, was allegedly facilitated through a local civic group in Katerini.

The hacker who stole $387.5 million from Bitget exchange has begun laundering funds by moving approximately 2,700 ZEC ($3.8 million) into Zcash's Ironwood shielded pool, which obscures transaction details. On-chain investigators link the attack to North Korean actors, with Elliptic calling it the largest suspected North Korean theft of 2026. Cross-chain swaps via Thorchain and others continue despite some funds being frozen by Near's SHIELD system.

A UK court has ordered former National Crime Agency officer Paul Chowles to repay £1,810,678.93 ($2.4 million) for stealing 50 Bitcoin from a seized wallet during the Silk Road 2.0 investigation in 2017. The coins, worth about £60,000 at the time, have appreciated significantly. Chowles was jailed for five and a half years in July 2025 after pleading guilty to theft and related offenses. The Crown Prosecution Service secured the confiscation order under the Proceeds of Crime Act 2002, noting that 30 of the 50 BTC were recovered from him, with the order reflecting Bitcoin's increased value since the theft.

Aiden Pleterski, Canada's self-styled 'Crypto King', will defend himself at a Toronto fraud and money laundering jury trial starting Monday after a judge denied his request for an adjournment.

Aiden Pleterski, a self-described 'crypto king' accused of defrauding investors of approximately $30 million through false profit claims on digital assets between 2021 and 2022, is set to stand trial in Ontario's Superior Court of Justice on October 5, 2024, after being charged with fraud and money laundering in May 2024. He is expected to represent himself due to inability to secure legal counsel, with the fraud charge carrying a maximum sentence of 14 years if convicted.