
How investigators and authorities are targeting the intermediaries that help North Korean hackers convert stolen digital assets into usable currency.
AI-generated summary
North Korean hackers stole $1.5 billion from Bybit in February 2025. The US Treasury has been actively sanctioning marketplaces like Huione and Xinbi that facilitate laundering for these actors.
North Korean hackers stole around $1.5 billion from Bybit in February 2025. While the hack itself has been widely covered and analyzed, few have focused on what happened afterward and what became of the stolen funds.
To move all that money, hackers needed to rely on an entire network of people willing to handle stolen assets, creating a chain of relationships that someone prepared to spend enough money could infiltrate.
That's what ZachXBT, a pseudonymous blockchain investigator, did. He committed 349,700 USDC and accepted a 5% loss on each completed order while posing as a client of a Chinese laundering network.
He eventually obtained information that helped him trace more than $12 million in Bybit-linked funds and, according to his account, contributed to Tether freezing 442,000 USDT.
His investigation led him to a network he believes laundered more than $1 billion from crypto thefts linked to the North Korean Lazarus Group, including proceeds from the Bybit attack.
The implications of his investigations extend to a much larger market for criminal financial services that American authorities have spent the past two years trying to disrupt.
In September, the US Treasury sanctioned Xinbi Guarantee, a marketplace it said has processed more than $24 billion in digital assets and fiat currency through its platforms since 2022, and explicitly identified North Korean hackers among the illicit actors reported to have used its services.
Treasury also acknowledged that criminals tried to preserve their operations by moving from Huione to Xinbi after it was sanctioned, showing how removing one marketplace doesn't eliminate the relationships and demand that supported it in the first place.
Believe it or not, hacking an exchange and stealing funds is actually the easiest part of this crime. Converting stolen crypto into fiat or another form of real purchasing power is where it gets difficult.
To do that, hackers rely on payment services and other shady relationships that let investigators and regulators intervene.
The $349,700 customer
The FBI attributed the Bybit theft to North Korean hackers on Feb. 26, 2025, identifying the activity as TraderTraitor and warning that stolen assets were being converted into Bitcoin and other cryptocurrencies before being distributed across thousands of blockchain addresses.
While it took no time to identify the hackers, identifying the intermediaries handling the stolen money required much more investigative work.
According to ZachXBT, he began that work when he saw more than 15 accounts in public Telegram and Discord groups seeking help with transactions tied to the stolen Bybit funds, suggesting that at least part of the subsequent laundering process involved intermediaries openly soliciting or arranging services.
He contacted several of those accounts and eventually developed a relationship with someone using the Telegram alias Jimmy Green, who presented himself as someone who needed help moving cryptocurrency between networks.
On March 6, 2025, ZachXBT says he funded a new Ethereum address with 349,700 USDC and began exchanging the dollar-linked token for USDT on Tron through the contact, accepting unfavorable exchange terms while trying to establish himself as a credible customer.
The 349,700 USDC represented capital committed to the transactions rather than a disclosed net investigative loss, while the 5% he says he lost on each order is the cost he was prepared to accept for access to information that ordinary blockchain analysis could not provide.
The arrangement also carried the risk that the intermediary could just disappear with the funds.
Hackers depend on intermediaries who might steal from them in turn, and without enforceable commercial protections, reputation and personal familiarity become especially important to keeping those relationships working.
That gave ZachXBT a way into the operation, since a customer willing to conduct repeated transactions became more valuable to the person providing the service.
The relationship eventually produced information beyond wallet addresses, including discussions of planned fund movements before the transactions occurred, allowing ZachXBT to compare statements made privately with activity subsequently recorded on public blockchains.
In one instance, the intermediary discussed moving funds to Solana before the corresponding movement took place, while other exchanges and wallet connections allegedly helped identify a larger cluster of assets linked to the Bybit theft.
This was a major turning point in his investigation, because on-chain data can't identify the person behind the transaction or its intent. Private conversations about a transaction provided the key evidence about who controlled it and what they used it for.
Even though ZachXBT's investigation still doesn't completely match the FBI's official record, it's still one of the most significant investigative efforts we've seen in a while. It showed that personal and commercial relationships can provide evidence blockchain alone can't, and that similar tactics could help investigate and eventually resolve other thefts.
Tracing $12 million differs from recovering it
ZachXBT said information from his relationship with Jimmy Green helped identify a cluster with more than $12 million in Bybit-linked funds, including transactions across several networks.
He also reported that Tether later froze 442,000 USDT linked to the North Korean hack. This showed that quickly identifying stolen assets, while they remain accessible through issuer-controlled tokens like USDT or USDC, can be crucial to recovering the funds.
The two amounts should not be confused: tracing more than $12 million does not mean the entire amount was frozen, and freezing 442,000 USDT does not mean the tokens were seized or returned to Bybit.
The specific 442,000 USDT figure and its connection to ZachXBT's investigation come from his account, although Tether has separately disclosed larger freezes tied to the Bybit theft.
There's a considerable distance between observing stolen cryptocurrency, identifying the people handling it, and obtaining legal or technical control over the proceeds.
Public blockchains don't prevent the assets from moving again, especially when they pass through services that refuse to cooperate with investigators or operate beyond the reach of relevant authorities.
Centrally issued stablecoins create a potential intervention point because their issuers can retain the administrative ability to restrict transfers from designated addresses.
Native Bitcoin has no equivalent issuer-controlled restriction, although authorities can still restrain assets held by custodians or seize the keys controlling them when they obtain the necessary access and legal authority.
That leaves investigators dependent on more than tracing accuracy, since an identified balance must also remain within reach of someone who has the technical ability and authority to act.
During Bybit's recovery effort, court orders and cooperation from financial intermediaries could restrict assets long after the initial theft, without guaranteeing full recovery.
The problem is that stolen cryptocurrency can become increasingly fragmented as it moves between wallets, chains, custodians, and trading counterparties, with each additional service potentially requiring another source of evidence or another legal process before the pursuit can continue.
That's why investigators can see where the funds traveled but have no way to stop the next transaction or recover the funds.
$4 billion in crypto laundering
The use of outside intermediaries isn't limited to the Bybit theft, and American enforcement records show a longer history of attempts to identify businesses that convert stolen crypto into assets criminals can use.
In March 2020, the Justice Department charged two Chinese nationals, Tian Yinyin and Li Jiadong, with laundering more than $100 million worth of crypto, primarily through activity connected to exchange hacks.
These charges show how individuals who don't carry out the hack can still play an essential role in the crime.
The Treasury's sanctions announcement also revealed that Tian converted nearly $1.4 million in Bitcoin into prepaid Apple iTunes gift cards, showing how laundering can eventually involve ordinary retail instruments rather than the more elaborate financial services usually associated with international cybercrime.
The same economic requirement operates on a much larger scale through marketplaces that connect criminals with merchants offering settlement, exchange, payment and other services.
In May 2025, the Treasury's Financial Crimes Enforcement Network identified Cambodia-based Huione Group as a financial institution of primary money laundering concern, finding that its operations had laundered at least $4 billion in illicit proceeds between August 2021 and January 2025.
Of that amount, FinCEN identified at least $37 million in crypto stemming from North Korean cyber thefts, along with other proceeds from investment fraud and cyber scams.
The $4 billion figure reflects illicit activity across several crime categories, and the $37 million represents the minimum North Korean-linked component identified in the agency's findings.
FinCEN's assessment also identified serious deficiencies in anti-money-laundering and customer-verification controls across the group, including an acknowledgment that inadequate checks had allowed one component to indirectly receive funds connected to a North Korean heist.
The significance of those findings extends beyond any individual transaction because an intermediary that offers repeated access to payment services can become infrastructure for multiple criminal customers, reducing the need for each organization to build its own arrangements for converting stolen assets.
That concentrates activity around businesses that can become targets for sanctions, seizures, restrictions on banking relationships and other enforcement measures.
Huione's marketplace handled a substantial volume of transactions and illicit services, and operators tried to keep operating after Telegram disrupted access to parts of the network.
Those marketplace transaction figures and FinCEN's narrower estimates of identified illicit proceeds measure different categories of activity, making it key not to treat all funds moving through a platform as proven criminal proceeds.
The customers moved
The difficulty is that a criminal marketplace can lose infrastructure without losing the demand that made its services profitable, particularly when users can still contact alternative providers.
In June 2026, the Justice Department announced the seizure of a cloud computing account that hosted backend infrastructure used by Huione Group subsidiaries allegedly involved in moving proceeds from fraud, cyber scams and other criminal activity.
The action followed earlier US restrictions on the group and targeted technology that supports the transfer and concealment of illicit funds.
Removing that infrastructure doesn't automatically eliminate relationships between customers and the intermediaries willing to serve them.
The Treasury made that limitation particularly explicit on Sept. 9, when it sanctioned Xinbi Guarantee, describing an illicit marketplace that connected criminal organizations with merchants providing financial services, technology, and other resources needed to support their operations.
According to Treasury, Xinbi had processed the equivalent of more than $24 billion in digital assets and fiat currency since approximately 2022, with its services primarily supporting transactions involving Southeast Asian markets.
The scale makes the platform relevant to enforcement efforts against the broader financial infrastructure that serves criminal organizations.
Treasury also said cybercriminals had attempted to preserve their operations by migrating activities from Huione-related services to Xinbi following FinCEN's earlier action, with the new marketplace offering substantially similar services to an overlapping group of customers.
The agencies described a commercial market where participants could seek another provider when enforcement made their previous arrangements less reliable.
During the Huione crackdown, Telegram removed thousands of channels associated with Huione Guarantee as merchants moved to alternative marketplaces.
This is why a crackdown's success cannot be measured solely by the number of websites, accounts, or servers taken offline, since customers who still need an illicit financial service can try to rebuild access through providers that remain operational.
The disruption still imposes costs, particularly when balances are frozen, settlements fail, or established counterparties become unavailable, but the economic incentive to move stolen funds continues as long as the underlying crime remains profitable.
The problem for enforcement agencies is making those services increasingly expensive and unreliable across the network of potential replacements.
Tether's freezes push crypto laundering networks toward other payment options
The enforcement action against Xinbi shows how financial restrictions can disrupt criminal operations while prompting the businesses involved to change their payment arrangements.
A series of Tether freezes restricted over $45 million in USDT across at least 22 wallets associated with Xinbi's operations.
The marketplace responded by telling users it would move toward USDD, a stablecoin structure that doesn't offer the same issuer-controlled address-freezing mechanism as USDT.
That was an important shift because the ability to freeze a token can be valuable to investigators when suspected proceeds remain within the issuer's administrative reach, while customers attempting to avoid those restrictions have an incentive to move toward instruments with different controls.
The move shows how restrictions on one part of the payment system can redirect transactions toward another, requiring investigators to follow both the assets and the businesses that provide access to them.
During the September crackdown, authorities also targeted Xinbi-linked infrastructure and restrained over $52 million in cryptocurrency, while withdrawals accelerated and competing marketplaces reportedly began restricting laundering-related merchants.
Those developments differ from the 442,000 USDT freeze ZachXBT attributes to North Korean hackers, since public reporting does not establish that the same addresses, participants, or funds were involved.
Both cases show that criminal operations depend on financial intermediaries whose services can create opportunities for intervention even after the original theft is complete.
AI outlook — possibilities, not facts
Increased regulatory pressure on stablecoin issuers to implement stricter freezing protocols.
Likely · Within months

France's National Assembly Finance Committee voted to tax stablecoin swaps and implement a crypto exit tax for wealthy residents. The measures, which would take effect in 2027, must be reintroduced during the upcoming floor debate after the committee rejected the budget.

Bankrupt crypto lender Celsius founder Alex Mashinsky has agreed to a permanent ban from securities, commodities, and crypto businesses under a New York settlement announced Oct. 9, which includes conditional state payment obligations of up to $35 million tied to federal forfeiture payments and prison term completion, without creating new payouts to Celsius creditors.

US Treasury Secretary Scott Bessent stated the US plans to seize approximately $1 billion in cryptocurrency this week as part of sanctions on Iran, citing efforts to economically isolate the country amid its ongoing military conflict that began in February. He referenced prior seizures and noted coordination with stablecoin issuers like Tether, which reported freezing $550 million in USDT in 2026.

Former Celsius CEO Alex Mashinsky has been permanently barred from the cryptocurrency, securities, and commodities industries under a settlement with New York Attorney General Letitia James that includes up to $35 million in conditional payments, resolving a 2023 civil lawsuit alleging he misled investors about Celsius's safety before its 2022 collapse.

Blockchain.com has applied to the CFTC for licenses to operate as a futures exchange and broker in the U.S. The move aims to bring prediction markets and derivatives in-house, allowing the firm to serve retail and institutional traders directly.

Hardware wallet maker Ledger is investigating reports of crypto losses linked to authorized reseller CryptoBilis in Southeast Asia. Users are advised to move funds to new wallets while the company investigates the potential compromise of devices.