
On-chain investigator ZachXBT wired $349,700 of his own funds to pose as a client and infiltrate a North Korean-linked crypto laundering operation, gathering intelligence that led to freezes and attribution of the $1.5 billion Bybit exploit and other hacks, while detailing interactions with launderer 'Jimmy Green' and connections to Huione Guarantee in Cambodia.
AI-generated summary
ZachXBT is a pseudonymous on-chain investigator known for tracing stolen cryptocurrency and attributing hacks to North Korean groups like Lazarus. He has previously assisted in freezing funds and worked with Paradigm as an incident response advisor.
Most on-chain sleuths trace stolen crypto from the sidelines. The pseudonymous ZachXBT says he wired $349,700 of his own money to the people moving it.
"Posing as a client, I gathered intel that helped action freezes for the Feb 2025 Bybit exploit and attribute illicit activity onchain." he wrote on X. ZachXBT explained the group was a Chinese gang working for North Korea.
That exploit he is referencing caused $1.5 billion in losses to the crypto exchange Bybit. The FBI attributed the incident to North Korean hackers it tracks as TraderTraitor. The alleged launderers, ZachXBT says, were not exactly hiding.
For those who don't spend their days on "Crypto Twitter" tracking the everyday goings on of crypto hacks and exploits, ZachXBT is likely the best-known and most prolific on-chain investigator in the space. The mostly pseudonymous 20-something-year-old has spent years tracing stolen crypto and naming the people behind scams and hacks. His threads lean on public blockchain data that anyone can check, and he's kept on with his investigations even after a former target sued and doxxed him in 2023.
"In Feb 2025, shortly after the $1.5B Bybit exploit attributed to the DPRK-linked group ‘TraderTraitor,' I observed a pattern of 15+ accounts asking for help with orders directly tied to stolen funds in public groups on Telegram and Discord," he wrote today in post on X.
He saw the same thing last week after the $387 million Bitget hack, which Bitget's CEO and blockchain tracing firms Ellipic and Chainalysis have linked to North Korea.
His North Korea record is pretty relevant. On the day of the Bybit hack, he connected it to Lazarus Group using on-chain data, and the FBI backed that attribution days later. He also showed that wallets used to launder the Bybit funds were tied to earlier Lazarus attacks, including the Phemex and BingX hacks.
In 2024, his tracing of the theft of roughly 4,100 BTC from a Genesis creditor helped lead to arrests. Paradigm hired him as an incident response advisor in February 2025, with co-founder Matt Huang saying he had returned more than $350 million to victims of hacks and scams. ZachXBT says grants from foundations and donations from individuals are what let him take on riskier cases like this one.
Back in 2025, ZachXBT started messaging the accounts complaining about Bybit-linked orders. One went by "Jimmy Green" on Telegram.
"On Mar 6, 2025, I funded a new address with 349.7K USDC on Ethereum in preparation to conduct several transactions with Jimmy Green," he said. Jimmy gave him an address to send the USDC to, in exchange for USDT on Tron.
That address, ZachXBT wrote, had been funded with gas by a wallet that "is directly traceable to Bybit exploit funds and is labeled on the public Bybit exploit blacklist site."
"I completed several additional transactions with him in order to build up trust," he said. "After that, Jimmy began to talk about moving Bybit funds for DPRK in advance of it happening, along with basic details about their operation in [Hong Kong] and mainland China."
The proof, per ZachXBT, was that "one day prior he stated funds would be moved to Solana and the next day they were."
Staying in the hunt cost money. "At this point, I realized I needed to continue losing 5% per order and gamble on capturing as much actionable intel as quickly as possible," he wrote.
"For this case, I fronted $349.7K and lost 5% on each order, with no guarantee Jimmy wouldn't disappear with the funds, and an unknown amount of personal risk from dealing with the syndicate," he said.
Jimmy was eager for more. On March 10, he kept pinging the fake persona until ZachXBT said, in character, it made him "lose trust in your business." Jimmy's answer was that "the team has prepared $1 million and is ready to start work at any time!"
In another chat, Jimmy explained the team's setup: "We have different divisions of labor. We take the u and distribute it to different acceptors." The "u" is apparently shorthand for USDT, the stablecoin issued by Tether.
The chats paid off on-chain. ZachXBT wrote that on March 12, 2025, he matched a screenshot Jimmy sent of himself bridging funds to an order created within minutes of the message, using amounts and timing on the Thorchain explorer, a public log of swaps on the decentralized protocol that moves coins directly across blockchains.
Jimmy then shared three Solana addresses. They exposed a cluster of more than $12 million in Bybit loot being swapped in real time, hopping from Bitcoin to Ether to Solana and finally to Tron. Tether later froze 442,000 USDT linked to the cluster.
Jimmy also dropped details ZachXBT could check. He said a team he knew had around $300K frozen in 2024, and ZachXBT found the freeze on-chain. The real figure was 332,000 USDC, stolen in the Poloniex exploit, the November 2023 hack that drained more than $100 million from the exchange and that researchers have tied to North Korea's Lazarus Group.
Then came the Cambodia link. Jimmy also said he had laundered $3 million in fraud proceeds for a different client, and ZachXBT traced those funds to a hot wallet used by Huione Guarantee, a Telegram marketplace where criminals sold laundering services and stolen data.
Huione Guarantee is part of Huione Group, the Cambodian conglomerate the U.S. Treasury's FinCEN targeted over alleged laundering of at least $4 billion. Telegram banned the marketplace in May 2025, and Chinese authorities arrested former Huione Group chairman Li Xiong after Cambodia deported him.
Not all of it was crime talk. "Throughout our conversations, Jimmy and I had a lot of small talk in between discussing laundering for DPRK," ZachXBT said. "He talked about playing mahjong, hunting wild rabbits, food, his fat reducing meal, family life, and vacations at Disney."
The sting is not a one-off. "Since 2022, I have helped action $75M+ in freezes related to DPRK incidents," ZachXBT wrote. He said his findings went immediately to trusted private-sector investigators and to the law enforcement assigned to the case, and that sensitivity around the investigation kept him from publishing sooner.
AI outlook — possibilities, not facts
Law enforcement will increase scrutiny on Telegram-based laundering services like Huione Guarantee
Likely · Within months
ZachXBT will continue to assist in freezing funds linked to North Korean cyber operations
Very likely · Within months

Blockchain investigator ZachXBT disclosed that he posed as a cryptocurrency client to infiltrate a Chinese laundering syndicate, funding repeated stablecoin trades to gain trust. He alleges the network laundered over $1 billion tied to Lazarus Group exploits, traced $12 million in Bybit 2025 exploit funds across chains, and contributed to a Tether freeze of 442,000 USDT. His investigation began after the February 2025 Bybit hack, where he engaged with Telegram alias Jimmy Green, leading to discussions about moving stolen assets before they occurred.

Nine suspects, including two Greek servicemen, have been arrested for allegedly running an $8 million cryptocurrency pyramid scheme. The operation, which reportedly targeted 10,000 investors, was allegedly facilitated through a local civic group in Katerini.

The hacker who stole $387.5 million from Bitget exchange has begun laundering funds by moving approximately 2,700 ZEC ($3.8 million) into Zcash's Ironwood shielded pool, which obscures transaction details. On-chain investigators link the attack to North Korean actors, with Elliptic calling it the largest suspected North Korean theft of 2026. Cross-chain swaps via Thorchain and others continue despite some funds being frozen by Near's SHIELD system.

A UK court has ordered former National Crime Agency officer Paul Chowles to repay £1,810,678.93 ($2.4 million) for stealing 50 Bitcoin from a seized wallet during the Silk Road 2.0 investigation in 2017. The coins, worth about £60,000 at the time, have appreciated significantly. Chowles was jailed for five and a half years in July 2025 after pleading guilty to theft and related offenses. The Crown Prosecution Service secured the confiscation order under the Proceeds of Crime Act 2002, noting that 30 of the 50 BTC were recovered from him, with the order reflecting Bitcoin's increased value since the theft.

Aiden Pleterski, Canada's self-styled 'Crypto King', will defend himself at a Toronto fraud and money laundering jury trial starting Monday after a judge denied his request for an adjournment.

Aiden Pleterski, a self-described 'crypto king' accused of defrauding investors of approximately $30 million through false profit claims on digital assets between 2021 and 2022, is set to stand trial in Ontario's Superior Court of Justice on October 5, 2024, after being charged with fraud and money laundering in May 2024. He is expected to represent himself due to inability to secure legal counsel, with the fraud charge carrying a maximum sentence of 14 years if convicted.