
AI-generated summary
The Bybit hack on February 21, 2025 resulted in the theft of approximately $1.5 billion in cryptocurrencies. The FBI attributed the attack to North Korea five days later, linking it to the Lazarus Group and Operation TraderTraitor.
A $3.5 million infiltration. ZachXBT claims to have committed its own funds to pose as a client of a Chinese money laundering network suspected of working for North Korean Lazarus hackers. Unveiled on October 5, its investigation made it possible to document circuits linked to the hacking of Bybit and to contribute to the freezing of funds.
The objective: to go beyond transaction monitoring to obtain information directly from the intermediaries responsible for moving stolen cryptocurrencies.
Key Points
ZachXBT claims to have raised approximately $3.5 million of its own funds.
He increased his exchanges with an operator using the pseudonym “Jimmy Green”.
The investigation identified a set of addresses associated with more than $12 million from the Bybit hack.
Around 442,000 USDT was frozen by Tether.
ZachXBT becomes a client to go up the network
After the Bybit hack, ZachXBT spotted accounts in public Telegram and Discord groups that appeared to deal with transactions related to stolen funds. He approaches one of these intermediaries, known under the pseudonym Jimmy Green, presenting himself as a client.
To establish the relationship, the investigator performs several exchanges between USDC and USDT. He claims to have mobilized approximately $3.497 million in USDC and accepted losses close to 5% per trade in order to gather more intelligence. This sum corresponds to the capital committed, and not to an announced total loss.
As trust builds, the intermediary communicates information about future movements of funds. He also claims that his team processed a significant portion of Bybit's loot. These declarations constitute avenues to be compared to the transactions visible on the blockchains.
ZachXBT thus identifies a set of addresses on Solana linked to more than 12 million dollars from the hack. According to his account, approximately 442,000 USDT was subsequently frozen by Tether. The information collected was passed on to private investigators and law enforcement.
Bybit: Track funds, then successfully block them
The starting point remains the theft of approximately $1.5 billion in cryptocurrencies, suffered by Bybit on February 21, 2025. Five days later, the FBI attributed the attack to North Korea and designated the malicious activity under the name TraderTraitor.
The American agency then describes a rapid dispersion: part of the assets were converted into bitcoins and other cryptocurrencies, then distributed among thousands of addresses on several blockchains. It calls on industry players to block transactions associated with identified addresses.
Infiltration provides a complementary piece to this monitoring. Public transactions make it possible to reconstruct pathways; exchanges with an operator can help link addresses and anticipate certain transfers.
But identifying, freezing and returning funds are three separate steps. The 12 million dollars identified therefore do not correspond to an amount recovered. Likewise, the freezing of the 442,000 USDT does not mean that Bybit has already obtained its restitution.
AI outlook — possibilities, not facts
Additional investigations will be launched into addresses identified on Solana linked to the Bybit hack
Likely · Within weeks
Tether could freeze more funds associated with investigated laundering network
Possible · Within months

Denmark faces a hack of its central CPR register, exposing the data of 8.8 million people. This incident reignites the debate on the security of state databases and digital identity wallets.

The Danish government announced on Monday the leak of the data of nearly 8.8 million people registered in the central population register, consulted illegally via access from a private company.

Near Intents has recovered all of the $3.8 million stolen in an attack on its cross-chain swap service, following a 48-hour ultimatum from its chief executive.

In the third quarter of 2026, cryptocurrency hacks resulted in the theft of $1.26 billion according to CertiK, despite a 40% increase in bitcoin over the same period. September was the worst month with $768.5 million lost, mainly due to code and infrastructure flaws. Net losses after recoveries amounted to 869.6 million for the quarter, while the sector's insurance capacity fell by 20% year-on-year. Major attacks have targeted Bitget, Liquid Network and Tectonic, exploiting vulnerabilities in third-party providers, cryptographic proofs and lending protocols. AI now accelerates the detection of flaws in smart contracts.

In its 2026 index published on September 23, Chainalysis ranks Brazil first in the world for crypto adoption, ahead of the United States. Latin American activity grew by 9.8%, driven by the massive use of stablecoins.

OpenAI fired three employees for sharing confidential information with a third-party organization. This case comes shortly after the cancellation of GPT-6.1 Astra.