The investigation centered on laundering activity following the February 2025 Bybit hack, in which approximately $1.5 billion in crypto was stolen. U.S. authorities later attributed that attack to North Korea, while ZachXBT said information obtained from the alleged laundering network helped identify more than $12 million in Bybit-linked funds and contributed to the freezing of 442,000 USDT.
ZachXBT disclosed the operation publicly on Oct. 5 after keeping details private while information was shared with investigators and law enforcement. His claim that the network handled more than $1 billion across multiple Lazarus Group-linked exploits remains based on his investigation and should not be treated as a judicial finding.
How Did ZachXBT Get Inside the Alleged Laundering Network?
ZachXBT said he began investigating after finding more than 15 accounts in public Telegram and Discord groups seeking assistance with transactions involving funds linked to the Bybit theft.
He eventually began dealing with an operator using the alias “Jimmy Green.” On March 6, 2025, ZachXBT funded a new Ethereum address with 349,700 USDC and conducted transactions with the operator while posing as a legitimate customer. He said each order cost him roughly 5%, meaning the operation required accepting real financial losses without certainty that the counterparty would continue cooperating.
The transaction trail became more useful when information supplied privately could be compared with subsequent blockchain activity. ZachXBT said one receiving address supplied by Jimmy was funded for transaction fees by a wallet traceable to Bybit exploit funds and included on Bybit’s public blacklist.
He also said Jimmy discussed plans to move stolen assets onto Solana before corresponding transfers appeared onchain. Three Solana addresses subsequently shared by the operator helped ZachXBT identify a cluster containing more than $12 million in Bybit-linked funds moving between Bitcoin, Ethereum, Solana and Tron.
Investor Takeaway
The investigation illustrates a limitation of blockchain transparency: investigators can often trace assets between addresses, but identifying the people coordinating those movements may require offchain intelligence. That distinction affects how quickly exchanges, stablecoin issuers and law enforcement can act on stolen funds.
Did the Investigation Actually Lead to Frozen Funds?
ZachXBT said Tether ultimately froze 442,000 USDT connected to the wallet cluster identified during the operation. He also matched information from the operator with 332,000 USDC previously frozen from funds linked to the Poloniex exploit.
The amounts are small compared with the $1.5 billion taken from Bybit, but they show how attribution can move from wallet tracing to an actionable freeze when funds reach assets or intermediaries with centralized controls.
The challenge is scale. FinanceFeeds reported in August that Bybit had recovered $48.4 million from the attack while another $30.5 million remained frozen across more than 28 exchanges and custodians. Together, that represented only about 5.3% of the original theft as either recovered or preserved.
FinanceFeeds has also reported other efforts to trace Lazarus-linked flows, including ZachXBT’s earlier allegations involving Tokenlon and tens of millions of dollars in suspected North Korea-linked funds.
Investor Takeaway
A wallet being identified is not equivalent to recovering the assets inside it. Recovery usually depends on reaching an exchange, stablecoin issuer, custodian or other intermediary capable of stopping movement before the funds are bridged, swapped or dispersed again.
What Did the Network Reveal About Lazarus Laundering?
ZachXBT said conversations with Jimmy indicated a structured operation involving multiple participants and different roles rather than one individual moving assets independently. The operator allegedly described activity in both mainland China and Hong Kong and claimed his team had handled a large portion of the Bybit proceeds.
One screenshot involving a bridge transaction was matched by ZachXBT to a THORChain order created within minutes. The pattern fits a broader laundering strategy in which stolen assets move quickly across chains and tokens, making freezes increasingly difficult as transaction paths multiply.
Another $3 million transaction discussed during the conversations was traced by ZachXBT to a Huione Guarantee-linked hot wallet. U.S. authorities have separately targeted the wider Huione network over alleged money-laundering activity. FinanceFeeds reported in June that the Justice Department seized backend infrastructure used by Huione Group subsidiaries as part of Operation Riptide.
Why Does the Investigation Matter Beyond Bybit?
ZachXBT said he has helped facilitate freezes totaling more than $75 million in assets connected to North Korean incidents since 2022. That figure is his own estimate, but the latest investigation provides an unusually detailed example of how private blockchain investigators can interact with stablecoin issuers, exchanges and law enforcement.
It also exposes a structural weakness in crypto asset recovery. Public blockchains provide transaction records in real time, yet laundering operations can exploit cross-chain bridges, decentralized exchanges, OTC intermediaries and private messaging channels faster than investigators can obtain freezes.
Investor Takeaway
For exchanges and investors, the important metric after a major hack is not simply how much crypto remains traceable. The more meaningful measures are how much has actually been frozen, how much has been returned to victims, and whether investigators can identify intermediaries before stolen assets disappear into harder-to-recover channels.







