BlockBeats news, October 5: On-chain detective ZachXBT posted on social media disclosing that he once posed as a client to infiltrate a Chinese organized crime money laundering network. The network is alleged to have laundered over $1 billion for hackers linked to North Korea's Lazarus Group in multiple exploit incidents. The intelligence he gathered helped drive the freezing of funds and on-chain attribution in the February 2025 Bybit $1.5 billion theft incident.
After the February 2025 Bybit incident, ZachXBT found in public Telegram and Discord groups that a large number of accounts were processing orders related to the stolen funds. He approached an operator using the pseudonym "Jimmy Green" as a client and gradually built trust through multiple USDC and USDT exchanges. The other party subsequently revealed fund transfer plans in advance and claimed that their team had laundered most of the Bybit stolen funds. ZachXBT said he chose to continue bearing a loss of about 5% per order in exchange for more actionable intelligence.
During the investigation, he identified a Solana address cluster involving more than $12 million in Bybit stolen funds, of which 442,000 USDT was subsequently frozen by Tether. He also confirmed the freezing of 332,000 USDC related to the Poloniex theft case and traced another $3 million in fraudulent proceeds to a hot wallet of Huione Guarantee, which was later sanctioned. The relevant findings have been submitted to private-sector investigators and law enforcement agencies.
ZachXBT stated that in this case he advanced $349,700 and bore financial losses and personal risk. Since 2022, he has helped drive the freezing of more than $75 million in assets related to North Korea-linked incidents. He also called on foundations and individuals to provide funding to support his continued investigation of cases that others may consider unfeasible.

