Skip to content

on-chain

ZachXBT fronts $349,700 to infiltrate Chinese launderers linked to Bybit hack

On-chain investigator ZachXBT ran six months of controlled transactions through a Chinese OTC syndicate operating for Lazarus, surfacing a Tron collection address and a $12M Bybit-linked cluster.

by 4 min read

On-chain investigator ZachXBT published a long-form report on October 5, 2026 detailing a months-long infiltration of a Chinese OTC laundering syndicate he says works for North Korea's Lazarus Group, including on funds from February's $1.5 billion Bybit hack. The Block summarises the operation. The French-language desks at Journal du Coin and Cryptoast corroborated the same figures from ZachXBT's write-up.

The operation

ZachXBT posed as a client of an operator working under the pseudonym "Jimmy Green", who solicited laundering business in open Telegram and Discord channels. The point was intelligence, not fund recovery: get collection addresses, map the OTC desks, trace the exit rails.

Reported figures:

  • Capital fronted: $349,700 USDC on Ethereum.
  • Burn per rotation: roughly 5%, accepted as an intelligence cost.
  • Cluster identified: at least $12 million of funds linked to the Bybit hack.
  • Frozen so far: $442,000 USDT across addresses linked to Jimmy's cluster.
  • Cumulative since 2022: $75 million frozen via disclosures tied to this and prior investigations.

The syndicate's claimed throughput, per ZachXBT citing Jimmy: "most of the $1.5 billion from Bybit" laundered through the same network, "consistent with laundering patterns I observed."

The on-chain trail

A single bridging mistake tied Jimmy's operation to Lazarus's Bybit flow. On March 12, 2025, ZachXBT reports he was sent a bridge screenshot that matched a THORChain order in the hack's known laundering fan-out. The receiving address Jimmy had used the previous day, prefixed 0xbaa5 on Tron, became the pivot: it tied the operator's identity to a cluster the FBI and multiple analytics firms had already flagged as Lazarus-adjacent.

The syndicate also showed operational tells. ZachXBT writes: "One day prior, he stated funds would be moved to Solana and the next day they were." That cross-chain foreknowledge is the kind of thing a passive observer cannot produce.

Where the funds went

ZachXBT cites a familiar set of rails for the exit:

  • THORChain — cross-chain swaps used extensively in the Bybit laundering operation.
  • Huione Guarantee — the Cambodia-based marketplace the US Treasury's FinCEN designated a primary money-laundering concern on May 1, 2025; its token (HUIONE) and infrastructure keep surfacing in DPRK-linked flows.
  • Solana — ZachXBT names Solana as a destination chain for post-rotation funds moving out of EVM clusters.

The attribution to Lazarus for the hack itself has been formal since February: Arkham Intelligence attributed the Bybit theft to Lazarus and the FBI issued a public service announcement naming the group within two weeks of the exploit.

Context

North Korean laundering operations have professionalised around a small number of recurring vendors. The pattern — Telegram-first intake, Chinese-language OTC desks, Huione as the clearing layer, THORChain and (increasingly) Solana as the mixing rails — has been documented across the DMM Bitcoin exploit (~$35M routed through Huione per prior ZachXBT work), the WazirX breach, and now Bybit at scale.

The piece is also a methodological shift. Previous ZachXBT investigations relied on open-source cluster analysis. This one is active-measures journalism — a researcher fronting real capital to buy access to a target's internal workflow. The cost model (5% per rotation, mid-six-figure capital) is now a known data point for anyone considering the same approach.

What to watch

  1. Further Tether/Circle freezes against addresses in the published cluster — Tether already acted on $442K and typically moves on fresh disclosures within days.
  2. A FinCEN or OFAC follow-up naming additional entities in the "Jimmy Green" cluster. The Huione designation is the template.
  3. ZachXBT's full address list. The published report names anchor addresses; the full cluster will be the material artifact other investigators and exchanges work from.
  4. Bybit's own clawback status. As of early October, Bybit had recovered a fraction of the $1.5B directly; this disclosure feeds that effort more than it closes it.

Related stories