Blockchain investigator ZachXBT disclosed on October 5, 2026, that he spent weeks inside a Chinese organized crime network he says has moved more than $1 billion in stolen cryptocurrency for North Korea’s Lazarus Group across several exploits.
In a 12-part thread on X, he described posing as a paying client, absorbing fees on every order, and collecting details that he says helped freeze assets tied to the February 2025 Bybit theft and link other illicit flows on public ledgers.
The account begins shortly after the Bybit incident, which U.S. authorities have attributed to TraderTraitor, a North Korean cluster associated with Lazarus.
ZachXBT wrote that he noticed more than 15 accounts in public Telegram and Discord communities seeking help with orders that traced directly to the stolen funds.
He contacted several of them.
One operator used the alias Jimmy Green, with the Telegram username long_991 and Telegram ID 7635649994.
On March 6, 2025, ZachXBT funded a fresh Ethereum (ETH) address, 0x073256b50d66a7eb005f2a504d0a4fb6ea62a276, with 349,700 USDC so he could place orders.Jimmy supplied a receiving address, 0xbaa551da0ae0c93025d9a983a68025a27dc15337, in exchange for USDT on Tron.
ZachXBT reported that the gas for that address came from another wallet, 0xbcb4, which he said is directly traceable to Bybit exploit funds and appears on a public Bybit blacklist.
He completed additional transfers to additional addresses Jimmy provided, accepting a 5 percent loss on each order to build credibility.
Once trust increased, ZachXBT said, Jimmy began describing movements of Bybit proceeds for a North Korean client before those movements occurred, and offered a basic account of an operation spanning Hong Kong and mainland China.
In one example, Jimmy said funds would shift to Solana the next day, and they did.
Jimmy also claimed his team had laundered most of the roughly $1.5 billion taken from Bybit, a statement ZachXBT said matched the laundering patterns he had already been tracking.
At that stage, ZachXBT decided to keep paying the 5 percent fee in hopes of capturing usable intelligence quickly.
On March 12, 2025, Jimmy sent a screenshot of himself bridging funds.
ZachXBT matched the amount and timing to a THORChain order created within minutes of the message, citing transaction hash 81a85130b36057428e64b6f97215f77b5a197776a8f1b3a61c8cd0ee1ebfa8c1.
Jimmy later shared three Solana addresses that, according to ZachXBT, exposed a cluster of more than $12 million in Bybit-linked funds being swapped in real time from Bitcoin to Ether to Solana and then to Tron.
1/ How I infiltrated a Chinese organized crime syndicate that has laundered $1B+ across multiple exploits for Lazarus Group.
Posing as a client, I gathered intel that helped action freezes for the Feb 2025 Bybit exploit and attribute illicit activity onchain. pic.twitter.com/jauRRt8875
— ZachXBT (@zachxbt) October 5, 2026
Tether later froze 442,000 USDT connected to that cluster. ZachXBT also said the cluster used an unusual method involving Uniswap liquidity positions in illiquid tokens.
Other remarks proved checkable.
Jimmy mentioned a team he knew that had about $300,000 frozen in 2024; ZachXBT identified an on-chain freeze of 332,000 USDC tied to the Poloniex exploit.
Jimmy also said he had laundered $3 million in fraud proceeds for another client; ZachXBT traced those funds to a hot wallet associated with Huione Guarantee, a marketplace later sanctioned, whose former chairman was arrested.
Between operational details, the chats included ordinary small talk about mahjong, hunting wild rabbits, food, a weight-loss meal, family life, and trips to Disney.
ZachXBT attributed awkward phrasing to translation software.
He wrote that he fronted the $349,700 himself, with no assurance the counterparty would not disappear with the money, and with personal risk from dealing with the syndicate.
Findings were shared promptly with private-sector investigators and law enforcement assigned to the case.
Publication was delayed because of the sensitivity of the inquiry.
Since 2022, he said, his work has helped secure more than $75 million in freezes related to North Korea-linked incidents.
He also noted that he is holding back significant findings from other cases and that grants and donations allow him to take on higher-risk work others may not pursue.
The thread is ZachXBT’s account of private conversations and on-chain matches. It does not, by itself, constitute a law-enforcement finding that a single Chinese network processed more than $1 billion for Lazarus.