Crypto Sleuth ZachXBT Fronted $350K to Pose as a Client of Lazarus' Chinese Launderers

Pseudonymous on-chain investigator ZachXBT says he posed as a client of a Chinese laundering syndicate tied to North Korea’s Lazarus Group, fronting $349,700 on March 6, 2025 and accepting a 5% loss per order to collect real-time intelligence. His operation reportedly revealed a cluster of more than $12 million in funds linked to the February 2025 Bybit exploit and helped prompt Tether to freeze 442,000 USDT connected to the cluster.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished 1 minute agoUpdated 1 minute ago0 views
Crypto Sleuth ZachXBT Fronted $350K to Pose as a Client of Lazarus' Chinese Launderers

Why It Matters

The admission shows an active, hands-on approach to blockchain investigations that goes beyond passive tracing and illustrates how informal investigators can produce on-chain leads that large firms and custodians act on. The work also intersects with major law-enforcement attributions: the FBI linked the Bybit theft to DPRK-associated hackers, increasing the significance of any on-chain evidence about laundering paths.

Key Facts

  • Investigator: ZachXBT (pseudonymous)
  • Date funds were fronted: March 6, 2025
  • Amount fronted: $349,700 USDC (349.7K)
  • Loss per order accepted: 5% on each order
  • Cluster uncovered: More than $12 million in Bybit-linked funds moving across chains to Solana and Tron (per ZachXBT)

Most blockchain sleuthing is observational; the on-chain investigator known as ZachXBT says he took a different tack during the aftermath of the February 2025 Bybit exploit. According to his account, he posed as a customer of a Chinese syndicate that was laundering funds for DPRK-linked hackers, funding a new Ethereum address with 349.7K USDC on March 6, 2025 and accepting a roughly 5% loss on each exchange order to build trust and collect evidence. ZachXBT says the operation produced traceable on-chain links between the alleged launderers and the Bybit exploit, which the FBI had attributed to a North Korea-linked group it tracks as “TraderTraitor.” He reports matching messages and screenshots from a contact known as “Jimmy Green” to rapid on-chain swaps recorded on Thorchain and other public ledgers, and says those addresses exposed a cluster of over $12 million in Bybit-related funds moving between Bitcoin, Ethereum, Solana and Tron. Tether later froze 442,000 USDT that ZachXBT ties to the cluster, and he says the chats allowed him to confirm prior freezes as well — for example locating 332,000 USDC frozen after the November 2023 Poloniex exploit, which researchers have connected to Lazarus Group activity. He also reports that the syndicate discussed operational details, including preparations to move funds and the existence of teams and divisions handling USDT acceptance and distribution. ZachXBT has a history of public tracing work: he linked the Bybit hack to Lazarus on the day it occurred, contributed to tracing funds from other high-profile incidents, and says his discoveries have supported over $75 million in asset freezes tied to North Korean incidents since 2022. He funds investigative work through grants and donations and has served in advisory roles, including a February 2025 incident-response role with Paradigm, which its co-founder said had helped return more than $350 million to victims of hacks and scams.

Keep Reading