On-chain investigator ZachXBT said he posed as an over-the-counter crypto client to infiltrate a Chinese-speaking criminal network allegedly used to launder crypto proceeds for North Korea-linked hackers. To gain trust, he said he put up 349,700 USDC in real swap transactions and accepted roughly 5% losses on each trade.
Undercover trades began after the Bybit hack
The operation started after Bybit lost $1.5 billion in a hack in February 2025. ZachXBT said he found at least 15 accounts in public Telegram and Discord groups looking to process swap orders connected to the stolen Bybit funds, then reached out to one operator using the alias Jimmy Green.
On March 6, 2025, he moved 349,700 USDC to a new address and gradually swapped the funds into USDT on Tron through the counterparty across multiple trades. He said he accepted around 5% slippage on each order to build credibility, but did not disclose the final net loss from the operation.
Once he had gained the group’s trust, ZachXBT said the counterparty began sharing how the team handled North Korean hacking proceeds and how operators in Hong Kong and mainland China split the work. He also said the contact flagged in advance that funds were about to move to Solana, and matching on-chain transfers appeared the next day, allowing him to compare addresses using timing, amounts and cross-chain records.
Three Solana addresses led to a $12 million cluster
ZachXBT said Jimmy Green later provided three Solana addresses, helping him identify a cluster of more than $12 million in funds tied to the Bybit theft. The assets moved across Bitcoin, Ethereum, Solana and Tron, with swaps and cross-chain transactions used to make tracing more difficult.
Tether later froze 442,000 USDT linked to the cluster, equal to about 3.7% of the identified amount. In other words, the probe produced some direct interdiction, but most of the tracked funds were neither frozen nor recovered.
ZachXBT estimates the network processed more than $1 billion
ZachXBT also connected the network to portions of fund flows tied to incidents involving Poloniex, Bitget and Kelp DAO. Based on that activity, he estimated the group had handled more than $1 billion in assets for Lazarus-linked hackers across multiple attacks. At the same time, no complete public address list for that full $1 billion figure has been published, and law enforcement has not formally confirmed every attribution.
Chainalysis put North Korean crypto theft at at least $2.02 billion in 2025
Chainalysis estimated that North Korean hackers stole at least $2.02 billion in crypto assets in 2025, up 51% year over year, bringing the historical total to $6.75 billion. The Bybit incident alone accounted for a major share of the year’s total crypto theft.
Chainalysis also found that North Korean laundering activity relied heavily on Chinese-language guarantee services, laundering brokers, cross-chain bridges, mixers and trading platforms with weaker identity checks. That broadly matches the division of labor described by ZachXBT, where hackers handled the intrusion while external brokers took care of swaps and cash-out.
The harder problem comes after the first hop
The investigation points to a split model in which hackers carry out the intrusion and theft, while outside intermediaries handle swaps, cross-chain transfers, address dispersion and final off-ramping.
That means blocking only the first addresses used by an attacker is not enough. Once funds move through bridges, decentralized exchanges and layers of intermediary wallets, the receiving addresses may already be several hops away from the original attack wallets.
TRM Labs has also warned that screening only first-layer addresses often fails to identify this kind of cross-chain illicit flow, and that platforms need multi-hop tracing and real-time intelligence sharing.
Tether’s ability to freeze USDT shows that centralized stablecoin issuers can still intervene after investigators identify addresses. But the $442,000 frozen represented only a small share of the cluster already found, and recovery becomes much harder once funds are converted into BTC or routed through permissionless cross-chain protocols.

