FILTERED RESULTS
FILTERS
Ads Top
DARK MODE
CHART
MCap $2.9T +0.1%24h Vol $87.8B -2.2%Fear & Greed 73/100Alts Index 59/100
BTC.D 58.9% +0.1%Stable.D 9.1% 0%ETH.D 11.3% 0%Others.D 20.7% -0.1%
FLUID$2.219+25.34%•ORCA$2.417+18.24%•CAP$0.0734+13.1%•NIGHT$0.0503+12.8%•FIL$1.159+9.96%•LIT$4.032+8.97%•ZRO$2.096+8.92%•OKB$132.62+8.91%•KAIA$0.0409+8.64%•NEAR$5.260+8.14%•
BR$0.4000-12.73%•STRK$0.0525-10.09%•SAND$0.0670-9.69%•SKY$0.0879-8.75%•PROS$0.7528-8.73%•AKE$0.0316-8.47%•MINA$0.1430-8.41%•MON$0.0304-7.88%•SOON$0.3367-5.62%•2Z$0.0426-4.73%•
Top movers 24h
    Filters
      Coins
      Sentiment
      Impact
      Search
      FILTERED RESULTS

        

      Upgrade your plan
      Dashboard

      ZachXBT Infiltrated a Chinese Syndicate and Traced Lazarus Group Funds Worth More Than $1 Billion

      • ZachXBT, posing as a client, carried out a series of transactions with a representative of a Chinese criminal syndicate.
      • According to him, this syndicate laundered funds for the North Korea-linked Lazarus group.
      • The investigator put up $349,700 of his own funds and deliberately took a roughly 5% loss on each order to gain access to inside information on the movement of stolen assets.

      Crypto sleuth ZachXBT explained how, posing as a client, he infiltrated a Chinese organized crime syndicate that, by his estimate, laundered more than $1 billion from several crypto exploits linked to the North Korean Lazarus group.

      According to ZachXBT, he began the operation shortly after the Bybit crypto exchange hack in February 2025. At the time, attackers stole around $1.5 billion in crypto assets. The investigator identified more than 15 accounts on Telegram and Discord that were publicly asking for help with orders tied to the stolen funds.

      ZachXBT posed as a client

      After spotting the suspicious accounts, ZachXBT began reaching out to them. One of them was a Telegram user going by the alias Jimmy Green.

      On March 6, 2025, the investigator funded a new Ethereum address with 349,700 USDC. He said the funds were intended to carry out several transactions with Jimmy Green.

      He предложив swapping USDC on the Ethereum network for USDT on the TRON network. The address he provided for the operation was funded from another wallet that, according to ZachXBT, could be traced directly to funds from the Bybit hack.

      This wallet was also flagged on Bybit’s public blacklist site.

      ZachXBT carried out several more deals with Jimmy Green to earn his trust. According to the investigator, after that the counterparty began sharing information about upcoming movements of North Korea-linked funds. In one case, Jimmy Green tipped him off in advance that the funds would be bridged to the Solana network. The next day, ZachXBT notes, that is exactly what happened.

      According to the counterparty, his team laundered most of the $1.5 billion stolen from Bybit. ZachXBT noted that the claim matched the laundering patterns he observed during onchain analysis.

      The investigator deliberately took losses

      To keep the operation going, ZachXBT decided to accept losses on each swap. He said he was losing roughly 5% on every order, as the primary goal was to obtain actionable intelligence, not to profit from the trades.

      Overall, the investigator put $349,700 of his own money on the line. At the same time, he said he had no guarantees that the counterparty would not disappear with the funds.

      “I had to keep taking a 5% loss on every order and take risks to gather as much actionable intel as possible in the shortest time,” ZachXBT said.

      He also noted that interacting with the syndicate created an uncertain level of personal risk for him.

      Bybit funds were moved across multiple networks

      One of the key episodes of the investigation was an operation on March 12, 2025. Jimmy Green sent ZachXBT a screenshot showing the process of moving funds through a cross-chain bridge. The investigator matched the amounts and timestamps shown in the image with a transaction that was created a few minutes after the message.

      Later, Jimmy Green provided three addresses on the Solana network. This allowed ZachXBT to identify a cluster holding more than $12 million in funds linked to the Bybit exploit.

      According to him, the assets moved from the Bitcoin network to Ethereum, then to the Solana network, and ultimately ended up on TRON. The transactions happened virtually in real time. Later, Tether froze 442,000 USDT linked to this cluster.

      According to ZachXBT, the participants also used a new laundering method via Uniswap liquidity pools with low-liquidity tokens.

      The syndicate did not work only with Bybit funds

      During the conversation, Jimmy Green also talked about other operations. In particular, he mentioned a team that had about $300,000 frozen in 2024. ZachXBT verified this on-chain and found that the actual amount was 332,000 USDC. According to him, these funds came from the Poloniex exploit.

      In another case, Jimmy Green described laundering $3 million in fraud proceeds for another client.

      ZachXBT traced these funds to a Huione Guarantee hot wallet. Later, sanctions were imposed on the entity, and its former head was arrested.

      As a result, during the operation the investigator obtained information not only about the movement of Lazarus funds, but also about the syndicate’s work with assets obtained through other cryptocurrency crimes.

      Between money laundering and everyday chatter

      ZachXBT noted that over the course of their extended communication, Jimmy Green gradually shared more and more information about his team’s activities. The conversations were not limited to cryptocurrencies and money laundering.

      The source talked about playing mahjong, hunting wild rabbits, food, a weight-loss diet, family, and a trip to Disneyland. ZachXBT suggested that the source’s unusual grammar could have been linked to the use of a translator.

      According to the investigator, Jimmy Green also provided basic information about the syndicate’s operational activities in Hong Kong and mainland China.

      ZachXBT shared the data with law enforcement

      The investigator said that all data obtained during the operation was passed on to trusted private-sector representatives and law enforcement agencies working on the relevant case. He had not disclosed the details earlier due to the sensitivity of the investigation.

      ZachXBT noted that not being able to publish findings right away is one of the hardest parts of his job. He said that he currently also holds a significant amount of information on several other cases, but cannot make it public immediately.

      As a reminder, earlier ZachXBT said that North Korea earns up to $1 million in cryptocurrency per month through fake developers.

      Сообщение ZachXBT Infiltrated a Chinese Syndicate and Traced Lazarus Group Funds Worth More Than $1 Billion появились сначала на INCRYPTED.


      Source: Incrypted
      .

      Terra Founder Do Kwon Sentenced to 15 Years in Prison for Fraud