Culture

ZachXBT Fronted $350K to Infiltrate Lazarus Group's Chinese Laundering Syndicate

ZachXBT funded a new Ethereum wallet with 349,700 USDC on March 6, 2025, posed as a paying customer of a Chinese crime syndicate he alleges laundered $1B+ for Lazarus Group, and held the story for 18 months while the case was still live.

5 min read
A lone analyst's hands hover over a glowing laptop keyboard in a dim room, surrounded by scattered printouts covered in flowchart diagrams and highlighted transaction trails, a half-empty
Share

One pseudonymous investigator, no badge, no subpoena power, and 349,700 USDC of his own money did what exchange compliance desks couldn't.

Key takeaways

  • ZachXBT funded a new Ethereum wallet with 349,700 USDC on March 6, 2025, posing as a paying client of a Chinese crime syndicate he alleges laundered over $1 billion across multiple Lazarus Group exploits, absorbing a 5% loss per order to maintain cover.
  • His intelligence helped expose a $12M+ cluster of funds tied to the February 2025 Bybit hack and contributed to Tether freezing 442,000 USDT linked to that cluster.
  • ZachXBT held the thread for 18+ months while the case was live, publishing the full 12-part account on October 5, 2026, on X.

ZachXBT, the pseudonymous on-chain investigator and Paradigm Incident Response Advisor, published a 12-part thread on October 5, 2026, detailing how he spent months embedded as a paying customer inside a Chinese organized crime network he alleges processed over $1 billion in stolen cryptocurrency for North Korea's Lazarus Group. The operation, which began in early March 2025, produced a mapped $12M+ fund cluster, a 442,000 USDT freeze by Tether, and an on-chain attribution trail connecting the syndicate directly to the February 2025 Bybit hack.

"How I infiltrated a Chinese organized crime syndicate that has laundered $1B+ across multiple exploits for Lazarus Group. Posing as a client, I gathered intel that helped action freezes for the Feb 2025 Bybit exploit and attribute illicit activity onchain," ZachXBT wrote in the opening post of the thread.

How the Operation Worked

On March 6, 2025, ZachXBT funded a fresh Ethereum wallet (address: 0x073256b50d66a7eb005f2a504d0a4fb6ea62a276) with 349,700 USDC and began transacting with a Telegram operator using the alias "Jimmy Green" (handle: long_991, Telegram ID: 7635649994). He accepted a 5% loss on every order. At that rate, across 349,700 USDC, the direct cost of maintaining cover ran to roughly $17,485 in absorbed losses, paid out of his own pocket with no institutional backstop.

ZachXBT reports that Jimmy claimed his team operated from Hong Kong and mainland China and had processed "most" of the stolen Bybit assets. These are ZachXBT's accounts of private conversations, not independently verified statements. The syndicate was also linked, per ZachXBT's thread, to laundering approximately $3 million in fraud proceeds for other clients, with wallet trails connecting to addresses associated with Huione Guarantee, the Southeast Asian illicit-finance marketplace flagged by FinCEN.

The on-chain link to Bybit's loot was not circumstantial. Jimmy Green's receiving wallet received gas from an address on the public Bybit exploit blacklist, a verifiable, chain-native connection to the $1.5 billion hack the FBI attributed to the Lazarus-linked TraderTraitor group. That gas transaction was the thread that unraveled the $12M+ cluster.

Tether subsequently froze 442,000 USDT tied to the identified addresses. ZachXBT says he shared intelligence with private-sector investigators and law enforcement throughout; no agency has issued a public confirmation of its involvement or confirmed that his intel drove the freeze.

What Compliance Apparatus Missed

The Bybit hack is the largest crypto theft on record at approximately $1.5 billion, primarily in ETH. It was attributed to a state-sponsored actor. Every major exchange held or processed funds that passed through Lazarus Group pipelines in its aftermath.

The syndicate ZachXBT infiltrated was not operating in the shadows of some dark-web marketplace. It advertised through public Telegram and Discord support channels. Fifteen-plus accounts filed open support tickets. The laundering infrastructure was visible to anyone looking.

No exchange compliance team caught it from that same public information. A pseudonymous individual with a $350K stake and internet access did.

Custodial compliance regimes are built for regulatory defensibility, not real-time intelligence. They answer to audit committees, not blockchain explorers. The result is a gap that one person with chain-native methodology closed faster and more precisely than the institutional apparatus surrounding the same stolen funds.

The mechanism that made it possible is the same property critics frame as a privacy threat: every transaction is public. ZachXBT could map the $12M+ cluster, verify Jimmy's wallet against the public Bybit blacklist, and hand Tether actionable addresses precisely because the ledger is open.

The FinCEN surveillance rules that regulators have pushed against self-custody and on-chain privacy tools would have added friction to the investigator, not the launderer.

ZachXBT also reported that he had no guarantee Jimmy wouldn't disappear with the funds and acknowledged an unknown amount of personal risk from dealing with the syndicate directly. That risk was uncompensated. No agency cut a check. He also claims to have helped action $75 million or more in total freezes tied to North Korean incidents since 2022, a figure attributed to him and unconfirmed by any government body.

The Huione Guarantee connection is worth pausing on. The syndicate was not a single-client shop serving only Pyongyang. It was shared infrastructure, processing Lazarus Group loot alongside fraud proceeds from other criminal operations.

That model, one laundering network serving multiple criminal clients across jurisdictions, is the adversary the compliance industry has no coherent framework for. The Chinese state hacking coverage that has dominated the threat landscape focuses on intrusion. The laundering layer that converts those intrusions into spendable fiat has gotten far less structural attention.

What to Watch

The 442,000 USDT freeze is confirmed. Whether additional freezes or enforcement actions follow from the intelligence ZachXBT shared with law enforcement remains unannounced.

If a government agency publicly confirms its involvement or discloses that ZachXBT's intel contributed materially to a broader action, the thesis that pseudonymous chain-native investigators are structurally more effective than custodial compliance in real-time interdiction gets considerably harder to argue against. If it emerges that Bybit's or another exchange's internal team identified and froze the specific cluster before ZachXBT's intel reached Tether, or that a sealed government investigation was already running in parallel, the picture changes.

Watch for agency statements, additional Tether or Circle freeze disclosures tied to the 0x073256b50d66a7eb005f2a504d0a4fb6ea62a276 cluster, and any follow-on legal action touching the Jimmy Green network.

Sources

Frequently Asked Questions

How did ZachXBT confirm that "Jimmy Green" was connected to the actual Bybit hack funds?

The connection was on-chain. Jimmy Green's receiving wallet received gas from an address already on the public Bybit exploit blacklist, a publicly verifiable transaction linking the syndicate's operational wallet to the documented theft. ZachXBT then mapped a $12M+ cluster of Bybit-linked funds moving through the syndicate's infrastructure, and that cluster became the basis for Tether's 442,000 USDT freeze.

Why couldn't exchange compliance teams catch this when the syndicate was advertising openly in public Telegram and Discord channels?

Custodial compliance is built around regulatory requirements and audit processes, not active on-chain intelligence. Filing suspicious activity reports, running KYC on account holders, and responding to law enforcement subpoenas are the actual outputs of a compliance department. None of those workflows are designed to monitor a public Telegram channel advertising laundering services and cross-reference its operator's wallet against a public hack blacklist in real time. ZachXBT operated with chain-native methodology and no institutional constraints. That is a structural difference, not a resource one.

What is Huione Guarantee and why does its connection to this syndicate matter?

Huione Guarantee is a Southeast Asian online marketplace FinCEN has identified as a major node in illicit finance, facilitating scam infrastructure, money laundering, and fraud-proceeds processing across the region. Its appearance in ZachXBT's thread means the syndicate he infiltrated was not solely a DPRK-serving operation. It was shared criminal infrastructure, routing Lazarus Group's state-sponsored theft proceeds on the same rails used for Southeast Asian fraud operations. That shared-infrastructure model significantly expands the threat surface beyond any single nation-state actor.

News and analysis, not financial, investment, legal, or tax advice. Figures and quotes are verified against primary sources where possible. See our editorial and financial disclosures.

Keep reading

All of TFTC

The Commoner

Truth for the Commoner, every weekday. Money, machines, and the people trying to control both.

Independent writing by Marty Bent at TFTC since 2017. Money, markets, AI, energy and privacy, delivered free to your inbox.

Free, every weekday. Unsubscribe anytime using the link in each newsletter. By subscribing you agree to our Terms and acknowledge our Privacy Policy. Read recent issues.