Onchain researcher ZachXBT deployed 349,700 USDC of his own capital in an undercover operation to expose a Chinese illicit finance ring, tracing over $12 million tied to the $1.5 billion Bybit hack executed in February 2025 by North Korea's Lazarus Group.
His investigation provided crucial transaction intel that contributed to Tether freezing 442,000 USDT linked to the cyberheist.
Undercover Infiltration of the Lazarus Laundering Ring
Following the Bybit breach, the FBI formally attributed the attack on February 26, 2025, designating the threat activity as TraderTraitor. Federal authorities warned that the hackers were swapping stolen assets into Bitcoin and distributing them across thousands of temporary addresses.
While public tracking mapped the initial movement, identifying the illicit broker networks required direct interaction. ZachXBT spotted more than 15 accounts across Telegram and Discord actively offering laundering services for the stolen funds. He established contact with an operational broker using the Telegram alias Jimmy Green.
On March 6, 2025, ZachXBT funded a fresh Ethereum address with 349,700 USDC, converting the funds into USDT on Tron through the intermediary. He accepted a fixed 5% loss per completed order to build transaction history and gain access to high-level information. During these interactions, the intermediary disclosed incoming off-chain actions before execution, such as transferring funds to Solana. The investigation ultimately uncovered a Chinese laundering syndicate that had processed over $1 billion in stolen crypto for Lazarus Group.
Sanctions Evasion and Black-Market Off-Ramps
The operation underscores how cybercriminals rely on underground marketplaces to convert digital assets into fiat currency. In September, the US Treasury sanctioned Xinbi Guarantee, a dark-market platform that has processed over $24 billion in digital assets and fiat currency since 2022. Treasury officials revealed that illicit networks migrated to Xinbi Guarantee after law enforcement targeted Huione, illustrating the resilience of black-market financial rails.
The findings build on broader actions against illegal transaction networks, such as when the UK sanctioned platforms like Cryptomus and TokenSpot or when asset freezes occurred after major breaches where Tether freezes stolen USDT to restrict hacker liquidity.
Key Takeaways
- $1.5 Billion Stolen: Bybit suffered a massive exploit in February 2025, linked by the FBI to North Korea's TraderTraitor (Lazarus Group).
- $349,700 USDC Committed: ZachXBT funded transactions on March 6, 2025, taking 5% losses to infiltrate Telegram intermediary Jimmy Green.
- $12M+ Traced, 442K USDT Frozen: The undercover probe exposed a syndicate handling $1 billion+ in illicit funds and led to Tether freezing 442,000 USDT.
- $24 Billion Marketplace Sanctioned: US Treasury hit Xinbi Guarantee in September after illicit volume migrated from Huione.
Why It Matters
While smart contract exploits and exchange breaches capture headlines, off-ramping stolen crypto into usable fiat remains the primary bottleneck for state-sponsored cybercrime groups. ZachXBT's investigation highlights that pure blockchain analytics must be coupled with human intelligence to expose dark-market over-the-counter (OTC) operations.
As regulatory authorities target platforms like Xinbi Guarantee and Huione, central issuers and exchanges face mounting pressure to implement rapid, automated freezing mechanisms to prevent stolen funds from exiting through cross-chain bridges.



