On-chain researcher ZachXBT revealed in an Oct. 5 disclosure that he successfully infiltrated a Chinese money-laundering network operating for North Korea's Lazarus Group. To gain access to the syndicate, which is alleged to have laundered over $1 billion across multiple crypto exploits, ZachXBT posed as an over-the-counter (OTC) client and fronted 349,700 USDC.
Posing as a Trading Counterparty
The undercover operation began following the Feb. 21, 2025 exploit of cryptocurrency exchange Bybit. ZachXBT identified roughly 15 accounts soliciting assistance with orders connected to stolen funds across public Telegram and Discord groups. He initiated contact with a user using the Telegram alias Jimmy Green.
To establish trust, ZachXBT funded a new Ethereum wallet with 349,700 USDC on March 6, 2025, executing multiple trades to exchange USDC on Ethereum for USDT on Tron. ZachXBT accepted a 5% loss per order during these transactions. As the relationship deepened, the contact disclosed upcoming movements of stolen funds and details regarding laundering operations based in Hong Kong and mainland China.
On March 12, 2025, the contact provided a screenshot of a cross-chain transfer that matched an order logged on the THORChain explorer within minutes. Further communications revealed three Solana addresses, exposing a wallet cluster responsible for moving more than $12 million in stolen Bybit funds across Bitcoin, Ethereum, Solana, and Tron. Subsequent intelligence led stablecoin issuer Tether to freeze 442,000 USDT connected to the wallet cluster.
Ties to Major Exploits and Law Enforcement Action
The syndicate's activities extended beyond Bybit. The contact referenced a previous fund freeze in 2024, which matched an on-chain freeze of 332,000 USDC linked to the Poloniex hack.
The FBI previously issued an alert on Feb. 26, 2025, stating that North Korean cyber actors stole approximately $1.5 billion in virtual assets from Bybit under the campaign name TraderTraitor. Federal authorities noted stolen assets were converted into Bitcoin and disbursed across thousands of wallets to evade tracking. Intelligence gathering regarding money laundering networks remains critical as international law enforcement scales up measures against state-sponsored crypto theft, mirroring actions like recent US Treasury sanctions on illicit crypto transfers.
Key Takeaways
- Undercover Access: ZachXBT fronted 349,700 USDC and paid 5% transaction fees to infiltrate the syndicate.
- Scope of Laundering: The Chinese syndicate processed over $1 billion for North Korea's Lazarus Group.
- Targeted Freezes: On-chain intelligence uncovered $12 million in Bybit stolen funds, resulting in 442,000 USDT frozen by Tether and earlier links to 332,000 USDC frozen from Poloniex.
Why It Matters
This investigation highlights a shift toward active, counterparty-level intelligence gathering by independent security researchers to uncover illicit OTC infrastructure. As state-sponsored syndicates utilize increasingly complex cross-chain bridges across Bitcoin, Solana, and Tron, private-sector and community-funded sleuthing serves as a vital first line of defense before institutional enforcement steps in. Continued grant funding for these high-risk operations will be essential to keeping pace with sovereign cybercrime networks.



