Onchain investigator ZachXBT spent $349,700 of his own funds while posing as a scammer on Telegram to infiltrate a Chinese OTC laundering network processing funds tied to North Korea and the $1.5 billion Bybit hack. Operating under the alias Jimmy Green, the primary launderer offered a 5% fee structure to clean stolen crypto while sharing detailed operational updates regarding DPRK state-backed hackers.
Infiltrating the Laundering Network on Telegram
In February 2025, ZachXBT identified more than 15 accounts seeking transaction assistance in public social groups following the Bybit exploit. One account, posting in THORChain's 10,845-member public chat, advertised illicit mixing services across BTC, ETH, SOL, and TRX using a Virginia-area US phone number. ZachXBT initiated a test order using marked Railgun funds, paying a 5% fee that yielded 23,750 USDT back on a $25,000 transfer.
During their conversations, "Jimmy Green" claimed his firm was China's largest coin-laundering operation and boasted of washing nearly all of the $1.5 billion stolen in ETH from Bybit. Jimmy provided real-time updates on North Korean operational delays, including instances where Kim Jong-un allegedly suspended operations or limited releases to 30 BTC out of a 50 BTC batch due to address tracking fears.
Tactical Intelligence and Asset Freezes
The undercover dialogue yielded actionable transaction intelligence before funds were moved. On March 12, 2025, Jimmy shared proof of bridging 1.192 BTC to ETH, matching a live THORChain transaction executed minutes later. Jimmy also disclosed three Solana wallet addresses that exposed a cluster holding over $12 million in Bybit proceeds, enabling Tether to freeze 442,000 USDT.
The operation also tied previous exploits to the syndicate, including 332,000 USDC linked to the 2024 Poloniex breach and $3 million routed through sanctioned Cambodian marketplace Huione Guarantee. Jimmy shared screenshots of wallets containing 1.2 million USDT alongside personal photos and offer details, including an available $1 million reserve for instant swaps. Similar public support inquiries were recently observed following the $387 million Bitget hack.
Key Takeaways
- ZachXBT allocated $349,700 of personal funds to track North Korean laundering channels.
- The syndicate claimed responsibility for washing $1.5 billion in stolen Bybit funds at a 5% cut.
- Intelligence led to Tether freezing 442,000 USDT and uncovered $12 million in tracked Solana assets.
- Over $75 million in DPRK-linked assets have been frozen through ZachXBT's efforts since 2022.
Why It Matters
This investigation highlights how major state-sponsored crypto exploits rely on surprisingly crude operational bottlenecks, such as public Telegram customer support chats. Even as laundering groups process hundreds of millions of dollars, human error and social engineering remain critical vulnerabilities in tracking cross-chain illicit flows. Building on previous investigations into Chinese OTC laundering syndicates, law enforcement relies heavily on independent researchers to map cross-chain bridges like THORChain and Railgun to mitigate persistent nation-state cyber threats.



