# The Undercover Investigation That Exposed a $12 Million Crypto Laundering Network Tied to North Korea
A pseudonymous blockchain investigator has revealed how he went deep undercover to infiltrate a Chinese-organized crime syndicate accused of laundering over $1 billion in stolen cryptocurrency on behalf of North Korea. The operation, which involved personally risking hundreds of thousands of dollars, reportedly led to the exposure of more than $12 million in funds tied to one of the largest crypto exchange exploits in history.
## Going Deep: An Investigator’s Gamble
The investigator, known in crypto circles as ZachXBT, says he stepped into the world of illicit finance by posing as a potential client of the laundering network. In early March 2025, he wired $349,700 in USDC — a stablecoin issued by Circle — to a wallet address controlled by someone he had identified on Telegram under the name “Jimmy Green.”
Rather than simply tracking the funds from the outside, ZachXBT decided to play along. He agreed to facilitate cryptocurrency swaps, each time accepting a 5% loss on every order. This calculated gamble was designed to build trust with the syndicate and gather actionable intelligence about how the stolen funds were being moved and laundered.
The risks were substantial. Not only was he risking nearly $350,000 of his own money with no guarantee he would recover it, but he was also exposing himself to potential retaliation from an organized crime network. Despite these dangers, he persisted.
## Mapping the Network
Jimmy Green was eager to find new clients. On March 10, 2025, he kept reaching out to ZachXBT’s fake persona, eventually revealing that his team had $1 million ready to begin operations at a moment’s notice. Through these conversations, ZachXBT learned details about the syndicate’s internal operations, including their division of labor and how they routed stolen stablecoins — abbreviated as “USDT” in their shorthand — through a network of intermediaries.
The operation was based out of Hong Kong and mainland China, according to the messages exchanged between the two parties. Jimmy discussed everything from business operations to personal life, including hobbies like playing mahjong and hunting wild rabbits, as well as more mundane topics like food and family vacations.
## Tracing $12 Million in Stolen Funds
The breakthrough came on March 12, 2025. ZachXBT matched a screenshot Jimmy sent of himself bridging funds to a cryptocurrency swap, cross-referencing the transaction details with the Thorchain explorer — a public ledger that tracks decentralized cross-chain swaps. By analyzing the timing and amounts, he confirmed Jimmy was actively moving the funds in real time.
Jimmy then shared three Solana wallet addresses, which ZachXBT used to trace a cluster of over $12 million in stolen cryptocurrency. The funds had been moved through a dizzying sequence of blockchains — hopping from Bitcoin to Ethereum to Solana and finally to Tron — in an attempt to obscure their origin.
These funds were traced back to the February 2025 Bybit exploit, a hack that caused approximately $1.5 billion in losses to the crypto exchange. The U.S. Federal Bureau of Investigation attributed the attack to a North Korean hacking operation it tracks under the name TraderTraitor. ZachXBT’s research further linked the wallets used to launder the Bybit funds to earlier attacks on exchanges including Phemex and BingX.
Following the investigation, Tether, the company behind the USDT stablecoin, froze 442,000 USDT tied to the laundering cluster.
## A Broader Pattern of North Korean Activity
ZachXBT says the Bybit case was not an isolated incident. The same patterns he observed in the Bybit investigation reappeared shortly after the $387 million Bitget hack, which Bitget’s CEO and blockchain tracing firms Elliptic and Chainalysis also attributed to North Korean actors.
Since 2022, ZachXBT says he has helped facilitate more than $75 million in freezes connected to incidents tied to the Democratic People’s Republic of Korea (DPRK). His findings are shared directly with private-sector investigators and the law enforcement teams assigned to each case.
The Bybit connection also linked back to the Lazarus Group, a notorious North Korean state-sponsored hacking collective. On the day of the Bybit exploit, ZachXBT used on-chain data to connect the attack to Lazarus Group, and the FBI backed that attribution within days. His work also revealed that wallets used to launder the Bybit funds were tied to previous Lazarus operations, including the Phemex and BingX hacks.
In 2024, his tracing efforts contributed to the arrest of individuals connected to the theft of roughly 4,100 BTC from a Genesis creditor. More broadly, his work has been credited with helping return more than $350 million to victims of crypto hacks and scams.
## The Cambodia Connection
Beyond the Bybit-linked laundering, Jimmy Green also revealed that he had helped launder $3 million in fraud proceeds for a different client. ZachXBT traced those funds to a hot wallet associated with Huione Guarantee, a Telegram-based marketplace where criminals could purchase laundering services and stolen data.
Huione Guarantee is part of Huione Group, a Cambodian conglomerate that the U.S. Treasury’s Financial Crimes Enforcement Network (FinCEN) targeted for allegedly facilitating the laundering of at least $4 billion. In May 2025, Telegram banned the marketplace entirely. Chinese authorities later arrested former Huione Group chairman Li Xiong following his deportation from Cambodia.
## How One Investigator Funds a One-Man War on Crypto Crime
Unlike many on-chain analysts who operate from the sidelines, ZachXBT has chosen a path that requires significant personal financial risk. He says the operation to infiltrate the Chinese syndicate was funded out of his own pocket, with no external backing for this particular case.
His work is not entirely self-funded, however. He notes that grants from foundations and donations from individuals have allowed him to take on riskier investigations that would otherwise be impossible. In February 2025, the venture capital firm Paradigm hired him as an incident response advisor, lending additional institutional support to his efforts.
The decision to go undercover was not made lightly. “I had to continue losing 5% per order and gamble on capturing as much actionable intel as quickly as possible,” he wrote.
The sensitivity of the investigations also means that findings are not always published immediately. ZachXBT said operational security and the need to protect ongoing law enforcement efforts kept him from sharing details sooner.
## A New Model for Crypto Accountability
ZachXBT’s approach represents a departure from traditional on-chain analysis. Rather than simply publishing findings for the public and law enforcement to discover independently, he actively inserted himself into criminal networks to gather direct evidence. The result was a level of detail — including specific wallet addresses, operational timelines, and insider details about the syndicate’s structure — that most blockchain researchers never achieve.
His work highlights both the power of public blockchain data and the lengths to which bad actors will go to obscure their financial trails. Despite the cross-chain hopping and complex laundering techniques, every transaction left a permanent record on a public ledger that could ultimately be traced and frozen.
## Frequently Asked Questions
**Who is ZachXBT?**
ZachXBT is a pseudonymous on-chain investigator who has spent years tracing stolen cryptocurrency and attributing hacks to their perpetrators. He operates primarily on social media platforms where he publishes detailed threads analyzing blockchain data.
**What was the Bybit exploit?**
The Bybit exploit was a hack that occurred in February 2025 and resulted in approximately $1.5 billion in losses for the cryptocurrency exchange Bybit. The FBI attributed the attack to TraderTraitor, a North Korean hacking group.
**Why did ZachXBT lose 5% on each transaction?**
The 5% loss per order was the cost ZachXBT accepted as part of his undercover operation. By agreeing to facilitate cryptocurrency swaps at a slight loss, he was able to build credibility with the laundering network and gather intelligence about how stolen funds were being moved.
**How did ZachXBT identify the laundering network?**
ZachXBT identified patterns of accounts requesting help with orders that were directly tied to stolen Bybit funds on public messaging platforms like Telegram and Discord. He then infiltrated the network by posing as a client willing to facilitate swaps.
**What happened to the frozen funds?**
Tether froze 442,000 USDT linked to the laundering cluster. The U.S. Treasury’s FinCEN also targeted Huione Group, the Cambodian conglomerate connected to the laundering operations, for facilitating the laundering of at least $4 billion.
**What is the Lazarus Group?**
The Lazarus Group is a North Korean state-sponsored cybercrime organization responsible for numerous high-profile hacks and cryptocurrency thefts over the past several years. It is tracked by the FBI and other international law enforcement agencies.
**How is ZachXBT funded?**
ZachXBT funds his work through a combination of personal savings, grants from foundations, and donations from individuals. He was also hired by Paradigm as an incident response advisor in February 2025.
**What is Huione Guarantee?**
Huione Guarantee was a Telegram-based marketplace where criminals could purchase money laundering services and stolen data. It was part of Huione Group, a Cambodian conglomerate sanctioned by the U.S. Treasury’s FinCEN. The platform was banned by Telegram in May 2025.
**Has ZachXBT’s work led to arrests?**
Yes. In 2024, his tracing of roughly 4,100 BTC stolen from a Genesis creditor contributed to arrests. He has also helped facilitate more than $75 million in freezes related to North Korean incidents since 2022.
**Is it dangerous to do this kind of work?**
ZachXBT has acknowledged significant personal risk, including a previous lawsuit and doxing campaign against him in 2023 by a former target of his investigations. His undercover operations involve direct engagement with organized crime networks, adding further layers of danger.
## Conclusion
The investigation led by ZachXBT demonstrates the evolving nature of cryptocurrency crime and the equally evolving tactics used to combat it. By going undercover and personally fronting hundreds of thousands of dollars in stolen funds, he was able to uncover a sophisticated laundering network with ties to North Korean state-sponsored hackers and Chinese organized crime.
The operation exposed over $12 million in Bybit exploit funds, resulted in the freezing of hundreds of thousands of dollars in stablecoins, and revealed connections to other major crypto hacks and a sprawling Cambodian laundering operation. His work underscores the importance of on-chain transparency and the critical role that individual investigators can play in the broader fight against cryptocurrency-enabled crime.
The case also raises important questions about the balance between public disclosure and operational security, the personal risks that crypto investigators face, and the ongoing challenge of holding both hackers and their launderers accountable in a borderless digital financial system.
Thank you for reading



