Blockchain investigator ZachXBT has detailed an undercover operation that linked funds from the Bybit hack to a laundering network. As of early October 2026, he described spending $349,700 to pose as a client of an alleged Chinese organized crime syndicate. The group was said to have moved more than $1 billion across exploits for North Korea-linked actors, including proceeds from Bybit’s approximately $1.5 billion theft in February 2025. The work helped map specific on-chain clusters and contributed to asset freezes.
The investigation continues to inform attribution efforts. It has restricted public disclosure until the case was no longer active. Existing law-enforcement and private-sector probes remain separate. ZachXBT relies partly on direct interaction combined with blockchain analysis while routing findings through shared intelligence channels. This highlights the difference between pure on-chain tracing and human-sourced operational intelligence.
The Drivers of the Current Situation
The main issue is the post-hack laundering of Bybit funds attributed to Lazarus Group’s TraderTraitor cluster. Shortly after the February 2025 breach, ZachXBT observed multiple accounts seeking assistance with transactions tied to the stolen assets. No single public trail fully exposed the intermediaries at the time. He initiated contact with an operator using the alias “Jimmy Green.”
The investigator has limited the disclosed methods to building trust through repeated trades. Some interactions involved accepting losses to establish credibility. On March 6, 2025, he funded a fresh Ethereum address with 349,700 USDC. Subsequent messages produced wallet details, screenshots of swaps, and advance information on fund movements. These were matched against public transactions, including THORChain activity that traced back to Bybit-linked addresses. Three Solana addresses revealed a cluster holding more than $12 million in related funds moving across Bitcoin, Ethereum, Solana, and Tron. Only the combination of chat intelligence and on-chain verification produced the attribution. Tether later froze approximately 442,000 USDT connected to the cluster.
A complete picture requires ongoing monitoring of remaining flows. Limited freezes under a multi-billion-dollar theft form a narrower path. Independent investigators and agencies are actively examining related activity. The situation is a hybrid forensic challenge tied to cross-chain obfuscation techniques.
Impact and Broader Context
Questions about how ZachXBT traced Bybit hack funds to a Lazarus-linked network keep growing. The undercover approach creates uncertainty around the full scale of the syndicate’s role. It also affects strategies for disrupting state-linked laundering operations. Security researchers, exchanges, and law enforcement continue to study the disclosed methods and addresses.
The issue drives debate on cryptocurrency crime investigation. It raises questions about how effectively human intelligence complements blockchain analytics, the limits of voluntary freezes by issuers, risks to investigators conducting undercover work, effects on future attribution of North Korean activity, and competition between independent researchers and formal agencies. Stakeholders stress that the operator’s claims about handling most of the Bybit proceeds have not been independently confirmed. ZachXBT says the intelligence assisted freezes and on-chain attribution while the case remained active.
The delayed public disclosure forced renewed attention onto the 2025 Bybit incident nearly two years later. The current review shows how hybrid investigative techniques will influence responses to similar large-scale thefts.
New freezes, additional wallet linkages, or official statements will clarify the extent of the network and any further recoveries.
This analysis uses ZachXBT’s public thread, supporting on-chain reports, and related coverage. Attribution details and recovery outcomes remain subject to ongoing investigation and possible further developments.
