Blockchain investigator ZachXBT disclosed on October 5 that he spent approximately $3.5 million of his own money, around $3.497 million in USDC, to pose as a client of a Chinese money-laundering network believed to be working on behalf of North Korea's Lazarus group. The operation was aimed at tracing funds stolen in the February 21, 2025 hack of exchange Bybit, one of the largest crypto thefts on record at roughly $1.5 billion.

According to ZachXBT, the infiltration involved direct exchanges with an intermediary operating under the pseudonym Jimmy Green. To maintain cover and gather intelligence on how the network moved money, the investigator accepted losses of around 5% on each transaction processed through the operation.

Addresses linked to stolen funds

The work led ZachXBT to identify a set of addresses on the Solana blockchain connected to more than $12 million in funds originating from the Bybit hack. Separately, stablecoin issuer Tether froze about 442,000 USDT tied to the investigation.

ZachXBT said the information gathered during the infiltration was passed on to private investigators and law enforcement agencies.

A hack attributed to North Korea

The Bybit theft, which took place on February 21, 2025, prompted a swift response from US authorities. Five days after the attack, the FBI publicly attributed it to North Korea, designating the malicious activity under the name TraderTraitor. The bureau described how the stolen funds were rapidly converted into bitcoin and other cryptocurrencies and dispersed across thousands of addresses spanning multiple blockchains, a pattern consistent with previous laundering operations linked to North Korean state-sponsored hacking groups.

For European exchanges and compliance teams, the case underscores the scale of resources now being devoted to tracking state-linked laundering networks, and the extent to which private investigators are operating alongside, and sometimes ahead of, formal law enforcement channels in pursuing funds stolen from crypto platforms.