Blockchain investigator ZachXBT says he infiltrated a Chinese-language cryptocurrency laundering network that handled funds connected to the February 2025 theft from Bybit, tracing the group’s activity to wallets associated with North Korea’s Lazarus Group and helping freeze part of the proceeds.
The investigation offers a rare view of how alleged laundering brokers operate through public Telegram and Discord channels: advertising swaps, directing customers to wallet addresses, and moving value through several blockchains quickly enough to complicate tracing. ZachXBT said he shared his findings with private-sector investigators and relevant law-enforcement agencies after conducting a series of test transactions with the group.
According to ZachXBT, the operation began when he noticed more than 15 accounts in public chat groups requesting customer support for transactions directly tied to funds stolen from Bybit. The accounts appeared after the hack attributed to “TraderTraitor,” a designation used by U.S. authorities for North Korea-linked activity.
He contacted several of the accounts and eventually established communication with a Telegram user calling himself “Jimmy Green,” using the handle long_991 and Telegram ID 7635649994.
Test swaps exposed links to Bybit funds
On March 6, 2025, ZachXBT said he funded a fresh Ethereum wallet with 349,700 USDC to conduct controlled transactions. He said Green offered to receive USDC on Ethereum and return USDT on the TRON network, a cross-chain service commonly used by brokers seeking to move stablecoin value between networks.
The Ethereum address supplied by Green was 0xbaa551da0ae0c93025d9a983a68025a27dc15337, while the TRON receiving address was TPwXAPwYaDCm7GrzNFiMmNnofrxEVURXRM.
ZachXBT said the Ethereum wallet used by Green received gas funding from an address beginning with 0xbcb4. That funding address, he said, could be traced to Bybit theft proceeds and had already appeared on a public blacklist tracking wallets associated with the incident.
Rather than ending the contact after the initial transfer, ZachXBT said he continued making transactions with the group, accepting a 5% loss on each order in order to gather further evidence. He identified additional addresses used in the dealings, including Ethereum address 0x1893ef01e700b1359280e11736d1b89fe97ed216 and TRON addresses TS5hY6mm6UsCLNdVDWnsRA69LuAwfdn158 and TMGjdFeBf9T6kGB9ZmLzeaAPYWBokuyTuS.
The arrangement points to a laundering model built around apparent convenience. A customer who wants stablecoins on a different chain can use a broker instead of navigating a bridge or regulated service. For a criminal group, that same process can obscure the trail by splitting transfers across networks and counterparties.
Advance transaction details matched on-chain activity
ZachXBT said Green began sharing details about future movements of funds associated with the Bybit theft, including intended transfers to Solana. He said the transfers subsequently appeared on-chain in patterns consistent with the information he had received.
Green claimed the group processed most of the roughly $1.5 billion taken from Bybit, according to ZachXBT. That claim cannot independently establish the full scale of the group’s role, but the investigator said its advance transaction information repeatedly matched blockchain activity.
One example came on March 12, 2025, when Green allegedly sent a screenshot of a cross-chain transfer. ZachXBT matched it to an order created minutes later using the timing and amount shown on THORChain’s public explorer. He identified the transaction as 81a85130b36057428e64b6f97215f77b5a197776a8f1b3a61c8cd0ee1ebfa8c1.
The exchanges also produced three Solana addresses that ZachXBT said helped identify a cluster holding or processing more than $12 million in Bybit-linked stolen funds:
9gSwa2Mew9P21Wxs8nFgDujTurKZx1nBEVRv6K5sJP6eEvZJGsDymrSUQyF23HLKEgUpjfd9XN1GTmm8AG6pFS7H8S6T5gL2w5z4M9TCehMgQjxVm3Q6R7WDHp6WFfbtZSAy
ZachXBT said the cluster moved assets in a rapid sequence across Bitcoin, Ethereum, Solana and TRON: BTC to ETH, ETH to SOL, and SOL to TRON. Shifting assets across several ledgers can slow investigations because analysts must map wallet ownership and transaction relationships separately on each network.
Tether later froze 442,000 USDT associated with the cluster at Ethereum address 0x652d7f9edaaa8891be2de74ea568d70af823d89e, according to ZachXBT.
Illiquid tokens added another laundering route
The investigation also described the use of illiquid tokens in Uniswap liquidity pools. In such a scheme, a wallet can trade through an obscure token pool with limited normal market activity, creating a harder-to-follow path between the original asset and the eventual proceeds.
ZachXBT said Green referenced an earlier case from 2024 in which about $300,000 had been frozen. His own on-chain review identified 332,000 USDC linked to funds from the Poloniex theft.
Green also described laundering $3 million from a separate scam for another client, ZachXBT said. The investigator traced those funds to a Huione Guarantee hot wallet. That detail suggests the alleged network did not operate solely for North Korea-linked actors, but may have functioned as a service provider for multiple types of cybercrime proceeds.
A public-channel laundering market
The case challenges the assumption that cryptocurrency laundering requires hidden infrastructure or private access. ZachXBT’s account describes brokers advertising or responding to requests in public chat communities, then shifting to direct messages to coordinate addresses, amounts and chain preferences.
That visibility creates an opening for blockchain investigators, but only when chat intelligence can be connected to on-chain records. Wallet funding, timing, transaction amounts, cross-chain routes and repeated counterparties formed the basis of ZachXBT’s assessment, rather than a single address or a broker’s claims.
ZachXBT said he personally fronted 349,700 USDC during the operation. He also said he has helped freeze more than $75 million tied to North Korea-linked hacking cases since 2022.
The Bybit-related findings show how stablecoin swaps and cross-chain services can turn public chat groups into a practical layer of laundering infrastructure. Freezing 442,000 USDT did not resolve the larger theft, but it demonstrates that wallet tracing can still produce actionable intervention when investigators identify funds before they are dispersed through more intermediaries.
For deeper context on hacks, regulations, and safety, explore our guide on crypto crime trends and key tips for traders.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
