Investigator Uncovers Crypto Network Tied to Lazarus Group
An independent blockchain investigator known as ZachXBT has successfully infiltrated a cryptocurrency laundering operation tied to the notorious Lazarus Group following the significant $1.5 billion hack on the Bybit exchange. His investigation sheds light on the methods used by hackers to circulate stolen assets.
Unveiling the Laundering Operations
Through a combination of private conversations and public blockchain data, ZachXBT claims to have traced over $1 billion in laundered funds across various hacks. Although this figure is his estimate, it highlights the vast scale of activities connected to these illicit networks. His findings have been instrumental in freezing stolen assets and exposing operators claiming ties to major thefts.
Infiltration Tactics and Findings
Posing as a potential client, ZachXBT entered Telegram and Discord groups where he identified more than 15 accounts linked to the Bybit hack. In March 2025, he created a new Ethereum wallet and strategically exchanged USDC for USDT, incurring minor losses to gain trust within the network. This infiltration allowed him to gather critical information from an operator known as “Jimmy Green,” who alleged that his team processed the majority of stolen assets from Hong Kong and mainland China.
Linking Chats to Blockchain Transactions
By matching the operator’s claims with blockchain records, ZachXBT demonstrated how Jimmy’s wallet received funds from an address associated with the Bybit theft. Further evidence was provided through screenshots that aligned with timing and amounts of THORChain transfers. This meticulous work enabled him to identify wallet clusters involving over $12 million in stolen funds and resulted in Tether freezing 442,000 USDT related to these activities.
The Federal Bureau of Investigation previously attributed the Bybit theft to North Korean entities, labeling the operation as TraderTraitor. Their advisory highlighted the dispersion of stolen assets across thousands of blockchain addresses, emphasizing the complexity of tracking these funds.
Implications and Future Outlook
ZachXBT’s efforts have reportedly led to the freezing of more than $75 million linked to North Korean cyber activities since 2022. Despite these successes, the recovery of stolen assets remains a challenging endeavor. The investigator’s work underscores the importance of patient undercover operations, detailed blockchain analysis, and prompt dissemination of information to prevent further movement of illicit funds. The case exemplifies how individual dedication can significantly impact the fight against cybercrime.
