ZachXBT spent $349,700 of his own money to go undercover inside a crypto laundering ring.

The on-chain sleuth says he posed as a client of a Chinese network that, by his count, has laundered more than $1 billion across multiple hacks for North Korea's Lazarus Group, including funds from the $1.5B Bybit hack in February 2025.

How he did it:
- He noticed 15+ accounts in Telegram and Discord groups asking for help moving funds tied to the Bybit exploit.
- He funded a fresh Ethereum address with 349,700 USDC and placed orders with a vendor using the name "Jimmy Green".
- He accepted roughly 5% losses on each order to look credible and watch how the network handled dirty money.

What came out of it: a cluster holding more than $12M linked to the Bybit hack, and $442,000 in USDT frozen.

Now the part worth keeping in mind. As of Oct 6, public releases from the FBI, US Treasury and Tether don't name "Jimmy Green" or confirm that one Chinese network moved $1B+ for Lazarus, and no charges or court filings identify the operator. This is a strong investigation, not a verdict.

It still says a lot. A single independent researcher, with his own money, got closer to the laundering pipeline than most official statements show. And the pipeline he describes runs through ordinary chat apps and OTC desks, not some hidden dark web.

The uncomfortable math: $442K frozen against $1B+ alleged laundered. Tracing works. Recovering is another story.

Should exchanges and stablecoin issuers be moving this fast on their own, without waiting for law enforcement?

Like and follow for more on-chain investigations explained simply.

#Lazarus #Bybit