He spent $350,000 of his own money posing as a client—and got inside a North Korean hackers’ laundering pipeline 🦖
🤔 有想法进群聊
On October 5, on-chain investigator ZachXBT revealed that on March 6, 2025, he sent 349,700 USDC to an Ethereum address, posing as a client of a money-laundering operation. He even willingly took a 5% loss on every transaction, just to track in real time where $1.5 billion in stolen funds was going. The part he didn’t spell out is even more serious: he might never get the money back, and he could end up being targeted.
First, some background. In February 2025, a major exchange was hacked for around $1.5 billion. The FBI pointed the finger at a North Korean hacking group codenamed TraderTraitor. Soon after the attack, ZachXBT noticed something unusual: more than 15 accounts were openly soliciting business in public Telegram and Discord groups, offering to process transactions involving funds stolen in the hack. The people moving the stolen money weren’t even hiding.
He didn’t just watch the data from the sidelines—he got involved. His contact went by the name “Jimmy Green.” ZachXBT started with a few small transactions to build trust. Then Jimmy began sharing information about where the funds would move in advance: he said they’d be sent to Solana on a certain day, and the next day, the money really did arrive on Solana. The definitive confirmation came on March 12, 2025: Jimmy sent a screenshot of a cross-chain transaction, and ZachXBT matched it to an order that had been created minutes earlier using the amount and timestamp on Thorchain’s public explorer.
The clues began to connect. 💰 Jimmy provided three Solana addresses, which led to a cluster of stolen funds worth more than $12 million. The funds were being moved in real time between Bitcoin, Ethereum, Solana, and TRON. Tether later froze 442,000 USDT from the cluster. Jimmy also mentioned that the team had around $300,000 frozen in 2024. ZachXBT’s on-chain investigation identified the actual figure as 332,000 USDC, linked to a November 2023 theft worth more than $100 million—another clue pointing to the same group. Following the $3 million in scam proceeds Jimmy said he had handled, ZachXBT also traced the money to an old marketplace’s hot wallet on Telegram. The marketplace specialized in this kind of business and also sold data. The group behind it was implicated in at least $4 billion in activity by the U.S. FinCEN, and Telegram banned it in May 2025. ⚖️
This wasn’t an isolated case. In September 2026, another exchange was hacked for around $387 million, and the same playbook played out again. ZachXBT says that since 2022, he has helped freeze more than $75 million in funds linked to North Korea. A co-founder of Paradigm has also said publicly that he helped victims of hacks and scams recover more than $350 million.
My take: the most valuable thing in this story isn’t the plot—it’s the cost structure. On-chain investigations are never free. He had to front the money himself, lose 5% on every transaction, and risk having the funds swallowed up or putting his personal safety in danger. Anonymity is basically just a pane of glass in the face of on-chain records and social engineering. What’s truly rare is someone willing to put real money on the line to shatter it.
One contrasting detail to end on: in their chats, Jimmy also talked about mahjong, hunting rabbits, weight-loss meals, and taking his family to Disneyland. On one side, billions in stolen money; on the other, the ordinary details of everyday life. These networks have never been as far removed from ordinary people as they might seem.
What do you think? Is it worth spending your own money to get directly involved like this?
Every day, I bring you the latest in crypto—not just what’s happening, but the logic and opportunities behind it 👀🚀
Tap the profile picture to watch the livestream
🤔 有想法进群聊
On October 5, on-chain investigator ZachXBT revealed that on March 6, 2025, he sent 349,700 USDC to an Ethereum address, posing as a client of a money-laundering operation. He even willingly took a 5% loss on every transaction, just to track in real time where $1.5 billion in stolen funds was going. The part he didn’t spell out is even more serious: he might never get the money back, and he could end up being targeted.
First, some background. In February 2025, a major exchange was hacked for around $1.5 billion. The FBI pointed the finger at a North Korean hacking group codenamed TraderTraitor. Soon after the attack, ZachXBT noticed something unusual: more than 15 accounts were openly soliciting business in public Telegram and Discord groups, offering to process transactions involving funds stolen in the hack. The people moving the stolen money weren’t even hiding.
He didn’t just watch the data from the sidelines—he got involved. His contact went by the name “Jimmy Green.” ZachXBT started with a few small transactions to build trust. Then Jimmy began sharing information about where the funds would move in advance: he said they’d be sent to Solana on a certain day, and the next day, the money really did arrive on Solana. The definitive confirmation came on March 12, 2025: Jimmy sent a screenshot of a cross-chain transaction, and ZachXBT matched it to an order that had been created minutes earlier using the amount and timestamp on Thorchain’s public explorer.
The clues began to connect. 💰 Jimmy provided three Solana addresses, which led to a cluster of stolen funds worth more than $12 million. The funds were being moved in real time between Bitcoin, Ethereum, Solana, and TRON. Tether later froze 442,000 USDT from the cluster. Jimmy also mentioned that the team had around $300,000 frozen in 2024. ZachXBT’s on-chain investigation identified the actual figure as 332,000 USDC, linked to a November 2023 theft worth more than $100 million—another clue pointing to the same group. Following the $3 million in scam proceeds Jimmy said he had handled, ZachXBT also traced the money to an old marketplace’s hot wallet on Telegram. The marketplace specialized in this kind of business and also sold data. The group behind it was implicated in at least $4 billion in activity by the U.S. FinCEN, and Telegram banned it in May 2025. ⚖️
This wasn’t an isolated case. In September 2026, another exchange was hacked for around $387 million, and the same playbook played out again. ZachXBT says that since 2022, he has helped freeze more than $75 million in funds linked to North Korea. A co-founder of Paradigm has also said publicly that he helped victims of hacks and scams recover more than $350 million.
My take: the most valuable thing in this story isn’t the plot—it’s the cost structure. On-chain investigations are never free. He had to front the money himself, lose 5% on every transaction, and risk having the funds swallowed up or putting his personal safety in danger. Anonymity is basically just a pane of glass in the face of on-chain records and social engineering. What’s truly rare is someone willing to put real money on the line to shatter it.
One contrasting detail to end on: in their chats, Jimmy also talked about mahjong, hunting rabbits, weight-loss meals, and taking his family to Disneyland. On one side, billions in stolen money; on the other, the ordinary details of everyday life. These networks have never been as far removed from ordinary people as they might seem.
What do you think? Is it worth spending your own money to get directly involved like this?
Every day, I bring you the latest in crypto—not just what’s happening, but the logic and opportunities behind it 👀🚀
Tap the profile picture to watch the livestream
