On-chain detective ZachXBT operated undercover for months, posing as a client to infiltrate a criminal group suspected of laundering funds for the North Korea-linked Lazarus Group. The operation directly led to the freezing of funds tied to the $1.5 billion Bybit hack from February 2025.

ZachXBT identified more than 15 accounts across public Telegram and Discord groups seeking assistance with transactions tied to stolen Bybit funds. He engaged with one Telegram user operating under the alias Jimmy Green, building trust through multiple transactions over time.

On March 6, 2025, ZachXBT executed a critical transaction, transferring $3.497 million in USDC to an Ethereum address to conduct a USDC-to-TRON USDT swap with the criminal party—a common laundering technique to obscure fund origins.

The gas funds used for the Ethereum address traced directly back to the original Bybit hack. The address itself had been publicly flagged on Bybit's hack blacklist, providing direct on-chain evidence of the group's involvement with stolen assets.

In subsequent communications, the group confirmed their role in processing the stolen Bybit funds and provided advance notice of planned fund movements across Solana, giving ZachXBT critical intelligence.

By cross-referencing transaction times, specific amounts and comprehensive on-chain data, ZachXBT identified a wallet cluster holding over $12 million in Bybit hack funds. These assets had traversed multiple networks—Bitcoin to Ethereum to Solana to TRON—in an attempt to obfuscate their origin.

As a direct result of this intelligence, Tether froze approximately 442,000 USDT within the wallet cluster. The laundering group had also attempted to wash funds through Uniswap liquidity pools and by swapping into low-liquidity tokens.

The group additionally admitted to processing around $3 million in fraud proceeds for other clients. ZachXBT traced these related funds to wallets associated with Huione Guarantee, an entity previously sanctioned by authorities.

ZachXBT risked $3.497 million of his personal capital during the undercover operation, enduring approximately 5 percent loss risk per transaction to gain necessary trust and access. He shared the intelligence with investigative agencies and law enforcement.

This operation extends ZachXBT's track record of helping freeze more than $75 million tied to North Korea-linked incidents since 2022. Lazarus Group, also known as TraderTraitor, has been implicated in the $625 million Ronin Bridge exploit in 2022, the $235 million WazirX hack in 2024 and the $1.5 billion Bybit breach.