ZachXBT Says He Paid $349,700 to Sit Inside a Laundering Ring

ZachXBT spent 349,700 USDC to find out where stolen money goes. The on-chain investigator published an account of posing as a paying client of what he called a Chinese organized crime syndicate, one he says has laundered more than $1 billion across multiple exploits for Lazarus Group, the hacking operation attributed to North Korea. He dealt with a vendor using the alias "Jimmy Green", took a loss of about 5% on every order to look like ordinary business, and checked what Jimmy told him against public blockchain records. Tether later froze 442,000 USDT on addresses that work identified. Four outlets carried the account, and none of them has the counterparty's real name.
What the cover cost
The money went out on 6 March 2025, when ZachXBT funded an Ethereum address with stablecoins, according to Decrypt and CryptoSlate. The Bybit hack those funds trace back to happened the month before, in February 2025, and cost the exchange $1.5 billion. By 12 March, CryptoSlate reported, Jimmy was supplying evidence of transfers across chains, which ZachXBT matched against THORChain's public swap records. The Block adds that Jimmy's receiving address was traceable to the Bybit exploit funds and already sat on the exchange's own blacklist, and that he named movements to Solana before they happened. That last detail is The Block's alone.
How the vendor described the work
Decrypt quotes Jimmy on how the operation is organised.
"We have different divisions of labor. We take the u and distribute it to different acceptors," Jimmy said.
The "u" is USDT, and the acceptors are the receiving channels that take it on. ZachXBT ran a credibility test of his own inside the conversation. Jimmy mentioned a freeze of roughly $300,000 from 2024, and ZachXBT independently put the real figure at 332,000 USDC tied to the Poloniex hack, which Protos sizes at $100 million. That Poloniex number is Protos's alone. Decrypt and The Block both place Huione Guarantee, the Telegram marketplace run by the Cambodia-based Huione Group, inside the same picture, with The Block tying the link to a $3 million job.
The part every account agrees on
The concrete results are smaller than the headline figure. A cluster of addresses held more than $12 million in Bybit exploit funds swapped across bitcoin, ether, Solana and Tron, and Tether's freeze of 442,000 USDT came off that cluster. Both figures appear in The Block, Decrypt and CryptoSlate alike. ZachXBT says he reported his findings to law enforcement immediately, and puts his running total at $75 million in freezes tied to North Korean incidents since 2022. The Block says operational sensitivity is why the account appears now and not last year. The $1 billion is his own allegation, and CryptoSlate says so plainly, separating it from anything investigators have confirmed. The Block alone writes that the group handled most of the $1.5 billion. Tracing of this kind is no longer unusual: analysts followed $387.5 million out of Bitget across four chains in September, and wallet trackers have tied $30 million of bitcoin sales to Lazarus addresses.
No arrest on the record
Nothing read here names the agencies that received the material, and nothing says a charge has followed. Jimmy Green's identity is unestablished. Neither Bybit nor Tether has commented on the account in anything read here, and how much of the 349,700 USDC came back is not stated anywhere. ZachXBT closed with a request for grants and donations to fund higher-risk work, which is the plainest signal of what this method costs. One date is also unsettled. Protos and CryptoSlate put the post on 5 October, while The Block timestamped its write-up 6 October at 5:51 a.m. New York time, and Decrypt and Cointelegraph published the same day. The post came first and we could not fix the hour.
Read also: PeckShield Counts 50 August Hacks, CertiK Puts Losses $79M Higher