Blockchain investigator ZachXBT revealed on Monday that he spent weeks posing as a client of a Chinese money-laundering crew that he says has washed more than $1 billion for North Korea’s Lazarus Group, including much of the $1.5 billion stolen from Bybit in February 2025.
In a 12-post thread on X, ZachXBT said the intelligence he gathered helped trigger freezes on Bybit-linked funds and helped attribute other on-chain illicit flows. To win the group’s trust, he fronted $349,700 of his own money, and he lost 5% on every order.
The FBI attributed the Bybit theft to TraderTraitor, a North Korean cluster within the Lazarus group. Shortly after the hack, ZachXBT noticed more than 15 accounts in public Telegram and Discord communities asking for help with orders that traced directly to the stolen funds. Some of those requests were posted in THORChain’s community; THORChain is a cross-chain swap protocol.
One of those accounts used the alias “Jimmy Green” (Telegram handle long_991, user ID 7635649994). His Chinese-language Telegram bio offered to process flagged BTC, ETH, SOL, and TRX through a mixing and “isolation” service whose funds would not flow back. A TRM Labs graph in the thread shows 64.38 ETH moving from a Bybit exploit wallet to a Jimmy Green address on Feb. 25, 2025, and into THORChain 14 minutes later.
How did ZachXBT get inside?
Writing as “kj,” ZachXBT contacted Jimmy on Feb. 25, 2025. He claimed to hold “marked” ETH, meaning crypto flagged by exchanges and analytics firms, and said he wanted clean USDT on Tron in return. Jimmy asked for the address, the amount, and the fee. They settled on 5% for a 100 ETH trial that kj said would arrive from Railgun, a privacy protocol.
On March 6, 2025, ZachXBT funded a fresh Ethereum wallet with 349.7K USDC. Jimmy supplied 0xbaa551da0ae0c93025d9a983a68025a27dc15337 to receive the USDC in exchange for USDT on Tron. ZachXBT found that the gas for that address came from a wallet traceable to Bybit exploit funds and listed on Bybit’s public blacklist. He then ran several more swaps to build trust.
The crew was wary as well. Jimmy told kj his boss suspected him of being a scammer. He then described the outfit as a professional laundering, isolation, and freeze-prevention operation and claimed it was China’s largest. He also explained the division of labour: incoming USDT was split among different “acceptors,” so a freeze on one person’s batch would not stop the rest.
What did the launderers reveal?
Once he trusted kj, Jimmy began saying where Bybit funds would move before they moved. On one occasion, he said the money would go to Solana the next day, and it did. On March 10, 2025, he said work had dried up because North Korean flows had been suspended for 10 days, and that the team had $1 million ready for other clients.
“This time, almost all the 1.5 billion eth was laundered by our team,” Jimmy said. ZachXBT said the claim matched the laundering patterns he had observed. At that point, he decided to keep absorbing the 5% fee per order to gather as much actionable intelligence as quickly as possible.
On March 12, 2025, Jimmy shared a screenshot of himself swapping 1.192 BTC for 51.73 ETH. ZachXBT matched the amounts and timing to a THORChain order created within minutes of the message, transaction 81a85130b36057428e64b6f97215f77b5a197776a8f1b3a61c8cd0ee1ebfa8c1. TRM’s graph traces that bitcoin back through intermediary wallets to the Bybit exploiter.
Jimmy also handed over three Solana addresses. They exposed a cluster of more than $12 million in Bybit funds being swapped in real time from BTC to ETH, then to SOL, and finally to Tron. Tether later froze 442K USDT linked to the cluster. According to ZachXBT, the cluster also used a new laundering method built on Uniswap liquidity pools seeded with illiquid tokens.
Two of Jimmy’s other stories also held up on-chain. A team, he said, had about $300K frozen in 2024, turned out to have lost 332K USDC from the November 2023 Poloniex exploit, frozen in May 2024. ZachXBT traced a $3 million batch of fraudulent proceeds that Jimmy laundered for a friend to a hot wallet associated with Huione Guarantee. The US blacklisted Huione last year, and its former chairman, Li Xiong, was later arrested in Cambodia and extradited to China.
Between orders, Jimmy chatted about mahjong, shooting wild rabbits, his fat-reducing diet, family life, and holidays at Disney. ZachXBT attributes his stilted English to a translation tool.
ZachXBT said he shared his findings immediately with private-sector investigators and the law-enforcement officers assigned to the case, and that the sensitivity of the investigation kept him from publishing sooner. He says he has helped action more than $75 million in DPRK-related freezes since 2022. Jimmy Green’s real identity has not been disclosed, and no law-enforcement agency has commented publicly.
The disclosure follows ZachXBT’s report last week that launderers handling funds from the $387.5 million Bitget hack were openly filing support tickets in public groups. Bitget has since blamed North Korean attackers. NEAR Intents said that attackers attempted to move more than $50 million in Bitget proceeds through its protocol.
Community Discussion
Join the conversation. Ask questions, share solutions, and help others.
Be the first to start the discussion!
