ZachXBT: He Spent $349,700 Going Undercover With North Korea's Money Launderers
Crypto investigator ZachXBT says he fronted $349,700 of his own money posing as a customer of Chinese launderers moving North Korea's stolen billions.
Key numbers
$349.7K
Fronted
5%
Cost per order
$12M+
Bybit cluster exposed
442K USDT
Frozen by Tether
On 6 March 2025, two weeks after North Korean hackers stole $1.5 billion from the crypto exchange Bybit, an anonymous investigator put $349,700 of his own money into a fresh account and went looking for a money launderer. He found one on Telegram, a messaging app popular with traders, going by the name "Jimmy Green". For the following weeks he played the part of a customer, paid the man's fees, and listened.
The investigator is ZachXBT, who has spent five years tracing stolen crypto in public and has 1.1 million followers on X. On 5 October 2026 he told the story in a 12-part thread. He says Jimmy belonged to a Chinese organised crime syndicate that has laundered more than $1 billion from several thefts for the Lazarus Group, North Korea's state hacking operation. His first line: "How I infiltrated a Chinese organized crime syndicate that has laundered $1B+ across multiple exploits for Lazarus Group."
Everything known about Jimmy Green comes from ZachXBT's account. Jimmy Green is an alias. Nobody has been publicly named, charged or arrested over the operation, and no government has confirmed the syndicate's size. ZachXBT says he passed his findings at the time to investigators in the private sector and to the law enforcement officers assigned to the Bybit case, and held the story back for about 18 months because the investigation was sensitive.
Powered by Cyntri AI
The technology behind this newsroom. Built by Cyntri AI.
AI-assisted publishing, content pipelines and analytics. Crypto Media Zone is our working example.
Powered by Cyntri AI
The man behind the handle
ZachXBT does not publish his real name. His X profile calls him a "Scam survivor turned 2D investigator", and his picture is a cartoon penguin. His trade is reading blockchains, the public ledgers on which every crypto payment is recorded. It is the work of a forensic accountant going through bank statements, except that anyone can open these statements.
His record is why people listen. In August 2024 he traced the theft of 4,064 bitcoin, then about $243 million, from a single creditor of the crypto lender Genesis, and US prosecutors charged two men the following month. In January 2026 he identified John Daghita, later charged with stealing $46 million in seized crypto held for the US Marshals. Within hours of the Bybit theft he sent evidence to the analytics firm Arkham Intelligence pointing at Lazarus. Five days later the FBI publicly blamed a North Korean unit it calls TraderTraitor. Since February 2025 he has also advised Paradigm, a crypto venture capital firm, on hacks at the companies it backs.
Shopping for a launderer
Stealing crypto is the easy half. Turning it into money that can be spent is harder, because every movement shows up on the ledger and the companies that issue digital dollars can freeze them. North Korea pays others to do that part. After Bybit, ZachXBT noticed more than 15 accounts in public Telegram and Discord groups (open online chat rooms, closer to a busy trading floor than a back alley) complaining about delayed orders that were, on the ledger, directly tied to the stolen money. The launderers were handling customer complaints in public.
He messaged several of them, and Jimmy Green answered. The deal was a swap. ZachXBT would send USDC, a digital dollar issued by the US company Circle, on the Ethereum network. Jimmy would send back USDT, a rival digital dollar issued by Tether, on a different network called Tron. In everyday terms it was a back-street money changer swapping dollars held at one bank for dollars held at another, and asking no questions. The commission was steep. ZachXBT says he lost 5% on every order.
The first clue came before any talk of North Korea. Every blockchain transfer needs a small fee, called gas, which works like the stamp on a letter. The account Jimmy gave for receiving payment had been topped up with gas by another account that ZachXBT traced directly to the Bybit theft, and which is listed on the public blacklist of addresses linked to the hack. ZachXBT completed several more orders to build trust. Then Jimmy started talking.
What Jimmy said
According to the thread, Jimmy began describing moves of Bybit money for North Korea before they happened, along with basic details of the group's operation in Hong Kong and mainland China. "One day prior he stated funds would be moved to Solana and the next day they were," ZachXBT wrote. Solana is another blockchain network. Jimmy claimed his team had laundered most of the $1.5 billion, which ZachXBT says fitted the patterns he was seeing on the ledger. At that point, he wrote, he decided to keep losing 5% an order and gather as much as he could, as fast as he could.
On 12 March 2025 Jimmy sent a screenshot of himself moving funds through a bridge, a service that carries money from one blockchain to another, like a currency desk at a border crossing. ZachXBT matched the amount and the timing to an order on THORChain, a cross-network swap service, created within minutes of the message. Roughly $1.2 billion of the Bybit money passed through THORChain in the weeks after the theft.
Jimmy also shared three Solana addresses. They opened up a cluster of more than $12 million in Bybit money being hopped in real time from bitcoin to ether to SOL and finally to Tron, each hop making the trail harder to follow. Tether later froze 442,000 USDT linked to that cluster. ZachXBT says the same group tried a newer trick on Uniswap, an automated exchange where anyone can open a market for a token by putting money into a shared pot, known as a liquidity pool. The group built its pools around obscure tokens that almost nobody else trades. ZachXBT called the method novel and gave no further detail.
Two of Jimmy's boasts checked out. He mentioned that a team he knew had about $300,000 frozen in 2024. ZachXBT found the freeze, which was in fact 332,000 USDC taken in the theft at the exchange Poloniex, robbed of more than $100 million in November 2023. Jimmy also spoke of laundering $3 million of fraud proceeds for a different client. ZachXBT traced that money to a hot wallet, the cash drawer of an online business, belonging to Huione Guarantee, a Telegram marketplace that served the scam compounds of Cambodia. In May 2025 the US Treasury's Financial Crimes Enforcement Network labelled the Huione Group a primary money-laundering concern, and in April 2026 its former chairman, Li Xiong, was extradited from Cambodia to China to face money-laundering charges.

Mahjong, rabbits and Disney
Between the orders, the two men made small talk. Jimmy talked about playing mahjong, hunting wild rabbits, food, a fat-reducing meal plan, his family and holidays at Disney. ZachXBT put his awkward grammar down to a translation app. In replies to the thread he said "a good bit of them are Fujian based in China", a reference to the coastal province opposite Taiwan, and that the crew "Tried to recruit me". He added that Jimmy's Telegram account was deleted earlier this year.
The risk was his alone. He fronted $349,700 "with no guarantee Jimmy wouldn't disappear with the funds", paid 5% on every round, and took on what he called an unknown amount of personal risk from dealing with the syndicate. He says he was not paid for the work. The thread ends with a request for donations and grants from foundations, and a note that he is "currently sitting on significant findings from other cases". He says that since 2022 he has helped bring about more than $75 million in freezes linked to North Korean thefts.
The thread landed while the same kind of desk was busy again. On 24 September 2026 the exchange Bitget lost $387.5 million in a theft that analysts tied to the same North Korean unit. On 28 September ZachXBT posted that Chinese launderers handling the Bitget money were openly asking for help in public Discord and Telegram groups, the same pattern that led him to Jimmy Green eighteen months earlier.
The aftermath
By ZachXBT's account his work produced at least one concrete result: Tether froze 442,000 USDT linked to the $12 million Bybit cluster that Jimmy Green's addresses revealed. That is a small fraction of the $1.5 billion stolen, and most of the Bybit money is still out of reach. Nobody has been publicly charged over the laundering network he describes, and Jimmy Green has not been identified. His Telegram account is gone.
The thread names no new suspects and publishes no new addresses for the public to chase, which fits ZachXBT's statement that the findings went to law enforcement first. The laundering desks have not closed. Within weeks of the $387.5 million Bitget theft in September 2026, ZachXBT was again pointing at Chinese launderers advertising for help in open chat groups, and some of the stolen Zcash coins were being moved into the coin's private pool, which hides who paid whom.
The thread also renewed an old complaint. The best-known investigator in crypto does most of his work without pay, funded by grants and donations, while the money he helps freeze goes back to exchanges and their customers. He ended the thread asking for support and saying more cases are waiting.
What this teaches
- Stolen crypto is only useful to the thief once it is laundered, and the launderers are a separate, paid business that can be watched.
- North Korea's laundering network runs partly in public: open Telegram and Discord groups where orders tied to stolen money are discussed.
- Digital dollars such as USDT and USDC can be frozen by their issuers, which is why thieves swap out of them fast and why timely tips matter.
- Claims from a single undercover source, however detailed, remain claims until confirmed by authorities or courts.
- Independent investigators carry real financial and personal risk, often without pay.

COMMENTS