Blockchain investigator ZachXBT spent $349,700 to expose North Korean crypto laundering networks
A blockchain investigator’s $349,700 undercover purchase of access to North Korean cryptocurrency laundering networks reveals how stolen digital assets move from exchanges to spendable cash, and exposes the intermediaries who make the crime work. Institutional investors and platform operators now face pressure to block these pipelines before assets fragment across chains and become permanently untraceable.
- ZachXBT infiltrated a laundering ring by posing as a customer, spending $349,700 USDC while accepting 5% losses per transaction to gain intelligence on Bybit theft proceeds.
- His investigation traced $12 million in stolen Bybit funds and contributed to Tether freezing 442,000 USDT, though tracing and freezing funds does not mean they were recovered.
- The Treasury sanctioned Xinbi Guarantee in September after it processed more than $24 billion in illicit digital assets since 2022, yet criminals simply migrated to successor marketplaces, showing enforcement only slows, not stops, the laundering ecosystem.
- $1.5B stolen from Bybit by North Korean hackers in February 2025
- $4B laundered through Cambodia’s Huione Group between August 2021 and January 2025
- $24B processed by sanctioned Xinbi Guarantee marketplace since 2022
North Korean hackers stole approximately $1.5 billion from the cryptocurrency exchange Bybit in February 2025, in an operation the FBI attributed to North Korean actors and labeled TraderTraitor. While the theft itself drew immediate attention, the subsequent movement of stolen assets through intermediaries has become the focus of a more complex investigation: how criminals convert blockchain-native digital tokens into fiat currency and off-ramp proceeds without detection. That question matters to institutional holders and platform operators because it maps the exact weakness enforcement agencies and exchanges must exploit to interrupt these flows. According to reporting by CryptoSlate, a pseudonymous blockchain investigator using the handle ZachXBT staged an undercover operation to infiltrate the laundering pipeline, gaining firsthand access to the people and services that make the crime economically viable.
ZachXBT infiltrates North Korean laundering network by posing as high-volume customer
ZachXBT committed 349,700 USDC, a dollar-pegged stablecoin issued by Circle, and deliberately accepted unfavorable 5% losses on each transaction to establish himself as a credible, repeat customer within a Chinese-led laundering network.
His target was a Telegram intermediary using the alias Jimmy Green, who publicly solicited help moving cryptocurrency between networks in open Discord and Telegram groups dedicated to converting stolen Bybit proceeds.
By March 6, 2025, ZachXBT had built enough rapport to access operational intelligence: private discussions of planned fund movements before transactions appeared on public blockchains, including advance notice of moves to Solana and other networks.
This private-intelligence advantage proved critical because blockchain analysis alone cannot identify the person behind a transaction or its criminal intent. An on-chain address holding stolen tokens reveals only movement, not ownership or purpose.
Conversations about where funds would travel next, confirmed later by matching those statements to actual on-chain activity, created the bridge between pseudonymous wallets and the human actors controlling them.
ZachXBT’s relationship with Jimmy Green eventually produced information identifying a cluster of over $12 million in Bybit-linked assets distributed across multiple blockchain networks and custodians.
The arrangement carried substantial risk: the intermediary could disappear with the funds, leaving ZachXBT’s capital unrecoverable.
Tether freeze of 442,000 USDT shows critical difference between tracing and recovery
Intelligence from ZachXBT’s investigation contributed to Tether, the issuer of USDT, the largest stablecoin by trading volume, freezing 442,000 USDT linked to the North Korean theft. This outcome highlights a fundamental asymmetry in cryptocurrency crime: identifying stolen assets on a public blockchain does not equal recovering them.
The 12 million dollars traced does not match the 442,000 USDT frozen, and the frozen amount represents only a fraction of the total Bybit theft still moving through exchanges, bridges and wallet addresses beyond reach of American authorities.
Centrally issued stablecoins like USDT and USDC create intervention points that native Bitcoin lacks, because their issuers retain the technical ability to restrict transfers from designated addresses. Once stolen crypto passes through decentralized exchanges, non-custodial wallets or services operating outside U.S. jurisdiction, that issuer-controlled restriction becomes useless.
Bitcoin held in custodial accounts can be seized only if authorities obtain both legal authority and the technical means to access or control the private keys, a process requiring multiple judicial and law enforcement steps.
The fragmentation of stolen funds across blockchains, custodians and trading counterparties means each movement potentially requires separate evidence or a new legal process before pursuit can continue.
Investigators can observe where the funds traveled but cannot prevent the next transaction.
Treasury sanctions on Xinbi and Huione show enforcement slows but does not eliminate criminal infrastructure
The U.S. Treasury’s Financial Crimes Enforcement Network identified Cambodia-based Huione Group as a financial institution of primary money laundering concern in May 2025, finding it had laundered at least $4 billion in illicit proceeds between August 2021 and January 2025, including a minimum of $37 million in cryptocurrency stolen by North Korean cyber thieves. Four months earlier, in September 2024, Treasury sanctioned Xinbi Guarantee, a marketplace it said processed more than $24 billion in digital assets and fiat currency since 2022 and explicitly identified North Korean hackers among its illicit users. Despite that designation, criminals did not cease operations; instead, they migrated their relationships to successor marketplaces.
The economic logic underlying these marketplaces matters for institutional compliance and platform policy. Intermediaries offering repeated access to payment services, settlement mechanisms and currency-exchange functions become infrastructure serving multiple criminal organizations simultaneously.
Rather than forcing each hacking group to build isolated laundering arrangements, these centralized marketplaces concentrate activity and reduce transaction costs for criminal customers. Shutting down one marketplace eliminates convenience but not demand; the relationships and commercial patterns that supported it simply migrate to the next service willing to operate beyond enforcement reach.
Treasury’s own findings acknowledged that Huione had laundered funds connected to North Korean heists.
A separate case from 2020 underscores the durability of these networks: the Justice Department charged two Chinese nationals, Tian Yinyin and Li Jiadong, with laundering over $100 million in stolen cryptocurrency primarily through activity connected to exchange hacks. Tian converted nearly $1.4 million in Bitcoin into Apple iTunes gift cards, demonstrating how laundering ultimately depends on commodity merchants willing to accept payment from unknown sources, a problem that extends far beyond cryptocurrency infrastructure into retail payment systems. Each enforcement action removes individuals and temporary services but leaves the underlying economic incentive intact: criminals holding stolen digital assets will find buyers and payment channels as long as the spread between wholesale and retail prices justifies the operational risk.
The CCS read. Freezing stablecoins mid-flow proves that institutional intervention works, but only when stolen assets remain within custodial or issuer-controlled systems. Bitcoin and assets on decentralized exchanges fragment faster than investigators can legally restrain them, leaving recovery dependent on either rapid on-chain tracing combined with human intelligence (as ZachXBT demonstrated) or cooperation from services operating beyond U.S. jurisdiction. Exchanges and stablecoin issuers have direct tools; law enforcement does not.
The unresolved question is whether intermediaries can be disrupted faster than they migrate. Xinbi’s successor to itself suggests that naming and sanctioning individual marketplaces may create temporary friction but no lasting barrier, as long as criminals can relocate relationships to new entities or jurisdictions. Regulatory agencies have not yet articulated whether the solution requires blocking entire payment corridors, a move that could impair legitimate commerce, or identifying whether specific individuals (like Jimmy Green) can be located and prosecuted under U.S. law, which would require identifying the actual person behind the alias and establishing jurisdiction over their activities.