ZachXBT traces $1B in Lazarus Group funds through Chinese laundering network
The FBI’s February 2025 alert tying North Korea’s Lazarus Group to the $1.5 billion Bybit theft has gained a new layer: blockchain investigator ZachXBT says he went undercover inside a Chinese laundering network to trace more than $1 billion of those stolen funds. For institutions running exchange and OTC counterparty risk, the disclosure shows how Lazarus-linked laundering now routes through informal trading desks that formal sanctions lists rarely capture in time.
- The FBI said North Korea’s TraderTraitor unit stole approximately $1.5 billion in virtual assets from Bybit on or about Feb. 21, 2025.
- ZachXBT fronted 349,700 USDC to build trust with a contact using the alias “Jimmy Green” before tracing the network.
- Tether froze 442,000 USDT tied to a cluster that ZachXBT says moved more than $12 million in Bybit exploit funds.
- $1.5B FBI estimate of North Korea’s Bybit theft in Feb. 2025
- $1B+ total ZachXBT says the syndicate laundered for Lazarus Group
- 349,700 USDC he fronted to pose as a paying client
The FBI said in a Feb. 26, 2025 alert that North Korea’s state-sponsored TraderTraitor group stole approximately $1.5 billion in virtual assets from the exchange Bybit on or about Feb. 21, 2025, one of the largest crypto heists ever recorded. The bureau listed more than 50 Ethereum addresses it said were holding or connected to the stolen funds and urged exchanges, bridges and DeFi platforms to block transactions linked to them. Blockchain investigator ZachXBT said in an Oct. 5 disclosure on X that he infiltrated the Chinese network laundering that money, posing as a paying client to trace more than $1 billion moved through exploits for Lazarus Group, as first reported by CryptoSlate.
FBI Warned Stolen Bybit Funds Were Already Spreading Across Chains
The PSA said TraderTraitor actors had already converted some stolen assets into Bitcoin and dispersed them across thousands of addresses on multiple blockchains within days of the theft.
The bureau warned the funds would be “further laundered and eventually converted to fiat currency,” and asked RPC node operators, blockchain analytics firms and virtual asset service providers to block the listed addresses.
At $1.5 billion, the Bybit theft dwarfs other recent exchange breaches, including the $351.6 million Bitget hot wallet breach that the exchange confirmed this year. It set the scale of laundering that investigators like ZachXBT have spent months trying to trace.
ZachXBT Fronted 349,700 USDC to Pose as “Jimmy Green’s” Client
ZachXBT said the investigation began after he spotted at least 15 Telegram and Discord accounts soliciting orders he linked to the stolen Bybit funds. He contacted several