Researcher Infiltrates Lazarus Group’s Crypto Laundering Network After $1.5B Bybit Hack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Blockchain investigator ZachXBT says he infiltrated a Chinese crypto laundering network linked to North Korea’s Lazarus Group after the $1.5 billion Bybit hack.

His investigation connected private chats with public blockchain records and, he says, helped freeze stolen funds while exposing operators who claimed to handle money from several major thefts.

In an October 5 disclosure on X, the independent investigator said the syndicate had laundered more than $1 billion across multiple exploits. That figure remains his assessment, rather than a confirmed total from law enforcement. The findings offer a closer look at the people moving stolen assets after hackers breach crypto platforms.

Following the February 2025 theft, ZachXBT said he found more than 15 accounts seeking help with transactions tied to stolen Bybit funds in public Telegram and Discord groups. He approached an operator named “Jimmy Green” and posed as a client.

On March 6, 2025, he funded a fresh Ethereum wallet with 349,700 USDC and began exchanging USDC for USDT on Tron. He said he accepted losses of about 5% per order to build trust and keep access to the network.

The operator later shared wallet addresses, screenshots, and advance details about planned transfers. According to ZachXBT, Jimmy claimed his team had processed most of the stolen Bybit assets and operated from Hong Kong and mainland China. Those statements are allegations from the chats, not proof of the operator’s identity or location.

Matching Chats with Blockchain Transfers

The key technical step was checking what the operator said against recorded transactions. ZachXBT reported that Jimmy’s receiving wallet obtained gas, the crypto used to pay transaction fees, from an address linked to the Bybit theft.

A screenshot shared on March 12 reportedly matched a THORChain transfer in both timing and amount. The supplied evidence also shows a Telegram account identifier appearing in separate screenshots, helping connect the operator’s private profile with activity in a public THORChain group.

Three Solana addresses helped ZachXBT identify a wallet cluster involving more than $12 million in Bybit funds. He described money moving through Bitcoin, Ethereum, Solana, and Tron. Switching networks adds steps to the trail, but matching transfer amounts and times can help investigators connect those steps.

ZachXBT said Tether later froze 442,000 USDT linked to that cluster. He also shared intelligence with investigators and law enforcement to support further freezes. The available reporting does not include a separate Tether statement confirming his role in that specific action.

The FBI attributed the February 21, 2025, Bybit theft to North Korea in its February 26 advisory, naming the activity TraderTraitor. It warned that stolen assets were spreading across thousands of addresses on multiple blockchains.

Cybersecurity News previously reported on North Korean hackers moving $300 million from the Bybit theft, providing useful background on the laundering challenge.

ZachXBT says his work has helped freeze more than $75 million linked to North Korean incidents since 2022. His latest account has also drawn calls for support for independent investigators facing financial losses and personal risks. The claims still need further independent confirmation.

Freezing assets is not the same as returning them to victims. Still, the case shows how patient undercover work, blockchain tracing, and timely reporting can create chances to block stolen funds before they move again.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

The post Researcher Infiltrates Lazarus Group’s Crypto Laundering Network After $1.5B Bybit Hack appeared first on Cyber Security News.