1 min read

ZachXBT Says $349,700 Operation Traced Lazarus Funds

The investigator said the probe identified more than $12 million linked to the February 2025 Bybit hack and helped freeze 442,000 USDT.

Mentioned assets
Anonymous hands examine a smartphone beside a metal security token / TokenPost.ai
Anonymous hands examine a smartphone beside a metal security token / TokenPost.ai

On-chain investigator ZachXBT said he spent $349,700 in USDC posing as a customer of a Chinese laundering network, helping identify funds tied to North Korean cyberattacks and the February 2025 Bybit hack.

ZachXBT said he funded an Ethereum address on March 6, 2025, to transact with a vendor using the alias “Jimmy Green.” He accepted a loss of about 5% on each transaction while gathering information, with no guarantee the counterparty would return the funds.

The operation led to three Solana addresses that ZachXBT said revealed a wallet cluster holding more than $12 million linked to the Bybit theft. He said the funds moved through Bitcoin, Ether, Solana and Tron, and that Tether later froze 442,000 USDT connected to the cluster.

ZachXBT alleged the broader network processed more than $1 billion in cryptocurrency stolen through exploits linked to North Korea’s Lazarus Group. The FBI has attributed approximately $1.5 billion stolen from Bybit on or about Feb. 21, 2025, to North Korean actors tracked as TraderTraitor.

ZachXBT disclosed the operation Oct. 5, 2026, after saying its findings had been shared with private investigators and law enforcement.

Simon Yoon

Reporter

Simon Yoon reports on blockchain technology for TokenPost. Send corrections or tips to info@tokenpost.com.

Loading…