# ZachXBT Says $349,700 Operation Traced Lazarus Funds

By Simon Yoon

Canonical URL: https://www.tokenpost.com/news/technology/27462
Published: 2026-10-07T14:20:12.000Z
Updated: 2026-10-07T14:20:12.000Z
Section: Technology

> The investigator said the probe identified more than $12 million linked to the February 2025 Bybit hack and helped freeze 442,000 USDT.

On-chain investigator ZachXBT said he spent $349,700 in USDC posing as a customer of a Chinese laundering network, helping identify funds tied to North Korean cyberattacks and the February 2025 Bybit hack.

ZachXBT said he funded an Ethereum address on March 6, 2025, to transact with a vendor using the alias “Jimmy Green.” He accepted a loss of about 5% on each transaction while gathering information, with no guarantee the counterparty would return the funds.

The operation led to three Solana addresses that ZachXBT said revealed a wallet cluster holding more than $12 million linked to the Bybit theft. He said the funds moved through Bitcoin, Ether, Solana and Tron, and that Tether later froze 442,000 USDT connected to the cluster.

ZachXBT alleged the broader network processed more than $1 billion in cryptocurrency stolen through exploits linked to North Korea’s Lazarus Group. The FBI has attributed approximately $1.5 billion stolen from Bybit on or about Feb. 21, 2025, to North Korean actors tracked as TraderTraitor.

ZachXBT disclosed the operation Oct. 5, 2026, after saying its findings had been shared with private investigators and law enforcement.
