Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Undercover Blockchain Probe Maps Lazarus-Linked Laundering After $1.5B Bybit Theft
Undercover Blockchain Probe Maps Lazarus-Linked Laundering After $1.5B Bybit Theft
Read Time:3 Minute, 27 Second

An independent blockchain investigator says he infiltrated a Chinese organized-crime network that helped move cryptocurrency linked to North Korea’s Lazarus Group after the $1.5 billion Bybit theft. By posing as a customer and deliberately accepting costly exchange terms, ZachXBT gained access to private conversations, wallet addresses and planned transfers that could be compared with activity recorded on public blockchains.

The operation offers a rare view of the financial layer that follows a major cryptocurrency breach. Attackers may steal assets in a single event, but converting and dispersing them requires brokers, cross-chain transfers and repeated exchanges. That process creates both complexity and investigative opportunities, because transaction timing and amounts remain visible even when funds move between networks.

Building trust with a suspected laundering operator

After the February 2025 Bybit breach, ZachXBT reported finding more than 15 accounts in public Telegram and Discord groups seeking transaction help associated with the stolen funds. He contacted an operator using the name “Jimmy Green” and presented himself as a client. On March 6, he funded a newly created Ethereum wallet with 349,700 USDC and began exchanging USDC for USDT on the Tron network.

The investigator says he tolerated losses of roughly five percent on each order to establish credibility and preserve access. As trust developed, the operator allegedly shared screenshots, wallet destinations and advance information about transfers. Jimmy claimed that his team had handled most of the stolen Bybit assets and operated from Hong Kong and mainland China. Those claims came from private chats and do not independently establish the person’s identity, location or role.

Private messages were tested against public ledgers

The strongest part of the investigation came from correlating statements with on-chain records. According to ZachXBT, a wallet supplied by the operator received transaction-fee funds from an address tied to the Bybit incident. A screenshot sent on March 12 reportedly matched a THORChain transfer in both value and timing. An account identifier appearing across separate screenshots also helped connect a private Telegram profile with participation in a public THORChain group.

Three Solana addresses then led to a larger wallet cluster involving more than $12 million in Bybit-linked funds. The reported flow crossed Bitcoin, Ethereum, Solana and Tron. Moving between blockchains can fragment the trail and force investigators to use several analytical systems, but closely matching amounts, timestamps and funding relationships can reconnect the steps.

Freezes can interrupt laundering, not finish recovery

ZachXBT said Tether froze 442,000 USDT connected to the identified cluster and that intelligence was shared with investigators and law enforcement to support additional action. Public reporting did not include a separate Tether statement confirming his role in that particular freeze. He also says his work has contributed to freezing more than $75 million tied to North Korean activity since 2022.

A freeze is not the same as restitution. Ownership must still be established, legal processes may cross several jurisdictions, and funds can remain inaccessible for long periods. Nevertheless, rapid notification can prevent another transfer and preserve assets while authorities assemble evidence. Independent investigators also take financial and personal risks when they fund undercover transactions or interact directly with alleged criminal brokers.

What the case reveals about the Lazarus ecosystem

The FBI attributed the February 21, 2025 Bybit theft to North Korea and tracks the activity as TraderTraitor. Its advisory warned that stolen assets were being distributed through thousands of addresses across multiple chains. The laundering account is consistent with that broader challenge, but several details remain allegations from ZachXBT and await confirmation by law enforcement or other independent sources.

  • Cross-chain movement slows analysis but does not erase transaction history.
  • Small fee-funding transfers can connect wallets that appear unrelated.
  • Private screenshots become stronger evidence when amounts and times match public records.
  • Stablecoin issuers can create a narrow intervention point before funds move again.

The episode shows why cryptocurrency incident response cannot end when the initial hack is contained. Exchanges, analytics teams, issuers and investigators need fast channels for sharing wallet intelligence. Patient human infiltration, combined with transparent ledger data, can expose the service providers that turn a technical compromise into usable criminal proceeds.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Undercover Blockchain Probe Maps Lazarus-Linked Laundering After $1.5B Bybit Theft, use the discussion on Forum.

>> forum community

Comments

Leave a Reply