On-chain investigator ZachXBT said on October 5 that he spent weeks in early 2025 posing as a client of a Chinese laundering syndicate he ties to North Korean exploit proceeds, including the February 2025 Bybit hack.
The account is a 12-post thread. He says the work produced freezes, and an attribution he could not publish until now because the case was still live. Findings, he says, went straight to private-sector investigators and law enforcement assigned to the file. No agency has posted a confirmation.
The Crypto Times reported his September 28 list of five aliases he said were laundering the $387.5 million Bitget exploit. In that post he wrote that he had tracked the same pattern after multiple TraderTraitor-attributed exploits and planned to share more of the data in the coming weeks. This thread is that later file.
Who He Says He Dealt With
The FBI, in PSA I-022625-PSA on February 26, 2025, said North Korea was responsible for the theft of about $1.5 billion from Bybit on or about February 21, 2025, and that it refers to that activity as TraderTraitor.
ZachXBT says that after the exploit he saw more than 15 accounts asking for help with orders tied to stolen funds in public Telegram and Discord groups. He says he contacted several. One used the alias Jimmy Green. The Telegram handle and numeric ID are in the thread.
He says that on March 6, 2025, he funded a fresh Ethereum address, 0x073256b50d66a7eb005f2a504d0a4fb6ea62a276, with 349,700 USDC and began swapping that USDC for Jimmy’s USDT on Tron. The address page shows activity about 577 days before October 5, 2026, consistent with early March 2025. The native transaction list opened that day did not show the 349,700 USDC credit. That amount is unconfirmed.
The addresses Jimmy used, as published in the thread, are:
- 0xbaa551da0ae0c93025d9a983a68025a27dc15337 and TPwXAPwYaDCm7GrzNFiMmNnofrxEVURXRM
- 0x1893ef01e700b1359280e11736d1b89fe97ed216, TS5hY6mm6UsCLNdVDWnsRA69LuAwfdn158, TMGjdFeBf9T6kGB9ZmLzeaAPYWBokuyTuS
ZachXBT says 0xbaa5 was funded with gas by 0xbcb4, which he says is directly traceable to Bybit exploit funds and labeled on the public Bybit exploit blacklist.
What He Says the Chats Showed
ZachXBT says Jimmy described moves of Bybit funds for a DPRK client before they happened, including a next-day transfer to Solana that then occurred, and gave a basic account of an operation in Hong Kong and mainland China. Jimmy also said his team laundered most of the $1.5 billion, a claim ZachXBT did not independently quantify. ZachXBT says the claim was consistent with laundering patterns he had already been watching.
On March 12, 2025, Jimmy sent a screenshot of a bridge. ZachXBT says the amount and timing matched a THORChain order created within minutes, hash 81a85130b36057428e64b6f97215f77b5a197776a8f1b3a61c8cd0ee1ebfa8c1.
Jimmy later shared three Solana addresses. ZachXBT says they opened a cluster of more than $12 million in Bybit exploit funds moving BTC to ETH to Solana to Tron in real time:
- 9gSwa2Mew9P21Wxs8nFgDujTurKZx1nBEVRv6K5sJP6e
- EvZJGsDymrSUQyF23HLKEgUpjfd9XN1GTmm8AG6pFS7H
- 8S6T5gL2w5z4M9TCehMgQjxVm3Q6R7WDHp6WFfbtZSAy
He says 442,000 USDT linked to that cluster was later frozen by Tether at 0x652d7f9edaaa8891be2de74ea568d70af823d89e. That address is a Uniswap V2 WAFF-USDT pair. Its page shows about 442,399 USDT in the pool.
A separate remark ZachXBT attributes to Jimmy, about a team that had about $300,000 frozen in 2024, he says he matched to a 332,000 USDC freeze from the Poloniex exploit. Another, about $3 million in fraud proceeds for a different client, he says was traced to a hot wallet of Huione Guarantee, since sanctioned.
FinCEN, on May 1, 2025, identified Cambodia-based Huione Group as a financial institution of primary money-laundering concern under Section 311 of the USA PATRIOT Act and proposed cutting its access to the US system. That is a FinCEN finding, not an OFAC sanctions designation.
The thread does not break down how the $1 billion figure in the opening post was calculated.
Why ZachXBT Held the File
ZachXBT says the sensitivity of the investigation kept the thread off X until October 5, 2026. He also says that since 2022 he has helped action more than $75 million in freezes tied to DPRK incidents, and that this case cost him the 5% spread on money he fronted, plus personal risk he does not detail.
The small talk—mahjong, food, a Disney trip—is in the thread as color. It is not evidence. The evidence he is offering is the address overlaps, the blacklist gas funder, the THORChain timing match, and the Tether freeze.
Also Read: Base Vault Hack: $6M in wstETH Drained After Attacker Gains Whitelist Access
