Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Zammad Zero-Day Exploited to Hijack Sessions, Execute Code
October 5, 2026
Researcher Infiltrates Lazarus Group Crypto Laundering After Bybit Hack
October 5, 2026
Google Gemini AI to gain full computer access: What it means for users
October 5, 2026
Home/CyberSecurity News/Researcher Infiltrates Lazarus Group Crypto Laundering After Bybit Hack
CyberSecurity News

Researcher Infiltrates Lazarus Group Crypto Laundering After Bybit Hack

Key Takeaways A blockchain investigator infiltrated a crypto laundering network tied to North Korea’s Lazarus Group following the February 2025 Bybit hack. The infiltration involved posing as a...

Jennifer sherman
Jennifer sherman
October 5, 2026 4 Min Read
2 0

Key Takeaways

  • A blockchain investigator infiltrated a crypto laundering network tied to North Korea’s Lazarus Group following the February 2025 Bybit hack.
  • The infiltration involved posing as a client, gathering intelligence from private chats, and cross-referencing it with public blockchain transactions.
  • This operation reportedly led to the freezing of significant stolen funds and exposed key individuals within the laundering syndicate.
  • The network is alleged to have processed over $1 billion from various exploits.

Investigator Infiltrates Lazarus Group’s Crypto Laundering Network After Bybit Heist

A prominent independent blockchain sleuth, known as ZachXBT, has revealed a successful infiltration of a Chinese-operated cryptocurrency laundering syndicate. This network is allegedly linked to the notorious North Korean state-sponsored hacking collective, the Lazarus Group, and was actively processing funds stolen in the substantial Bybit hack of February 2025.

Table Of Content

  • Key Takeaways
  • Investigator Infiltrates Lazarus Group’s Crypto Laundering Network After Bybit Heist
  • Undercover Operation to Uncover Illicit Flows
  • Connecting Digital Breadcrumbs to Blockchain Reality
  • What You Should Do

ZachXBT’s detailed investigation meticulously connected private communications with public blockchain records. This intricate work, he states, was instrumental in freezing a portion of the illicitly obtained funds and unmasking operators who purportedly handled assets from numerous high-profile crypto thefts.

In a disclosure shared on October 5, 2026, the independent researcher claimed the sophisticated syndicate had laundered in excess of $1 billion across various exploits. While this figure represents his current assessment rather than an officially confirmed total by law enforcement, his findings offer an unprecedented look into the individuals and methods employed to move stolen assets after breaches of cryptocurrency platforms. pic.twitter.com/jauRRt8875

Undercover Operation to Uncover Illicit Flows

Following the significant February 2025 Bybit theft, ZachXBT identified over 15 distinct accounts within public Telegram and Discord channels that were openly seeking assistance with transactions related to the stolen Bybit funds. Adopting an undercover persona, he approached one of these operators, who went by the alias “Jimmy Green,” posing as a potential client.

On March 6, 2025, the investigator initiated his undercover operation by funding a new Ethereum wallet with 349,700 USDC. He then commenced a series of exchanges, converting USDC to USDT on the Tron network. To cultivate trust and maintain access to the illicit network, ZachXBT deliberately accepted losses of approximately 5% per transaction.

Over time, the operator “Jimmy Green” reportedly shared critical information, including specific wallet addresses, screenshots of transactions, and advance details regarding upcoming transfers. According to ZachXBT, Jimmy asserted that his team had processed the majority of the stolen Bybit assets and claimed to operate from both Hong Kong and mainland China. It is important to note that these statements are allegations made during the private chats and do not constitute independent proof of the operator’s true identity or geographical location.

Connecting Digital Breadcrumbs to Blockchain Reality

A crucial aspect of the investigation involved rigorously cross-referencing the operator’s claims with verifiable blockchain transactions. ZachXBT reported that “Jimmy Green’s” receiving wallet obtained “gas,” the cryptocurrency used to cover transaction fees, from an address directly linked to the original Bybit theft.

Further evidence emerged on March 12, when a shared screenshot reportedly matched a THORChain transfer in both its precise timing and the amount involved. The provided intelligence also highlighted a recurring Telegram account identifier across multiple screenshots, effectively linking the operator’s private profile to activity observed in a public THORChain group.

The investigator also leveraged three specific Solana addresses to identify a wallet cluster that held over $12 million in Bybit funds. ZachXBT detailed the movement of these funds across various blockchain networks, including Bitcoin, Ethereum, Solana, and Tron. While switching between networks is a common tactic to obscure money trails, matching transaction amounts and timestamps proved vital in connecting these disparate steps for investigators.

ZachXBT confirmed that Tether subsequently froze 442,000 USDT associated with the identified cluster. He also shared his gathered intelligence with other investigators and law enforcement agencies to facilitate additional freezes. Independent confirmation from Tether regarding ZachXBT’s specific role in this action has not been publicly released.

The FBI officially attributed the February 21, 2025, Bybit theft to North Korea in its February 26 advisory, designating the activity as “TraderTraitor.” The advisory warned that the stolen assets were being dispersed across thousands of addresses on multiple blockchain networks.

ZachXBT estimates that his investigative efforts since 2022 have contributed to the freezing of over $75 million linked to North Korean-backed incidents. His latest report has also sparked discussions about the critical need for support for independent investigators who often face significant financial risks and personal dangers. The claims made by ZachXBT await further independent verification.

While freezing assets does not automatically equate to their return to victims, this case powerfully illustrates how a combination of patient undercover work, meticulous blockchain tracing, and timely intelligence sharing can create crucial opportunities to intercept and block stolen funds before they are further dissipated.

What You Should Do

  • Monitor Transactions: Cryptocurrency exchanges and financial institutions should implement enhanced monitoring for suspicious transaction patterns, especially those involving multiple blockchain networks or rapid asset conversions.
  • Strengthen KYC/AML: Reinforce Know Your Customer (KYC) and Anti-Money Laundering (AML) protocols to better identify and prevent illicit financial activities.
  • Collaborate with Investigators: Law enforcement and private security firms should foster closer collaboration with independent blockchain investigators to leverage their specialized expertise.
  • Educate Users: Users of cryptocurrency platforms should be vigilant about unsolicited offers for transaction assistance, especially in public forums, as these can be fronts for laundering operations.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

BreachCybersecurityExploitHackerSecurity

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Google Gemini AI to gain full computer access: What it means for users

Next Post

Critical Zammad Zero-Day Exploited to Hijack Sessions, Execute Code

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
GlassWorm Supply Chain Attack Hides Malware in Fake VS Code Themes
October 5, 2026
macOS Sonoma 14.4 Enhances Full Disk Access Security
October 5, 2026
Google Pauses Open-Source Bug Bounty Program Due to AI-Generated Spam
October 5, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us