ZachXBT Says Undercover Chats Helped Trace Funds Linked to $1.5B Bybit Hack

Daily Feed
ZachXBT Says Undercover Chats Helped Trace Funds Linked to $1.5B Bybit Hack

ZachXBT Says Undercover Chats Helped Trace Funds Linked to Bybit Hack

Blockchain investigator ZachXBT says he posed as a crypto-laundering client to gather information about people handling funds linked to the $1.5 billion Bybit hack. His account, reported by Cybersecurity News, describes undercover chats alongside on-chain analysis. It does not independently establish who the alleged operators were or how much they handled.

  • The FBI attributed the February 2025 Bybit theft to North Korea.
  • ZachXBT says he contacted an operator using the name “Jimmy Green.”
  • TRM Labs tracked hundreds of millions of dollars moving through illicit channels.
  • Claims about a $1 billion network and a 442, 000 USDT freeze remain attributed, not independently confirmed.

What happened to the Bybit funds

Bybit was hacked on February 21, 2025, with approximately $1.5 billion in Ethereum tokens stolen, according to TRM Labs. Five days later, the FBI publicly attributed the theft to North Korea and identified the activity as TraderTraitor. TRM made a similar broad attribution.

That attribution concerns responsibility for the hack. It does not establish that everyone who later handled funds connected to the theft belonged to North Korea, Lazarus Group, or any particular organization.

TRM Labs tracked the stolen assets as they moved through intermediary wallets and crypto services. The firm estimated that at least $160 million had passed through illicit channels within 48 hours, more than $200 million by February 23, and more than $400 million by February 26. These figures estimate how much moved through illicit channels by those dates. They are not a final accounting of money laundered, recovered, or tied to identified people.

How ZachXBT says he gathered information

According to Cybersecurity News’ account of ZachXBT’s disclosures, he found more than 15 public Telegram and Discord accounts offering help with transactions linked to stolen Bybit funds. He says he contacted an operator using the name “Jimmy Green” and posed as a client.

The account says ZachXBT funded a new Ethereum wallet with 349, 700 USDC on March 6, 2025, then began exchanging USDC for USDT on Tron. He reportedly accepted losses of about 5% per order to build trust. The reporting does not explain how the funds moved between networks or what those losses represented. Calling them a particular fee or a direct cross-chain swap would go beyond what is known.

The operator allegedly sent wallet addresses, screenshots, and advance information about planned transfers. A screenshot shared on March 12 reportedly matched a THORChain transfer in timing and amount. Cybersecurity News also reported that a Telegram account identifier appeared in separate screenshots and in a public THORChain group.

These details come from ZachXBT’s account, as relayed by Cybersecurity News. They offer investigative leads, but do not independently establish the operator’s identity, the authenticity of every communication, or who controlled the wallets. “Infiltrated” makes for a dramatic headline. The reported conduct was undercover engagement and information gathering.

What the alleged network claimed

Cybersecurity News reported that ZachXBT identified a wallet cluster involving more than $12 million in Bybit funds, using three Solana addresses in his analysis. The cluster finding is attributed to ZachXBT. The reporting does not independently confirm the total.

ZachXBT also reportedly estimated that the alleged network had laundered more than $1 billion across multiple exploits. That is his estimate, not a figure confirmed by law enforcement. It covers multiple thefts, not necessarily the Bybit hack alone.

In private chats, the operator allegedly claimed his team processed most of the stolen Bybit assets and was based in Hong Kong and mainland China. These are claims from the reported conversations, not verified facts about the speaker, his location, or the group’s role.

Cybersecurity News also reported that ZachXBT said 442, 000 USDT connected to the cluster had been frozen. Tether has not separately confirmed that claim in the reporting cited here. A freeze can restrict the movement of tokens, but it does not mean the funds were returned to Bybit or its users.

Why cross-chain laundering is difficult to follow

A crypto swap exchanges one asset for another. A bridge moves value between different blockchain networks, often by locking or burning assets on one chain and issuing or releasing corresponding assets on another. Both can make an investigation harder, especially when funds pass through multiple wallets and services in quick succession.

They do not automatically erase the trail. Public blockchains can reveal transaction timing, amounts, and links between wallets. These patterns help investigators build a picture of how funds moved, but they are clues, not automatic proof that the same person controls every connected wallet.

Stablecoins such as USDC and USDT are designed to track the U.S. dollar and are issued by private companies. Their issuers can sometimes freeze tokens, creating an intervention point that does not exist for every crypto asset. That power has limits: a freeze is not a reversal, proof of ownership, or a promise of repayment.

TRM Labs’ Nick Carlsen, a North Korea expert and former FBI subject matter expert, described the activity as a “flood the zone” technique: moving funds rapidly across platforms to put pressure on compliance teams, analysts, and law enforcement. That is an expert interpretation of the laundering pattern, not proof that every transfer followed a centrally directed plan.

TRM also reported that much of the stolen value was later converted into Bitcoin and that, when the firm conducted its analysis, much of that Bitcoin remained largely stationary. The observation applies to the period covered by the analysis. It does not establish what happened to the funds afterward.

The reporting describes a plausible combination of on-chain tracing and private intelligence. It does not establish how much of the Bybit funds were ultimately recovered, whether the alleged operators faced enforcement action, or whether the people ZachXBT contacted belonged to a specific criminal organization.

Key questions and answers

  • What does “infiltrated” mean in this case?

    ZachXBT reportedly posed as a client and gathered information through private communications. The account does not independently establish the operator’s identity.

  • Did the FBI link the Bybit hack to North Korea?

    The FBI publicly attributed the February 21, 2025, theft to North Korea, and TRM Labs reached a similar conclusion. That does not prove every alleged money handler belonged to a North Korean group.

  • How much of the stolen money had moved through illicit channels?

    TRM estimated that more than $400 million had moved through illicit channels by February 26, 2025. That does not mean the money was traced to identified people or recovered.

  • Did the alleged network launder more than $1 billion?

    That was reportedly ZachXBT’s estimate across multiple exploits, not a confirmed total. It should not be treated as the amount laundered from Bybit alone.

  • Were 442, 000 USDT returned to victims?

    No return has been established. ZachXBT reportedly said the tokens were frozen, but a freeze does not prove the funds were recovered or repaid.

Share this article

Powered by ADBYTES

Advertise smarter.

Adbytes.Media is a transparent advertising network where advertisers reach real audiences and publishers, affiliates & everyday members earn ADBYTES tokens. Join the community and start earning today.

Back to Blog