Cyber Security News

Researcher Infiltrates Lazarus Group’s Crypto Laundering Network After $1.5B Bybit Hack

Blockchain investigator ZachXBT says he infiltrated a Chinese crypto laundering network linked to North Korea’s Lazarus Group after the $1.5 billion Bybit hack.

His investigation connected private chats with public blockchain records and, he says, helped freeze stolen funds while exposing operators who claimed to handle money from several major thefts.

In an October 5 disclosure on X, the independent investigator said the syndicate had laundered more than $1 billion across multiple exploits. That figure remains his assessment, rather than a confirmed total from law enforcement. The findings offer a closer look at the people moving stolen assets after hackers breach crypto platforms.

Following the February 2025 theft, ZachXBT said he found more than 15 accounts seeking help with transactions tied to stolen Bybit funds in public Telegram and Discord groups. He approached an operator named “Jimmy Green” and posed as a client.

On March 6, 2025, he funded a fresh Ethereum wallet with 349,700 USDC and began exchanging USDC for USDT on Tron. He said he accepted losses of about 5% per order to build trust and keep access to the network.

The operator later shared wallet addresses, screenshots, and advance details about planned transfers. According to ZachXBT, Jimmy claimed his team had processed most of the stolen Bybit assets and operated from Hong Kong and mainland China. Those statements are allegations from the chats, not proof of the operator’s identity or location.

Matching Chats with Blockchain Transfers

The key technical step was checking what the operator said against recorded transactions. ZachXBT reported that Jimmy’s receiving wallet obtained gas, the crypto used to pay transaction fees, from an address linked to the Bybit theft.

A screenshot shared on March 12 reportedly matched a THORChain transfer in both timing and amount. The supplied evidence also shows a Telegram account identifier appearing in separate screenshots, helping connect the operator’s private profile with activity in a public THORChain group.

Three Solana addresses helped ZachXBT identify a wallet cluster involving more than $12 million in Bybit funds. He described money moving through Bitcoin, Ethereum, Solana, and Tron. Switching networks adds steps to the trail, but matching transfer amounts and times can help investigators connect those steps.

ZachXBT said Tether later froze 442,000 USDT linked to that cluster. He also shared intelligence with investigators and law enforcement to support further freezes. The available reporting does not include a separate Tether statement confirming his role in that specific action.

The FBI attributed the February 21, 2025, Bybit theft to North Korea in its February 26 advisory, naming the activity TraderTraitor. It warned that stolen assets were spreading across thousands of addresses on multiple blockchains.

Cybersecurity News previously reported on North Korean hackers moving $300 million from the Bybit theft, providing useful background on the laundering challenge.

ZachXBT says his work has helped freeze more than $75 million linked to North Korean incidents since 2022. His latest account has also drawn calls for support for independent investigators facing financial losses and personal risks. The claims still need further independent confirmation.

Freezing assets is not the same as returning them to victims. Still, the case shows how patient undercover work, blockchain tracing, and timely reporting can create chances to block stolen funds before they move again.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

ClingSTUN Backdoor Exploits Multiple IoT Vulnerabilities to Gain Persistent Remote Access

ClingSTUN is a Linux backdoor that exploits vulnerable internet-connected devices to give attackers lasting remote…

15 minutes ago

FBI Removes Accenture Contractor After Unpatched PeopleSoft Flaw Exposes Thousands of Employees

The FBI removed an Accenture contractor on October 5, 2026, after a missed security patch…

15 minutes ago

Google Adds 6 Advanced Protection Features to Android 17 Against Sophisticated Attacks

Google has detailed six Advanced Protection enhancements for Android 17, targeting sophisticated attacks, scams and…

44 minutes ago

Atlassian Patches Critical Vulnerabilities in Jira, Confluence, Bitbucket, and Five More Products

Atlassian has disclosed a critical arbitrary file access vulnerability affecting eight products, including Jira, Confluence,…

1 hour ago

Top 10 Best SAST Tools in 2026 [Ranked & Scored]

The AI-code flood made one truth undeniable: static analysis only matters if developers fix what…

2 hours ago

Top 10 Best Just-in-Time (JIT) Access Tools in 2026 [Ranked & Scored]

Credentials that always work are credentials worth stealing which is why mitigating how attackers exploit…

2 hours ago