ZachXBT Went Undercover to Track Stolen Funds from Bybit’s 2025 Hack

By Venga
6 min read

Table of Contents

What do you do when $1.5 billion worth of crypto gets stolen? You follow the money of course.

That’s basically what ZachXBT did after the $1.5B Bybit hack in 2025. The stolen funds were quickly moved across different blockchains and wallets, making them increasingly difficult to trace… but not impossible. 

But wait, do you know ZachXBT?

He’s one of crypto’s best-known on-chain investigators, basically the Sherlock Holmes of the blockchain world. However, instead of footprints, cigarette ashes or handwriting, he analyses public transactions, wallet addresses and does a lot of digging on-chain to follow stolen crypto.

His work has made him particularly well known for tracking funds connected to hacks, scams and other crypto-related crimes.

And well, this time, he went one step further and went undercover (and no, we’re not talking about the game), so get your popcorn ready for the story. 

The undercover operation

Quick reminder, the Bybit hack from early 2025, which was the biggest crypto heist ever by the way, was later attributed by the FBI to North Korean actors tracked as TraderTraitor. The stolen assets, as always, were moved through multiple wallets and blockchains as the attackers tried to make them more difficult to trace.

That’s where ZachXBT’s investigation started to get particularly interesting as you can imagine.

After the hack, ZachXBT noticed more than 15 accounts on Telegram and Discord looking for help moving funds linked to the attack.

One of them was a user called “Jimmy Green.”

ZachXBT's screenshot of Jimmy Green Telegram Account
ZachXBT's screenshot of Jimmy Green Telegram Account

ZachXBT decided to follow this Jimmy Green lead, present himself as a client, put up $349,700 of his own money and accepted a 5% loss on each transaction to build trust with the suspected laundering operation. Yeah, that’s a pretty expensive investigation…

He wasn’t simply sending money and watching what was going on. His idea was to build enough trust to get information directly from someone involved in the operation, while at the same time comparing it with what was happening publicly on-chain.

Fast forward a bit, and apparently, the talk between the two got surprisingly casual. Besides discussing the movement of billions in stolen crypto, they talked about mahjong, family, food, hunting rabbits and even Disney vacations. Because even crypto hackers can be Mickey Mouse fans, alright.

Jokes aside, the conversations may sound surprisingly normal, but they were still happening alongside discussions around moving and laundering stolen crypto. According to ZachXBT, Jimmy even shared information about how the group operated and discussed transactions involving funds linked to North Korea.

The real deal was on-chain

Again according to ZachXBT, Jimmy began revealing where funds would move before they actually moved, and apparently also shared related wallet addresses. Jackpot! It helped ZachXBT identify a cluster containing more than $12M in Bybit-linked funds moving across Bitcoin, Ethereum, Solana and Tron.

Transactions Map from ZachXBT's investigation
Transactions Map from ZachXBT's investigation

This was one of the most important parts of the investigation because ZachXBT could compare the information he was receiving privately with transactions happening publicly on the blockchain.

In one example, Jimmy shared a screenshot of himself bridging funds and ZachXBT was able to match the amounts and timing with an order visible on the THORChain explorer that had been created within minutes of Jimmy’s message.

In another case, Jimmy told ZachXBT that funds would be moved to Solana in advance. So the following day, ZachXBT observed the funds moving there, providing another piece of evidence that the conversations were connected to real fund movements. 

One thing is sure though, this investigation showed how quickly stolen crypto funds could move between different networks. 

Using some of the gathered information, ZachXBT says 442,000 USDT linked to that cluster was later frozen by Tether. This stays far from the total stolen amount but still constitutes a small win.

Additionally, he also connected other information from the conversations to the 2023 Poloniex hack and to funds linked to the sanctioned crypto marketplace Huione Guarantee.

In the Poloniex case, Jimmy mentioned that a team he knew had around $300,000 frozen in 2024, and ZachXBT was able to identify the transaction on-chain, finding that the actual amount was around 332,000 USDC.

In another conversation, Jimmy claimed to have laundered around $3M in fraud proceeds for another client, which again, ZachXBT traced to a hot wallet associated with Huione Guarantee, a marketplace that has been sanctioned by U.S. authorities and linked to illicit financial activity. Yes, he’s good!

Naturally, not every claim made by Jimmy during their conversations could simply be taken as a fact. For example, he claimed that his team had laundered most of the $1.5B stolen from Bybit, but while ZachXBT said the claim was consistent with the laundering patterns he observed, the specific amount had not been independently confirmed in full.

But overall, analysing the blockchain activity using wallet addresses, transaction amounts and timing, provided a way to compare what Jimmy was saying with what was actually happening, and allowed ZachXBT to significantly move his investigation forward.

Following the Lazarus trail

Apparently, the operation ZachXBT infiltrated was a Chinese organized crime syndicate that had laundered more than $1B across multiple exploits for the Lazarus Group.

If you are not familiar with it yet, Lazarus Group is the name commonly used for a North Korea-linked crypto hacking operation. Yes, this group has been associated with a lot of major cyberattacks and crypto thefts, and yes again, it has become one of the biggest concerns in crypto security around the world.

ZachXBT’s investigation suggested that the people helping move these funds were not necessarily hiding in some mysterious underground places. 

Some of the activity he identified started with people openly asking for help in public Telegram and Discord groups. Not so low profile.

ZachXBT also says that, since 2022, he has helped freeze more than $75M related to North Korea-linked attacks.

Why are we only hearing about this now?

Well first of all, ZachXBT mentioned he immediately shared his findings with private-sector investigators and law enforcement, but waited to publicly publish them because the investigation was pretty sensitive.

That explains why the events he described happened much earlier than his publication. Revealing all this information publicly while the investigation was still active could have compromised all the work they were doing.

And again, for this particular case, he wasn’t just putting his time into the investigation. He went fully uncovered, revealed that he personally fronted $349,700, accepted a 5% loss on every order he was making, and took on quite some personal risk by dealing with the suspected network. 

Sometimes, following stolen crypto isn’t just a case of opening a blockchain explorer and looking at a few wallets.

And then came Bitget

A couple of weeks ago, a major attack targeted Bitget resulting in $388M stolen from the platform. Well, here’s where things get particularly interesting. 

ZachXBT says that he spotted the same pattern again. 

Some illicit actors linked to this exploit were apparently openly creating support tickets in public Telegram and Discord groups, asking for help with orders involving the stolen funds. Yes, that closely resembles the pattern he originally noticed following the Bybit hack. 

The two investigations are separate, and we don’t know the full picture of the Bitget attack yet, so it would be too early to say that the same network was behind both incidents. However, this similarity is certainly something investigators will be watching closely.

In any case, we saw that even when hackers are making the trail messy, our crypto investigators are still following it. Thanks Zach!


Disclaimer: The content provided in this article is for educational and informational purposes only and should not be considered financial or investment advice. Interacting with blockchain, crypto assets, and Web3 applications involves risks, including the potential loss of funds. Venga encourages readers to conduct thorough research and understand the risks before engaging with any crypto assets or blockchain technologies. For more details, please refer to our terms of service.

Tagged in:

News

Last Update: October 08, 2026