Press Enter to search · ESC to close

Regulation

ZachXBT Infiltrated North Korea’s Bybit Launderer on Telegram, Freezing Funds

ZachXBT posed as a scammer on Telegram to infiltrate a Chinese crew accused of laundering most of Bybit's $1.5 billion haul for North Korea, spending nearly $350,000 of his own money. The investigator says the intel helped freeze funds and attribute the flows, exposing how thin the line between private sleuthing and state enforcement has become.

Undercover Investigation Exposes North Korea’s Crypto Laundering Pipeline

On-chain investigator ZachXBT successfully infiltrated a Chinese money-laundering crew accused of washing the bulk of the $1.5 billion stolen from Bybit on behalf of North Korea, posing as a fellow scammer on Telegram to extract operational intelligence directly from the group’s leadership.

Over the course of the operation, the launderer — who is believed to handle proceeds tied to Pyongyang’s Lazarus Group — reportedly repaid the investigator’s cover with casual updates about Kim Jong-un, dinner photographs, and an invitation to play mahjong. ZachXBT claims the resulting intelligence helped exchanges and compliance teams freeze funds and attribute the Bybit flows to specific North Korean wallets.

The Cost of Going Undercover

The operation was not cheap. ZachXBT says he fronted roughly $349,700 of his own money to maintain the persona and access the laundering network, a level of personal financial exposure that underscores how thin the funding model remains for independent blockchain sleuths operating at the front line of state-sponsored cybercrime.

His work sits in a growing grey zone between private investigation and law enforcement. While chain-analysis firms and exchanges now rely heavily on figures like ZachXBT for attribution, there is no formal infrastructure to reimburse or protect them, and the personal risk — legal, financial, and physical — is borne almost entirely by the individual.

Why Bybit Matters

The Bybit breach ranks among the largest single crypto thefts ever recorded, and the speed and sophistication of the laundering operation has alarmed regulators. North Korean actors have repeatedly demonstrated the ability to convert stolen assets into untraceable value within hours, often routing funds through mixers, over-the-counter brokers, and shell entities in multiple jurisdictions.

The fact that a lone investigator could penetrate the crew’s Telegram channels raises uncomfortable questions for exchanges and law enforcement alike: if one person with a burner account can get inside, why are institutional compliance systems still lagging on attribution?

Forward Outlook

The episode is likely to intensify pressure on exchanges to tighten counterparty screening and on policymakers to formalize channels for rewarding and protecting independent investigators. It also highlights a structural reality of crypto enforcement: the most actionable intelligence on North Korean laundering increasingly comes not from government agencies but from pseudonymous researchers willing to spend their own money and take personal risk.

As sanctions regimes tighten around mixers and OTC desks, expect more of this hybrid model — private sleuths feeding public enforcement — to become the default backbone of crypto crime response.

View original

Share
Risk notice This site provides news and information on the crypto, blockchain and Web3 industry for reference only and does not constitute investment advice or any promise of returns. Virtual currency-related activities are illegal financial activities in mainland China; digital asset prices are highly volatile; use at your own risk. This site does not provide trading, token issuance or related referral services.

Related Reading

Latest News

TREE NEWS share card
Long-press image above → Save to Photos / Share
Pitch us Feedback