Undercover Investigation Exposes North Korea’s Crypto Laundering Pipeline
TREE NEWS reports: On-chain investigator ZachXBT successfully infiltrated a Chinese money-laundering crew accused of washing the bulk of the $1.5 billion stolen from Bybit on behalf of North Korea, posing as a fellow scammer on Telegram to extract operational intelligence directly from the group’s leadership.
Over the course of the operation, the launderer — who is believed to handle proceeds tied to Pyongyang’s Lazarus Group — reportedly repaid the investigator’s cover with casual updates about Kim Jong-un, dinner photographs, and an invitation to play mahjong. ZachXBT claims the resulting intelligence helped exchanges and compliance teams freeze funds and attribute the Bybit flows to specific North Korean wallets.
The Cost of Going Undercover
The operation was not cheap. ZachXBT says he fronted roughly $349,700 of his own money to maintain the persona and access the laundering network, a level of personal financial exposure that underscores how thin the funding model remains for independent blockchain sleuths operating at the front line of state-sponsored cybercrime.
His work sits in a growing grey zone between private investigation and law enforcement. While chain-analysis firms and exchanges now rely heavily on figures like ZachXBT for attribution, there is no formal infrastructure to reimburse or protect them, and the personal risk — legal, financial, and physical — is borne almost entirely by the individual.
Why Bybit Matters
The Bybit breach ranks among the largest single crypto thefts ever recorded, and the speed and sophistication of the laundering operation has alarmed regulators. North Korean actors have repeatedly demonstrated the ability to convert stolen assets into untraceable value within hours, often routing funds through mixers, over-the-counter brokers, and shell entities in multiple jurisdictions.
The fact that a lone investigator could penetrate the crew’s Telegram channels raises uncomfortable questions for exchanges and law enforcement alike: if one person with a burner account can get inside, why are institutional compliance systems still lagging on attribution?
Forward Outlook
The episode is likely to intensify pressure on exchanges to tighten counterparty screening and on policymakers to formalize channels for rewarding and protecting independent investigators. It also highlights a structural reality of crypto enforcement: the most actionable intelligence on North Korean laundering increasingly comes not from government agencies but from pseudonymous researchers willing to spend their own money and take personal risk.
As sanctions regimes tighten around mixers and OTC desks, expect more of this hybrid model — private sleuths feeding public enforcement — to become the default backbone of crypto crime response.




