Skip to content

InvestNot yet confirmed elsewhere1 publisher2 min readPublished

ZachXBT paid a Chinese laundering network 5% an order to trace $12M in stolen Bybit funds

Investigator ZachXBT posed as a paying client of a Chinese laundering network and traced more than $12 million of North Korea's stolen Bybit funds. The trace covers under 1% of the roughly $1.5 billion taken, so the broker proved reachable even as recovery stayed small.

The Investor · Invest desk

How we use AISend a correction

Photograph accompanying ZachXBT paid a Chinese laundering network 5% an order to trace $12M in stolen Bybit funds
Photo: arkm.com

What happened

  • ZachXBT found his way in through more than 15 accounts in public Telegram and Discord groups that were seeking help with transactions tied to the stolen Bybit funds.
  • On March 6, 2025, he funded a new Ethereum address with 349,700 USDC and began swapping it for Tron USDT through a contact using the Telegram alias Jimmy Green.
  • The contact discussed planned fund movements before they happened, letting him check private statements against what later showed up on the public blockchain.
  • By his own account, the information he gathered contributed to Tether freezing 442,000 USDT.
  • In September the US Treasury sanctioned Xinbi Guarantee, a marketplace it said had processed more than $24 billion since 2022, and named North Korean hackers among its users.

Why it matters

  • constraint A broker held together by reputation and repeat custom cannot screen hard for investigators without turning away the regular clients it values most.
  • exposure Anyone converting stolen crypto into spendable money can be reached through the clients they accept, including a client paying 5% an order to watch them.
  • decision The trace became frozen money only after Tether acted, so a stablecoin issuer's choice settles whether evidence gathered inside a laundering desk recovers anything.

Against the size of the theft, the recovered sums are small. More than $12 million traced out of roughly $1.5 billion stolen is about 0.8% [16]. The 442,000 USDT that Tether froze, by ZachXBT's account, is about 0.03% of the haul, or roughly three dollars in every ten thousand [17]. It is also about 3.7% of what he traced [18].

The cost side is the better puzzle. CryptoSlate treats the 349,700 USDC as capital committed to the trades, not a disclosed net loss [4]. The price of entry was the 5% he gave up on each completed order [1], plus the risk that the contact would disappear with the funds [9]. CryptoSlate did not report how many orders he ran. If the whole sum went through once, the fee was about $17,485 [15], and the frozen USDT is roughly 25 times that [20]. On that assumption one paying client bought a freeze for about four cents on the dollar, or rather, bought information that he says helped bring one about [7].

Naming the thieves was quick. The FBI attributed the theft to North Korean hackers, under the label TraderTraitor, on Feb. 26, 2025, and warned that the proceeds were being converted into Bitcoin and other coins and spread across thousands of addresses [2]. According to CryptoSlate, the client relationship gave him information that ordinary blockchain analysis could not provide [10].

The brokers may respond by vetting clients harder and giving up business to do it. Freezes may also stay rare, since each one needs an issuer willing to act [7]. The likeliest path, on Treasury's own evidence, is that the trade moves, as it did when criminals shifted from Huione to Xinbi after Huione was sanctioned [12]. Xinbi's more than $24 billion in processed volume since 2022, by Treasury's count [11], is about 16 times the Bybit theft [19].

We think the cash-out desk is the right place to look and a poor place to expect volume. CryptoSlate argues that converting stolen crypto into spendable money is the hard part of the crime, and that the payment services involved let investigators and regulators intervene [13]. The counter-thesis comes from the same Treasury record, in which a venue of that size was itself the replacement for a sanctioned one [12]. If 442,000 USDT stays the only freeze this line of work produces, the evidence supports a narrower claim: a broker can be watched from inside, while recovery stays near three dollars per ten thousand stolen [17].

What to watch

  • Further Tether or other issuer freezes tied to the same broker network, the test of whether 442,000 USDT was a first batch or the whole result.
  • A Treasury designation of a successor venue to Xinbi Guarantee, repeating the move it described from Huione to Xinbi.
  • Disclosure of how many orders ZachXBT ran and his net loss, which would replace the single-pass fee estimate with the real cost of access.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence45
Adoption
Insufficient
Hype gap+25
Incentives
Insufficient
Confidence40
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    ZachXBT, a pseudonymous blockchain investigator, committed 349,700 USDC and accepted a 5% loss on each completed order while posing as a client of a Chinese laundering network.

  2. [2]

    The FBI attributed the Bybit theft to North Korean hackers on Feb. 26, 2025, identifying the activity as TraderTraitor and warning that stolen assets were being converted into Bitcoin and other cryptocurrencies before being distributed across thousands of blockchain addresses.

  3. [3]

    On March 6, 2025, ZachXBT says he funded a new Ethereum address with 349,700 USDC and began exchanging it for USDT on Tron through a contact using the Telegram alias Jimmy Green, accepting unfavorable exchange terms.

    ReportedSupportedSource: ZachXBT, as reported by CryptoSlate2 sources— create a free account to open themView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. cryptoslate.com

    1 article · October 10, 2026

    Stealing $1.5B in crypto is easy, cashing out is the trap

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories