Invest6 publishers3 min readPublished
ZachXBT staked $349.7K of his own money to pose as a client of North Korea's launderers
ZachXBT says he fronted $349.7K in USDC to pose as a client of the Chinese syndicate laundering North Korea's Bybit haul. The only recovery on record, a 442K USDT freeze by Tether, covers at most 3.7% of the $12M+ cluster he says the sting exposed.
The Investor · Invest desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- His counterparty, a Telegram contact called Jimmy Green, took USDC on Ethereum and paid out USDT on Tron.
- After several trust-building trades, Jimmy began describing North Korea's Bybit fund moves before they happened, plus details of the operation in Hong Kong and mainland China.
- The FBI attributed the $1.5 billion February 2025 Bybit exploit to North Korean hackers it tracks as TraderTraitor.
- ZachXBT says he has helped action more than $75 million in North Korea-linked freezes since 2022, paid for by grants and donations.
- He says the same public solicitations reappeared after last week's $387 million Bitget hack, another theft Bitget's CEO, Elliptic and Chainalysis have linked to North Korea.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- cost An individual investigator's money, backed by grants and donations, ended up as float inside North Korea's laundering pipeline, and every order handed 5% to the people he was investigating.
- constraint Getting money back for Bybit's victims depended on what one issuer chose to freeze, and that was a small slice of the funds the sting identified.
- precedent With the same public solicitations reappearing after the Bitget hack, the approach can be repeated, and the limit on the next case is how much float an investigator can afford to lose.
The $349.7K was float [1]. ZachXBT put it in a new Ethereum address and cycled it through Jimmy's swaps [12], so each order sent back USDT for most of what went out. The cost was the 5% each order lost [2]. At that rate, one full pass of the stake costs $17,485 [16]. Decrypt's account does not give the number of orders, the total loss, or whether anyone reimbursed him.
He put the exposure higher than the haircut. "For this case, I fronted $349.7K and lost 5% on each order, with no guarantee Jimmy wouldn't disappear with the funds, and an unknown amount of personal risk from dealing with the syndicate," he said [6]. He chose to keep paying the fee: "At this point, I realized I needed to continue losing 5% per order and gamble on capturing as much actionable intel as quickly as possible," he wrote [8].
The recovery side is Tether's freeze of 442K USDT [4]. Counting both stablecoins at a dollar, the freeze is about 1.26 times the stake [17] and about 0.03% of the $1.5 billion taken from Bybit [19]. It is also under 0.6% of the freeze total he claims since 2022 [20].
There are three ways to score it. On the investigator's own costs, the sting probably paid: his haircuts would only exceed the frozen sum after about 25 full-stake orders [21]. On attribution, the freeze count undersells it. The address Jimmy supplied had been funded with gas by a wallet traceable to Bybit exploit funds [15], Jimmy said funds would move to Solana a day before they did [14], and ZachXBT says the same group has laundered more than $1 billion for Lazarus Group across several exploits [22]. On money returned to victims, the result is thin, at most 3.7 cents per dollar of the cluster he identified [18].
I think the third score is the right one for anyone relying on this model to get stolen money back. The investigation found more than $12 million [3], and what got frozen was the part one issuer acted on [4]. The counter-thesis is that attribution compounds: an investigator who can see a syndicate's next chain move ahead of time can feed freezes on later thefts, and the $387 million Bitget hack, where he says the same pattern reappeared, is the next test [11]. If freezes or seizures traced to the Hong Kong and mainland China details Jimmy gave turn up beyond Tether's 442K [13], my view is wrong.
The capital came from a pseudonymous investigator who says grants from foundations and donations from individuals are what let him take cases this risky [10]. He got in through 15+ accounts asking for help with stolen-fund orders in public Telegram and Discord groups [7].
What to watch
- ZachXBT disclosing his order count or net loss, the figure that sets the sting's real cost against the 442K USDT frozen.
- Freezes or seizures traced to the Hong Kong and mainland China details Jimmy gave, beyond Tether's single action.
- Whether issuers freeze funds from the $387 million Bitget hack, where he says the same public solicitations reappeared.