$350K Undercover Operation Exposes Network Moving Stolen Digital Assets

Blockchain investigator ZachXBT says he penetrated a Chinese organized-crime network suspected of processing cryptocurrency stolen in major cyberattacks attributed to North Korean hackers.


The investigation began after the $1.5 billion Bybit theft in February 2025, which the FBI attributed to North Korea's TraderTraitor actors.


Rather than observing transactions solely from the blockchain, ZachXBT posed as a customer and conducted real exchanges with suspected laundering intermediaries.


Public Support Requests Opened the Door

Following the Bybit incident, ZachXBT identified more than 15 accounts requesting assistance with transactions allegedly connected to stolen funds in public Telegram and Discord communities.


$349,700 Used to Establish Trust

On March 6, 2025, he funded a fresh Ethereum address with 349,700 USDC and began dealing with an operator using the identity “Jimmy Green.”


The intermediary offered to exchange Ethereum-based USDC for USDT on Tron. ZachXBT says he accepted losses of roughly 5% per transaction while building credibility.


One wallet supplied by Jimmy had received gas funding from another address directly associated with stolen Bybit assets and publicly blacklisted by the exchange.


Private Messages Matched On-Chain Movements

The investigation became more significant when information provided privately began matching subsequent blockchain transactions.


Transfers Were Discussed Before They Happened

According to ZachXBT, Jimmy disclosed planned movements of Bybit-related assets and, in one case, discussed a transfer to Solana before it appeared on-chain.


On March 12, the operator also supplied a screenshot of a bridging transaction. ZachXBT matched its amount and timing with a THORChain order created within minutes of the conversation.


Three Solana addresses later disclosed by the intermediary exposed a cluster containing more than $12 million in Bybit-linked proceeds moving across Bitcoin, Ethereum, Solana and Tron.


ZachXBT says Tether subsequently froze 442,000 USDT associated with the cluster.


Investigation Expanded Beyond Bybit

The conversations also produced leads involving earlier cryptocurrency thefts.


After Jimmy discussed funds belonging to another team that had been frozen in 2024, ZachXBT traced approximately 332,000 USDC to the Poloniex exploit.


The investigator says the broader organization has processed more than $1 billion across multiple exploits associated with North Korean operations.


That figure should be treated carefully: it is ZachXBT's assessment based on his investigation and should not be presented as an independently verified law-enforcement total.


Human Intelligence Meets Blockchain Forensics

The operation demonstrates how cryptocurrency investigations can extend beyond conventional wallet tracing.


By combining undercover interaction, wallet-funding relationships, cross-chain transaction timing and public blockchain records, investigators can potentially connect otherwise anonymous financial infrastructure to the people coordinating transactions.


The case also fits a broader trend.

 Chainalysis estimates Chinese-language money-laundering networks processed $16.1 billion during 2025, highlighting how specialized laundering services have become an increasingly important layer of the global cybercrime economy.


For North Korean operators, these networks potentially solve one of the hardest stages of cryptocurrency theft: turning traceable stolen assets into funds that can be moved, exchanged and ultimately monetized.