ZachXBT, the pseudonymous blockchain investigator whose work has led to arrests and asset freezes across the cryptocurrency industry, spent 349,700 of his own dollars posing as a client of a money laundering service to find out how North Korea moves stolen funds.
He funded a fresh wallet with 349,700 USDC, a token designed to hold a value of one US dollar, and placed repeated orders with a vendor using the name Jimmy Green, who took the business over Telegram and Discord. Each order cost him roughly 5%, with nothing to stop the vendor keeping the lot, and he kept placing them to collect as much as he could before the access closed.
What he collected was mostly conversation. Jimmy described operations in Hong Kong and mainland China, talked about mahjong and hunting wild rabbits between orders, and said his team had laundered most of the $1.5B taken from the exchange Bybit.
The checks on that account came from the chain itself. On one occasion Jimmy said the money would move to Solana, and the next day it did; a screenshot of a bridge transfer dated 12 March matched an order created on THORChain minutes earlier.
More solid still was the wallet paying the transaction fees. It traced back to funds from the Bybit theft that the exchange had already put on its public blacklist, which connected the service directly to the stolen money rather than to Jimmy's description of it. A blacklist of that kind is a public list of addresses an exchange will not accept deposits from.
From there the trail widened. Three Solana addresses identified a cluster holding about $12M of Bybit proceeds, and Tether froze 442,000 USDT linked to it, while other wallets connected to Huione Guarantee, a marketplace the United States has formally moved against.
The service was not working for North Korea alone. The same investigation turned up around $3M of fraud proceeds handled for another customer, and a $300,000 freeze in 2024 connected to an earlier theft from the exchange Poloniex, which places the operation closer to a general-purpose laundering business than a state contractor.
ZachXBT puts the network's total at more than $1B laundered across several thefts attributed to North Korea, and says he passed everything to law enforcement as he gathered it. Since 2022 his work has contributed to freezing around $75M of funds tied to the country.
The Theft That Started It
The Bybit hack in February 2025 remains the largest cryptocurrency theft recorded, and the way it happened matters more than the size. Attackers did not break into the exchange. They compromised a developer machine at Safe{Wallet}, the wallet software Bybit used to hold its reserves, then waited for a scheduled transfer from offline storage to the wallet used for daily business and redirected it to addresses they controlled.
The Federal Bureau of Investigation attributed the theft to the North Korean state group it tracks under three names, TraderTraitor, Lazarus Group and APT38. It said the attackers converted part of the haul to Bitcoin and scattered it across thousands of addresses on several blockchains within days.
That speed is why services like Jimmy's exist. Stealing the money takes one compromised laptop; turning $1.5B of traceable tokens into spendable currency takes an industry.
Where Stolen Crypto Goes To Be Cleaned
The marketplace that keeps appearing in these investigations has already been named by the American authorities. In May 2025 the Treasury's financial crimes unit designated Cambodia's Huione Group a primary money laundering concern and moved to cut it off from the United States financial system, citing at least $4B of illicit cryptocurrency handled since 2021. The analytics firm Elliptic put the figure closer to $11B.
Around $37M of that was tied to Lazarus, including proceeds from Bybit. "Huione is the marketplace of choice for DPRK hackers and criminal syndicates," the Treasury Secretary, Scott Bessent, said at the time, using the abbreviation for North Korea's formal name.
One detail from that action explains the whole economics. Huione issued its own dollar-pegged token designed to be impossible to freeze, which is a direct response to the single control that works in this market, because Tether and other issuers can and do freeze tokens at an address when told to.
The group's affiliated lender later faced a run on deposits and halted business. The laundering layer, in other words, is under real pressure, which is context for a network still able to charge 5% a time.
What One Person Can Do Alone
The method here is the part worth sitting with, because it is unusual and it has costs. An investigator who pays a criminal service and records what its operators say is gathering evidence an agency would need authorisation, a case number and a prosecutor to obtain. Money moved from his pocket into a network he was investigating, and he accepted that some of it might never come back.
The resulting account is also one person's record of private conversations with someone using a false name. The chain evidence is independently verifiable and the conversations are not, and a court would treat the two very differently.
What can be checked is the outcome. The investigation identified a specific cluster of $12M, Tether froze a specific 442,000 USDT, and both happened faster than any formal process has managed against the same funds.
The Freezes Are Small Against The Theft
Setting the recoveries beside the theft is the clearest way to read this. The investigation surfaced about $12M and froze a fraction of that, against $1.5B taken in a single morning. Across four years of this work the total frozen stands at roughly $75M, which is around 5% of the Bybit hack alone.
That gap is the structural problem rather than a criticism of the work. Tracing stolen cryptocurrency has become routine and often public, while getting it back still depends on an exchange, an issuer or a jurisdiction choosing to act, and North Korea has spent years building routes through places where nobody will.