How did ZachXBT infiltrate the North Korean laundering crew for the $1.5 billion Bybit hack?

ZachXBT infiltrated a Chinese laundering syndicate by posing as a scammer on Telegram, gaining direct access to operatives moving $1.5 billion for North Korea. The operation provided intelligence that allowed authorities to freeze stolen crypto assets and verify the North Korean origin of the Bybit exploit flows.
How did ZachXBT infiltrate the North Korean laundering crew for the $1.5 billion Bybit hack?

On-chain investigator ZachXBT successfully infiltrated a Chinese laundering crew by posing as a fellow scammer on Telegram to track $1.5 billion in stolen funds from the Bybit hack. By embedding himself within their communications, ZachXBT established a rapport with a key launderer who shared sensitive intelligence, including personal photos of dinner, updates on North Korean leader Kim Jong-un, and an invitation to play mahjong. This social engineering feat allowed the investigator to map the flow of assets and attribute them directly to North Korean state-sponsored actors.

To maintain the operation and secure actionable intelligence, ZachXBT fronted $349,700 of his own capital to facilitate the tracking process. The information gathered during this undercover mission was instrumental in identifying the specific wallets used to move the $1.5 billion. Consequently, security teams and law enforcement agencies were able to freeze a portion of the illicit funds, significantly disrupting the DPRK’s ability to cash out the proceeds from the 2026 exploit.

This incident highlights the evolving nature of North Korean cyber-warfare, which increasingly relies on sophisticated networks of third-party facilitators in China to bypass exchange KYC protocols. For the broader crypto market, the success of this investigation underscores the importance of on-chain forensics in mitigating the impact of large-scale exchange hacks. It also puts centralized exchanges (CEXs) like Bybit under increased pressure to enhance their monitoring of suspicious OTC (over-the-counter) flows linked to these laundering syndicates.

From a regulatory perspective, the US Treasury’s Office of Foreign Assets Control (OFAC) is likely to use this intelligence to issue new sanctions against the specific Telegram handles and wallet clusters identified by ZachXBT. Investors should watch for increased volatility in assets associated with these frozen funds and a potential tightening of withdrawal limits on major exchanges as platforms bolster their anti-money laundering (AML) defenses.

The geopolitical implications are significant, as North Korea continues to use stolen cryptocurrency to fund its weapons programs, bypassing traditional financial sanctions. The ability of independent investigators to penetrate these high-level laundering rings suggests that while the Lazarus Group remains a potent threat, the transparency of the blockchain remains a critical tool for global security agencies in 2026.

Editorial method

This report is based on the linked source and is labeled with its publication date, provider, category and market-impact assessment. Market interpretation is informational, not investment advice.