Stealing $1.5B in crypto is easy, cashing out is the trap
Blockchain investigator ZachXBT infiltrated a Chinese laundering network to track $1.5 billion in crypto stolen by North Korean hackers from Bybit, exposing the complex challenges criminals face when cashing out illicit digital assets.
North Korean hackers pilfered roughly $1.5 billion from Bybit in February 2025. While the initial breach received extensive coverage and analysis, very few reports examined the aftermath or the ultimate destination of the stolen funds.
To move such massive sums, hackers must depend on an entire network of individuals willing to handle illicit assets. This dynamic creates a chain of personal connections that someone willing to invest sufficient capital can infiltrate.
That is precisely the strategy employed by ZachXBT, a pseudonymous blockchain investigator. Posing as a client of a Chinese laundering network, he invested 349,700 USDC and agreed to absorb a 5% loss on every completed order.
His efforts ultimately yielded information that helped trace upwards of $12 million in Bybit-associated funds and, based on his records, aided Tether in freezing 442,000 USDT.
His findings steered him toward a network he believes has laundered in excess of $1 billion originating from crypto thefts tied to the North Korean Lazarus Group, including capital from the Bybit breach.
The broader implications of these investigations point to a sprawling underground market for criminal financial services that American law enforcement has spent the last two years attempting to dismantle.
In September, the U.S. Treasury sanctioned Xinbi Guarantee—a marketplace accused of processing over $24 billion in digital assets and fiat currency since 2022—and explicitly named North Korean hackers among the unlawful groups utilizing its platform.
Furthermore, the Treasury noted that criminals attempted to maintain operations by transitioning from Huione to Xinbi following the former’s sanctions, demonstrating how shutting down one marketplace fails to eradicate the underlying demand and relationships that sustained it.
Surprising as it may sound, breaking into an exchange and lifting funds represents the easiest phase of these cybercrimes. Converting stolen cryptocurrency into fiat currency or other forms of tangible purchasing power is where the real challenges begin.
To accomplish this, hackers rely on payment handlers and shadowy networks that inadvertently create entry points for regulators and investigators.
The $349,700 customer
On Feb. 26, 2025, the FBI formally attributed the Bybit robbery to North Korean actors operating under the moniker TraderTraitor, cautioning that the pilfered assets were being converted into Bitcoin and other cryptocurrencies before dispersing across thousands of unique blockchain addresses.
While pointing out the hackers took little time, uncovering the intermediaries managing the laundered capital demanded much heavier investigative legwork.
According to ZachXBT, the process began when he noticed more than 15 accounts across public Telegram and Discord channels soliciting assistance with transactions connected to the stolen Bybit capital, indicating that parts of the laundering pipeline relied on open solicitations.
He reached out to several of these accounts, eventually forging a connection with an individual using the Telegram handle Jimmy Green, who posed as a broker needing assistance moving crypto across different blockchain networks.
On March 6, 2025, ZachXBT funded a fresh Ethereum address with 349,700 USDC and began swapping the dollar-pegged token for USDT on the Tron network via his contact, accepting poor conversion rates to establish his credibility as a legitimate client.
The 349,700 USDC constituted working capital committed to the operation rather than a confirmed net investigative loss, while the 5% fee sacrifice represented the price he was willing to pay to access intelligence standard blockchain analytics could never reveal.
Naturally, the strategy carried an inherent risk that the intermediary might simply abscond with the capital.
Because hackers must depend on intermediaries who might betray them in return, and because formal legal protections do not apply, personal familiarity and reputation remain paramount in keeping these illicit partnerships functioning.
This reality provided ZachXBT with an opening, as a customer who executed repeated transactions naturally became increasingly valuable to the service provider.
In time, the relationship generated intelligence stretching far beyond wallet addresses, including advance discussions regarding planned fund movements. This allowed ZachXBT to compare private statements against subsequent public blockchain activity.
On one occasion, the intermediary outlined plans to shift funds to Solana ahead of the actual transfer, while subsequent exchange and wallet associations helped flag a broader cluster of assets connected to the Bybit heist.
This breakthrough marked a major turning point for the investigation, as public ledger data alone cannot expose the identity or true intent behind a transaction. Private communications provided the vital evidence regarding who controlled the funds and how they were deployed.
Although ZachXBT’s independent probe does not completely align with official FBI findings, it remains one of the most remarkable investigative accomplishments of recent years. It proved that interpersonal and commercial networks can unearth evidence unreachable via the blockchain alone, serving as a blueprint for probing future crimes.
Tracing $12 million differs from recovering it
ZachXBT reported that data gathered through his association with Jimmy Green helped uncover a cluster comprising over $12 million in Bybit-tied funds, spanning multiple network transactions.
He also noted that Tether subsequently froze 442,000 USDT tied to the North Korean incident. This highlighted how swiftly identifying stolen assets—while they still reside within issuer-managed tokens like USDT or USDC—can prove vital to asset recovery.
These two figures should not be conflated: tracing more than $12 million does not mean the entire sum was frozen, and freezing 442,000 USDT does not equate to funds being seized or repatriated to Bybit.
While the specific 442,000 USDT metric and its link to ZachXBT’s efforts stem from his personal account, Tether has independently disclosed much larger freezes associated with the same hack.
A vast gulf exists between observing stolen crypto, identifying the handlers, and securing actual legal or technological control over the proceeds.
Public ledgers cannot prevent assets from shifting once more, particularly when they move through privacy services or entities that reject investigator cooperation or operate entirely outside legal jurisdictions.
Centralized stablecoin issuers present a distinct point of intervention because administrators retain the technical power to restrict transfers originating from flagged wallet addresses.
Native Bitcoin lacks any comparable issuer-controlled kill switch, though authorities can still restrain funds held by third-party custodians or seize private keys when they possess proper legal authority and technical access.
Consequently, investigators rely on more than mere tracking precision; an identified balance must also fall within the physical reach of an entity possessing the authority and technical means to act.
Throughout Bybit’s recovery campaign, court orders and intermediary cooperation allowed for asset restrictions long after the initial theft occurred, albeit without guaranteeing a full financial recovery.
The core challenge is that pilfered digital assets frequently fragment as they bounce between wallets, chains, custodians, and traders. Each additional hop may demand a fresh legal mandate or evidentiary source before the pursuit can continue.
This reality explains why investigators can frequently watch where capital travels while remaining powerless to halt the next transaction or reclaim the funds.
$4 billion in crypto laundering
The reliance on outside brokers is not unique to the Bybit incident; U.S. enforcement archives document a long-running pattern of identifying enterprises dedicated to scrubbing stolen crypto into usable capital.
Back in March 2020, the Department of Justice indicted two Chinese nationals—Tian Yinyin and Li Jiadong—for laundering upwards of $100 million in cryptocurrency, primarily tied to major exchange breaches.
These prosecutions underscored how individuals who do not execute the initial hacks still perform an indispensable function within the criminal ecosystem.
Furthermore, Treasury sanctions disclosures revealed that Tian converted nearly $1.4 million in Bitcoin into prepaid Apple iTunes gift cards, illustrating how money laundering can ultimately devolve into ordinary retail instruments rather than sophisticated institutional finance.
This identical economic imperative operates on a massive scale via marketplaces linking criminals with merchants offering settlement, exchange, and payout utilities.
In May 2025, the Financial Crimes Enforcement Network (FinCEN) designated the Cambodia-based Huione Group as a primary money laundering concern, estimating that its operations scrubbed at least $4 billion in illicit revenues between August 2021 and January 2025.
Out of that total sum, FinCEN identified at least $37 million in cryptocurrency originating from North Korean cyber heists, alongside proceeds generated by investment scams and cyber frauds.
While the $4 billion figure encompasses illicit transactions across diverse criminal categories, the $37 million represents the minimum North Korean-linked component specifically confirmed by agency findings.
ZachXBT infiltrates $1B crypto syndicate to expose Lazarus Group
FinCEN’s review also uncovered severe shortcomings within the group’s anti-money-laundering and customer-verification frameworks, admitting that lax oversight enabled one affiliate to inadvertently process capital linked to a North Korean heist.
The significance of these discoveries transcends isolated transactions because any intermediary offering reliable payment processing functions as infrastructure for multiple criminal enterprises, sparing individual syndicates the need to build custom laundering apparatuses.
This concentration of illicit activity makes such enterprises prime targets for financial sanctions, asset seizures, and severed banking relationships.
Although Huione’s marketplace processed staggering transaction volumes, operators sought alternative workarounds after Telegram disrupted specific network segments.
Marketplace turnover metrics and FinCEN’s conservative estimates of verified illicit proceeds measure distinct categories of activity, making it crucial to avoid labeling every dollar flowing through a platform as proven crime revenue.
The customers moved
A persistent dilemma for regulators is that a criminal marketplace can lose its digital infrastructure without extinguishing the underlying demand that made its services profitable, particularly when users can readily pivot to alternate providers.
In June 2026, the Department of Justice announced the seizure of a cloud computing account that hosted backend servers utilized by Huione Group subsidiaries, which were allegedly implicated in moving proceeds from scams and frauds.
This enforcement action followed earlier U.S. sanctions targeting technology integral to concealing illicit capital.
Nevertheless, neutralizing technical infrastructure does not automatically sever the ties binding criminal clients to willing intermediaries.
The U.S. Treasury underscored this limitation on Sept. 9 by sanctioning Xinbi Guarantee, describing an illicit marketplace that connected criminal syndicates with merchants providing technical and financial resources.
According to Treasury estimates, Xinbi processed the equivalent of over $24 billion in digital and fiat assets beginning around 2022, with its operations predominantly servicing Southeast Asian markets.
This immense scale places the enterprise squarely in the crosshairs of global efforts targeting criminal financial plumbing.
The Treasury further reported that cybercriminals attempted to sustain operations by migrating activities from Huione-linked channels to Xinbi following FinCEN’s earlier crackdown, with the new venue providing virtually identical services to an overlapping clientele.
Federal agencies outlined an agile commercial market where participants simply seek out new vendors whenever law enforcement disrupts established channels.
During the Huione sweep, Telegram purged thousands of channels connected to Huione Guarantee as merchants fled toward alternative marketplaces.
Consequently, the success of any law enforcement crackdown cannot be gauged strictly by the number of offline servers, accounts, or websites seized, given that persistent demand drives users to rebuild operations via surviving providers.
While such disruptions impose genuine costs—freezing balances, collapsing settlements, or cutting off trusted partners—the economic incentive to launder funds remains intact as long as cybercrime stays lucrative.
The central task for regulatory authorities is driving up costs and unreliability across the entire web of potential replacement services.
Tether’s freezes push crypto laundering networks toward other payment options
The regulatory clampdown on Xinbi illustrates how financial interventions can disrupt criminal operations while simultaneously forcing bad actors to alter their payment strategies.
A coordinated series of Tether freezes locked down more than $45 million in USDT across at least 22 wallets linked to Xinbi’s network.
In response, the marketplace informed users it would transition toward USDD, an alternative stablecoin architecture lacking the issuer-controlled address-freezing capabilities inherent to USDT.
This transition marked a critical development: while token-freezing mechanisms give investigators immense leverage when assets remain within administrative reach, targets eager to evade such oversight naturally migrate toward financial instruments governed by looser controls.
This migration demonstrates how squeezing one segment of the payment pipeline redirects transactions elsewhere, demanding that investigators track both the assets and the platforms facilitating their movement.
During the September offensive, authorities also targeted Xinbi-related infrastructure, restrained over $52 million in crypto assets, and watched withdrawal requests spike while rival marketplaces began cutting ties with laundering merchants.
These events remain distinct from the 442,000 USDT freeze credited to ZachXBT’s North Korean investigation, as public reporting does not confirm overlapping addresses, participants, or funds.
Even so, both scenarios prove that criminal syndicates rely on financial middlemen whose services create vulnerabilities, even long after a cyber theft concludes.
Where token issuers can freeze balances, exposure centers on identifiable wallet addresses. Where marketplaces service diverse criminal cartels, vulnerability extends to infrastructure, merchant alliances, and settlement networks.
Both avenues diminish the ease with which bad actors can move and spend stolen money without incurring heavy risks.
People behind the transfers are harder to replace
ZachXBT’s probe gained traction because he illustrated how paid human relationships yield actionable intelligence regarding the individuals coordinating transfers.
Criminal middlemen who routinely handle stolen digital assets cultivate professional reputations, preferred counterparts, and specialized knowledge regarding which platforms can process funds without triggering security alarms.
Such partnerships enhance operational efficiency over time, particularly when syndicates must shift immense wealth anonymously without risking theft by their own brokers.
At the same time, these dependencies create vulnerabilities that are difficult to replicate quickly if a trusted provider vanishes, especially if successor services demand steeper fees, reject suspect assets, or prove unreliable.
These operational relationships also supply investigators with critical evidence, as service providers can inadvertently expose details about upcoming transactions, network participants, and underlying payment infrastructure.
While investigators must rigorously cross-reference such intelligence against observable blockchain activity—acknowledging that receiving stolen funds does not automatically prove intent or knowledge on the recipient’s part—comparing private chatter with public ledger movements helps eliminate ambiguities that pure transactional tracing cannot resolve.
The broader enforcement record emphasizes that crippling criminal financial services demands far more than periodic website takedowns, because the client demand and commercial motives supporting these networks invariably outlive the hardware used to host them.
Seizing assets, restricting financial access, prosecuting operators, and unmasking settlement brokers can shift the financial calculus, though the threshold where operational expenses eclipse crime revenue varies by enterprise.
This reality also clarifies why the nominal dollar value of a crypto hack cannot be treated as clean, spendable revenue for a foreign government, let alone a verified sum deployed for specific state or military budgets.
The initial breach, the volume routed through intermediary wallets, the capital successfully converted into purchasing power, and the total assets recovered by authorities represent entirely distinct metrics requiring independent verification.
For North Korean hackers, relying on professional laundering networks injects severe post-breach risk, confirming that seizing stolen assets does not eliminate the monumental hurdle of getting third parties to accept, exchange, and spend them.
ZachXBT’s infiltration highlights how human dependencies can convert customer interactions into investigative breakthroughs, while U.S. crackdowns on Huione and Xinbi show how supporting infrastructure remains vulnerable even as criminals scramble to new providers.
The ultimate structural weakness is that stealing cryptocurrency and successfully deploying it in the physical world are two distinct challenges—and the latter remains tethered to commercial relationships whose participants possess assets, reputations, and financial interests of their own.
Efforts by North Korean hackers to render their loot spendable inevitably drag them back into webs of human trust, and those who provide that trust have plenty left to lose.
Frequently Asked Questions
- Who is ZachXBT? ZachXBT is a well-known pseudonymous blockchain investigator who uses on-chain data and investigative techniques to track stolen cryptocurrency and expose illicit financial networks.
- How did ZachXBT infiltrate the laundering network? He posed as a client of a Chinese laundering network, committing 349,700 USDC and accepting a 5% loss per transaction to establish credibility and gather private communications.
- What is the main challenge for crypto hackers after a theft? While hacking an exchange is relatively straightforward, converting stolen digital assets into fiat currency or real purchasing power without getting caught or losing funds to intermediaries is extremely difficult.
- What role do stablecoins like USDT play in tracking stolen funds? Centrally issued stablecoins like USDT allow issuers to freeze funds at specific addresses, providing a vital point of intervention for investigators and regulators.
- Why do enforcement actions often fail to stop criminal networks completely? Shutting down a marketplace infrastructure does not eliminate the underlying criminal demand; users simply migrate to alternative service providers and backup channels.



