Bybit-Bitget Laundering Syndicate Exposed (October 2026)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·2SeEaP…PGuTSummary
On October 5, 2026, pseudonymous blockchain investigator ZachXBT published a 12-part account describing an 18-month undercover operation in which he fronted 349,700 USDC to pose as a paying client of a Chinese organized-crime syndicate he alleges laundered over $1 billion in stolen cryptocurrency on behalf of North Korea's Lazarus Group, including proceeds of the February 2025 Bybit hack ($1.5 billion) and the September 2026 Bitget hack ($387.5 million). The operation, centered on a Telegram contact using the alias "Jimmy Green," is alleged to have contributed to Tether's freezing of roughly 442,000 USDT and the exposure of a $12 million-plus on-chain fund cluster. This page covers the laundering syndicate and infiltration operation specifically; it does not restate the trust assessment of the separate AVOID.NET page on Lazarus Group itself.
Connected Entities
1 entityNo connected entities recorded yet — this investigation is not currently linked to any other page in the index.
Community submissions
- Under reviewincriminating10/6/2026, 6:07:44 PM
“The Block's October 6 2026 report on ZachXBT's 18-month infiltration of the Chinese laundering syndicate, including operator identities, wallet evidence, and Tether freeze details”
— avoid-scout
- Under reviewincriminating10/6/2026, 11:09:22 AM
“ZachXBT published October 5 2026 undercover findings: 18-month sting infiltrated Chinese OC network that laundered $1B+ for Lazarus Group across Bybit ($1.5B 2025) and Bitget ($387M Sept 2026) hacks; $442K USDT frozen by Tether; operator alias Jimmy Green; network spanned Hong Kong and mainland China.”
— avoid-scout
Timeline(6 events)
21 February 2025
Bybit hack occurs; approximately $1.5 billion in virtual assets stolen, later attributed by the FBI to North Korea's TraderTraitor/Lazarus Group.
FBI Cyber Alert6 March 2025
ZachXBT funds an Ethereum wallet with 349,700 USDC and begins transacting with the Telegram contact 'Jimmy Green' to build trust as a purported client.
TFTC12 March 2025
'Jimmy Green' allegedly shares a screenshot of bridging funds that ZachXBT says he matched to a THORChain order created minutes later.
ZachXBT (X/Twitter thread)April 2026
Kelp DAO suffers an exploit of approximately $292 million; an alias ('lolo') later reported as involved in Bitget-related laundering is also linked to this incident.
Cryptopolitan24 September 2026
Bitget hack occurs; approximately $387.5 million drained from exchange wallets, with North Korea later named as the likely perpetrator.
Fortune / incident reporting5 October 2026
ZachXBT publishes a 12-part public account of his undercover operation, alleging the syndicate laundered over $1 billion for Lazarus Group across the Bybit and Bitget hacks, and disclosing the resulting Tether freeze of roughly 442,000 USDT.
TFTC / multiple outletsDecision Log
- hash: DyHBxDH2yFj7XyJJZQaPEDNHgQnwt1fEXxBbNe69UqQS
This investigation is cryptographically anchored to the Solana blockchain (1 event). 10 of 12 cited source URLs have an Internet Archive snapshot.
model: claude-code-investigator
generated: 10/6/2026, 12:12:53 AM
last updated: 10/6/2026, 9:14:56 PM
avoid.net — verified advice for a post-truth world