Stealing $1.5B in crypto is easy, cashing out is the trap
North Korean hackers stole around $1.5 billion from Bybit in February 2025. While the hack itself has been widely covered and analyzed, few have focused on what happened afterward and what became of the stolen funds. To move all that money, hackers needed to rely on an entire network of people willing to handle stolen […] The post Stealing $1.5B in crypto is easy, cashing out is the trap appeared first on CryptoSlate.
North Korean hackers stole around $1.5 billion from Bybit in February 2025. While the hack itself has been widely covered and analyzed, few have focused on what happened afterward and what became of the stolen funds.
To move all that money, hackers needed to rely on an entire network of people willing to handle stolen assets, creating a chain of relationships that someone prepared to spend enough money could infiltrate.
That's what ZachXBT, a pseudonymous blockchain investigator, did. He committed 349,700 USDC and accepted a 5% loss on each completed order while posing as a client of a Chinese laundering network.
He eventually obtained information that helped him trace more than $12 million in Bybit-linked funds and, according to his account, contributed to Tether freezing 442,000 USDT.
His investigation led him to a network he believes laundered more than $1 billion from crypto thefts linked to the North Korean Lazarus Group, including proceeds from the Bybit attack.
The implications of his investigations extend to a much larger market for criminal financial services that American authorities have spent the past two years trying to disrupt.
In September, the US Treasury sanctioned Xinbi Guarantee, a marketplace it said has processed more than $24 billion in digital assets and fiat currency through its platforms since 2022, and explicitly identified North Korean hackers among the illicit actors reported to have used its services.
Treasury also acknowledged that criminals tried to preserve their operations by moving from Huione to Xinbi after it was sanctioned, showing how removing one marketplace doesn't eliminate the relationships and demand that supported it in the first place.
Believe it or not, hacking an exchange and stealing funds is actually the easiest part of this crime. Converting stolen crypto into fiat or another form of real purchasing power is where it gets difficult.
To do that, hackers rely on payment services and other shady relationships that let investigators and regulators intervene.
The FBI attributed the Bybit theft to North Korean hackers on Feb. 26, 2025, identifying the activity as TraderTraitor and warning that stolen assets were being converted into Bitcoin and other cryptocurrencies before being distributed across thousands of blockchain addresses.
While it took no time to identify the hackers, identifying the intermediaries handling the stolen money required much more investigative work.
According to ZachXBT, he began that work when he saw more than 15 accounts in public Telegram and Discord groups seeking help with transactions tied to the stolen Bybit funds, suggesting that at least part of the subsequent laundering process involved intermediaries openly soliciting or arranging services.
He contacted several of those accounts and eventually developed a relationship with someone using the Telegram alias Jimmy Green, who presented himself as someone who needed help moving cryptocurrency between networks.
On March 6, 2025, ZachXBT says he funded a new Ethereum address with 349,700 USDC and began exchanging the dollar-linked token for USDT on Tron through the contact, accepting unfavorable exchange terms while trying to establish himself as a credible customer.
The 349,700 USDC represented capital committed to the transactions rather than a disclosed net investigative loss, while the 5% he says he lost on each order is the cost he was prepared to accept for access to information that ordinary blockchain analysis could not provide.
The arrangement also carried the risk that the intermediary could just disappear with the funds.
Hackers depend on intermediaries who might steal from them in turn, and without enforceable commercial protections, reputation and personal familiarity become especially important to keeping those relationships working.
That gave ZachXBT a way into the operation, since a customer willing to conduct repeated transactions became more valuable to the person providing the service.
The relationship eventually produced information beyond wallet addresses, including discussions of planned fund movements before the transactions occurred, allowing ZachXBT to compare statements made privately with activity subsequently recorded on public blockchains.
In one instance, the intermediary discussed moving funds to Solana before the corresponding movement took place, while other exchanges and wallet connections allegedly helped identify a larger cluster of assets linked to the Bybit theft.
This was a major turning point in his investigation, because on-chain data can't identify the person behind the transaction or its intent. Private conversations about a transaction provided the key evidence about who controlled it and what they used it for.
Even though ZachXBT's investigation still doesn't completely match the FBI's official record, it's still one of the most significant investigative efforts we've seen in a while. It showed that personal and commercial relationships can provide evidence blockchain alone can't, and that similar tactics could help investigate and eventually resolve other thefts.
ZachXBT said information from his relationship with Jimmy Green helped identify a cluster with more than $12 million in Bybit-linked funds, including transactions across several networks.
He also reported that Tether later froze 442,000 USDT linked to the North Korean hack. This showed that quickly identifying stolen assets, while they remain accessible through issuer-controlled tokens like USDT or USDC, can be crucial to recovering the funds.
The two amounts should not be confused: tracing more than $12 million does not mean the entire amount was frozen, and freezing 442,000 USDT does not mean the tokens were seized or returned to Bybit.
The specific 442,000 USDT figure and its connection to ZachXBT's investigation come from his account, although Tether has separately disclosed larger freezes tied to the Bybit theft.
There's a considerable distance between observing stolen cryptocurrency, identifying the people handling it, and obtaining legal or technical control over the proceeds.
Public blockchains don't prevent the assets from moving again, especially when they pass through services that refuse to cooperate with investigators or operate beyond the reach of relevant authorities.
Centrally issued stablecoins create a potential intervention point because their issuers can retain the administrative ability to restrict transfers from designated addresses.
Native Bitcoin has no equivalent issuer-controlled restriction, although authorities can still restrain assets held by custodians or seize the keys controlling them when they obtain the necessary access and legal authority.
That leaves investigators dependent on more than tracing accuracy, since an identified balance must also remain within reach of someone who has the technical ability and authority to act.
During Bybit's recovery effort, court orders and cooperation from financial intermediaries could restrict assets long after the initial theft, without guaranteeing full recovery.
The problem is that stolen cryptocurrency can become increasingly fragmented as it moves between wallets, chains, custodians, and trading counterparties, with each additional service potentially requiring another source of evidence or another legal process before the pursuit can continue.
That's why investigators can see where the funds traveled but have no way to stop the next transaction or recover the funds.
The use of outside intermediaries isn't limited to the Bybit theft, and American enforcement records show a longer history of attempts to identify businesses that convert stolen crypto into assets criminals can use.
In March 2020, the Justice Department charged two Chinese nationals, Tian Yinyin and Li Jiadong, with laundering more than $100 million worth of crypto, primarily through activity connected to exchange hacks.
These charges show how individuals who don't carry out the hack can still play an essential role in the crime.
The Treasury's sanctions announcement also revealed that Tian converted nearly $1.4 million in Bitcoin into prepaid Apple iTunes gift cards, showing how laundering can eventually involve ordinary retail instruments rather than the more elaborate financial services usually associated with international cybercrime.
The same economic requirement operates on a much larger scale through marketplaces that connect criminals with merchants offering settlement, exchange, payment and other services.
In May 2025, the Treasury's Financial Crimes Enforcement Network identified Cambodia-based Huione Group as a financial institution of primary money laundering concern, finding that its operations had laundered at least $4 billion in illicit proceeds between August 2021 and January 2025.
Of that amount, FinCEN identified at least $37 million in crypto stemming from North Korean cyber thefts, along with other proceeds from investment fraud and cyber scams.
The $4 billion figure reflects illicit activity across several crime categories, and the $37 million represents the minimum North Korean-linked component identified in the agency's findings.