On-Chain Investigator ZachXBT: Money Laundering Gang Publicly Seeks Assistance
On-chain investigator ZachXBT stated that a group of Asian illicit actors, identified as handling stolen funds for North Korean attackers, is seeking help in public Discord servers and Telegram channels they use, to process card exchanges and withdrawals. The funds originate from the approximately $387.5 million theft incident at Bitget. Bitget disclosed on September 24 that unauthorized transfers occurred from hot and warm wallets, initially estimated at about $351.6 million, later revised to approximately $387.5 million, accounting for transfers on Zcash and TRON from the same incident. CEO Gracy Chen stated that the methods closely align with known North Korean hacker group patterns.
ZachXBT listed five aliases and corresponding chat accounts, along with on-chain exchange hashes, including Cc, jack, Melon, lolo/Marin, and HELP ME. Screenshots show users complaining in THORChain and SwapKit support channels about XRP not being credited to Bitcoin: one user claimed to have deposited 277,724 XRP but only received 431 back; another wrote that asset loss would cause significant trouble. Funds are reportedly jumping across different blockchains through cross-chain bridges and entering mixing services like Wasabi. THORChain has been accused of not banning wallets associated with the attackers.
The alias lolo/Marin, marked as Alias 4, previously appeared in the money laundering path of the April 18 Kelp DAO attack, which involved approximately $292 million. About 116,500 rsETH were withdrawn from a LayerZero-based cross-chain facility, with LayerZero and a security firm attributing the attack to TraderTraitor (also known as UNC4899), part of the broader Lazarus cluster. The FBI has linked TraderTraitor to the $308 million theft from Japan's DMM Bitcoin in 2024 and the $1.5 billion theft from Bybit in February 2025. ZachXBT noted that the same money laundering pattern has been observed after multiple attacks attributed to TraderTraitor, and plans to release more data in the coming weeks.
The sellers are intermediaries eager to convert stolen funds into Bitcoin and sever traceability, while buyers are service nodes still providing cross-chain exchanges and mixing services. The incident was driven by the need to process card exchanges, forcing operators into public customer service channels, with funds flowing from exchange hot wallets to bridges, then to mixing pools. The beneficiaries are investigators who can align chat identities with hashes on-chain, while the pressured parties are cross-chain protocols that failed to freeze paths in time and service providers still accepting support tickets. Analysis firms like TRM also noted overlaps between Bitget's stolen funds and past North Korean-related money laundering networks.
Source: Public Information
ABAB AI Insight
Three days ago, ZachXBT publicly stated he did not intend to follow up on the Bitget case, citing a lack of time for industry parties that do not support his work; three days later, he issued a lengthy post with five aliases, Discord IDs, and THORChain hashes, indicating that the investigation trigger was not a request for help from the exchange, but rather money launderers posting their tickets in public channels. This aligns with his past style: first mapping wallets, then waiting for people to present off-chain identities. Alias 4 appears in both Kelp and Bitget's money paths, advancing the two TraderTraitor-attributed incidents from "similar methods" to "the same group of movers."
The capital path involves state-backed attackers responsible for breaches and withdrawals, outsourcing to Chinese intermediaries for cross-chain and mixing services. Of the $387.5 million, approximately 10.3 million XRP left Bitget in three transactions, with 200,000 XRP entering THORChain. The intermediaries seek fees and exchange channels, avoiding public identities tied to attackers; the card exchanges forced them to report transaction hashes in Discord, effectively linking people, tickets, and chains. Wasabi receives Bitcoin that has already crossed bridges, aiming to convert freezeable exchange assets into harder-to-intercept mixed outputs.
This parallels how Lazarus used mixers to handle Ronin in 2022, the layered movements after the Bybit theft in 2025, and the FBI naming TraderTraitor after the DMM Bitcoin case. At the industry stage, attacks have shifted from "steal and run" to "must have a standby exchange": bridges and customer service channels have become laundering capacities. THORChain's refusal to pre-ban wallets shifts the cost of scrutiny to post-tracking. Bitget's loss adjustment from $351.6 million to $387.5 million indicates that hot wallet audits lag behind on-chain diversions.
Structural judgments reflect a reconstruction of the industry chain that regulatory changes have yet to catch up with. The mechanism is that licensed exchanges can freeze accounts, cross-chain protocols automatically exchange by hash, and customer service fixes issues by ticket, with three systems not sharing the same sanction list. State actors are responsible for high-cost intrusions, outsourcing low-tech, high-exposure movements to contractors who speak Chinese and use Discord. Public requests lower the cost of off-chain evidence collection and expose the outsourcing structure: attacks can be professionalized, but the laundering phase still relies on those who shout "assets not received" in public channels. If more hashes and accounts align in the coming weeks, the pricing power will shift from "can it be attributed to North Korea" to "which layer of service providers must be held accountable."