Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

How Stolen Crypto Becomes Spendable: The Hidden Network Behind $1.5B Bybit Hack

A blockchain investigator infiltrated a cryptocurrency laundering network to trace funds from the February 2025 Bybit theft, revealing how North Korean hackers depend on intermediaries to convert stolen assets into usable money—and where authorities can intervene.
2 hours ago 15 views
How Stolen Crypto Becomes Spendable: The Hidden Network Behind $1.5B Bybit Hack

North Korean hackers stole approximately $1.5 billion from the cryptocurrency exchange Bybit in February 2025. While the initial theft received significant attention, the subsequent movement and conversion of those stolen funds has received less scrutiny—despite being critical to understanding how cybercriminals actually benefit from major exchange breaches.

Converting cryptocurrency theft into spendable money requires more than hacking an exchange. Thieves must rely on intermediaries willing to handle stolen assets, creating a network of relationships that investigators can potentially penetrate.

The Undercover Customer

Blockchain investigator ZachXBT, operating under a pseudonym, infiltrated a Chinese cryptocurrency laundering network by posing as a customer. Beginning in early March 2025, he funded transactions with 349,700 USDC, accepting unfavorable 5% exchange losses on each trade to establish credibility and gain access to the operation.

Working through a contact using the Telegram alias Jimmy Green, ZachXBT conducted repeated transactions while gathering information about planned fund movements. By comparing private discussions about upcoming transfers with actual blockchain activity, he obtained evidence that on-chain data alone could not provide: confirmation of who controlled specific addresses and their intent.

This approach revealed a cluster of more than $12 million in Bybit-linked funds across multiple blockchain networks. ZachXBT also reported that his investigation contributed to Tether freezing 442,000 USDT connected to the theft, though this represents only a portion of the stolen funds.

The Distance Between Tracing and Recovery

Identifying stolen cryptocurrency on public blockchains differs significantly from actually recovering it. While ZachXBT traced over $12 million in Bybit-linked assets, the frozen USDT amount demonstrates a key vulnerability in criminals' operations: centrally issued stablecoins like USDT can be restricted by their issuers, creating potential intervention points.

Native Bitcoin and other non-issued cryptocurrencies lack equivalent issuer controls. Authorities must instead rely on seizing assets held by custodians or obtaining keys through legal processes and cooperation from financial intermediaries.

As stolen cryptocurrency moves between wallets, blockchains, custodians, and trading counterparties, it fragments further. Each transfer may require additional evidence gathering or separate legal processes, allowing funds to move beyond regulatory reach.

Larger Criminal Infrastructure

The Bybit theft is one example within a broader ecosystem of cryptocurrency laundering services. In May 2025, the U.S. Treasury's Financial Crimes Enforcement Network identified Cambodia-based Huione Group as a financial institution of primary money laundering concern, finding it had laundered at least $4 billion in illicit proceeds between August 2021 and January 2025.

In September 2025, the Treasury sanctioned Xinbi Guarantee, a marketplace it said processed over $24 billion in digital assets and fiat currency since 2022, with North Korean hackers identified among its users. When Huione was sanctioned, criminals migrated to other providers, demonstrating that closing individual marketplaces does not eliminate the underlying demand for laundering services.

Where Vulnerability Emerges

For North Korean hackers, the theft itself is only the beginning. Converting stolen assets into forms criminals can actually use requires relationships with service providers who have reputational and financial interests to protect.

These dependencies create investigative opportunities. Service providers can reveal information about future transactions, other participants, and payment infrastructure needed to complete orders. When compared against observable blockchain activity, private communications between criminals and intermediaries can establish intent and control in ways public transactions alone cannot.

According to enforcement records, these vulnerabilities extend beyond major thefts. In 2020, the Justice Department charged two Chinese nationals with laundering over $100 million in cryptocurrency primarily from exchange hacks, including converting nearly $1.4 million in Bitcoin into prepaid Apple iTunes gift cards.

The Ongoing Challenge

Investigators still face substantial obstacles. Seizing assets, restricting financial access, and prosecuting service providers can increase the costs of operating criminal financial services, but the commercial incentives supporting those services often outlast periodic enforcement actions.

The dollar amount of a cryptocurrency theft cannot be automatically equated with money successfully converted into usable revenue or verified as spent for any particular purpose. The original theft, amounts moved through intermediaries, value converted into other forms, and amounts ultimately recovered are separate measures requiring separate evidence.

For now, North Korean hackers' reliance on commercial arrangements to make stolen cryptocurrency spendable remains their essential weakness—and investigators' most promising avenue for intervention.

Market snapshot

Top cryptocurrency prices

Explore all prices
Market prices will appear after the next scheduled refresh.