ZachXBT is a cryptocurrency investigator who publishes under the handle @zachxbt on X. His work examines crypto scams, thefts and the movement of stolen funds, combining blockchain transactions with evidence such as communications and public records.

His investigations are useful when you want to understand how a theft happened, where the money went, or what connects a suspected actor to an incident. A good first read is his September 2024 investigation into a $243 million theft: it shows both the transaction trail and the evidence used to connect it to people.

What is ZachXBT known for?

In a September 2025 account of his work, ZachXBT described himself as an independent researcher whose work had expanded from exposing questionable activity to helping teams respond to security incidents and investigating thefts for victims. His published cases show how that work can connect separate incidents and give exchanges and security teams leads to act on.

On February 26, 2025, he announced that he was joining Paradigm as an incident response advisor to assist its portfolio companies. Paradigm co-founder Matt Huang announced the appointment the same day.

The $243 million theft: connecting a money trail to people

In his September 19, 2024 thread, ZachXBT described a theft from a single crypto holder a month earlier. According to his investigation, attackers impersonated support staff to gain access to the victim's accounts and funds. He then followed the stolen assets through exchanges and conversions between cryptocurrencies.

One specific clue appears in point 11b of the readable copy of the thread: ZachXBT says a participant reused a deposit address, linking laundered funds back to the stolen funds. The reused address gave him a connection to follow across two parts of the money trail. It did not, by itself, identify who controlled the address; his argument about the people involved also drew on recordings and communications. He credits other investigators and exchange security staff, and distinguishes assets frozen from funds already returned.

How a reused address connected the trail

One clue in ZachXBT's $243 million investigation.

Earlier in the trail

Stolen funds

Later in the trail

Laundered funds

Same deposit address

Reused across both parts of the trail

ZachXBT's finding Address reuse linked laundered funds back to the stolen funds, according to his investigation.

What can this connection establish?

It supports a connection between funds. Identifying the person who controlled an address requires separate evidence. ZachXBT's argument about the people involved also drew on recordings and communications.

Conceptual illustration of point 11b in ZachXBT's September 2024 investigation, rather than a complete transaction map. Read the thread copy.

A later legal development adds a separate piece of evidence. On September 8, 2026, the US Department of Justice reported that Malone Lam pleaded guilty to participating in a RICO conspiracy. Its release describes a broader criminal enterprise involving more than $245 million. That figure has a different scope from the $243 million theft in the original thread.

The thread lays out ZachXBT's investigative argument. The later DOJ release records a guilty plea by Lam, whom he named in the investigation. That plea does not establish every allegation in the thread or resolve the legal position of everyone mentioned. This case lets you compare an early public investigation with a specific subsequent outcome.

Bybit: a documented contribution to attribution

The February 2025 Bybit hack provides another view of his work. On February 21, Arkham credited ZachXBT with solving its attribution bounty. Arkham said his submission tied the attack to Lazarus Group through analysis of test transactions, connected wallets and timing, and that it had shared the submission with Bybit.

In a February 22 post, ZachXBT also described an on-chain connection between the Bybit and Phemex hacks: funds from the two incidents had been commingled.

On February 26, the FBI attributed the theft of approximately $1.5 billion from Bybit to North Korea, using its designation TraderTraitor. The FBI notice does not mention ZachXBT or say it relied on his work.

Arkham's announcement documents ZachXBT's contribution; the FBI notice gives a separate government attribution. Neither establishes that the stolen balance was recovered.

Where to follow ZachXBT and what to read first

His main public channels are @zachxbt on X and Investigations by ZachXBT on Telegram. He links both in his public researcher statement. Use X for investigation threads and subsequent replies, and Telegram for alerts, updates and links to research.

For a first investigation with a later legal outcome, open the $243 million thread on X or its readable copy, then read the DOJ update on Lam's guilty plea. For a closer look at the transaction analysis itself, try his April 2024 report, How Lazarus Group laundered $200M from 25+ crypto hacks to fiat from 2020–2023.

Start with its Nexus Mutual founder hack section. ZachXBT compares mixer deposits and withdrawals using amounts and timing. In one part, he acknowledges that they do not match one to one, then describes a later connection between a post-mix address and the original theft address as additional support for his interpretation.

That passage shows where observation becomes inference: similar timing and amounts suggest a connection; the later address link strengthens it. It gives you a specific argument to examine in the accompanying transaction references and graphs. Read that section through to the fund destinations before moving to another incident in the report.