ZachXBT pfp

ZachXBT

@zachxbt

114 Following
81064 Followers


ZachXBT pfp
ZachXBT
@zachxbt
I am pausing my activity on Warpcast for the foreseeable future due to the current issue with large number of bots. Recent posts over the past few months have received hundreds of likes and recasts coming mostly from bots.
161 replies
160 recasts
763 reactions

ZachXBT pfp
ZachXBT
@zachxbt
Posted an overview about all of the recent account restrictions for Coinbase users and how it relates to $300M+ stolen via social engineering scams. https://x.com/zachxbt/status/1886411879939031530
18 replies
116 recasts
267 reactions

ZachXBT pfp
ZachXBT
@zachxbt
A Coinbase user was likely social engineered and scammed for 110 cbBTC ($11.5M) on Base last month by a threat actor. The stolen funds were immediately swapped, bridged, and laundered through multiple instant exchanges and funds consolidated with other Coinbase victims on Ethereum. Theft transaction hash 0x8639f4b4420d47d68f27dc27967ff62ec913106e5b9ce99011de99b8d91813cd 0xb5895314777776da645529df83cd0d0883ed456e2c81e27c97eb5cf45a59c36b 0xfa26f3917519444c7d3d9ca05fc70b289d44958cb55801b9221d7b492f41c76d Coinbase social engineering scams have resulted in $150M+ / yr stolen from users due to data breaches, email/call spoofing, bad detection, etc
10 replies
117 recasts
278 reactions

ZachXBT pfp
ZachXBT
@zachxbt
Someone was likely hacked for $29M (6.27M SUI) on Sui last month on December 12th, 2024. The stolen funds were bridged from Sui to Ethereum via Bridgers and then deposited to Tornado Cash in batches. Primary theft address 0x731c2cd8f060428e7bb520899c855b48bf4b22d981f07a69ce3d0a258f3e589a Theft transaction hash 4xo5ub1BbxgHjFwJv7iBaC4mfds8JSpHAYihAeKDwPBU 6VbgJTWMvomi4VY8hoZcUNPUVaaFcWjZRfxjtdV6MCHo 2WHUdTGonBwDsYW4nVK7zVEVtG9PnRSE9HCRgcmouYgM The victim transferred their .sui domains to a new uncompromised address shortly after the theft. Current limitations with Sui block explorers make the theft difficult to trace.
7 replies
99 recasts
349 reactions

ZachXBT pfp
ZachXBT
@zachxbt
The P2P marketplace Noones was likely exploited for ~$7.9M on Ethereum, Tron, Solana, & BSC on January 1-2, 2025 as its hot wallets saw hundreds of suspicous outflows for <$7K per txn. Shortly after the platform made an announcement about maintenance although no official statement was made about any security incident. Funds were bridged to Ethereum/BSC and then deposited to Tornado Cash. Theft consolidation addresses: Ethereum 0x72c1eabafc42a2ac6d0447b02c657b96f07402e6 0x4b0edd27196063476d91b634333be289beca9202 0x6c9b55b50e6a42fd7a14b49ba7747096090b0465 Tron TLRzLWbrCPVjXEcTDHv4Lavm6CxonUgJST TSnsmxEPy7rqk9XRsCiYEk5ntchweGFq2A BSC 0x72c1eabafc42a2ac6d0447b02c657b96f07402e6 Solana BBJoEgHq1igbH4fXfLtxRBodpFb1qcYQRk4UCpzVKobo
0 reply
57 recasts
189 reactions

ZachXBT pfp
ZachXBT
@zachxbt
Here’s a 31 minute video of the phishing scammer ‘Vkevin’ secretly being recorded draining victims while running a fake Safeguard verification bot scam on Telegram. https://x.com/zachxbt/status/1882370833429254523
10 replies
79 recasts
282 reactions

ZachXBT pfp
ZachXBT
@zachxbt
The Blockchain Bandit attacker woke up after being dormant for multiple years and consolidated 51,000 ETH ($172.2M) to a single multisig. Multisig address 0xC45C36017b0B7708f493534Ca4f0930964C1D542
34 replies
197 recasts
755 reactions

ZachXBT pfp
ZachXBT
@zachxbt
A few hours ago a victim was drained on Solana for $2.2M+ worth of meme coins ($1.43M PNUT, $400K ZEREBRO, $130K ALCH, etc) Theft address 7DQZQzydMPhFdhQnFYkwwNkykqeYADcj14JxYLAgVbBm 2CJ5d3o6MaCsgmZNZRrDE9fHuWRZ3Gpc5MBdMkz6HUxy 8qRK51ghCidRvwpYNRiu9hdUsg6UA7ZQF71HCAeUnBDZ
20 replies
72 recasts
435 reactions

ZachXBT pfp
ZachXBT
@zachxbt
A few hours ago wallets tied to crypto influencer JRNY saw ~$4M worth of crypto assets suspiciously transferred out and sold indicating a potential private key compromise. Theft address 0xc467150582cfc8eec4132a483c76101d3636f598 0x6fd6c8fd64c7efdb8eec902161d3bbc035430456 0xa2dd5e2ab84240cbecc7beaca9946afef97ae74a
15 replies
28 recasts
219 reactions

ZachXBT pfp
ZachXBT
@zachxbt
Multisig exploiter just transferred 9980 ETH ($31.4M) to the crypto exchange exchange eXch, swapping from Ethereum to Bitcoin in 7 orders. Source address 0x2d146Aa23645950FDefBb23f636A5d1674FE1047 Destination address bc1qffvx38hplm6ym5el5yakxmntezv7tg6yurghnq bc1qut035lpe0k6yklcrkaquhvg4x65lkg5n3uvnel bc1qe6yk9rnae0l96775gu99zvjdy496j3rrfc5sm0 bc1q4cwvw5x89pjaquq5e25ghjgffevmz6rtz043tx bc1qpj24paw8hunju2z6fharwej82rfjywexsz629a bc1qrzzdx82jv4t4tlkfc0gsqjpjp2r9r6ptq7rtuf bc1qyht95cksxh2un0elgdaq0up874s99kj80ev97d
5 replies
43 recasts
321 reactions

ZachXBT pfp
ZachXBT
@zachxbt
Looks like the crypto casino Metawin was exploited for $4M+ on Ethereum and Solana earlier today. See 115+ theft addresses tied to the exploiter below. So far stolen funds have been transferred to Kucoin and a HitBTC nested service. https://www.chainabuse.com/report/094193aa-aba7-4af8-b7e6-84f0a6b608db
13 replies
104 recasts
295 reactions

ZachXBT pfp
ZachXBT
@zachxbt
The crypto exchange M2 was hacked for ~$13M from hot wallets on multiple chains yesterday. Theft addresses ETH: 0x968b6984cba14444f23ee51be90652408155e142 BTC: bc1qu4kh7wa38xpkrp8frgxl4sak88wx0jug8n3vfj SOL: EKko14NvgqdvNttUb8JjXkVGuUs6BTikjfN3hqW4LQoL
3 replies
25 recasts
235 reactions

ZachXBT pfp
ZachXBT
@zachxbt
Looks like $20M of seized funds tied to the US Government was likely stolen in the past hour. Theft address 0x3486ee700ccaf3e2f9c5ec9730a2e916a4740a9f 0xbf6f7c503e858aded4e18ce2bcf93846fd726c15 0x15d0a31ed5050ed8decd3c101aaee0b2ad2e6441
18 replies
35 recasts
283 reactions

ZachXBT pfp
ZachXBT
@zachxbt
I recently spoke with Andy Greenberg from WIRED, who did a profile that dives into my journey over the past few years. It was a great experience to reflect on the evolution of my investigations. https://www.wired.com/story/meet-zachxbt-243-million-crypto-theft/
16 replies
97 recasts
427 reactions

ZachXBT pfp
ZachXBT
@zachxbt
My new research detailing a Chinese OTC trader named Yicong Wang who Lazarus Group has used since 2022 to off-ramp tens of millions from crypto hacks. https://x.com/zachxbt/status/1849071080180240751
7 replies
46 recasts
191 reactions

ZachXBT pfp
ZachXBT
@zachxbt
Tapioca DAO hack is likely the result of a team member downloading malware as the theft is tied on-chain to other recent hacks such as Nexera, Concentric, Masa, SpaceCatch, Reach, Serenity Shield, MurAll, etc I have previously covered which were the result of fake job scams (contagious interview). Stolen funds from this incident were bridged from Arbitrum to BSC where ~$4.7M currently sits. 0x69d91e56ca80f2a4d7b808b59053ea5c5505ffe2
5 replies
29 recasts
152 reactions

ZachXBT pfp
ZachXBT
@zachxbt
I went and attributed 16 exchange hot wallets on Starknet so they would be publicly tagged on block explorers as I noticed none were previously tagged anywhere. Binance 0x0213c67ed78bc280887234fe5ed5e77272465317978ae86c25a71531d9332a2d OKX 0x0269ea391a9c99cb6cee43ff589169f547cbc48d7554fdfbbfa7f97f516da700 Bybit 0x076601136372fcdbbd914eea797082f7504f828e122288ad45748b0c8b0c9696 Kraken 0x620102ea610be8518125cf2de850d0c4f5d0c5d81f969cff666fb53b05042d2 Kucoin 0x0566ec9d06c79b1ca32970519715a27f066e76fac8971bbd21b96a50db826d90 HTX 0x03fd14213a96e9d90563ebe1b224f357c6481a755ee6f046c8ce9acd9b8654a7 MEXC 0x069a7818562b608ce8c5d0039e7f6d1c6ee55f36978f633b151858d85c022d2f Gate 0x00e91830f84747f37692127b20d4e4f9b96482b1007592fee1d7c0136ee60e6d Bitget 0x0299b9008e2d3fa88de6d06781fc9f32f601b2626cb0efa8e8c19f2b17837ed1 HitBTC 0x04b555a99b585adf082754e5ea36e4202f13efa649e6ac16dfe8c0e217c454bc CoinEX 0x00fb108ed29e1b5d82bb61a39a15bbab410543818bf7df9be3c0f5dd0d612cf3
13 replies
59 recasts
156 reactions

ZachXBT pfp
ZachXBT
@zachxbt
45 minutes ago a victim was drained for 12K spWETH ($32.4M) Theft address 0x471c725Bd1F29850CBb8eeA4cdf6c9Ce3caC5607 Theft txn hash https://etherscan.io/tx/0xf7c00f18175cdea49f8fdad6a1d45edeb318f18f3009f51ab9f4675171c1d8fb
17 replies
12 recasts
119 reactions

ZachXBT pfp
ZachXBT
@zachxbt
The project Truflation was hacked a few hours ago for $5M+ on multiple chains from the treasury multisig and personal wallets EVM theft address 0x53d2094b31429a13e739358b16354d8e0826b25a 0x2122a76213b23daf633b850cb659750db0cac801 0x4ec10144f1a96eed9b04d324d0997b5325c56472 0x7ea07c76328fc789435fc77a2a4d527c5bbc333e 0x3f8e5cc8abd032dd6ad652423e951ab06f833126 SOL theft address 6v4R3z5ahHqx3pbxMpYQMu26cuQoonLX2Rqq7WF35yzp
6 replies
25 recasts
110 reactions

ZachXBT pfp
ZachXBT
@zachxbt
My new post sharing an investigation on a $243M theft from last month which lead to multiple arrests and $9M+ frozen https://x.com/zachxbt/status/1836752923830702392
20 replies
36 recasts
193 reactions