Последние посты

Investigations by ZachXBT
12 сент., 06:29
Community alert: Revolut appears to have exposed personally identifiable information (PII) for a subset of users due to failing to detect a fraudulent government request.Exposed data included: -Copy of passport and/or driver's licence, plus the verification selfie -Account statements, IBAN, withdrawal records, and full transaction history including Bitcoin -Full name, date of birth, occupation -Home address, email, phone numberWhile the incident is likely limited in size it seems to have been targeted at high net worth users.An email alerting users was sent out to multiple Revolut users yesterday.


Investigations by ZachXBT
6 сент., 13:59
Community Alert: Multiple verified WooX users have reported withdrawals stuck in pending or processing over the past three days.WooX was incubated by Kronos Research, and in Q4 2025 it was acquired by FusionX Digital, a firm which allegedly has ties to BitMart founder Sheldon Xia.On July 26, 2026, BitMart announced it would cease operations and restructure. Its users have been left without access to millions in stuck funds, with complaints increasing on X. Sheldon Xia has published only vague statements claiming user assets are safe, and those claims still have not been independently verified.As of this post, WooX has not yet issued a statement.


Investigations by ZachXBT
24 авг., 14:18
Community Alert: I've reviewed evidence that two US based investment platforms: BitcoinIRA & iTrustCapital allegedly had data breaches this year but appear to have not disclosed the incidents publicly.Leaked info: Personal details, Portfolio holdings, Banking details, Custodian details, Verification status, etcExample: Threat actor ‘Tiffany’ targeted a BitcoinIRA user and stole $1.2M+ using the db in June 2026.I reached out to both companies for comment on August 21 but have not heard back yet.
Investigations by ZachXBT
22 авг., 11:48изменён
Bottom 5 jurisdictions globally for victims ranked in order:🥇 Canada 🥈 UK 🥉 India 4). Nigeria 5). Morocco, Algeria, or Bangladesh(If you contact me from any of these countries I will likely automatically decline the case)
Investigations by ZachXBT
26 июл., 15:36изменён
Telegram keeps allowing scam ads to be displayed in my channel to subscribers.If you are a premium user please consider using boosts for my channel https://t.me/boost/investigations so I can unlock the feature to disable ads (need to hit level 50).


Investigations by ZachXBT
20 июл., 14:35
It appears the bridge TeleSwap had a $735K+ exploit on July 15, 2026 and still has not disclosed the incident publicly after five days.Shortly after the suspicious outflows its Bitcoin hot wallet stopped processing transactions. Two hours ago the attacker deposited the funds to Tornado.Theft addresses bc1pz95zv3qhpmt52yezs84a5zrddrk5jsxm8a60rln5kzlk06e87a3q8pf79l 0x2448cbaee50a67030692b7519a954e5550dc2718 0xfc5048fbba2f74ed482ffcd7663601f818c5bb47 0xf8706a51f8df01a71f408e50c901dd14916a12c7TeleSwap Bitcoin hot wallet bc1q5wnpn4k99wc587maaaa6eqnx27g4r6mduxg2s5
Investigations by ZachXBT
15 июл., 21:53изменён
Hot take: All hardware wallets are complete garbage and l do not advise using them for important tasks like signing transactions or storing funds.Much better to have a separate iPhone with its only purpose being to use as your hardware wallet.Ledger is the worst and Ledger Live has regular updates for UI / apps for no good reason that break simple actions.(Only do this if you are not low iq)
Investigations by ZachXBT
12 июл., 05:09изменён
An entity previously received ESPORTS, RIVER, & LIGHT tokens via Sablier vesting contract and is also directly tied to a signer on three LAB multisigs. These four BSC tokens have experienced market manipulation incidents on centralized exchanges. I peviously
Investigations by ZachXBT
10 июл., 13:13изменён
An early Solana whale tied to the initial Genesis block distribution appears to have likely had 180.9K SOL ($14.2M) stolen a few hours ago.I began reviewing the irregular unstaking and bridging activity from Solana to Ethereum with @specterinvestigation who first spotted these movements.Victim HwtbQBNnLERakdUDuCCLWmUs2oETLFQZeHUWeQdPadsTheft address Ffd1oB2aYM5UzMYUM7TmxULDRQb6KzgrBwmgj9U1C2bE 653pnn5fzF51FfotBwxua55Es4QXxTdaXJLbPczVmswp 0xaa5cfa4e96dda0f9aa30f4dc948b542a9b5817c6 0x536b4ee7507c41143e1b0bd1bf3f2b84be404836 0xbf11bdfbeb9ed137c352c81e45d191cacae6b0cf


Investigations by ZachXBT
8 июл., 12:32изменён
Update: AscendEX has not posted on X (Twitter) for 9 days since my post and user withdrawals are still not being processed while deposits are being accepted. I reviewed a case where a large victim has been getting no response from the AscendEX co-founder


Investigations by ZachXBT
6 июл., 10:14
Over the past week multiple people created ZACHXBT meme coins on various chains using my likeness to take advantage of the recent narrative.None of the tokens were promoted by myself as I have always stated I will never support or launch a meme coin.All tokens sent to my donation wallet were market sold and the entire amount was sent to charity.~$41K total was donated to Direct Relief & Give Directly via The Giving Block to support the Venezuela earthquake response.Transaction reciepts:1). 25K USDT sent to Give Directly on July 6, 2026 at 4:16 am UTC 0x687556d7011b0750f3daf9e3a9f800d04ba233c84362faf8c3851b40cd0f71ae2). 5k USDT sent to Direct Relief on July 6, 2026 at 4:51 am UTC 0xc9146816d5c0d97b432d663b422b46854ba6e047ce7e9ea8073d43c1205ba0703). 153 SOL ($11K) total sent to Direct Relief on June 28, 2026 44idg3MiJiprAnqBbt5fZM9K4deDzZdqnJ3dPtS6hFLqQk3omvqWz7LjgCapMX94q7Ba
Investigations by ZachXBT
5 июл., 08:57изменён
Community alert: KuCoin has sent legal threats to a victim whose stolen funds were laundered via KuCoin accounts with purchased mule KYC. The case involves a $250K Atomic stealer theft from August 18, 2025 where the stolen funds were transferred to multiple



Investigations by ZachXBT
2 июл., 07:19изменён
Community alert: I have observed multiple reports that the centralized exchange AscendEX (formerly Bitmax) is delaying user withdrawals for days / weeks or not processing withdrawals. I reviewed known hot wallets on Arkham/TRM and its reserves appear to lack
Investigations by ZachXBT
30 июн., 04:59изменён
Community alert: KuCoin has sent legal threats to a victim whose stolen funds were laundered via KuCoin accounts with purchased mule KYC.The case involves a $250K Atomic stealer theft from August 18, 2025 where the stolen funds were transferred to multiple KuCoin deposit addresses.Theft address 0x6368D06895b7becdcAC0806F438EfA653fE0a68DKucoin deposit addresses 0x6043b2d79670a417fc523213155812846e893dc7 0xa0fdb49aa589538d5622b92e9122727873558a13 0x4a4b5c7db9aa8355a5e5abbfc1926cd6b2d9f610 0xe7bb69f6c0ae0c1418bd86ec9697af9914d6875e 0x35d65ec360347f7dc41a929cc7ce9f2485a4f833In recent months I have provided warnings about KuCoin due to blocking legit users, enabling illicit activity (AudiA6, DNMs, etc), and have observed delayed responses to law enforcement for victims.


Investigations by ZachXBT
27 июн., 05:53изменён
One hour ago funds from the recent Humanity Protocol exploit and Kelp DAO exploit commingled suggesting potential overlap between the attackers for both incidents.Transaction hash: 5d31655a905b1b39ce1a477268b5084cc821157371860b792e60a3fa4aa24931On April 18, 2026 ~$292M was stolen from Kelp DAO's LayerZero bridge due to compromised infra and Lazarus Group was alleged as the attacker.On June 9, 2026 ~$32M was stolen from Humanity Protocol team addresses and deployer after a developers device became compromised.The H token previously raised concerns over insider supply control and active market making tactics on CEXs where the exploit coincided shortly before investor unlocks.However I believe the new evidence from above rules out insiders as being behind the exploit.H/t @specterinvestigation for helping flag these transactions.


Investigations by ZachXBT
26 июн., 03:49изменён
Community alert: I have observed multiple reports that the centralized exchange AscendEX (formerly Bitmax) is delaying user withdrawals for days / weeks or not processing withdrawals.I reviewed known hot wallets on Arkham/TRM and its reserves appear to lack large cap tokens such as ETH, USDT, USDT, SOL, etc indicating they likely are facing liquidity issues.AscendEX (Bitmax) was founded by George (Jing) Cao & Ariel Ling in 2018. In December 2021 they were reportedly hacked by Lazarus Group for $78M.EVM hot wallets 0x983873529f95132BD1812A3B52c98Fb271d2f679 0x4240781A9ebDB2EB14a183466E8820978b7DA4e2Tron hot wallet TP523ZC2721Dnu6nxYSFi14cWUBfu8YTXGSolana hot wallets Cv7hXMfMh5eu2WBtyZXogYDPj55Xo1Ufsuwn7oeG6Epy 6iVBAsquJRaLsXbojb18kqTW1d5iVLspVjCtsReZBKhY
Investigations by ZachXBT
25 июн., 11:35
The Polish social engineering threat actor Wojtek Kulisz aka 'Merry' appears to have been recently raided by Poland law enforcement along with three other people. While the press release today did not share his name or photo, multiple designer clothes and
Investigations by ZachXBT
25 июн., 11:32изменён
The Polish social engineering threat actor Wojtek Kulisz aka 'Merry' appears to have been recently raided by Poland law enforcement along with three other people.While the press release today did not share his name or photo, multiple designer clothes and jewelry items flexed from his public Instagram account 'wojtekk' match items seized during the raid.


Investigations by ZachXBT
25 июн., 06:21
A few hours ago the price of M (MemeCore) suddenly crashed >75% on centralized exchanges from $14B to $3.8B FDV falling outside of the top 25 tokens ranked by market cap.Myself, Mlm, & Wazz previously highlighted a number of red flags on X about MemeCore with inorganic supply concentration and deceptive practices by its team to boost user numbers.According to data on Arkham there's not been a single transfer >$50k onchain in 2+ weeks on BSC.Dexscreener data indicates there's <$100K total liquidity onchain on BSC.The community needs answers from Binance & Bybit about why M was listed for perps and why Kraken & Bitget listed M spot as these highly manipulated tokens continue to give our industry a bad reputation and extract from retail.


Investigations by ZachXBT
22 июн., 10:51изменён
Three hours ago 10.6K ETH ($18.5M) moved from an address linked to the $575M Hashflare investment fraud after sitting dormant onchain for 3.5 yrs.In 2025 both co-founders Sergei Potapenko and Ivan Turogin plead guilty and forfeited $450M of assets to the US government.The entity began laundering funds via HiFiSwap and Near Intents from Ethereum to Bitcoin and began using two instant exchanges.H/t to Cyvers for helping first flag these movements to me.Hashflare address 0xff575a22975cc413771825eb84c163189a4d5d22 Hashflare transfer 0xd0eafd5c03b24c2f54c579745cacbffe4c6df2d19973e55d52a5f40aa1d089e0 Recipient address 0xc82f007bb4096a47d14ed0d46ee8143d37539d04 0x3297a41f528345c3b97af8c6ffe1401cc07b2527

Ссылки
