BTC $82,534.70 +1.05%
ETH $2,487.94 +0.55%
BNB $742.83 +1.05%
XRP $1.40 +1.05%
SOL $109.17 +0.13%
TRX $0.3316 -0.28%
DOGE $0.0857 +1.90%
ADA $0.2449 +5.46%
BCH $277.12 +1.19%
LINK $12.82 +1.05%
HYPE $84.33 +0.19%
AAVE $167.75 +1.21%
SUI $1.07 +3.00%
XLM $0.1950 +1.44%
ZEC $1,211.55 +1.97%
AAPL $336.24 -1.32%
AMZN $262.52 +2.92%
GOOGL $351.92 +0.82%
MSFT $535.16 +2.31%
META $718.30 -0.35%
NVDA $230.08 -0.65%
TSLA $383.09 +2.11%
SNDK $1,588.43 -2.04%
INTC $104.88 -2.37%
SPCX $162.97 -1.28%
MU $1,030.97 -1.13%
AMD $609.14 -2.08%
BTC $82,534.70 +1.05%
ETH $2,487.94 +0.55%
BNB $742.83 +1.05%
XRP $1.40 +1.05%
SOL $109.17 +0.13%
TRX $0.3316 -0.28%
DOGE $0.0857 +1.90%
ADA $0.2449 +5.46%
BCH $277.12 +1.19%
LINK $12.82 +1.05%
HYPE $84.33 +0.19%
AAVE $167.75 +1.21%
SUI $1.07 +3.00%
XLM $0.1950 +1.44%
ZEC $1,211.55 +1.97%
AAPL $336.24 -1.32%
AMZN $262.52 +2.92%
GOOGL $351.92 +0.82%
MSFT $535.16 +2.31%
META $718.30 -0.35%
NVDA $230.08 -0.65%
TSLA $383.09 +2.11%
SNDK $1,588.43 -2.04%
INTC $104.88 -2.37%
SPCX $162.97 -1.28%
MU $1,030.97 -1.13%
AMD $609.14 -2.08%

zachxbt

ZachXBT is a cryptocurrency detective and a council member of Polygon Labs.
All
Article
Flash

ZachXBT revealed an undercover investigation: infiltrating a money laundering group suspected of being part of the Lazarus Group and assisting in freezing funds related to the Bybit attack incident

"On-Chain Detective" ZachXBT stated that he once disguised himself as a client to infiltrate a criminal gang suspected of laundering money for the North Korean-backed hacker organization Lazarus Group, and assisted in freezing funds related to the 2025 Bybit attack incident.ZachXBT indicated that after Bybit was attacked for $1.5 billion in February 2025, he discovered over 15 accounts seeking help with transactions related to the stolen funds in public Telegram and Discord groups. He then contacted a Telegram user using the alias "Jimmy Green" and built trust through multiple transactions.According to his disclosure, on March 6, 2025, he transferred $3.497 million USDC to an Ethereum address for exchanging USDC with TRON chain USDT. The Gas funds for that address trace back to the Bybit attack funds and have been publicly marked as a Bybit attack blacklist address.ZachXBT stated that in subsequent communications, the other party revealed that their team had participated in handling the stolen funds from Bybit and disclosed in advance that the funds would be transferred on chains such as Solana. By matching transaction times, amounts, and on-chain data, he discovered a wallet cluster involving over $12 million of Bybit attack funds, with funding paths including BTC→ETH→SOL→TRON and others, among which approximately 442,000 USDT had been frozen by Tether. The gang also attempted to launder money through Uniswap liquidity pools and low liquidity tokens.In addition, the other party revealed that they had helped other clients handle approximately $3 million in scam proceeds, and ZachXBT tracked the related funds flowing to sanctioned Huione Guarantee-related wallets.ZachXBT disclosed that during this investigation, he initially invested $3.497 million and bore about 5% loss risk for each transaction. The intelligence obtained was promptly provided to relevant investigative agencies and law enforcement. Since 2022, he has assisted in freezing over $75 million related to North Korea-related incidents.

ZachXBT: Revolut allegedly caused the leakage of information for some high-net-worth users due to mistakenly trusting a forged government request

On-chain detective ZachXBT posted on his personal channel that Revolut allegedly leaked some users' personal identifiable information (PII) due to failing to recognize a forged government agency information request.According to his disclosure, Revolut previously received a request for customer information retrieval that appeared to come from a real government agency and was sent through the agency's official email domain. Because the email had valid domain authentication information, Revolut believed the request was legitimate and responded accordingly.The potentially involved data includes users' names, birth dates, occupations, addresses, email addresses, and phone numbers, as well as copies of passports or driver's licenses, identity verification selfies, account statements, IBANs, withdrawal records, and complete transaction histories, including Bitcoin transaction records. Revolut stated in the notification sent to users that no biometric facial telemetry data was leaked.ZachXBT indicated that the scale of the incident may currently be limited, but it appears to primarily target high-net-worth users. Several Revolut users received notifications regarding the related security incident yesterday. Revolut officials had previously reminded users to verify suspicious information through in-app customer service to avoid providing personal or financial information.

first_img BitMart founder Sheldon responded to the employee accountability statement, claiming the content is false and will report to the police

BitMart founder Sheldon stated that regarding the public accountability statement released by a BitMart employee through the official Twitter account, he has completed the collection of evidence related to the content and claims that the information is all false. Sheldon indicated that he will report to the police during the day in the United States and send a lawyer's letter to the X platform, requesting technical and data evidence collection regarding the relevant content. Sheldon also stated that employee assets do not take precedence over customer assets, and everyone is a customer, with no privileges existing. Previously, BitMart employees publicly questioned the whereabouts of platform assets and related handling situations. Sheldon had previously stated that he would respond to the whereabouts of platform assets by the 19th.Blockchain investigator ZachXBT posted on the X platform questioning the BitMart exchange. In response to the relevant account, he stated that if BitMart indeed has sufficient liquidity, it should directly return the funds to all users instead of issuing vague statements. ZachXBT pointed out that BitMart's related actions have caused real users to be unable to use their funds normally, and there is insufficient transparency. This statement has raised market concerns about the safety of the exchange's funds and operational transparency.

ZachXBT: American female scammer impersonates customer service to steal over 5 million dollars in cryptocurrency assets

On-chain detective ZachXBT posted that U.S. threat actor Tiffany Milanovich participated in the theft of approximately $5 million in crypto assets by impersonating hardware wallet and centralized exchange customer service.Her methods included disguising as Bitcoin IRA email support, during one attack transferring about $1.2 million in BTC and ETH from the victim's Trezor wallet, and in another case stealing about $500,000 in BTC from a Coinbase account. Tiffany induced victims to hand over access to their funds under the guise of "customer service calls," later boasting about the stolen money on social media and Telegram groups, mocking victims with recordings, and collaborating with other threat actors to launder money using phishing panels and instant exchange services, with some of the stolen funds still dormant on-chain.The threat actor codenamed "Tiffany" is suspected of participating in multiple crypto asset thefts, gambling the stolen funds at crypto casinos. The platform Shuffle has frozen related accounts based on evidence submitted by ZachXBT; Tiffany previously shared a search and seizure warrant from Connecticut, dated before some of the incidents involved.ZachXBT has obtained chat logs, recordings, and on-chain evidence, anticipating that this individual may face further legal consequences. This threat actor is also linked to the John Daghita (Lick) case, who is suspected of stealing over $46 million in crypto assets from a U.S. government-seized wallet.
app_icon
ChainCatcher Building the Web3 world with innovations.