20931
ZachXBT

@zachxbt #20931

full time on-chain clown
69757 Follower 111 Following
I went and attributed 16 exchange hot wallets on Starknet so they would be publicly tagged on block explorers as I noticed none were previously tagged anywhere.

Binance 0x0213c67ed78bc280887234fe5ed5e77272465317978ae86c25a71531d9332a2d
OKX 0x0269ea391a9c99cb6cee43ff589169f547cbc48d7554fdfbbfa7f97f516da700
Bybit 0x076601136372fcdbbd914eea797082f7504f828e122288ad45748b0c8b0c9696
Kraken 0x620102ea610be8518125cf2de850d0c4f5d0c5d81f969cff666fb53b05042d2
Kucoin 0x0566ec9d06c79b1ca32970519715a27f066e76fac8971bbd21b96a50db826d90
HTX 0x03fd14213a96e9d90563ebe1b224f357c6481a755ee6f046c8ce9acd9b8654a7
MEXC 0x069a7818562b608ce8c5d0039e7f6d1c6ee55f36978f633b151858d85c022d2f
Gate 0x00e91830f84747f37692127b20d4e4f9b96482b1007592fee1d7c0136ee60e6d
Bitget 0x0299b9008e2d3fa88de6d06781fc9f32f601b2626cb0efa8e8c19f2b17837ed1

HitBTC 0x04b555a99b585adf082754e5ea36e4202f13efa649e6ac16dfe8c0e217c454bc
CoinEX 0x00fb108ed29e1b5d82bb61a39a15bbab410543818bf7df9be3c0f5dd0d612cf3
45 minutes ago a victim was drained for 12K spWETH ($32.4M)

Theft address
0x471c725Bd1F29850CBb8eeA4cdf6c9Ce3caC5607

Theft txn hash
https://etherscan.io/tx/0xf7c00f18175cdea49f8fdad6a1d45edeb318f18f3009f51ab9f4675171c1d8fb
/police
The project Truflation was hacked a few hours ago for $5M+ on multiple chains from the treasury multisig and personal wallets

EVM theft address
0x53d2094b31429a13e739358b16354d8e0826b25a
0x2122a76213b23daf633b850cb659750db0cac801
0x4ec10144f1a96eed9b04d324d0997b5325c56472
0x7ea07c76328fc789435fc77a2a4d527c5bbc333e
0x3f8e5cc8abd032dd6ad652423e951ab06f833126
SOL theft address
6v4R3z5ahHqx3pbxMpYQMu26cuQoonLX2Rqq7WF35yzp
/police
My new post sharing an investigation on a $243M theft from last month which lead to multiple arrests and $9M+ frozen

https://x.com/zachxbt/status/1836752923830702392
A number of large accounts on X currently have their account compromised and all are promoting the same meme coin scam.

https://x.com/zachxbt/status/1836473279479189916
/police
Cencora, a top 50 publicly traded company in the US made a $75M ransomware payment earlier this year but did not share the BTC transactions so I decided to do it for them.

https://x.com/zachxbt/status/1836403999030788570
/police
Happy to have played a part in freezing $7M as a direct result of my Lazarus Group investigation.

https://x.com/zachxbt/status/1834881201326178808?
/police
A threat actor hacked the McDonald’s Instagram account and began promoting a meme coin scam.
/police
A few hours ago a victim was drained for 55.4M DAI

Transaction hash
0xf70042bf3ae7c22f0680f8afa078c38989ed475dfbe5c8d8f30a50d4d2f45dc4

Theft address
0x5D4b2A02c59197eB2cAe95A6Df9fE27af60459d4
Seven hours ago a suspicious transfer was made from a potential victim for 4064 BTC ($238M)

Transaction hash
4b277ba298830ea538086114803b9487558bb093b5083e383e94db687fbe9090

Funds were quickly transferred to ThorChain, eXch, Kucoin, ChangeNow, Railgun, Avalanche Bridge.
/police
Nexera (NXRA) was exploited for ~$1.5M a few hours ago. Attacker is connected on-chain to other recent private key compromise incidents such as SpaceCatch, Concentric Finance, OKX DEX, Serenity Shield, Reach, and many more.

Stolen funds sit
0xe697949817a45446776376db203c04d31b580a10
0x6bd33c8256f7a37336b2b8fe967321e25540337b
On-chain clown of the day: The Pancake Bunny exploiter accidentally transferred $3.6M to the DAI contract address 8 hrs ago

0x72df3d8b97b92188eb7516277836fd07e994b276c858052815a398cc52c91bc1
Sorta Finance was created by the same group of scammers who deploy Compound V2 forks on different EVM chains.

Posted on Warpcast about three other scams they did earlier this year

https://x.com/zachxbt/status/1816443881447440789
/police
Someone was phished for $4.69M worth of PT-ezETH & PT-sz-rsETH an hour ago

Theft transaction hash
0x7357787481b25c99b61912af8159f866d4ff2e7d97039425b529e2890b23c4f6
0x26820ddb9aeb9a74ac757be5e182c83ec20443d2273bbd68d1d1fa86f2b131a0

More than $23.2M has been phished from Pendle users since March 2024
/police
Looks like the Indian crypto exchange WazirX was potentially hacked for $230M+

Primary theft address
0x04b21735E93Fa3f8df70e2Da89e6922616891a88

Attacker still has $100M+ worth of SHIB and $4.7M+ FLOKI to sell
/police
I have been closely following the movements of the $305M DMM Bitcoin hack.

Shared some details of where those funds are going and the related 29M USDT blacklist over the weekend.

https://x.com/zachxbt/status/1812466959109521649?
/police
Sharing the $25M ransom payment made by CDK on June 21, 2024 to BlackSuit.

Transaction hash
8a41d7a6b75580f34f177628c39bd52ae9c8adc633fb5c874b3a09b253f3d4ef

Address
bc1q0c03s0c80uuxjq4jcyfhs4k8w5wu6ca9xhxsw9

Funds were transferred to a variety of centralized services after.
/police
Community Alert: Compound Finance website seems to potentially be hijacked do not visit the site for the time being.

Currently redirects to a newly registered phishing site.
/police
Now we even have Messi promoting meme coin pump and dumps on Instagram.

https://x.com/wazzcrypto/status/1804194766453719094
Update: Bittensor was halted as the result of additional thefts earlier today likely due to private key leakage
US government just transferred 3940 BTC ($243M) of funds from the Silk Road hack to Coinbase Prime

Transaction hash
0f3f9a7c01d85c5747a3ae6cc9621cc30360390c4b681c1f95573e6bbcffed4f

Coinbase Prime Deposit address
3FGcXf5HiPkitjQp4xjGu7Gte6aK7w43su

https://blockchair.com/bitcoin/transaction/0f3f9a7c01d85c5747a3ae6cc9621cc30360390c4b681c1f95573e6bbcffed4f
Recently helped identity and contact the main NFTPerp exploiter after they were attacked for $775K on Blast the other week.

https://x.com/nftperp/status/1801690415323652409
Robert Robb aka Poker Brat plead guilty on Friday just a few months after my post from December 2023 detailing his MEV bot investment fraud scheme.

https://x.com/zachxbt/status/1731745308449575015
BTC Turk ($90M+) and Sportsbet ($3.5M+) were both hacked earlier today on multiple chains likely by the same threat actor due to commingling of funds.

Funds were quickly transferred to Coinbase, Binance, Gate, MEXC, Bybit, Gate, ChangeNow, FixedFloat and withdrawn to Bitcoin

and

Funds were bridged via THORChain/Wan Bridge to Bitcoin

Theft address 0x327a81d0d128db8886d265be73c9fdda97194f30
r4tvMzLrhWGCZ6W9yZRhWguEhovxsHSTRB
TJZwDMSp9PsjvaCn7SKHCbkFEX8jgEY6XC
TTKhC17M3xdXtrKDU5niLg4YH2rK742D8D
TDgZKxhyFQWCsNK1p7d1tVifeuW2DJTUEo
TQWSmSqns2BLczLEMpy96tNq3MagM66H4b
TJZ8NNxJETGDzGaWwSHwjGrzzz2Zhvexo2