Investigations by ZachXBT


Гео и язык канала: не указан, Английский
Категория: Криптовалюты


Reports, news, & insights shared by ZachXBT
Donation address
EVM
0x9D727911B54C455B0071A7B682FcF4Bc444B5596
SOL
investigations.sol

Связанные каналы  |  Похожие каналы

Гео и язык канала
не указан, Английский
Категория
Криптовалюты
Статистика
Фильтр публикаций


In the past hour a victim was drained for 12K spWETH ($32.4M)

Theft txn hash
0xf7c00f18175cdea49f8fdad6a1d45edeb318f18f3009f51ab9f4675171c1d8fb

Theft address
0x471c725Bd1F29850CBb8eeA4cdf6c9Ce3caC5607

h/t ScamSniffer


Have seen an uptick in irl robberies targeting crypto traders located in Western Europe over the past few months.

The cases all involve known people in the crypto community where they were held at gunpoint.

As the rest of the cycle continues be extra mindful of who you share your wins with and meet up with irl.






My new post sharing an investigation on a $243M theft from last month which lead to multiple arrests and $9M+ frozen

https://x.com/zachxbt/status/1836752923830702392?

30k 4 243 303

Imagine compromising this many large acounts on X/Twitter and only making $8.5K off the scam from pulling the LP


Community Alert: A number of large accounts on X currently have their account compromised and are posting the same meme coin scam.

Would imagine these accounts all connected to a site/app and gave permissions to post.

Reminder to always go to X settings and revoke connected apps you do not use.

Settings -> Security and account access -> Apps and Sessions or Connected apps then periodically revoke inactive ones.

33k 3 266 318



Which one of you hacked the McDonald’s Instagram to promote a meme coin scam?


A few hours ago a victim was drained for 55.4M DAI

Transaction hash
0xf70042bf3ae7c22f0680f8afa078c38989ed475dfbe5c8d8f30a50d4d2f45dc4

Theft address
0x5D4b2A02c59197eB2cAe95A6Df9fE27af60459d4


Seven hours ago a suspicious transfer was made from a potential victim for 4064 BTC ($238M)

Transaction hash
4b277ba298830ea538086114803b9487558bb093b5083e383e94db687fbe9090

Funds were transferred to ThorChain, eXch, Avalanche Bridge, ChangeNow, Kucoin, Railgun.


Nexera (NXRA) was exploited for ~$1.5M a few hours ago. Attacker is connected on-chain to recent private key compromise incidents such as SpaceCatch, Concentric Finance, OKX DEX, Serenity Shield, Reach, and many more.

Stolen funds sit
0xe697949817a45446776376db203c04d31b580a10
0x6bd33c8256f7a37336b2b8fe967321e25540337b


On-chain clown of the day: The Pancake Bunny exploiter accidentally transferred $3.6M to the DAI contract address 8 hrs ago

0x72df3d8b97b92188eb7516277836fd07e994b276c858052815a398cc52c91bc1


Someone was phished for $4.69M worth of PT-ezETH & PT-sz-rsETH an hour ago.

More than $23.2M has been phished from Pendle users since March 2024

Theft transaction hash
0x7357787481b25c99b61912af8159f866d4ff2e7d97039425b529e2890b23c4f6
0x26820ddb9aeb9a74ac757be5e182c83ec20443d2273bbd68d1d1fa86f2b131a0


Renzo Discord is currently compromised do not click any links for the moment.


As a way to reduce spam on X (formerly Twitter) the team will soon be adding a way to disable links in the replies.

Hopefully this will cut down on all of the gold verified phishing scams under the replies of posts we see so frequently.


Looks like the Indian crypto exchange WazirX was potentially hacked for $230M+

Primary theft address
0x04b21735E93Fa3f8df70e2Da89e6922616891a88

Attacker still has $100M+ worth of SHIB and $4.7M+ FLOKI to sell

Update: My tracing thus far on the incident


The Ethena Discord server is currently compromised do not click links for the time being.

52k 4 182 318

Sharing the $25M ransom payment made by CDK on June 21, 2024 to BlackSuit.

Transaction hash
8a41d7a6b75580f34f177628c39bd52ae9c8adc633fb5c874b3a09b253f3d4ef

Address
bc1q0c03s0c80uuxjq4jcyfhs4k8w5wu6ca9xhxsw9

Funds were then transferred to multiple centralized services after.


Community Alert: Compound Finance website seems to potentially be hijacked do not visit the site for the time being.

Currently redirects to a newly registered phishing site.

Update: Compound Team resolved this

Показано 20 последних публикаций.