In the past hour a victim was drained for 12K spWETH ($32.4M)
Theft txn hash
0xf7c00f18175cdea49f8fdad6a1d45edeb318f18f3009f51ab9f4675171c1d8fb
Theft address
0x471c725Bd1F29850CBb8eeA4cdf6c9Ce3caC5607
h/t ScamSniffer
Theft txn hash
0xf7c00f18175cdea49f8fdad6a1d45edeb318f18f3009f51ab9f4675171c1d8fb
Theft address
0x471c725Bd1F29850CBb8eeA4cdf6c9Ce3caC5607
h/t ScamSniffer
π±203π113π€£28β€27π14π«‘8π7π€―6π5π₯°4π¦4
I went and attributed 15 exchange hot wallets on Starknet so they would be publicly tagged on block explorers as I noticed none were previously tagged anywhere (sharing them below).
Which ecosystem should I do next?
Any interested teams send me a message on X/Twitter.
Binance 0x0213c67ed78bc280887234fe5ed5e77272465317978ae86c25a71531d9332a2d
OKX 0x0269ea391a9c99cb6cee43ff589169f547cbc48d7554fdfbbfa7f97f516da700
Bybit 0x076601136372fcdbbd914eea797082f7504f828e122288ad45748b0c8b0c9696
Kraken 0x620102ea610be8518125cf2de850d0c4f5d0c5d81f969cff666fb53b05042d2
Kucoin 0x0566ec9d06c79b1ca32970519715a27f066e76fac8971bbd21b96a50db826d90
HTX 0x03fd14213a96e9d90563ebe1b224f357c6481a755ee6f046c8ce9acd9b8654a7
MEXC 0x069a7818562b608ce8c5d0039e7f6d1c6ee55f36978f633b151858d85c022d2f
Gate 0x00e91830f84747f37692127b20d4e4f9b96482b1007592fee1d7c0136ee60e6d
Bitget 0x0299b9008e2d3fa88de6d06781fc9f32f601b2626cb0efa8e8c19f2b17837ed1
HitBTC 0x04b555a99b585adf082754e5ea36e4202f13efa649e6ac16dfe8c0e217c454bc
CoinEX 0x00fb108ed29e1b5d82bb61a39a15bbab410543818bf7df9be3c0f5dd0d612cf3
ChangeNow 0x062b6edccf9d86aff918634e53f3fac9545a8bcf84bcb59a0a09f9194d18282d
XT 0x0786c463590ca32345e0118a0303a8f66af10882d7315ce282840feb5d6817f9
Bitrue 0x01a103074e6ea2f988b427c77e671207c20d6005d407a685eeee2e1f61028392
Bitmart 0x04de639e634c071c3ce8b1c69fac0500aab5ddb25a08fd0f757176243e4c0467
Which ecosystem should I do next?
Any interested teams send me a message on X/Twitter.
Binance 0x0213c67ed78bc280887234fe5ed5e77272465317978ae86c25a71531d9332a2d
OKX 0x0269ea391a9c99cb6cee43ff589169f547cbc48d7554fdfbbfa7f97f516da700
Bybit 0x076601136372fcdbbd914eea797082f7504f828e122288ad45748b0c8b0c9696
Kraken 0x620102ea610be8518125cf2de850d0c4f5d0c5d81f969cff666fb53b05042d2
Kucoin 0x0566ec9d06c79b1ca32970519715a27f066e76fac8971bbd21b96a50db826d90
HTX 0x03fd14213a96e9d90563ebe1b224f357c6481a755ee6f046c8ce9acd9b8654a7
MEXC 0x069a7818562b608ce8c5d0039e7f6d1c6ee55f36978f633b151858d85c022d2f
Gate 0x00e91830f84747f37692127b20d4e4f9b96482b1007592fee1d7c0136ee60e6d
Bitget 0x0299b9008e2d3fa88de6d06781fc9f32f601b2626cb0efa8e8c19f2b17837ed1
HitBTC 0x04b555a99b585adf082754e5ea36e4202f13efa649e6ac16dfe8c0e217c454bc
CoinEX 0x00fb108ed29e1b5d82bb61a39a15bbab410543818bf7df9be3c0f5dd0d612cf3
ChangeNow 0x062b6edccf9d86aff918634e53f3fac9545a8bcf84bcb59a0a09f9194d18282d
XT 0x0786c463590ca32345e0118a0303a8f66af10882d7315ce282840feb5d6817f9
Bitrue 0x01a103074e6ea2f988b427c77e671207c20d6005d407a685eeee2e1f61028392
Bitmart 0x04de639e634c071c3ce8b1c69fac0500aab5ddb25a08fd0f757176243e4c0467
β€271π83π₯54π«‘23π€£17π16π₯±10π4π2π2π2
Investigations by ZachXBT
I went and attributed 15 exchange hot wallets on Starknet so they would be publicly tagged on block explorers as I noticed none were previously tagged anywhere (sharing them below). Which ecosystem should I do next? Any interested teams send me a messageβ¦
Probably will do Solana, Sui, Base, Arbitrum, or Aptos at some point as the exchange attribution on those chains is awful for anyone who frequently checks the chain.
β€240π52π―37π₯20π«‘13π€£9π6π5π3π€¨3π₯°2
Sharing 13 high confidence wallets with $27.75M tied to MustStopMurad so people can track them. I made a longer post on X/Twitter explaining my rationale behind mapping out this cluster of wallets.
ETH
0x6b411100c72ba2445e50ffd20839c28b3546de7c
0xcbd0dee0c3eed152c3398b062361becc4a15522b
0x13fc38ec99a8217a06d1dc6db8c0bf0ee97ebf7f
0x71b4fd11eef705ba60176e7c034cd1a4f97ae02d
0x30b46a659761b576a00028b44d1e37fdc64b034d
0x5b1569db234a0f2884814a3f7184f01cf641b0c6
0x464e0a666734ba93e231d929ace538eaf05ff424
0xdb47714727cba70f0408ba30dc4ea0b5ac436055
0x52ba2171d6d0aaf6e817769b9d54576e79a98d1a
SOL
7QZGS7MQ4S6hRmE8iXoFTXgQ2hXVUCho2ZhgeWvLNPZT
GyBkVYkHBPMapyQeueQ6d44YthwqYiX4ajgnGLqq9P7r
2xn57hPD2v6ighJFPXNPSoiGUXkW4KKo8Hb3NpXmHZvZ
D38TJXnQuqAapH7uqhrHVj3AixHjtkB8DWT78m29WdPc
ETH
0x6b411100c72ba2445e50ffd20839c28b3546de7c
0xcbd0dee0c3eed152c3398b062361becc4a15522b
0x13fc38ec99a8217a06d1dc6db8c0bf0ee97ebf7f
0x71b4fd11eef705ba60176e7c034cd1a4f97ae02d
0x30b46a659761b576a00028b44d1e37fdc64b034d
0x5b1569db234a0f2884814a3f7184f01cf641b0c6
0x464e0a666734ba93e231d929ace538eaf05ff424
0xdb47714727cba70f0408ba30dc4ea0b5ac436055
0x52ba2171d6d0aaf6e817769b9d54576e79a98d1a
SOL
7QZGS7MQ4S6hRmE8iXoFTXgQ2hXVUCho2ZhgeWvLNPZT
GyBkVYkHBPMapyQeueQ6d44YthwqYiX4ajgnGLqq9P7r
2xn57hPD2v6ighJFPXNPSoiGUXkW4KKo8Hb3NpXmHZvZ
D38TJXnQuqAapH7uqhrHVj3AixHjtkB8DWT78m29WdPc
π309β€85π₯62π«‘42π32π‘16π€12π9π―8π7π₯±5
Tapioca DAO hack is likely the result of a team member downloading malware as the theft is tied on-chain to other recent hacks such as Nexera, Concentric, Masa, SpaceCatch, Reach, Serenity Shield, MurAll, etc I have previously covered which were the result of fake job scams (contagious interview)
Stolen funds from this incident were bridged from Arbitrum to BSC where ~$4.7M currently sits.
0x69d91e56ca80f2a4d7b808b59053ea5c5505ffe2
Stolen funds from this incident were bridged from Arbitrum to BSC where ~$4.7M currently sits.
0x69d91e56ca80f2a4d7b808b59053ea5c5505ffe2
π96π±48β€28π17π€―11π₯9π‘7πΏ4π2π€1π€¬1
Investigations by ZachXBT
Tapioca DAO hack is likely the result of a team member downloading malware as the theft is tied on-chain to other recent hacks such as Nexera, Concentric, Masa, SpaceCatch, Reach, Serenity Shield, MurAll, etc I have previously covered which were the resultβ¦
It also looks like Masa never disclosed their hack to the community for six figures on September 20, 2024.
Here are the theft addresses below and a screenshot of outflows from the Masa deployer
0x4c16506f257a3782dee8d245f9504439c21314f8
0x6483c58f4fd3c07ddad4c9b9b2756dc963d5dc0b
Here are the theft addresses below and a screenshot of outflows from the Masa deployer
0x4c16506f257a3782dee8d245f9504439c21314f8
0x6483c58f4fd3c07ddad4c9b9b2756dc963d5dc0b
π€£135π€38π±27β€19π15π5π4πΏ4πΎ4π‘4π€¬2
Looks like the crypto payments provider Transak was recently breached by a ransomware group who claims responsibility.
Transak in a blog post earlier today stated it is limited to names and basic identity info for a small portion of users while the ransomware group alleges it also includes PII and is a larger set of users.
According to Transak's website it has been integrated by Metamask, Trust Wallet, Coinbase, Ledger, etc for fiat to crypto on/off ramps
Transak in a blog post earlier today stated it is limited to names and basic identity info for a small portion of users while the ransomware group alleges it also includes PII and is a larger set of users.
According to Transak's website it has been integrated by Metamask, Trust Wallet, Coinbase, Ledger, etc for fiat to crypto on/off ramps
π135π€£39π38π€¬29β€15πΏ13π±10π₯5π₯°4π4π2
Investigations by ZachXBT
Looks like the crypto payments provider Transak was recently breached by a ransomware group who claims responsibility. Transak in a blog post earlier today stated it is limited to names and basic identity info for a small portion of users while the ransomwareβ¦
Update: Looks like Transak corrected the blog after my post to say the breach also included ID documents (passport, driver license, etc) and user selfies unlike what they previously said.
π240π€£86π56π€¬33πΏ14π13π₯12π’10π8π¦7π€·ββ2
Investigations by ZachXBT
Looks like $20M of seized funds tied to the US Government was likely stolen in the past hour. Theft address 0x3486ee700ccaf3e2f9c5ec9730a2e916a4740a9f 0xbf6f7c503e858aded4e18ce2bcf93846fd726c15 0x15d0a31ed5050ed8decd3c101aaee0b2ad2e6441
Update: The threat actor just transferred $19.2M back to the compromised US government address in the last 30 minutes.
This amount does not include the funds already transferred to instant exchanges (Switchain, HitBTC, N Exchange).
This amount does not include the funds already transferred to instant exchanges (Switchain, HitBTC, N Exchange).
π€£517π43π€39π28β€13π€ͺ12πΎ11π₯9π9πΏ6π6
The crypto exchange M2 was hacked for ~$13M from hot wallets on multiple chains yesterday.
Theft addresses
ETH: 0x968b6984cba14444f23ee51be90652408155e142
BTC: bc1qu4kh7wa38xpkrp8frgxl4sak88wx0jug8n3vfj
SOL: EKko14NvgqdvNttUb8JjXkVGuUs6BTikjfN3hqW4LQoL
Theft addresses
ETH: 0x968b6984cba14444f23ee51be90652408155e142
BTC: bc1qu4kh7wa38xpkrp8frgxl4sak88wx0jug8n3vfj
SOL: EKko14NvgqdvNttUb8JjXkVGuUs6BTikjfN3hqW4LQoL
π»74π24π23π±23π₯18π11π₯΄10π€£10πΎ6π€©4πΏ4
I did some initial tracing for the Andy Ayrey (Truth Terminal creator) hack this week which lead to $1.5M+ stolen from deploying multiple bundled meme coins and found one of the people involved in the incident appears to be a FWOG whale.
Theft consolidation address
0xcd27994d2a460e3f7bdee75974188040d7fe723e
6haUPtErdx5g88G6Rv4itwB37XzqvRjaCuJnn4J85Pro
Apc3eA9ScQksuZvfURQswZwVkusEYRaqeKEv4eXXbRZm
CAwocNV1VaEmXoi2XPnfcYZSxnJ3fBTiWNgtPtF3nriH
Holder address
AtdSsizerZZMVuStX4Ji5kAY1bPnNi9LdymfQ4DWuLcr
Theft consolidation address
0xcd27994d2a460e3f7bdee75974188040d7fe723e
6haUPtErdx5g88G6Rv4itwB37XzqvRjaCuJnn4J85Pro
Apc3eA9ScQksuZvfURQswZwVkusEYRaqeKEv4eXXbRZm
CAwocNV1VaEmXoi2XPnfcYZSxnJ3fBTiWNgtPtF3nriH
Holder address
AtdSsizerZZMVuStX4Ji5kAY1bPnNi9LdymfQ4DWuLcr
π217π57β€38π³18π₯΄16β€βπ₯13π«‘13π₯8π€6π4π2
Looks like the crypto casino Metawin was exploited for $4M+ on Ethereum and Solana earlier today.
See 115+ theft addresses tied to the exploiter here.
So far stolen funds have been transferred to Kucoin and a HitBTC nested service.
See 115+ theft addresses tied to the exploiter here.
So far stolen funds have been transferred to Kucoin and a HitBTC nested service.
π92π€£58π’22π14β€12π₯11π9π€9π6π4π4
Investigations by ZachXBT
I did some initial tracing for the Andy Ayrey (Truth Terminal creator) hack this week which lead to $1.5M+ stolen from deploying multiple bundled meme coins and found one of the people involved in the incident appears to be a FWOG whale. Theft consolidationβ¦
Do not buy the Wiz Khalifa Pump Fun it's the same hacker who compromised Andy Ayrey (Truth Terminal creator) the other day.
π€£324π142π«‘66β€36π±7π6πΏ6π4π¦4π₯3π2
Do not expect my help with ecosystems where people do not actively support my work (Arbitrum, Cosmos, zkSync, Aptos, Sui, Scroll, etc).
I currently only assist people on the chains which make my work possible: Solana, Ethereum, Bitcoin, OP/Stark.
There is already many scams as is so I would rather focus my time on helping the ecosystems which give back and fund public goods (I receive 1K+ inbounds / month).
This is just a general reminder for all of those people who think they are entitled to my time for free.
I currently only assist people on the chains which make my work possible: Solana, Ethereum, Bitcoin, OP/Stark.
There is already many scams as is so I would rather focus my time on helping the ecosystems which give back and fund public goods (I receive 1K+ inbounds / month).
This is just a general reminder for all of those people who think they are entitled to my time for free.
π1.08Kβ€413π€£177π―97π88π₯48πΏ40π33π12β‘10π€―9
Investigations by ZachXBT
Do not buy the Wiz Khalifa Pump Fun it's the same hacker who compromised Andy Ayrey (Truth Terminal creator) the other day.
On-chain clown of the day: The threat actor who hacked Andy Ayrey sold PNUT early for $6.4K and missed out on $31.6M.
Wallet address
Gx3uCAS7su6HjVASf74KkPgsU23DP5sg8LmqiHStXmmT
Wallet address
Gx3uCAS7su6HjVASf74KkPgsU23DP5sg8LmqiHStXmmT
π€£764π114π44β€34π€―24π€ͺ20π³15π₯8π6π«‘5π€©4
Multisig exploiter just transferred 9980 ETH ($31.4M) to the crypto exchange eXch, swapping from Ethereum to Bitcoin in 7 orders.
Source address
0x2d146Aa23645950FDefBb23f636A5d1674FE1047
Destination address
bc1qffvx38hplm6ym5el5yakxmntezv7tg6yurghnq
bc1qut035lpe0k6yklcrkaquhvg4x65lkg5n3uvnel
bc1qe6yk9rnae0l96775gu99zvjdy496j3rrfc5sm0
bc1q4cwvw5x89pjaquq5e25ghjgffevmz6rtz043tx
bc1qpj24paw8hunju2z6fharwej82rfjywexsz629a
bc1qrzzdx82jv4t4tlkfc0gsqjpjp2r9r6ptq7rtuf
bc1qyht95cksxh2un0elgdaq0up874s99kj80ev97d
Source address
0x2d146Aa23645950FDefBb23f636A5d1674FE1047
Destination address
bc1qffvx38hplm6ym5el5yakxmntezv7tg6yurghnq
bc1qut035lpe0k6yklcrkaquhvg4x65lkg5n3uvnel
bc1qe6yk9rnae0l96775gu99zvjdy496j3rrfc5sm0
bc1q4cwvw5x89pjaquq5e25ghjgffevmz6rtz043tx
bc1qpj24paw8hunju2z6fharwej82rfjywexsz629a
bc1qrzzdx82jv4t4tlkfc0gsqjpjp2r9r6ptq7rtuf
bc1qyht95cksxh2un0elgdaq0up874s99kj80ev97d
π153π80β€38π28π€22π₯18π17π³12π‘11π¨βπ»9πΏ6
A few hours ago wallets tied to crypto influencer JRNY saw ~$4M worth of crypto assets suspiciously transferred out and sold indicating a potential private key compromise.
Theft address
0xc467150582cfc8eec4132a483c76101d3636f598
0x6fd6c8fd64c7efdb8eec902161d3bbc035430456
0xa2dd5e2ab84240cbecc7beaca9946afef97ae74a
Theft address
0xc467150582cfc8eec4132a483c76101d3636f598
0x6fd6c8fd64c7efdb8eec902161d3bbc035430456
0xa2dd5e2ab84240cbecc7beaca9946afef97ae74a
π±211π87π€£70π39β€33π11π11π¨βπ»11π€¨9π€6π₯°5
Yubico (security key), Proton (email), & Tuta (email) all have sales going on today for those who still use gmail or have SMS 2FA enabled instead of a security key.
Proton lets you pay with crypto (BTC only). Tuta you can buy a giftcard with XMR from their official partner (ProxyStore).
Trezor & Ledger also have select items on sale as well if you still do not own hardware wallets and leave all funds in a hot wallet.
While most of you do this many others need the reminder as way too many thefts/incidents are preventable. Remember to only purchase items on the official site and not from random marketplaces/stores. I do not have referral links.
Proton lets you pay with crypto (BTC only). Tuta you can buy a giftcard with XMR from their official partner (ProxyStore).
Trezor & Ledger also have select items on sale as well if you still do not own hardware wallets and leave all funds in a hot wallet.
While most of you do this many others need the reminder as way too many thefts/incidents are preventable. Remember to only purchase items on the official site and not from random marketplaces/stores. I do not have referral links.
β€608π144π₯51π«‘26π€£20π₯΄13π€8πΎ8β7π4π3
A few hours ago a victim was drained on Solana for $2.2M+ worth of meme coins ($1.43M PNUT, $400K ZEREBRO, $130K ALCH, etc)
Theft address
7DQZQzydMPhFdhQnFYkwwNkykqeYADcj14JxYLAgVbBm
2CJ5d3o6MaCsgmZNZRrDE9fHuWRZ3Gpc5MBdMkz6HUxy
8qRK51ghCidRvwpYNRiu9hdUsg6UA7ZQF71HCAeUnBDZ
Theft address
7DQZQzydMPhFdhQnFYkwwNkykqeYADcj14JxYLAgVbBm
2CJ5d3o6MaCsgmZNZRrDE9fHuWRZ3Gpc5MBdMkz6HUxy
8qRK51ghCidRvwpYNRiu9hdUsg6UA7ZQF71HCAeUnBDZ
π’239π83β€33π26π€¬19π₯13π€ͺ11π10π9π‘7π€4