ZachXBT intercepts $7M from recent $330M BTC phishing heist
By: bitcoin ethereum news|2025/05/03 04:00:10
0
Share
On-chain investigator ZachXBT shed more light on the recent case of BTC phishing that took away 3,520 BTC from a single wallet. Apparently, the funds were stolen in a personalized scam targeting an elderly investor. On-chain investigator ZachXBT shed more light on the recent heist that took 3,520 BTC from a single wallet. The heist was noticed when Monero (XMR) rallied to a one-year high, as the thief was trying to cash out through an anonymous coin. ZachXBT reported that $7M was tracked and frozen with the help of other on-chain investigators and Binance’s team. Update: So far $7M+ has been frozen with the help of @CFInvestigators , @tanuki42_ , Binance Security team, and myself. — ZachXBT (@zachxbt) May 2, 2025 The heist was traced to two social media personalities, Nina/Mo, and W0rk, who operated from the UK. The scammers later deleted their social media, though they left tracks on the Bitcoin chain. The targeted individual was based in the USA, and apparently had little trouble in keeping the BTC, after moving the funds to a new address about a month ago. The targeted wallet belonged to a relatively early BTC whale, who used Gemini to build up the large wallet. Investigators suspect either lax security or trusting the scammers enough to expose the wallet or send funds. No malware or smart contracts have been involved. Confidence games have also spoofed investment opportunities, complete with deposit links for crypto. BTC phishing funds swapped or kept in new wallets Heists targeting BTC are relatively rare, as the coin is not held in easily accessible Web3 wallets. However, the phishing team still managed to make their target to expose the wallet. Some of the funds are still held in new addresses with smaller holdings, split into small sums of 5 BTC . Over 17 BTC were sent to a KuCoin hot wallet , with the potential to intercept the funds. The hacker address received multiple transactions from the victim, with the largest one for 2.78K BTC in a single transaction. Investigators have not answered whether the victim sent out the transactions willingly or if the wallet’s keys were compromised. The theft of BTC remains unusual, as most confidence scams often resort to using stablecoins. However, the pattern of attacking elderly investors remains valid. Stablecoins can be concealed more easily, using P2P markets like Huione Guarantee. Following the theft, the price of XMR remained elevated at above $280. Most of the XMR volume concentrated on KuCoin. Nearly 47% of all XMR activity is locked in several pairs on the South Korean exchange. One obstacle for the hacker may be the inability to withdraw XMR from the exchange. The coin saw highly elevated volumes as other traders joined. KuCoin only shares its reserves of BTC, ETH, and stablecoins, with no data on actual XMR available for withdrawal. While on the exchange, XMR offers no actual privacy. However, KuCoin has not been mentioned as one of the assistants of ZachXBT for intercepting some of the funds. The MEXC exchange was also used for some of the swaps. The market operator has not shared its XMR or other available reserves. Cryptopolitan Academy: Want to grow your money in 2025? Learn how to do it with DeFi in our upcoming webclass. Save Your Spot Source: https://www.cryptopolitan.com/zachxbt-intercepts-7m-from-recent-330m-btc-phishing-heist/
You may also like

From Mining Enterprise to Infrastructure Builder, Bitdeer Unpacks the Survival Logic behind BTC
Profit margins nearing the red line, miners are starting to use Bitcoin as fuel.

How Can Agentic Commerce Empower AI to Start Making Money?
The first wave of moneymaking AIs has arrived, which projects are worth paying attention to

February Correction: Is the Crypto Market Bottoming Out?
Based on historical experience, the most intense phase of this downturn may be about to end.

AI Payments Through the Lens of Fintech Giants: Five Levels, Stablecoin Infrastructure, Next-Gen Globalized Commerce
Stripe took fifteen years to turn seven lines of code into a business empire that powers 1.6% of the global GDP. Its next move is to define the next generation of global business rules.

Zuckerberg Retweets Stablecoin, Can Meta Win This "Comeback Game"?
Compared to the Libra era of 2019 when it attempted to disrupt the global financial system, the 2026 Meta is demonstrating a more stable and compliance-oriented approach.

Polymarket New Rule Release: How to Build a New Trading Bot
In 2026, a truly winning trading Bot is not the fastest taker, but the most excellent liquidity provider

Bitwise: The Institutional Wave is Here, So Why is the Market Still Sleeping?
There is a significant gap between the perceived cryptocurrency market and the actual cryptocurrency market.

WEEX LALIGA Partnership 2026: Where Football Excellence Meets Crypto Innovation
WEEX becomes official crypto exchange partner of LALIGA in Hong Kong and Taiwan. Discover how this partnership brings together football excellence and trading discipline.

AI Apocalypse, a massive short squeeze
AI is not the doomsday prophecy, but the dawn of a new era of abundance stemming from the collapse of cognitive cost.

The "Second Truth" of the Luna Crash: Jane Street Exits Ahead of Plunge
In the cryptocurrency industry that touts "decentralization," true asymmetry may have never disappeared.

Jane Street Market Manipulation, Stripe Considering Acquiring PayPal, What's the Overseas Crypto Community Talking About Today?
What Was Trending for Expats in the Last 24 Hours?
WEEX × LALIGA 2026: Trade Crypto, Take Your Shot & Win Official LALIGA Prizes
Unlock shoot attempts through futures trading, spot trading, or referrals. Turn match predictions into structured rewards with BTC, USDT, position airdrops, and LALIGA merchandise on WEEX.

a16z: Why Do AI Agents Need a Stablecoin for B2B Payments?
Smart contracts will be more like corporate entities, forming long-term relationships with their vendors and partners.

February 24th Market Key Intelligence, How Much Did You Miss?
1. On-chain Funds: $172.4M inflow to Ethereum this week; $233.9M outflow from Arbitrum
2. Highest Price Variation: $ESP, $MYX
3. Top News: AC's "Never Rekt" new project Flying Tulip has experienced a rug pull, currently priced at $0.0989

Web4.0, perhaps the most needed narrative for cryptocurrency
What is Justin Sun's All-in Web4.0 Vision?

Some Key News You Might Have Missed Over the Chinese New Year Holiday
On the day of commencement, should we go long or short?

Key Market Information Discrepancy on February 24th - A Must-Read! | Alpha Morning Report
1. Top News: Tariff Uncertainty Returns as Bitcoin Options Market Bets on Downside Risk
2. Token Unlock: $SOSO, $NIL, $MON

$1,500,000 Salary Job: How to Achieve with $500 AI?
The Essence of Agentification: Use algorithms to replicate your judgment framework, replacing labor costs with API costs.
From Mining Enterprise to Infrastructure Builder, Bitdeer Unpacks the Survival Logic behind BTC
Profit margins nearing the red line, miners are starting to use Bitcoin as fuel.
How Can Agentic Commerce Empower AI to Start Making Money?
The first wave of moneymaking AIs has arrived, which projects are worth paying attention to
February Correction: Is the Crypto Market Bottoming Out?
Based on historical experience, the most intense phase of this downturn may be about to end.
AI Payments Through the Lens of Fintech Giants: Five Levels, Stablecoin Infrastructure, Next-Gen Globalized Commerce
Stripe took fifteen years to turn seven lines of code into a business empire that powers 1.6% of the global GDP. Its next move is to define the next generation of global business rules.
Zuckerberg Retweets Stablecoin, Can Meta Win This "Comeback Game"?
Compared to the Libra era of 2019 when it attempted to disrupt the global financial system, the 2026 Meta is demonstrating a more stable and compliance-oriented approach.
Polymarket New Rule Release: How to Build a New Trading Bot
In 2026, a truly winning trading Bot is not the fastest taker, but the most excellent liquidity provider