News
Coverage of crypto exploits, drains and scams, alongside reports filed by people who lost funds. Every item names the addresses involved and what PublicAML sees on them.
Investigations
- Where Amir Capital’s money went: a four-chain trace
- Finiko: what the chain says, and why the published totals conflict
- Finiko’s FNK token: the $14 million taken from its pool two years after the collapse
- FomoPeek: the App Store app that read wallet keys off the phone
- Term Labs: all of the stolen ETH went to Tornado Cash, and the DAI went to Robinhood Chain
- Nesa: the "$50 million" exploit that cashed out at about 109 ETH, into KuCoin
- Nomic and Osmosis allBTC: the 40.65 BTC nobody noticed for 74 days
- Tectonic: the branch that skipped Tornado — 232 XMR1 still sitting on Hyperliquid
- Liquid Network hack: the 598.5 BTC has not moved
Items marked Report are filings from readers, published as they were filed. Most have not been checked by anyone, and an unchecked report puts no risk label on any address. File a report.
- Report · Theftethereum2 addressesInvestigator
Other blackmail report VR-0E90FB07
Second violent robbery in the same ZachXBT investigation, published 24 August 2026. On 20 April 2026 multiple attackers targeted a victim in France, tied them up and threatened them until they surrendered ~$110K in crypto. The stolen funds went to 0x3000d2A2ef9Bd8b614b368408768a6e25Bf4dE0F. Laundering path per ZachXBT: the funds were bridged to Ethereum and ~46 ETH (~$107K) was laundered through a Kucoin deposit address. Timing analysis on the matching Kucoin withdrawal identified 0x5fb7194CC893CdC8339fA1bD7E8B52cDB3d3d075, which then consolidated with proceeds from the first robbery. Both addresses in this report belong to the same operation: - 0x3000d2A2ef9Bd8b614b368408768a6e25Bf4dE0F — theft address, received the stolen funds directly - 0x5fb7194CC893CdC8339fA1bD7E8B52cDB3d3d075 — received the Kucoin withdrawal after laundering The investigation attributes both April 2026 robberies to a French actor operating as M1llionz / RichMilly666, $667K taken across the two incidents. The first robbery (17 April, ~7.2 BTC) is filed separately as VR-5B01D18E. ZachXBT's work led to a $93K Tether freeze tied to the case. Category note: physical coercion, not an online scam. The form has no category for robbery or extortion under physical threat, so this is filed under the closest available option (other blackmail). Source: ZachXBT thread, https://x.com/zachxbt/status/2091858014236295170 (posts 4/ and 5/ name these addresses). Filed by PublicAML from public reporting, not by a victim.
- Report · Phishingethereum1 addressInvestigator
Tech support phishing report VR-F1AD2F0C
Wallet attributed to Veer Chetal ("Wiz"/"Swag") in the $243M social-engineering theft of 19 August 2024, published by ZachXBT on 19 September 2024. The case: three actors — Malone Iam ("Greavys"), Veer Chetal ("Wiz"/"Swag") and Jeandiel Serrano ("Box"/"John") — socially engineered a single victim out of 4,064.3769 BTC (~$238M at the time, $243M across all assets). ZachXBT's investigation contributed to multiple arrests and to millions being frozen; a later superseding indictment confirmed the arrest of a further participant in Dubai. This address appears in ZachXBT's OSINT chart labelled "Wallet Address" for Veer Chetal. PublicAML read it out of that chart and verified it on-chain: an externally owned account, 109 transactions, activity clustered in early September 2024 — days after the theft — and our engine already scored it 40 on indirect exposure, tracing an inbound path from a mixer two hops out. Two other addresses in the same chart were deliberately NOT reported. PublicAML's own data classifies 0x6ef702810a1A221682FdEBCbd353e6E249e4248e and 0xe8Bde8169a2f6eD6855201AFcAc7Be05a5639B25 as centralised-exchange hubs. They are labelled "Wallet address" in the chart, but flagging an exchange hub would brand an intermediary rather than an actor. The seizure address published in a later update (0xb37d617716e46511E56FE07b885fBdD70119f768) is likewise excluded — it belongs to the authorities holding recovered funds. Category note: filed under tech-support phishing as the closest available label; the actual method was voice-based social engineering impersonating exchange and platform support. Source: https://x.com/zachxbt/status/1836752923830702392. Filed by PublicAML from public reporting plus our own verification, not by a victim of the incident.
- Report · Hackbsc6 addressesInvestigator
Contract exploit report VR-4690757D
LULA exploit on BNB Smart Chain, 29 July 2026, ~$578K lost. Reported by CertiK Alert; PublicAML read the addresses out of their call-trace screenshot and verified the contract types on-chain. Mechanism visible in the trace: a chain of contracts calls claimTeamReward() and claimReferralReward() on the LULA contract, which triggers recycle(amount = 5,466,425,413,399,659,914,651) and then LULA.transfer() payouts back to the callers. The privileged recycle() path is abused to mint rewards repeatedly. Addresses reported here, all with the same role — callers that received the drained LULA: 0x2a6Cf8592D1CC22BEd916481bb745ccAf80aE6F1 (received 5,335,604,142,729,676,918,919 LULA) 0xF60F0895301fdEF5f4795A8A6b57f5cb2A664E3c 0xFE2554A23b352dEC8A93aFD2DD463A453d8eE0CE 0xfD7eaBd41D826ADBA28Ef982BcC75AB1C679E4FA 0x6222155a9010Ec62dDe38e8E1606c7Bcd4Ce5897 0x296f885d55Fd78482e2bE4BC660518BE7E4d4481 (received 280,821,270,669,982,995,732 LULA) Verified via eth_getCode on BNB Smart Chain: the first five are minimal-proxy clones (48 bytes of code each) — disposable contracts deployed to repeat the reward claim. The last is an externally owned account. Deliberately NOT reported: 0x377a015f44C3FDf71060e94648EDC9e0316C7f1a appears in the same trace, but it carries 43,764 bytes of code and does not respond to name(). It may be protocol infrastructure rather than attacker-controlled, and we do not flag an address we cannot place with confidence. Source: https://x.com/CertiKAlert/status/2082309959484911845. Filed by PublicAML from public reporting plus our own on-chain verification, not by a victim of the incident.
- Report · Hackethereum2 addressesInvestigator
Contract exploit report VR-56B95658
Verus Ethereum Bridge exploit, 23 July 2026, ~$7.53M drained. Reported by CertiK Alert; PublicAML recovered the full addresses from their screenshot and verified everything on-chain. Root cause per CertiK: the "hashOfTransfers" value calculated from "serializedTransfers" decoded to draining transfers, letting the caller push forged imports through the bridge. 0xBda71b58cEc0b1C20A8f87cCD52FA0679747855c — the caller. Verified on-chain: submitImports on the Verus bridge contract 0x71518580f36FeCEFfE0721F06bA4703218cD7F63 in block 25592836 at 03:45:59 UTC on 23 July 2026, transaction 0xa1f1e65c1cea4dba4ae439cd4dcdba6cc2dbda0ed1228e61f29ae9c9324eb099. The same address had called setLatestData twice in the minutes before. 0xCFd0A20703cD11E0b9f665e1C3F1Ef989C142D54 — the recipient of the drained assets. All seven ERC-20 transfers in that transaction went here: 71.5 tBTC ($4.69M), 220,357 DAI, 149,275 USDC, 78,300 USDT, 92,784 scrvUSD, 31,475 EURC and 59.43 MKR, plus 1,137.45 ETH ($2.19M) as an internal transfer. Our enrich already flagged it as mixer-interaction before this report. Both are externally owned accounts, not contracts. The bridge contract itself is the victim and is not reported here. Source: https://x.com/CertiKAlert/status/2080153763332174170. Filed by PublicAML from public reporting plus our own on-chain verification, not by a victim of the incident.
- Report · Hackethereum2 addressesInvestigator
Contract exploit report VR-99A3B8E7
Addresses laundering the proceeds of the Term Labs exploit (23 August 2026, ~$8.5M lost), reported by PeckShieldAlert on 4 September 2026. PeckShield's alert referenced the exploiter address only inside a screenshot. PublicAML recovered the full addresses from the block numbers visible in that screenshot and verified every movement on-chain. 0xC14007663A5bb9F13d4d2AEE8c6FE9075eF1d83e — deposits into Tornado Cash. Verified on-chain: four deposits of 100 ETH each into the Tornado Router in blocks 25904455, 25904456, 25904457 and 25904460 on 4 September 2026 between 14:08:35 and 14:09:35 UTC. PeckShield reported 960 ETH (~$2.35M) deposited in total. Our own enrich already flagged this address as mixer-interaction before this report. 0xD5183d8BfC65a50863C62aF2538198A8288FFc13 — the funding address that supplied it. Verified on-chain: 100 ETH on 24 August, 400 ETH on 4 September 13:58, 100 ETH and 400 ETH on 4 September 19:10-19:12, then 2,000 ETH and 41.48 ETH on 5 September 05:03-05:16. Both are externally owned accounts, not contracts, and both are now effectively empty. Note on roles: PeckShield labels the first address the "Term Labs exploiter". The second is upstream of it and is recorded here as the source of the laundered funds, not as a separately confirmed exploiter. Source: https://x.com/PeckShieldAlert/status/2095881691017646109. Filed by PublicAML from public reporting plus our own on-chain verification, not by a victim of the incident.
- Report · Phishingethereum1 addressInvestigator
Tech support phishing report VR-B373F58A
Ethereum leg of the same support-impersonation theft, exposed by ZachXBT on 10 August 2026. In June 2026 a victim lost $1.2M in Bitcoin and Ethereum after the group drained their Trezor wallet, following a spoofed BitcoinIRA email sent under the alias "Patricia Massie". ZachXBT names this address alongside the bitcoin address in post 3/ of the thread. The bitcoin leg (6.9944 BTC, moved 19 June 2026) is filed separately as a Bitcoin report — this form accepts one chain per report. Method: the actor phones victims posing as exchange or hardware-wallet support and talks them into surrendering access to their funds. ZachXBT published recordings of her taunting victims after draining them. A second actor using the aliases "bled" and "harm" appears to have supplied the phishing panel infrastructure. The investigation names Tiffany Milanovich, a US-based threat actor tied to at least $5M in thefts of this type. Amount note: the $1.2M figure is the total loss across both chains as reported by ZachXBT; he does not break it down per chain. The 46 ETH entered here is the largest single movement observed on this address on-chain (11 August 2026), not a confirmed split of the stolen total. The address is now effectively empty. Source: ZachXBT thread, https://x.com/zachxbt/status/2086785488149774411. Filed by PublicAML from public reporting, not by a victim of the incident.
- Report · Phishingbitcoin1 addressInvestigator
Tech support phishing report VR-9FD8D72C
Theft address from a support-impersonation ("caller") operation exposed by ZachXBT on 10 August 2026. In June 2026 a victim lost $1.2M in Bitcoin and Ethereum. The group drained the victim's Trezor wallet after a spoofed BitcoinIRA email sent under the alias "Patricia Massie". The bitcoin leg of the theft went to this address: 6.9944 BTC arrived and left on 19 June 2026 across two transactions, and the address is now empty. Method: the actor phones victims posing as exchange or hardware-wallet support and talks them into surrendering access. ZachXBT published call recordings in which she taunts victims after draining them. Another actor operating as "bled"/"harm" appears to have supplied the phishing panel infrastructure. The investigation names Tiffany Milanovich, a US-based threat actor tied to at least $5M in thefts from hardware-wallet and centralised-exchange support impersonation. The Ethereum leg of the same June 2026 theft is 0x491333E8EA6f4fC2a2475DB01b649e1E4602ec3c, filed separately because this form takes one chain per report. Source: ZachXBT thread, https://x.com/zachxbt/status/2086785488149774411 (post 3/ names this address). Filed by PublicAML from public reporting, not by a victim of the incident.
- Report · Theftbitcoin1 addressInvestigator
Other blackmail report VR-5B01D18E
Theft address from a violent home invasion robbery in France, published by ZachXBT on 24 August 2026. On 17 April 2026 five attackers carried out a home invasion robbery against a victim in France and took ~7.2 BTC (~$557K). Several people were hospitalised. The stolen bitcoin was sent to this address. Laundering path per ZachXBT: the funds were bridged from Bitcoin to Ethereum via Chainflip, and $317K was then laundered through three Kucoin deposit addresses. He performed timing analysis on the matching withdrawals to link them to the same actor. The investigation attributes this and a second robbery (20 April 2026) to a French actor operating as M1llionz / RichMilly666, with $667K taken across both incidents. ZachXBT's work led to a $93K Tether freeze tied to the case. Category note: this was physical coercion, not an online scam. PublicAML's report form has no category for robbery or extortion under physical threat, so this is filed under the closest available option (other blackmail). The correct label would be theft under coercion. Source: ZachXBT thread, https://x.com/zachxbt/status/2091858014236295170 (post 2/ names this address). Filed by PublicAML from public reporting, not by a victim of the incident.
- Report · Phishingethereum1 addressInvestigator
Website phishing report VR-B11FE031
Cash-out wallet holding the proceeds of an Inferno Drainer approval-phishing theft. Traced by PublicAML from the victim address published by Scam Sniffer on 1 September 2026. Chain of events: 1. Victim 0x686618abb3730079601a5abead6ec24549c5ce34 signed a phishing approval in February 2024 and never revoked it. SYN arrived 30 August 2026 and was drained 25 hours later. 2. The drain transaction 0x1c000ae7bf83d24c79ebae962561e253ed26fc7d9a908e188dc721d33597b4bb is an execTransaction signed by 0x0000db5c8B030ae20308ac975898E09741e70000 — Inferno Drainer, already scored 100 (hacker) in our base. 3. 1,311,357 SYN moved to the victim's Gnosis Safe 0x9EC9ca0c7846E8726D5d734EFd291f855ea03447, then out in 14 transfers to CoW Protocol settlement 0x9008D19f58AAbD9eD0D60971565AA8510560ab41 between 00:48 and 01:01 UTC on 1 September. 4. The swap proceeds landed here: 14 internal ETH transfers from the CoW settlement contract to this address, 00:54-01:01 UTC on 1 September, totalling 45.0957 ETH. This address is an externally owned account, not a contract. As of 8 September 2026 it holds 45.0957 ETH and has made zero outgoing transactions — the funds have not moved since they arrived. Attribution basis: PublicAML /v1/trace swap-through followed the CoW batch settlements to the actual payee (attribution: same-payee-as-attributable-settlement), cross-checked against on-chain internal transfers. Filed by PublicAML from public sources and our own tracing, not by a victim of the incident.
- Report · Phishingethereum1 addressInvestigator
Website phishing report VR-F1D5B63D
Cash-out wallet holding the proceeds of an Inferno Drainer approval-phishing theft. Traced by PublicAML from the victim address published by Scam Sniffer on 1 September 2026. Chain of events: 1. Victim 0x686618abb3730079601a5abead6ec24549c5ce34 signed a phishing approval in February 2024, never revoked. SYN arrived 30 August 2026 and was drained 25 hours later. 2. The drain transaction 0x1c000ae7bf83d24c79ebae962561e253ed26fc7d9a908e188dc721d33597b4bb is an execTransaction signed by 0x0000db5c8B030ae20308ac975898E09741e70000 — Inferno Drainer, already scored 100 (hacker) in our base. 3. 1,311,357 SYN moved to the victim's Gnosis Safe 0x9EC9ca0c7846E8726D5d734EFd291f855ea03447, then out in 14 transfers to CoW Protocol settlement 0x9008D19f58AAbD9eD0D60971565AA8510560ab41 between 00:48 and 01:01 UTC on 1 September. 4. The swap proceeds landed here: 14 internal ETH transfers from CoW settlement to this address, 00:54–01:01 UTC on 1 September, totalling 45.0957 ETH. This address is an externally owned account, not a contract. As of 8 September 2026 it holds 45.0957 ETH and has made zero outgoing transactions — the funds have not moved since. Attribution basis: PublicAML /v1/trace swap-through, which followed the CoW batch settlements to the actual payee (attribution: same-payee-as-attributable-settlement), cross-checked against on-chain internal transfers. Filed by PublicAML from public sources and our own tracing, not by a victim of the incident.
- Report · Hackbitcoin1 addressInvestigator
Protocol attack report VR-717BCCC5
Liquid Network (Liquid Federation) protocol exploit, 7 September 2026. An Elements minting bug allowed the creation of unbacked L-BTC, which was then routed out through SideSwap's peg-out. Federation keys were not compromised and the transaction appeared valid — this was a protocol-level flaw, not a key compromise. Approximately 4,000 BTC (~$320M at the time) was siphoned from the Liquid Federation wallet and consolidated into bc1ql4mfu6aundtkksxklfajs2h3t9nzcd6gyqjlte. The party left an on-chain message reading "we are whitehats. contact us on chain." On 8 September 2026 roughly 3,400 BTC (~$315M) was returned, while 598.5 BTC (~$47.4M) was retained at the same address and has not been returned. Reported by PeckShieldAlert on X, 7 September 2026. This report is filed by PublicAML from public sources, not by a victim of the incident. The address is recorded as the consolidation point of exploited funds; the "whitehat" claim is the actor's own and is not independently verified.
- Report · Otherethereum1 addressInvestigator
Other report VR-1AC08533
My wallet seed phrase was compromised and my funds were drained. The stolen funds were sent to this address: 0x152bC6cEF7e314CF208c6185651597554Fa5bdD4. Requesting it be flagged as a hacker/theft address.
