Inside the $282mln ZachXBT investigation – How stolen Bitcoin hit Tornado Cash

ambcryptoPublished on 2026-01-20Last updated on 2026-01-20

Abstract

In a major social engineering attack on January 10th, an attacker stole over $282 million in Bitcoin and Litecoin from a single victim by impersonating Trezor support and tricking them into revealing their seed phrase. Blockchain investigator ZachXBT and security firm PeckShield tracked the stolen funds as the attacker used THORChain—a decentralized, non-KYC protocol—to move approximately $71 million across blockchains. The funds were then obscured using Tornado Cash mixer and swapped into privacy-focused cryptocurrencies like Monero. The theft occurred amid broader market declines, highlighting how social manipulation and cross-chain protocols are increasingly exploited for large-scale laundering.

On the night of 10th January, while most of the world was asleep, one of the largest individual heists in crypto history was unfolding in real-time.

It wasn’t a flaw in code or a breach of a protocol, but a breach of human trust.

In a major move of social engineering, an attacker successfully bypassed the gold standard of hardware wallet security, siphoning over $282 million in Bitcoin and Litecoin from a single victim.

But the theft was only the beginning.

Details of the scam

As blockchain investigator ZachXBT and security firm PeckShield tracked events in real time, the attacker moved quickly to launder the stolen funds across multiple blockchains.

Hardware wallets like Trezor are often described as the safest way to store crypto. But they have one major weakness, and that is the person using them.

Reports suggest the victim was tricked through a highly convincing impersonation scam.

The attacker pretended to be “Trezor Value Wallet” support and gained the victim’s trust. Following this, the attacker convinced the victim to share their seed phrase that controls the wallet.

Once that happened, the hardware wallet no longer mattered.

Funds lost and moved

After stealing more than $282 million worth of Bitcoin [BTC] and Litecoin [LTC], the attacker saw that the transactions were visible on public blockchains.

Hence, to hide the trail, the attacker turned to THORChain, a decentralized liquidity protocol.

Using THORChain, the attacker moved around $71 million, or roughly 928.7 BTC, across different chains.

Unlike centralized exchanges, THORChain does not require KYC, allowing the attacker to swap Bitcoin for Ethereum and Ripple [XRP] without providing any identification.

Once the funds reached the Ethereum [ETH] network, the attacker took further steps to hide them.

A large amount, including 1,468.66 ETH worth about $4.9 million, was sent through Tornado Cash, a privacy mixer.

For those unaware, mixers combine funds from many users, breaking the clear link between where the money came from and where it ends up.

The attacker also swapped large amounts into Monero, a privacy-focused cryptocurrency, pushing Monero’s price higher for a short time.

Market reaction and more

All of this happened during a period of market chaos.

On the same day, crypto markets were already falling due to Trump’s new tariff shock.

Bitcoin dropped 2.26% to $93,075, while Litecoin fell 7.19% as per CoinMarketCap data.

However, with so many scams surging, there are signs of progress.

Recently, Europol and international law enforcement agencies shut down a major fraud and money laundering network operating across multiple countries.

That group had stolen more than €700 million from thousands of victims.


Final Thoughts

  • This incident proves that crypto security failures no longer involve bugs but trusted narratives, too.
  • Cross-chain liquidity protocols have unintentionally become accelerants for large-scale laundering.

Related Questions

QWhat was the primary method used by the attacker to steal the $282 million in cryptocurrency?

AThe attacker used a highly convincing impersonation scam, pretending to be 'Trezor Value Wallet' support to trick the victim into sharing their seed phrase.

QWhich decentralized liquidity protocol did the attacker use to move the stolen funds across different blockchains?

AThe attacker used THORChain, a decentralized liquidity protocol, to move around $71 million worth of Bitcoin across different chains.

QWhat tool did the attacker use on the Ethereum network to further obscure the trail of the stolen funds?

AThe attacker used Tornado Cash, a privacy mixer, to obscure the trail of the stolen funds, including sending 1,468.66 ETH through it.

QBesides moving funds through THORChain and Tornado Cash, what other privacy-focused cryptocurrency did the attacker swap large amounts into?

AThe attacker swapped large amounts of the stolen funds into Monero, a privacy-focused cryptocurrency.

QAccording to the article, what major weakness in hardware wallet security did this incident highlight?

AThe incident highlighted that the major weakness in hardware wallet security is the human user, as the victim was socially engineered into compromising their own security.

Related Reads

Trading

Spot
Futures

Hot Articles

What is $BITCOIN

DIGITAL GOLD ($BITCOIN): A Comprehensive Analysis Introduction to DIGITAL GOLD ($BITCOIN) DIGITAL GOLD ($BITCOIN) is a blockchain-based project operating on the Solana network, which aims to combine the characteristics of traditional precious metals with the innovation of decentralized technologies. While it shares a name with Bitcoin, often referred to as “digital gold” due to its perception as a store of value, DIGITAL GOLD is a separate token designed to create a unique ecosystem within the Web3 landscape. Its goal is to position itself as a viable alternative digital asset, although specifics regarding its applications and functionalities are still developing. What is DIGITAL GOLD ($BITCOIN)? DIGITAL GOLD ($BITCOIN) is a cryptocurrency token explicitly designed for use on the Solana blockchain. In contrast to Bitcoin, which provides a widely recognized value storage role, this token appears to focus on broader applications and characteristics. Notable aspects include: Blockchain Infrastructure: The token is built on the Solana blockchain, known for its capacity to handle high-speed and low-cost transactions. Supply Dynamics: DIGITAL GOLD has a maximum supply capped at 100 quadrillion tokens (100P $BITCOIN), although details regarding its circulating supply are currently undisclosed. Utility: While precise functionalities are not explicitly outlined, there are indications that the token could be utilized for various applications, potentially involving decentralized applications (dApps) or asset tokenization strategies. Who is the Creator of DIGITAL GOLD ($BITCOIN)? At present, the identity of the creators and development team behind DIGITAL GOLD ($BITCOIN) remains unknown. This situation is typical among many innovative projects within the blockchain space, particularly those aligning with decentralized finance and meme coin phenomena. While such anonymity may foster a community-driven culture, it intensifies concerns about governance and accountability. Who are the Investors of DIGITAL GOLD ($BITCOIN)? The available information indicates that DIGITAL GOLD ($BITCOIN) does not have any known institutional backers or prominent venture capital investments. The project seems to operate on a peer-to-peer model focused on community support and adoption rather than traditional funding routes. Its activity and liquidity are primarily situated on decentralized exchanges (DEXs), such as PumpSwap, rather than established centralized trading platforms, further highlighting its grassroots approach. How DIGITAL GOLD ($BITCOIN) Works The operational mechanics of DIGITAL GOLD ($BITCOIN) can be elaborated on based on its blockchain design and network attributes: Consensus Mechanism: By leveraging Solana’s unique proof-of-history (PoH) combined with a proof-of-stake (PoS) model, the project ensures efficient transaction validation contributing to the network's high performance. Tokenomics: While specific deflationary mechanisms have not been extensively detailed, the vast maximum token supply implies that it may cater to microtransactions or niche use cases that are still to be defined. Interoperability: There exists the potential for integration with Solana’s broader ecosystem, including various decentralized finance (DeFi) platforms. However, the details regarding specific integrations remain unspecified. Timeline of Key Events Here is a timeline that highlights significant milestones concerning DIGITAL GOLD ($BITCOIN): 2023: The initial deployment of the token occurs on the Solana blockchain, marked by its contract address. 2024: DIGITAL GOLD gains visibility as it becomes available for trading on decentralized exchanges like PumpSwap, allowing users to trade it against SOL. 2025: The project witnesses sporadic trading activity and potential interest in community-led engagements, although no noteworthy partnerships or technical advancements have been documented as of yet. Critical Analysis Strengths Scalability: The underlying Solana infrastructure supports high transaction volumes, which could enhance the utility of $BITCOIN in various transaction scenarios. Accessibility: The potential low trading price per token could attract retail investors, facilitating wider participation due to fractional ownership opportunities. Risks Lack of Transparency: The absence of publicly known backers, developers, or an audit process may yield skepticism regarding the project's sustainability and trustworthiness. Market Volatility: The trading activity is heavily reliant on speculative behavior, which can result in significant price volatility and uncertainty for investors. Conclusion DIGITAL GOLD ($BITCOIN) emerges as an intriguing yet ambiguous project within the rapidly evolving Solana ecosystem. While it attempts to leverage the “digital gold” narrative, its departure from Bitcoin's established role as a store of value underscores the need for a clearer differentiation of its intended utility and governance structure. Future acceptance and adoption will likely depend on addressing the current opacity and defining its operational and economic strategies more explicitly. Note: This report encompasses synthesised information available as of October 2023, and developments may have transpired beyond the research period.

363 Total ViewsPublished 2025.05.13Updated 2025.05.13

What is $BITCOIN

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of BTC (BTC) are presented below.

活动图片