Inside the $282mln ZachXBT investigation – How stolen Bitcoin hit Tornado Cash

ambcryptoPublished on 2026-01-20Last updated on 2026-01-20

Abstract

In a major social engineering attack on January 10th, an attacker stole over $282 million in Bitcoin and Litecoin from a single victim by impersonating Trezor support and tricking them into revealing their seed phrase. Blockchain investigator ZachXBT and security firm PeckShield tracked the stolen funds as the attacker used THORChain—a decentralized, non-KYC protocol—to move approximately $71 million across blockchains. The funds were then obscured using Tornado Cash mixer and swapped into privacy-focused cryptocurrencies like Monero. The theft occurred amid broader market declines, highlighting how social manipulation and cross-chain protocols are increasingly exploited for large-scale laundering.

On the night of 10th January, while most of the world was asleep, one of the largest individual heists in crypto history was unfolding in real-time.

It wasn’t a flaw in code or a breach of a protocol, but a breach of human trust.

In a major move of social engineering, an attacker successfully bypassed the gold standard of hardware wallet security, siphoning over $282 million in Bitcoin and Litecoin from a single victim.

But the theft was only the beginning.

Details of the scam

As blockchain investigator ZachXBT and security firm PeckShield tracked events in real time, the attacker moved quickly to launder the stolen funds across multiple blockchains.

Hardware wallets like Trezor are often described as the safest way to store crypto. But they have one major weakness, and that is the person using them.

Reports suggest the victim was tricked through a highly convincing impersonation scam.

The attacker pretended to be “Trezor Value Wallet” support and gained the victim’s trust. Following this, the attacker convinced the victim to share their seed phrase that controls the wallet.

Once that happened, the hardware wallet no longer mattered.

Funds lost and moved

After stealing more than $282 million worth of Bitcoin [BTC] and Litecoin [LTC], the attacker saw that the transactions were visible on public blockchains.

Hence, to hide the trail, the attacker turned to THORChain, a decentralized liquidity protocol.

Using THORChain, the attacker moved around $71 million, or roughly 928.7 BTC, across different chains.

Unlike centralized exchanges, THORChain does not require KYC, allowing the attacker to swap Bitcoin for Ethereum and Ripple [XRP] without providing any identification.

Once the funds reached the Ethereum [ETH] network, the attacker took further steps to hide them.

A large amount, including 1,468.66 ETH worth about $4.9 million, was sent through Tornado Cash, a privacy mixer.

For those unaware, mixers combine funds from many users, breaking the clear link between where the money came from and where it ends up.

The attacker also swapped large amounts into Monero, a privacy-focused cryptocurrency, pushing Monero’s price higher for a short time.

Market reaction and more

All of this happened during a period of market chaos.

On the same day, crypto markets were already falling due to Trump’s new tariff shock.

Bitcoin dropped 2.26% to $93,075, while Litecoin fell 7.19% as per CoinMarketCap data.

However, with so many scams surging, there are signs of progress.

Recently, Europol and international law enforcement agencies shut down a major fraud and money laundering network operating across multiple countries.

That group had stolen more than €700 million from thousands of victims.


Final Thoughts

  • This incident proves that crypto security failures no longer involve bugs but trusted narratives, too.
  • Cross-chain liquidity protocols have unintentionally become accelerants for large-scale laundering.

Related Questions

QWhat was the primary method used by the attacker to steal the $282 million in cryptocurrency?

AThe attacker used a highly convincing impersonation scam, pretending to be 'Trezor Value Wallet' support to trick the victim into sharing their seed phrase.

QWhich decentralized liquidity protocol did the attacker use to move the stolen funds across different blockchains?

AThe attacker used THORChain, a decentralized liquidity protocol, to move around $71 million worth of Bitcoin across different chains.

QWhat tool did the attacker use on the Ethereum network to further obscure the trail of the stolen funds?

AThe attacker used Tornado Cash, a privacy mixer, to obscure the trail of the stolen funds, including sending 1,468.66 ETH through it.

QBesides moving funds through THORChain and Tornado Cash, what other privacy-focused cryptocurrency did the attacker swap large amounts into?

AThe attacker swapped large amounts of the stolen funds into Monero, a privacy-focused cryptocurrency.

QAccording to the article, what major weakness in hardware wallet security did this incident highlight?

AThe incident highlighted that the major weakness in hardware wallet security is the human user, as the victim was socially engineered into compromising their own security.

Related Reads

Apple's Desired On-Device AI Sees a Dark Horse Emerge: The First Cognitive Model is Born, 4B Matches GPT-5.4

A Chinese company, Tomorrow's Journey (Nextie), has introduced what it is calling the industry's first "cognitive model" for edge devices. Named New Journey Alpha, this 4-billion-parameter model reportedly matches the performance of trillion-parameter giants like GPT-5.4 in group intelligence tasks such as debate and collective decision-making. The development follows Andrej Karpathy's vision of stripping vast factual knowledge from large language models to retain only a smaller "cognitive core" capable of reasoning, planning, and knowing its own limits. This approach directly addresses the soaring computational costs and token expenses hindering AI's widespread deployment, as highlighted by incidents like Amazon shutting down an internal AI tool due to prohibitive costs. Trained via reinforcement learning on a corpus of academic papers from 1800-2020 to enhance generalization, the model enables three key advancements: 1) Improved decision quality in multi-agent systems, 2) Drastically reduced compute costs, allowing for cost-effective cloud or on-device (e.g., MacBook) deployment, and 3) The feasibility of "proactive" AI agents that act autonomously without user prompts, unlocking new commercial possibilities beyond today's reactive models. Built by the former Microsoft Xiaoice team—known for creating a 3.6B model that outperformed a 65B Llama model—the company is now focusing on the multi-agent systems sector, a field gaining significant investor interest. The model's economic impact is profound; by achieving high-level performance with minimal parameters, it fundamentally alters the cost structure of AI services, challenging the prevailing model of ever-larger parameter counts.

marsbit2h ago

Apple's Desired On-Device AI Sees a Dark Horse Emerge: The First Cognitive Model is Born, 4B Matches GPT-5.4

marsbit2h ago

OpenAI's 'Blueprint for the Future': Making AI Beneficial for Every Person on the Planet

A new transformative technology emerges every few generations. OpenAI draws a parallel with the advent of electricity in the 1920s, which initially brought convenience but ultimately enabled unprecedented progress in medicine, engineering, and living standards by empowering people to create new possibilities. AI is poised to recreate this phenomenon. Its true significance lies not in the technology itself, but in what people can achieve with it—from understanding a medical bill or starting a business to aiding scientific discovery. OpenAI believes AI should be universally accessible, allowing everyone to use it according to their own needs. This future, however, is not guaranteed. While transformative tech can centralize power, OpenAI's philosophy is that AI must serve humanity, augmenting human capabilities and broadly distributing its benefits. The company's first commitment is to build AI for human service, aiming to empower the many rather than concentrate power in a few. Safety, alignment with human intent, and oversight are paramount. OpenAI is optimistic about AI's potential to expand human welfare but remains clear-eyed about risks. The goal is to help people achieve more, not to replace them. Full automation is not the desired future; human judgment, values, and direction will become even more critical. OpenAI outlines three core goals: 1. Build automated AI researchers to accelerate and increasingly automate the research process itself, maintaining close human collaboration. The internal projection is that by March 2028, a significant portion of their research will be conducted by AI systems working alongside human researchers. 2. Accelerate economic development by advancing science, boosting productivity, and fostering growth, while ensuring the fruits are widely shared. 3. Provide a personal AGI for everyone on Earth, allowing individuals to benefit from this transformative technology in their own way. The company is entering its third phase, moving from foundational AGI research (Phase 1) to product deployment and learning from real-world use (Phase 2). The current challenge is making advanced AI abundant, affordable, safe, practical, and usable for all individuals and organizations. OpenAI concludes that a widely distributed power structure leads to a more resilient, adaptable, and free society. A positive AI future should not be controlled by a handful of entities but built, benefited from, and owned by many. If realized correctly, AI can become a cornerstone for enhancing global productivity, creativity, scientific advancement, and economic opportunity, fulfilling the mission to ensure AGI benefits all of humanity.

marsbit2h ago

OpenAI's 'Blueprint for the Future': Making AI Beneficial for Every Person on the Planet

marsbit2h ago

Arthur Hayes' New Article: AI Bubble Nears Bursting, Crypto Market Faces Short-Term Pressure

In a new essay, Arthur Hayes argues that the AI market bubble is approaching a rupture, which will place significant short-term pressure on crypto assets. He identifies rising oil prices, a trio of massive tech IPOs (SpaceX, Anthropic, OpenAI), and potential anti-AI political rhetoric from Trump as the three key catalysts for a correction. Hayes posits that the prolonged blockage of the Strait of Hormuz will drive energy prices higher, increasing operational costs for data centers and squeezing AI company profits. Simultaneously, the market may struggle to absorb the upcoming wave of multi-trillion dollar tech IPOs. Furthermore, with high inflation hurting his election chances, Trump could pivot to attacking the AI sector with proposals for heavy taxation and regulation to win over voters, spooking the market. Hayes notes that nearly all new dollar liquidity since 2022 has flowed into the AI sector, leaving little for Bitcoin, explaining its recent underperformance. He believes an AI stock crash would trigger a broad risk-off sentiment and credit contraction, dragging down crypto in the near term. Consequently, his fund, Maelstrom, has sold all AI-related stocks and non-core cryptocurrencies, retaining only Bitcoin and Ethereum while building positions in traditional energy stocks. He anticipates Bitcoin will bottom and resume its bull run only after the AI bubble pops and a new monetary easing cycle begins.

marsbit2h ago

Arthur Hayes' New Article: AI Bubble Nears Bursting, Crypto Market Faces Short-Term Pressure

marsbit2h ago

Trading

Spot
Futures

Hot Articles

What is $BITCOIN

DIGITAL GOLD ($BITCOIN): A Comprehensive Analysis Introduction to DIGITAL GOLD ($BITCOIN) DIGITAL GOLD ($BITCOIN) is a blockchain-based project operating on the Solana network, which aims to combine the characteristics of traditional precious metals with the innovation of decentralized technologies. While it shares a name with Bitcoin, often referred to as “digital gold” due to its perception as a store of value, DIGITAL GOLD is a separate token designed to create a unique ecosystem within the Web3 landscape. Its goal is to position itself as a viable alternative digital asset, although specifics regarding its applications and functionalities are still developing. What is DIGITAL GOLD ($BITCOIN)? DIGITAL GOLD ($BITCOIN) is a cryptocurrency token explicitly designed for use on the Solana blockchain. In contrast to Bitcoin, which provides a widely recognized value storage role, this token appears to focus on broader applications and characteristics. Notable aspects include: Blockchain Infrastructure: The token is built on the Solana blockchain, known for its capacity to handle high-speed and low-cost transactions. Supply Dynamics: DIGITAL GOLD has a maximum supply capped at 100 quadrillion tokens (100P $BITCOIN), although details regarding its circulating supply are currently undisclosed. Utility: While precise functionalities are not explicitly outlined, there are indications that the token could be utilized for various applications, potentially involving decentralized applications (dApps) or asset tokenization strategies. Who is the Creator of DIGITAL GOLD ($BITCOIN)? At present, the identity of the creators and development team behind DIGITAL GOLD ($BITCOIN) remains unknown. This situation is typical among many innovative projects within the blockchain space, particularly those aligning with decentralized finance and meme coin phenomena. While such anonymity may foster a community-driven culture, it intensifies concerns about governance and accountability. Who are the Investors of DIGITAL GOLD ($BITCOIN)? The available information indicates that DIGITAL GOLD ($BITCOIN) does not have any known institutional backers or prominent venture capital investments. The project seems to operate on a peer-to-peer model focused on community support and adoption rather than traditional funding routes. Its activity and liquidity are primarily situated on decentralized exchanges (DEXs), such as PumpSwap, rather than established centralized trading platforms, further highlighting its grassroots approach. How DIGITAL GOLD ($BITCOIN) Works The operational mechanics of DIGITAL GOLD ($BITCOIN) can be elaborated on based on its blockchain design and network attributes: Consensus Mechanism: By leveraging Solana’s unique proof-of-history (PoH) combined with a proof-of-stake (PoS) model, the project ensures efficient transaction validation contributing to the network's high performance. Tokenomics: While specific deflationary mechanisms have not been extensively detailed, the vast maximum token supply implies that it may cater to microtransactions or niche use cases that are still to be defined. Interoperability: There exists the potential for integration with Solana’s broader ecosystem, including various decentralized finance (DeFi) platforms. However, the details regarding specific integrations remain unspecified. Timeline of Key Events Here is a timeline that highlights significant milestones concerning DIGITAL GOLD ($BITCOIN): 2023: The initial deployment of the token occurs on the Solana blockchain, marked by its contract address. 2024: DIGITAL GOLD gains visibility as it becomes available for trading on decentralized exchanges like PumpSwap, allowing users to trade it against SOL. 2025: The project witnesses sporadic trading activity and potential interest in community-led engagements, although no noteworthy partnerships or technical advancements have been documented as of yet. Critical Analysis Strengths Scalability: The underlying Solana infrastructure supports high transaction volumes, which could enhance the utility of $BITCOIN in various transaction scenarios. Accessibility: The potential low trading price per token could attract retail investors, facilitating wider participation due to fractional ownership opportunities. Risks Lack of Transparency: The absence of publicly known backers, developers, or an audit process may yield skepticism regarding the project's sustainability and trustworthiness. Market Volatility: The trading activity is heavily reliant on speculative behavior, which can result in significant price volatility and uncertainty for investors. Conclusion DIGITAL GOLD ($BITCOIN) emerges as an intriguing yet ambiguous project within the rapidly evolving Solana ecosystem. While it attempts to leverage the “digital gold” narrative, its departure from Bitcoin's established role as a store of value underscores the need for a clearer differentiation of its intended utility and governance structure. Future acceptance and adoption will likely depend on addressing the current opacity and defining its operational and economic strategies more explicitly. Note: This report encompasses synthesised information available as of October 2023, and developments may have transpired beyond the research period.

363 Total ViewsPublished 2025.05.13Updated 2025.05.13

What is $BITCOIN

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of BTC (BTC) are presented below.

活动图片