BTC $62,816.87 -1.30%
ETH $1,874.08 -0.55%
BNB $607.72 -0.87%
XRP $1.00 -0.62%
SOL $75.69 -0.42%
TRX $0.3333 -0.58%
DOGE $0.0698 -0.62%
ADA $0.1823 -1.73%
BCH $205.46 -4.65%
LINK $8.77 +0.84%
HYPE $56.66 -0.53%
AAVE $87.12 -1.98%
SUI $0.6798 -1.13%
XLM $0.1587 -1.29%
ZEC $489.33 -1.28%
BTC $62,816.87 -1.30%
ETH $1,874.08 -0.55%
BNB $607.72 -0.87%
XRP $1.00 -0.62%
SOL $75.69 -0.42%
TRX $0.3333 -0.58%
DOGE $0.0698 -0.62%
ADA $0.1823 -1.73%
BCH $205.46 -4.65%
LINK $8.77 +0.84%
HYPE $56.66 -0.53%
AAVE $87.12 -1.98%
SUI $0.6798 -1.13%
XLM $0.1587 -1.29%
ZEC $489.33 -1.28%

zachxbt

ZachXBT is a cryptocurrency detective and a council member of Polygon Labs.
All
Article
Flash

ZachXBT: American female scammer impersonates customer service to steal over 5 million dollars in cryptocurrency assets

On-chain detective ZachXBT posted that U.S. threat actor Tiffany Milanovich participated in the theft of approximately $5 million in crypto assets by impersonating hardware wallet and centralized exchange customer service.Her methods included disguising as Bitcoin IRA email support, during one attack transferring about $1.2 million in BTC and ETH from the victim's Trezor wallet, and in another case stealing about $500,000 in BTC from a Coinbase account. Tiffany induced victims to hand over access to their funds under the guise of "customer service calls," later boasting about the stolen money on social media and Telegram groups, mocking victims with recordings, and collaborating with other threat actors to launder money using phishing panels and instant exchange services, with some of the stolen funds still dormant on-chain.The threat actor codenamed "Tiffany" is suspected of participating in multiple crypto asset thefts, gambling the stolen funds at crypto casinos. The platform Shuffle has frozen related accounts based on evidence submitted by ZachXBT; Tiffany previously shared a search and seizure warrant from Connecticut, dated before some of the incidents involved.ZachXBT has obtained chat logs, recordings, and on-chain evidence, anticipating that this individual may face further legal consequences. This threat actor is also linked to the John Daghita (Lick) case, who is suspected of stealing over $46 million in crypto assets from a U.S. government-seized wallet.

ZachXBT: The cryptocurrency exchange AscendEX is suspected of long-term delays in withdrawals, urging users to report to the police

According to on-chain detective ZachXBT, multiple reports indicate that the centralized cryptocurrency exchange AscendEX (formerly Bitmax) has recently delayed or failed to process users' withdrawal requests for several days or even weeks, yet the platform continues to accept user deposits.As early as the initial warning on June 26, ZachXBT pointed out that, after reviewing on-chain data from Arkham and TRM, several known hot wallets of AscendEX (covering EVM, Tron, and Solana networks) severely lack major market cap tokens such as ETH, USDT, and SOL, indicating that the platform is likely facing a serious liquidity crisis.The latest situation shows that, in the 9 days since the first warning, the official X account of AscendEX has remained inactive, and the platform's co-founder George (Jing) Cao has not responded to inquiries from users with large amounts of trapped funds. Currently, ZachXBT strongly advises users unable to withdraw their funds to report to law enforcement and regulatory agencies in their respective countries or regions as soon as possible.It is reported that AscendEX was founded by George (Jing) Cao and Ariel Ling in 2018. In December 2021, the platform was attacked by the hacker group Lazarus Group, resulting in approximately $78 million in asset losses.

ZachXBT: Indian scam gang suspected of social engineering to steal coins and self-reported to the police to trace and freeze funds

"On-chain detective" ZachXBT published a case analysis stating that in a cryptocurrency asset case involving an Indian scam gang, the relevant individuals reported the case to law enforcement after their assets were frozen, drawing attention. The incident began when a user sought help, claiming that approximately 5.73 BTC (about $475,000) was frozen on Changelly in March 2025.Subsequent on-chain analysis revealed that these funds could be traced back to multiple social engineering attacks and theft cases related to Bitcoin ATMs targeting U.S. users, with a total amount involved exceeding $1 million and several elderly victims. The investigation showed that the individual provided multiple changing explanations for the source of the funds, including "loan," "boss transfer," and "investment from 2014-2015," and there were significant contradictions in the evidence chain.More concerning is that this user had previously filed a police report in India in December 2025, attempting to recover the frozen funds (case number 3207-P/2025). Subsequent on-chain evidence collection and email data analysis indicated that they might be a "mule" for transferring funds, with some bank documents inconsistent with their identity information. ZachXBT noted that such cases demonstrate that social engineering attacks and cross-border fund transfers continue to occur and remind users to avoid interacting with funds from suspicious sources to prevent triggering compliance freezes or legal risks.
app_icon
ChainCatcher Building the Web3 world with innovations.