Investigations by ZachXBT
105K subscribers
202 photos
3 videos
6 files
161 links
Reports, news, & insights shared by ZachXBT

Useful links:
x.com/zachxbt
investigation.io
@investigations
Download Telegram
Investigations by ZachXBT
Community alert: I suggest avoiding Rain Protocol ($8.8B mkt cap; top 15) at all costs. As a prediction market RAIN has few users, minimal product traction, no notable backers, & a team with little track record in our industry. I traced the RAIN team addresses…
If you are an insider with incriminating business contracts, full chat logs, active MM agreements, or similar tied to CEX market manipulation schemes I am increasing my total bounty up to $100K paid in the crypto of your choice out of my own pocket.

In my opinion it will continue until one of the teams is made an examples of by regulators or the public.

I do not care how the documents are obtained.

Send me a DM on X (Twitter) for your submission:

x.com/zachxbt
❀389πŸ”₯194πŸ‘68🀣49❀‍πŸ”₯32πŸ‘21πŸ‘Ž12🐳11😁7πŸ’―6πŸ’Š5
Investigations by ZachXBT
Community Alert: As Token 2049 approaches be careful of sponsors as little due diligence is done on them for conferences (just because someone is a title or platinum sponsor does not mean they are credible) Title sponsor -Spacecoin (botted project) Platinum…
Community alert: Multiple users of the East Asian centralized exchange Ju (JuCoin) have reported withdrawal issues over the past week.

In March 2025 I first published a warning for Ju when they were listed as a Platinum sponsor for Token 2049 after I observed numerous red flags.

A recent analysis into the Ju proof of reserves posted on X (Twitter) alleged the self reported numbers of $511M in total reserves were likely overstated given the vast majority was issued USDC & USDT on their own chain JuChain without a clear backing.

Ju's ownership is opaque. The publicly listed team does not appear to actually control it. That fits a pattern seen with fraudulent offshore exchanges, where the actual principals, often Chinese, stay hidden.

Ju has publicly stated the delays are the result of upgrades and restructuring. Ju has rebranded multiple times in the past (Jubi β†’ JuCoin β†’ Joy Universe/Ju).

JuDAO was exploited for $225K in Apr 2026 due to a smart contract exploit.

JuDAO allegedly lost $20M in Sep 2025 due to deploying a proxy contract which incorrectly left 77M POL stuck.

At least $5M tied to the Bybit DPRK exploit was moved via Ju in 2025, while weeks earlier the team had claimed to offer financial support of up to 1,000 BTC ($95M) for Bybit.

A basic test for centralized exchanges is to see if the ownership is fully transparent and registered in high quality jurisdictions whereas Ju fails both.
❀185πŸ‘86🀣46🀨20πŸ‘€15πŸ—Ώ14πŸ”₯8πŸ’―6πŸ€ͺ5😁3πŸ€“2
Investigations by ZachXBT
If you send me a DM or tag me on X/Twitter asking me to look into a meme coin I am muting or blocking you for wasting my time. My notifications have gotten unbelievably low quality over the past few months. Here are some examples:
If you send l a DM or tag me on X/Twitter asking me to assist you with a prediction market I am muting or blocking you for wasting my time.

Prediction markets gamblers in 2026 have become the equivalent of meme coin gamblers from 2024 - 2025.

They’ll happily profit off to your likeness while all of the negatives become associated with you.

However one exception is I have an ongoing investigation into an Israeli national suspected of profiting from insider knowledge in relation to war.
🀣400❀153πŸ‘125πŸ”₯42πŸ‘Ž26πŸ‘€24😁17😭15πŸ’Š10πŸ₯±7✍4
Yesterday (June 11) TA6YHqB2xh5HhfmC7WoLQaWmqq7Vv4zCoQ received 120.2M USDT on Tron and began transferring $17.5M+ to Kucoin deposit addresses and $8M to various instant exchanges.

The entity created Monero orders which caused the XMR price to spike from $330 -> $420.

Another $8M+ was bridged from Tron to Bitcoin / Ethereum via Near Intents.

A few minutes ago Tether blacklisted an address directly related to Ta6YHq with 72M USDT: TBzrPEsStbZAUx2SBhD4oHz8UW3FX9Ak9W
🀣168πŸ‘87πŸ‘€50❀43πŸ”₯31🍾18😭10😁8πŸ€“3πŸ₯°2πŸ‘1
Three hours ago 10.6K ETH ($18.5M) moved from an address linked to the $575M Hashflare investment fraud after sitting dormant onchain for 3.5 yrs.

In 2025 both co-founders Sergei Potapenko and Ivan Turogin plead guilty and forfeited $450M of assets to the US government.

The entity began laundering funds via HiFiSwap and Near Intents from Ethereum to Bitcoin and began using two instant exchanges.

H/t to Cyvers for helping first flag these movements to me.

Hashflare address
0xff575a22975cc413771825eb84c163189a4d5d22
Hashflare transfer
0xd0eafd5c03b24c2f54c579745cacbffe4c6df2d19973e55d52a5f40aa1d089e0
Recipient address
0xc82f007bb4096a47d14ed0d46ee8143d37539d04
0x3297a41f528345c3b97af8c6ffe1401cc07b2527
❀156πŸ‘86πŸ”₯29😱23πŸ™14😭12πŸ—Ώ12😁11πŸ•Š7πŸ€”6🐳6
A few hours ago the price of M (MemeCore) suddenly crashed >75% on centralized exchanges from $14B to $3.8B FDV falling outside of the top 25 tokens ranked by market cap.

Myself, Mlm, & Wazz previously highlighted a number of red flags on X about MemeCore with inorganic supply concentration and deceptive practices by its team to boost user numbers.

According to data on Arkham there's not been a single transfer >$50k onchain in 2+ weeks on BSC.

Dexscreener data indicates there's <$100K total liquidity onchain on BSC.

The community needs answers from Binance & Bybit about why M was listed for perps and why Kraken & Bitget listed M spot as these highly manipulated tokens continue to give our industry a bad reputation and extract from retail.
πŸ‘408❀116🀣65πŸ‘32😁11🀬11πŸ‘Ž9🀨9πŸ¦„7πŸ€·β€β™€6πŸŽ‰1
The Polish social engineering threat actor Wojtek Kulisz aka 'Merry' appears to have been recently raided by Poland law enforcement along with three other people.

While the press release today did not share his name or photo, multiple designer clothes and jewelry items flexed from his public Instagram account 'wojtekk' match items seized during the raid.
🀣229❀57πŸ‘46πŸ‘15πŸ”₯13😁12😭8🫑6😒4🍾4πŸ’”1
Community alert: I have observed multiple reports that the centralized exchange AscendEX (formerly Bitmax) is delaying user withdrawals for days / weeks or not processing withdrawals.

I reviewed known hot wallets on Arkham/TRM and its reserves appear to lack large cap tokens such as ETH, USDT, USDT, SOL, etc indicating they likely are facing liquidity issues.

AscendEX (Bitmax) was founded by George (Jing) Cao & Ariel Ling in 2018. In December 2021 they were reportedly hacked by Lazarus Group for $78M.

EVM hot wallets
0x983873529f95132BD1812A3B52c98Fb271d2f679
0x4240781A9ebDB2EB14a183466E8820978b7DA4e2


Tron hot wallet
TP523ZC2721Dnu6nxYSFi14cWUBfu8YTXG

Solana hot wallets
Cv7hXMfMh5eu2WBtyZXogYDPj55Xo1Ufsuwn7oeG6Epy
6iVBAsquJRaLsXbojb18kqTW1d5iVLspVjCtsReZBKhY
😱223❀85πŸ₯΄35πŸ”₯25😭22πŸ‘11πŸ‘8πŸ™ˆ8😁7🀨7πŸ•Š6
One hour ago funds from the recent Humanity Protocol exploit and Kelp DAO exploit commingled suggesting potential overlap between the attackers for both incidents.

Transaction hash: 5d31655a905b1b39ce1a477268b5084cc821157371860b792e60a3fa4aa24931

On April 18, 2026 ~$292M was stolen from Kelp DAO's LayerZero bridge due to compromised infra and Lazarus Group was alleged as the attacker.

On June 9, 2026 ~$32M was stolen from Humanity Protocol team addresses and deployer after a developers device became compromised.

The H token previously raised concerns over insider supply control and active market making tactics on CEXs where the exploit coincided shortly before investor unlocks.

However I believe the new evidence from above rules out insiders as being behind the exploit.

H/t @specterinvestigation for helping flag these transactions.
❀175πŸ‘85😱37🀣11😭11😁8πŸ€“6πŸ€”5πŸ‘Ž4⚑1
Community alert: KuCoin has sent legal threats to a victim whose stolen funds were laundered via KuCoin accounts with purchased mule KYC.

The case involves a $250K Atomic stealer theft from August 18, 2025 where the stolen funds were transferred to multiple KuCoin deposit addresses.

Theft address
0x6368D06895b7becdcAC0806F438EfA653fE0a68D

Kucoin deposit addresses
0x6043b2d79670a417fc523213155812846e893dc7
0xa0fdb49aa589538d5622b92e9122727873558a13
0x4a4b5c7db9aa8355a5e5abbfc1926cd6b2d9f610
0xe7bb69f6c0ae0c1418bd86ec9697af9914d6875e
0x35d65ec360347f7dc41a929cc7ce9f2485a4f833

In recent months I have provided warnings about KuCoin due to blocking legit users, enabling illicit activity (AudiA6, DNMs, etc), and have observed delayed responses to law enforcement for victims.
🀬273❀82πŸ‘Ž37πŸ‘29πŸ”₯24😭16😱15😁14😑12😒5πŸ’”5
Investigations by ZachXBT
Community alert: I have observed multiple reports that the centralized exchange AscendEX (formerly Bitmax) is delaying user withdrawals for days / weeks or not processing withdrawals. I reviewed known hot wallets on Arkham/TRM and its reserves appear to lack…
Update: AscendEX has not posted on X (Twitter) for 9 days since my post and user withdrawals are still not being processed while deposits are being accepted.

I reviewed a case where a large victim has been getting no response from the AscendEX co-founder George (Jing) Cao on any of their concerns.

If you have funds stuck I encourage you to file a report with law enforcement and regulators in your country.
❀222🀣87πŸ‘72πŸ‘€42😒20😱17✍11πŸ”₯10😁10πŸ‘7πŸ‘Ž3
Investigations by ZachXBT
Community alert: KuCoin has sent legal threats to a victim whose stolen funds were laundered via KuCoin accounts with purchased mule KYC. The case involves a $250K Atomic stealer theft from August 18, 2025 where the stolen funds were transferred to multiple…
From July 2-3, 2026 a threat actor withdrew 3200 ETH from Tornado in relation to two large private key compromise thefts.

After $5.5M was laundered via Circle CCTP bridge and funds were transferred to seven Kucoin deposit addresses on Arbitrum.

Kucoin deposit addresses
0x85d7124a659fb0aeb7ccd283f3e24bc2364e7c55
0x764c80a719fdf932d4a5944e9e382f71958bffa3
0x83396ae682c821d56b0c51da86b536af0a4b9894
0x5dc523deceb53ff5e89e0f6683af77f274f51f56
0x295fdf140e7c706be5b9daffc68d97a224394cfe
0x4e6a42fa57392673580e15e35850324557f51467
0xe007625bf20387ed3c250e1dcf3d94d133480634
😱146❀53😭52πŸ”₯27πŸ‘23🫑18πŸ€ͺ12πŸ‘Ύ11😐10🐳9❀‍πŸ”₯6
Over the past week multiple people created ZACHXBT meme coins on various chains using my likeness to take advantage of the recent narrative.

None of the tokens were promoted by myself as I have always stated I will never support or launch a meme coin.

All tokens sent to my donation wallet were market sold and the entire amount was sent to charity.

~$41K total was donated to Direct Relief & Give Directly via The Giving Block to support the Venezuela earthquake response.

Transaction reciepts:

1). 25K USDT sent to Give Directly on July 6, 2026 at 4:16 am UTC
0x687556d7011b0750f3daf9e3a9f800d04ba233c84362faf8c3851b40cd0f71ae

2). 5k USDT sent to Direct Relief on July 6, 2026 at 4:51 am UTC
0xc9146816d5c0d97b432d663b422b46854ba6e047ce7e9ea8073d43c1205ba070

3). 153 SOL ($11K) total sent to Direct Relief on June 28, 2026
44idg3MiJiprAnqBbt5fZM9K4deDzZdqnJ3dPtS6hFLqQk3omvqWz7LjgCapMX94q7Ba3NznoCsgpdWFUysjHHuX
4Cm8hrg9Fgwrgot6GkqNtNdhjb4o48dintU1Wz8DBuZBuvGsSQjv4VE5KAivTPy7okj1XxJtEyqAaecJr8xAiXhi
❀677πŸ‘138πŸ”₯60😭28😁22❀‍πŸ”₯21πŸ’―12πŸ€ͺ12πŸ₯°11✍10🀯10
Investigations by ZachXBT
Update: AscendEX has not posted on X (Twitter) for 9 days since my post and user withdrawals are still not being processed while deposits are being accepted. I reviewed a case where a large victim has been getting no response from the AscendEX co-founder…
Update 2: AscendEX published the following announcement stating they will cease operations as the team blames current market conditions and MiCA.

AscendEX admits in its announcement withdrawals may or may not be processed.

Their public hot wallets still do not have liquid assets to process withdrawals for the multiple 7 figures in user claims I have verified.

Users with assets stuck should file a report with law enforcement and regulators in your country to hold its co-founder George (Jing) Cao responsible.
😒145😭94🀬55❀43πŸ‘35πŸ—Ώ17πŸ‘12πŸ’Š9πŸ€·β€β™€8πŸ€”7😑4
An early Solana whale tied to the initial Genesis block distribution appears to have likely had 180.9K SOL ($14.2M) stolen a few hours ago.

I began reviewing the irregular unstaking and bridging activity from Solana to Ethereum with @specterinvestigation who first spotted these movements.

Victim
HwtbQBNnLERakdUDuCCLWmUs2oETLFQZeHUWeQdPads

Theft address
Ffd1oB2aYM5UzMYUM7TmxULDRQb6KzgrBwmgj9U1C2bE
653pnn5fzF51FfotBwxua55Es4QXxTdaXJLbPczVmswp
0xaa5cfa4e96dda0f9aa30f4dc948b542a9b5817c6
0x536b4ee7507c41143e1b0bd1bf3f2b84be404836
0xbf11bdfbeb9ed137c352c81e45d191cacae6b0cf
😭254😱120❀40πŸ‘26🀣21πŸ‘€19🀯14🫑14πŸ”₯12😁7🌚6
Investigations by ZachXBT
An entity previously received ESPORTS, RIVER, & LIGHT tokens via Sablier vesting contract and is also directly tied to a signer on three LAB multisigs. These four BSC tokens have experienced market manipulation incidents on centralized exchanges. I peviously…
Community alert: Over the past 48 hour an entity initially funded by the LAB team deposited 18.4M LAB ($18.3M) to Aster and began selling LAB spot on the DEX which has caused the LAB price to drop another -54% from $1.2 to $0.55.

The entity received 196M+ LAB from the LAB team in April 2026 and transferred LAB to four Bitget deposit addresses.

On April 8 100M LAB total was transferred by the entity to two Bitget deposit addresses:
0xe39f91a0daffc5547ada79a09be30b8556f7dfba
0x77156a0a621d2ac7a075c0ac3172707c2e4aa191


From April 23 to 25 96M LAB total was transferred by the entity to two Bitget deposit addresses:
0x6593aa6c31c88397c37f71259625ec92fe4ee0bf
0xdd77bfbdc11cd37fd255ae35a4ac39df1f9d570a


From May 11 to 12 ~100M LAB was withdrawn from Bitget to ten addresses as market data from the period did not support any independent party accumulating a position of that size. Thus indicates the same entity. The LAB withdrawn sat dormant until this week.

From July 10 to 11 the entity began transferring LAB to three Aster deposit addresses and currently still holds another 81.5M LAB:
0xaad30cab22f772c1658b7845b5837d35bf3a467a
0x76ccfde9819500204985580d235dd8326fa0b241
0x628dd74f428a81cd34ece11331a7f1593f76047a


In May 2026 I published an investigation on X detailing how the LAB team engaged in opaque private loans/OTC, unilateral vesting changes, >95% supply control, and irregular MM activity.

This week the LAB price collapsed shortly before the rumored unlocks were scheduled to begin. After the LAB team made a vague announcement stating it was due to "large market participants".

It is disappointing no action was taken by Bitget, Binance, or Gate for allowing blatant market manipulation on tokens against users.
❀239πŸ‘92🀯45🍾30😁22πŸ‘15πŸ‘€14πŸ₯±12πŸ—Ώ11✍6πŸ¦„5
Hot take: All hardware wallets are complete garbage and l do not advise using them for important tasks like signing transactions or storing funds.

Much better to have a separate iPhone with its only purpose being to use as your hardware wallet.

Ledger is the worst and Ledger Live has regular updates for UI / apps for no good reason that break simple actions.

(Only do this if you are not low iq)
😭789πŸ‘482πŸ’―241πŸ‘Ž188❀150😱73πŸ€”67😁62🀨51πŸ”₯34πŸ₯΄32
It appears the bridge TeleSwap had a $735K+ exploit on July 15, 2026 and still has not disclosed the incident publicly after five days.

Shortly after the suspicious outflows its Bitcoin hot wallet stopped processing transactions. Two hours ago the attacker deposited the funds to Tornado.

Theft addresses
bc1pz95zv3qhpmt52yezs84a5zrddrk5jsxm8a60rln5kzlk06e87a3q8pf79l
0x2448cbaee50a67030692b7519a954e5550dc2718
0xfc5048fbba2f74ed482ffcd7663601f818c5bb47

0xf8706a51f8df01a71f408e50c901dd14916a12c7

TeleSwap Bitcoin hot wallet
bc1q5wnpn4k99wc587maaaa6eqnx27g4r6mduxg2s5
😭211🀣113❀40πŸ‘34🀬31😱21🐳21πŸ”₯14πŸ‘Ž12πŸ‘9πŸ™8
Telegram keeps allowing scam ads to be displayed in my channel to subscribers.

If you are a premium user please consider using boosts for my channel https://t.me/boost/investigations so I can unlock the feature to disable ads (need to hit level 50).
πŸ‘Ž2.35K🀣639πŸ‘214❀94😭73🌚26😁21πŸ™ˆ17πŸ‘€12πŸ”₯10πŸ₯°7