ZachXBT Profile picture
Dec 7, 2023 9 tweets 4 min read Read on X
1/ Throughout this year I have been monitoring someone who has withdrawn 11,200+ ETH ($25M) from Tornado Cash and spent the majority of it on Magic The Gathering (MTG) trading cards.

Here’s my analysis of where the funds went and what the potential source of funds could be.
2/ This person has withdrawn 110 X 100 ETH from Tornado to 11 addresses.

After they would:
1) Wrap the ETH
2) Transfer WETH to new address
3) Unwrap the WETH
4) Transfer USDC to MTG broker

(this is a strategy used to trick KYT at exchanges) Image
3/ After USDC was sent to a MTG US based broker that accepts crypto

How did I find the broker used?

1) Instagram username was same as on OpenSea

2) Directly contacted a few MTG sellers the broker interacted w/ on-chain

Broker address
0x80462101b56cb4125c645ff299d3e20c1d908c02
Image
Image
4/ After contacting MTG sellers were where things became interesting.

-buyer was spending millions on starter decks, alpha sets, sealed boxes

-buyer seemed to be overpaying by 5-10%

-buyer sent crypto up front and broker met up IRL with seller

-buyer was unknown to seller

-said the broker has limited crypto knowledge (likely does not know about Tornado)

*seller names will be kept private for their safety*
Image
5/ The funds also go to various deposit addresses at Kraken, Bitpay, and Coinbase.

0x34e158883efc81c5d92fde785fba48db738711ee
0x3a43ac6baf1fa6bdbc966dbdfe26cf545131898e
0x85cb90db50608a950858e023509d6a7fa289e212
0xbfe6def287c402114d39d0156e17fda79efff4d2
6/ Where do I think these funds could have originated from?

To start I began looking at the top Tornado depositors who were active throughout the past year using a Dune query created by @bax1337

-Anubis (12400 ETH)
-Cashio (11500 ETH)
-Uranium (11303 ETH)

Using timing and multi denomination reveal heuristics I arrived at the thesis that the funds potentially originated from the $50M Uranium Finance hack that occurred in April 2021.

Anubis had previously potentially been solved however and Casino did not deposit enough ETH earlier in the year to match the withdrawals of this person.

Image
Image
7/ Here’s some of my rationale behind it being the Uranium hacker:

Oct 4, 2022 the Uranium hacker deposited 5.01 ETH total to Aztec (privacy tool) at 22:03 UTC

0xd332be2c39de1f4ecd4ef6ce23ae826906a8a144ebbfefb9cf2a74c7d320f563

Just 2 hours later at 00:15 UTC on Oct 5 this person received 2.7 ETH from Aztec

0x2b8745157bd13cb7aa76444af67e7de0bf0b288bff50886b599942a17e0e298c
Image
8/ In March 2023 the Uranium hacker deposited 52 X 100 ETH to Tornado & this person received 52 X 100 ETH

March 6 & 14: Uranium Hacker deposits 52 X 100 ETH to Tornado

March 7 & 15: Our person withdrew huge volumes from Tornado

After they finished the Uranium hacker deposits more in May
Image
9/ While my analysis could be incorrect I find it very suspicious that this person:

-spends 8 figures on MTG
-is overpaying for MTG
-shields identity through broker who likely does not know what Tornado is
-receives $13.2M from Tornado post OFAC while in the US
-uses WETH method to obfuscate source

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with ZachXBT

ZachXBT Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @zachxbt

Apr 29
1/ How Lazarus Group laundered $200M from 25+ crypto hacks to fiat from 2020 - 2023

zachxbt.mirror.xyz/B0-UJtxN41cJhp…
2/ Traced 25+ connected hacks across multiple blockchains and through mixers to centralized exchanges.
Image
Image
3/ Identified accounts at Noones and Paxful (P2P marketplaces) that received funds from the hacks and were used to convert crypto to fiat.
Image
Image
Read 6 tweets
Apr 16
1/ An investigation into the alleged $11.1M @PrismaFi exploiter 0x77 (Trung) and the multiple other exploits they are connected to. Image
2/ On March 28, 2024 the Prisma team observed a series of transactions on the MigrateTroveZap contract which resulted in a loss of 3257 ETH ($11.1M)

Exploiter address
0x7e39e3b3ff7adef2613d5cc49558eab74b9a4202

A comprehensive post-morten of the incident can be found below:
Image
3/ At first the attacker communicated with the Prisma deployer the attack was whitehat.

Later that day all of the funds were deposited to Tornado Cash contradicting that statement.

The exploiter began making outrageous demands and asked for a $3.8M (34%) whitehat bounty

This amount is significantly higher than the industry standard 10% essentially extorting the team as the treasury does not have sufficient assets to reimburse users.Image
Image
Image
Read 9 tweets
Mar 21
1/ An investigation into the French dev Jolan Lacroix who recently stole $900K from the TICKER presale on Base before spending the funds on meme coins and Milady NFTs.
Image
Image
2/ TICKER launched a presale on March 16 raising a total of 877 ETH ($3.19M) via Party App on Base.

The token distribution was supposed to be: 24% LP, 71% presale/airdrops, 1% early contributors, 4% reserved for errors.

The team was fully anon.
Image
Image
3/ Immediately after TGE was where things went bad.

15% of the TICKER supply was sent to a dev (Jolan) assisting with the project to distribute the airdrop.

Instead of doing this Jolan sold 13% of the supply for $900K rugging everyone supporting the project.

0x3122445f0240df9530c8a360fb7631ad5aca4e24503e8856b9aedae05dab830cImage
Image
Image
Read 8 tweets
Feb 28
1/ An investigation into the phishing scammer Ultra (Nicolas) who has stolen millions through Discord compromises such as MetaKey and X/Twitter spam just to spend it all gambling on Stake, rare usernames, and Roblox items.
Image
Image
2/ In Feb 2023 the Dead Army Skeleton Discord was compromised
after an admin was phished.

The attacker spammed phishing links in the announcements channel with funds ending up at offtherip.eth and Monkey Drainer.

Image
Image
3/ A few days later Ultra thought it would be funny to flex $200K of the funds he had stolen by sending it to his “friend” Death.

Shortly after Death then steals the funds from Ultra for himself.

Then after Ultra starts crying.

Read 8 tweets
Feb 22
1/ Some time has passed but there is now evidence to share how Tyronejkd is connected to the $1M 0xCrystals/0xCube scam and @3PEACEART account.

Let’s jump in.
Image
2/ Last bull run this account popped up engagement farming with fake giveaways, stolen posts, & stolen punk pfp

They launched an NFT project they claimed was free with a limited supply. When people minted the actual price was 0.25 ETH & not free

When called out for the scheme they would delete posts & change usernamesImage
Image
Image
3/ Let’s go through some of the evidence that ties TyroneJKD to the project.

Here is TyroneJKD funding the 0xcube.eth address (ENS which is contract owner of the project)

0x396e5eb16248fa5e4e78a39bf856227534d4553156c68318b47bb043add108ba
Image
Image
Read 8 tweets
Feb 20
1/ An investigation into how the influencer Crypto Rover ghosted a project he was paid to promote, mislead followers about his trading positions, and also his shills for pump and dump meme coins. Image
2/ In May 2023 Rover was connected with a project was connected to help promote it.

During negotiations Rover said he can “pump projects from 1/2m to 10m easy”

They agreed on $10K + 1% of the supply for payment

Rover address
0x4472d6969c0750dd7ba8e387d2b007a80794802f
Image
Image
3/ After the payment was sent to Rover was where things started to go poorly.

On multiple occasions Rover agreed he was going to start promoting the project with posts but never did.
Image
Image
Read 10 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(