ZachXBT Profile picture
Dec 7 9 tweets 4 min read Twitter logo Read on Twitter
1/ Throughout this year I have been monitoring someone who has withdrawn 11,200+ ETH ($25M) from Tornado Cash and spent the majority of it on Magic The Gathering (MTG) trading cards.

Here’s my analysis of where the funds went and what the potential source of funds could be.
2/ This person has withdrawn 110 X 100 ETH from Tornado to 11 addresses.

After they would:
1) Wrap the ETH
2) Transfer WETH to new address
3) Unwrap the WETH
4) Transfer USDC to MTG broker

(this is a strategy used to trick KYT at exchanges) Image
3/ After USDC was sent to a MTG US based broker that accepts crypto

How did I find the broker used?

1) Instagram username was same as on OpenSea

2) Directly contacted a few MTG sellers the broker interacted w/ on-chain

Broker address
0x80462101b56cb4125c645ff299d3e20c1d908c02
Image
Image
4/ After contacting MTG sellers were where things became interesting.

-buyer was spending millions on starter decks, alpha sets, sealed boxes

-buyer seemed to be overpaying by 5-10%

-buyer sent crypto up front and broker met up IRL with seller

-buyer was unknown to seller

-said the broker has limited crypto knowledge (likely does not know about Tornado)

*seller names will be kept private for their safety*
Image
5/ The funds also go to various deposit addresses at Kraken, Bitpay, and Coinbase.

0x34e158883efc81c5d92fde785fba48db738711ee
0x3a43ac6baf1fa6bdbc966dbdfe26cf545131898e
0x85cb90db50608a950858e023509d6a7fa289e212
0xbfe6def287c402114d39d0156e17fda79efff4d2
6/ Where do I think these funds could have originated from?

To start I began looking at the top Tornado depositors who were active throughout the past year using a Dune query created by @bax1337

-Anubis (12400 ETH)
-Cashio (11500 ETH)
-Uranium (11303 ETH)

Using timing and multi denomination reveal heuristics I arrived at the thesis that the funds potentially originated from the $50M Uranium Finance hack that occurred in April 2021.

Anubis had previously potentially been solved however and Casino did not deposit enough ETH earlier in the year to match the withdrawals of this person.

Image
Image
7/ Here’s some of my rationale behind it being the Uranium hacker:

Oct 4, 2022 the Uranium hacker deposited 5.01 ETH total to Aztec (privacy tool) at 22:03 UTC

0xd332be2c39de1f4ecd4ef6ce23ae826906a8a144ebbfefb9cf2a74c7d320f563

Just 2 hours later at 00:15 UTC on Oct 5 this person received 2.7 ETH from Aztec

0x2b8745157bd13cb7aa76444af67e7de0bf0b288bff50886b599942a17e0e298c
Image
8/ In March 2023 the Uranium hacker deposited 52 X 100 ETH to Tornado & this person received 52 X 100 ETH

March 6 & 14: Uranium Hacker deposits 52 X 100 ETH to Tornado

March 7 & 15: Our person withdrew huge volumes from Tornado

After they finished the Uranium hacker deposits more in May
Image
9/ While my analysis could be incorrect I find it very suspicious that this person:

-spends 8 figures on MTG
-is overpaying for MTG
-shields identity through broker who likely does not know what Tornado is
-receives $13.2M from Tornado post OFAC while in the US
-uses WETH method to obfuscate source

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with ZachXBT

ZachXBT Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @zachxbt

Oct 25
1/ An investigation into the Canadian scammer known as Yahya for their involvement in 17+ SIM swaps which resulted in more than $4.5M stolen.
Image
Image
2/ Yahya’s job was to do lookups on X/Twitter accounts using his panel so the scammer Skenkir could get US targets for SIM swaps.

As compensation for his work Yahya would receive a % of the proceeds stolen from each attack.

EX: Here is screenshots of Yahya showing off tools

Image
Image
Image
3/ In July 2023 Yahya & HZ (scammer who had assets seized by FBI) scammed someone named Amir for $250k (136 ETH) after pretending to sell access to his panel.

In doing so this revealed Yahya’s wallet address:
0x7da33a98247b584b0070355881be9085126b53e1

7-2-23 at 3:04 UTC payment sent
7-2-23 at 3:20 UTC confirmation

HZ context:



Image
Image
Image
Image
Read 12 tweets
Sep 10
1/ Part 2 of a breakdown into how @trader1sz @Trader_XO @TraderNJ1 @PetaByteCapital pump and dumped 6 figures of PAAL on their followers.
Image
2/ While XO & SZ both made PR statements placing all the blame on PetaByte & NJ for CBOT while both were actively involved with another one of their promotions for PAAL

Thankfully NJ/PB connected their wallet addresses from CBOT & BABYSHIB shills to PAAL making it easy to find
Image
Image
3/ How did I confirm which one was Trader SZ wallet?

0xa040e70e576b239aa699c4d5f42ae431611ce6c7

Well he received multiple honorary NFTs to this wallet
Image
Image
Read 12 tweets
Sep 10
1/ Part 1 of an breakdown into how @TraderNJ1 @PetaByteCapital have deceived multiple projects by leveraging the names of other influencer to obtain free tokens from CBOT and BABYSHIB to dump on followers undisclosed.
Image
Image
2/ Recently this audio clip of Trader NJ surfaced asking for a % of CBOT token supply to shill with Peta, and others saying they will make tweets saying a project is the next 10-20X.
3/ EX 1: BABYSHIB

In Telegram messages provided by the BabyShib team it shows a conversation with Peta/NJ discussing marketing for 3.5% of the supply

They even claim to have “no intentions of selling anything anytime soon”

NJ/Peta provide both wallets to receive tokens

Image
Image
Image
Read 12 tweets
Jul 24
1/6 My issues with WorldCoin Image
2/6 Most alarming to me is how the WorldCoin team has boasted about how many users they have.

When in reality they have been exploiting people in developing countries.

https://t.co/b9smMB4yqatechnologyreview.com/2022/04/06/104…

Image
Image
3/6 Verification that you’re a real person seems to only currently be enforced at the enrollment level.

This has lead to the emergence of a Black Market for accounts. Currently accounts got as low as $1 per account on Telegram.
Image
Image
Read 6 tweets
Jul 20
1/ Here is my analysis of the $60M Anubis DAO rug pull.

I noticed a clear trend in 2023 of funds being withdrawn from Tornado Cash and bridged to Polygon before consolidating to two exchange accounts. Image
2/ Here are the two exchange deposit addresses which have exposure to all of the Tornado Cash funds.

0x51da686c7a2f973ad11fafed6ce9a3ffc020349f
0x253d7ba533b7d13720fb5ec5a7d1e64d4ff3f58b

Interestingly Beerus (bsl.eth) has sent 95 ETH to the 0x51d address Image
3/ Well who controls the 0x51da address? Beerus friend Ersan does who is active in the CSGO scene.

h/t @Gr1zzlyTrades for the find Image
Read 6 tweets
Jul 17
1/ An investigation into the Canadian phishing scammer known as Soup (Dan) who has helped steal millions in assets by attacking the Discord servers of projects like @Orbiter_Finance @PikaProtocol
Image
Image
2/ Soup creates fake @decryptmedia websites and poses as Luke Hamilton (a real Decrypt employee)

He works with other scammers to approach team members of crypto projects to trick them into joining a fake Decrypt Discord server in an elaborate attempt to steal their Discord token

Image
Image
Image
3/ He accidentally revealed his wallet address after proving Blue (phishing scammer I recently covered) controlled the ENS address purplelobster.eth by having Blue send Soup $25.

0x21bc8046245880e9d3ec5ed808048a93518e933a https://t.co/yml7nrxkKf

Image
Image
Read 11 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(