Onchain Investigator | Peace ✌️ Specteranalyst.sol (.eth)

Joined May 2024
Specter retweeted
Regarding who is behind the hack: I present to you THE LAZARUS GROUP. just linked this hack to the AFX hack, which stole $24M in July and was specifically attributed to TraderTraitor. The stolen XRP from Bitget was bridged and can be directly linked to the funds stolen in the AFX hack. Stay smart.
关于攻击原因: 安全团队已初步定位攻击来源。黑客入侵了钱包服务的一个关键后台系统,并利用该系统伪造转账信息、调用授权签名流程,将资金转出。可以排除私钥泄漏的情况——这意味着更恶劣的风险场景已被排除。目前确认止损已完成,平台不存在进一步资金流失的风险。黑客具体入侵手法仍在技术核查中,完整报告将在调查结束后发布。 关于提币恢复: 多组技术团队正在并行推进系统修复与安全加固,提币恢复准备工作同步进行。我们将在有明确时间窗口后第一时间公告,不提前承诺无法兑现的时间。
17
44
20
266
159,116
Specter retweeted
The #1 reason you don't want to launder money for DPRK is that DPRK will absolutely hack you. RIP Bitget. TraderTraitor says thank you for your service. 0xCbCfd64A96837D874943641fc9BA159C10d6CC80 -> 0xA0772d6E70D2c97CFB70628C7B00f666A6476feb
Regarding who is behind the hack: I present to you THE LAZARUS GROUP. just linked this hack to the AFX hack, which stole $24M in July and was specifically attributed to TraderTraitor. The stolen XRP from Bitget was bridged and can be directly linked to the funds stolen in the AFX hack. Stay smart.
21
27
6
396
68,764
Regarding who is behind the hack: I present to you THE LAZARUS GROUP. just linked this hack to the AFX hack, which stole $24M in July and was specifically attributed to TraderTraitor. The stolen XRP from Bitget was bridged and can be directly linked to the funds stolen in the AFX hack. Stay smart.
关于攻击原因: 安全团队已初步定位攻击来源。黑客入侵了钱包服务的一个关键后台系统,并利用该系统伪造转账信息、调用授权签名流程,将资金转出。可以排除私钥泄漏的情况——这意味着更恶劣的风险场景已被排除。目前确认止损已完成,平台不存在进一步资金流失的风险。黑客具体入侵手法仍在技术核查中,完整报告将在调查结束后发布。 关于提币恢复: 多组技术团队正在并行推进系统修复与安全加固,提币恢复准备工作同步进行。我们将在有明确时间窗口后第一时间公告,不提前承诺无法兑现的时间。
17
44
20
266
159,116
for more better visual ... check this
1
1
21
7,098
Specter retweeted
Total loss: $353M The remaining addresses rwNhefsz1UQEusxhCvHip3RANinWi4CTck rDRV9nLg8xbLsafKZnhNgWuE1TiSLE95hs TBWNguTTgezw9dVorX441C6nDrZpRxYwKD
Where tf is bitget team @BitgetWallet @GracyBitget Another $8.2M was just withdrawn on avalanche Loss: 185M
2
6
1
31
9,513
Total loss: $353M The remaining addresses rwNhefsz1UQEusxhCvHip3RANinWi4CTck rDRV9nLg8xbLsafKZnhNgWuE1TiSLE95hs TBWNguTTgezw9dVorX441C6nDrZpRxYwKD
Where tf is bitget team @BitgetWallet @GracyBitget Another $8.2M was just withdrawn on avalanche Loss: 185M
2
6
1
31
9,513
Where tf is bitget team @BitgetWallet @GracyBitget Another $8.2M was just withdrawn on avalanche Loss: 185M
9
3
1
73
12,831
Another 650k was withdrew again @bitget are you people a retarded?
1
7
1,637
Crazy that I just realized this. One of MetaMask’s swap router contracts was blacklisted by Tether in 2021 and remained blacklisted I noticed the address was flagged while investigating the Payy Network hack.
2
2
57
7,450
Looking into this campaign, and I’d say proper research by victims could have prevented many of these losses. There were several red flags, but the promise of easy profits may have caused people to overlook them. The threat actor(s) behind this campaign have drained $500K+ and appear to still be active. I found a few of the YouTube videos used in the campaign, identified some of the theft addresses, and looked into how victims were being tricked. One interesting part of the setup: the attackers registered ENS names containing “Uniswap,” making the addresses appear connected to legitimate DeFi activity: 0x331314385625D9912f8a5ee1bF86b837DCB42990 : uniswap-v3-router.eth 0x6E0CD1C8e1Df611E53E23B7900Ed8A830f4C871C : uniswap-defi.eth 0x0E111ba687517937F08B189b84FbD02d86cbd739: uniswap-v2-pool.eth These addresses were shown as sources of incoming transactions, making it look like contract were receiving profits from their deployed arbitrage trading bots via Uniswap. But that wasn’t what was actually happening. The attackers provided victims with a tutorial and code for creating the supposed arbitrage bot. The source code itself wasn’t the main trap. The real trick was the development interface. Victims were directed to an interface designed to look like Remix and instructed to use it to compile and deploy the contract. After victims deployed the contract and funded it with their own assets, the attacker was able to drain the funds. The attacker still appears to hold a significant portion of the stolen funds at these addresses: 0xcf27FAFb41e183C567E23786bB1f3E80a44b8Ef3 0x8d3736f31de511ad19c168973190a2e0c75f776a Stay smart.
LATEST: 🚨 TRM Labs says 9 fake YouTube tutorials on building a crypto arbitrage bot with Claude tricked 224 victims into deploying self-draining smart contracts, netting scammers 274.60 ETH over 6 months.
5
8
50
12,023
Looking into this campaign, and I’d say proper research by victims could have prevented many of these losses. There were several red flags, but the promise of easy profits may have caused people to overlook them. The threat actor(s) behind this campaign have drained $500K+ and appear to still be active. I found a few of the YouTube videos used in the campaign, identified some of the theft addresses, and looked into how victims were being tricked. One interesting part of the setup: the attackers registered ENS names containing “Uniswap,” making the addresses appear connected to legitimate DeFi activity: 0x331314385625D9912f8a5ee1bF86b837DCB42990 : uniswap-v3-router.eth 0x6E0CD1C8e1Df611E53E23B7900Ed8A830f4C871C : uniswap-defi.eth 0x0E111ba687517937F08B189b84FbD02d86cbd739: uniswap-v2-pool.eth These addresses were shown as sources of incoming transactions, making it look like contract were receiving profits from their deployed arbitrage trading bots via Uniswap. But that wasn’t what was actually happening. The attackers provided victims with a tutorial and code for creating the supposed arbitrage bot. The source code itself wasn’t the main trap. The real trick was the development interface. Victims were directed to an interface designed to look like Remix and instructed to use it to compile and deploy the contract. After victims deployed the contract and funded it with their own assets, the attacker was able to drain the funds. The attacker still appears to hold a significant portion of the stolen funds at these addresses: 0xcf27FAFb41e183C567E23786bB1f3E80a44b8Ef3 0x8d3736f31de511ad19c168973190a2e0c75f776a Stay smart.
LATEST: 🚨 TRM Labs says 9 fake YouTube tutorials on building a crypto arbitrage bot with Claude tricked 224 victims into deploying self-draining smart contracts, netting scammers 274.60 ETH over 6 months.
5
8
50
12,023
Replying to @haydenzadams
A few months ago, this Phantom user swapped $2M worth of ETH for just $25K worth of LIT. The transaction went through 0x and was routed through a low-liquidity token (AVAIL pool), resulting in a massive loss.
3
2
36
2,068
The rate at which crypto related companies data is being breached is crazy. In a month, we have seen breaches involving: Trezor x 2 SafePal Pocket Bitcoin Revolut These are just the ones that have been disclosed and confirmed. Just imagine what we don't know about. “Pseudonymous,” my foot.
7
1
58
5,489
The rate at which crypto related companies data is being breached is crazy. In a month, we have seen breaches involving: Trezor x 2 SafePal Pocket Bitcoin Revolut These are just the ones that have been disclosed and confirmed. Just imagine what we don't know about. “Pseudonymous,” my foot.
7
1
58
5,489
Yesterday, Tether froze $40M USDT linked to Xinbi, an illicit marketplace in SEA, following its sanctioning by the UK FCDO in March 2026. Xinbi Company Limited was sanctioned for operating cryptocurrency-based services, including selling stolen personal data and profiting from scam centres. Interestingly, two TRON wallets linked to Xinbi were blacklisted during the designation, but they had already been emptied, meaning no funds were actually frozen from those addresses. Six months later, Tether froze another $51M, with $39.2M directly linked to those two addresses and XinbiPay. Earlier today, Xinbi announced that, starting today, it will only accept USDD deposits: “We will only accept USDD deposits.” USDD is presented as a decentralised stablecoin by TRON DAO. It has previously been promoted on TRONScan, where @tanuki42_ caught advertisements encouraging USDT users to swap their assets for USDD. "No one can freeze your USDD" Interestingly, they will finally get the illicit volume they actually wanted While such a large amount could shake them, it’s nothing compared to what they have processed. And as you can see, they have resumed operations and are ready to roll with USDD. Stay Smart
7
1
44
5,668
OFAC designated Xinbi and associated entities, and the assets frozen yesterday were coordinated by the USG.
4
2,349
Specter retweeted
Yesterday, Tether froze $40M USDT linked to Xinbi, an illicit marketplace in SEA, following its sanctioning by the UK FCDO in March 2026. Xinbi Company Limited was sanctioned for operating cryptocurrency-based services, including selling stolen personal data and profiting from scam centres. Interestingly, two TRON wallets linked to Xinbi were blacklisted during the designation, but they had already been emptied, meaning no funds were actually frozen from those addresses. Six months later, Tether froze another $51M, with $39.2M directly linked to those two addresses and XinbiPay. Earlier today, Xinbi announced that, starting today, it will only accept USDD deposits: “We will only accept USDD deposits.” USDD is presented as a decentralised stablecoin by TRON DAO. It has previously been promoted on TRONScan, where @tanuki42_ caught advertisements encouraging USDT users to swap their assets for USDD. "No one can freeze your USDD" Interestingly, they will finally get the illicit volume they actually wanted While such a large amount could shake them, it’s nothing compared to what they have processed. And as you can see, they have resumed operations and are ready to roll with USDD. Stay Smart
7
1
44
5,668
Specter retweeted
1/ Thought it might be helpful to translate this for crypto folks so you know who is hacking you. tl;dr the word "Lazarus" doesn't mean anything anymore, it's just a collective name used to describe various North Korean cyber operations. The (relevant) clusters are as follows:
13
52
6
249
17,115
Specter retweeted
Looking into the @shivon X hack & solana:5erj4fz47YLFZc677GNipfaK1G8UrwwPTyy9HPaMtLmk launch Interestingly, Most of these bundle wallets appear to have been initially funded around July 11 by: 0xc39Ed9da17210ee1F6a1649204ac08c8e51220F4 After receiving their initial funding, the wallets bought random/unknown meme tokens something that could potentially make the wallets appear less “fresh” and create an artificial transaction history. Then they went silent...Until yesterday. The bundle wallets were subsequently funded by the addresses below and used to buy solana:5erj4fz47YLFZc677GNipfaK1G8UrwwPTyy9HPaMtLmk. 0xB353c51AEd42DCcC729D9115A44d2E3b3bFD7222 0xFb7D3b5fE5529AE9800c79F9B857863F0730a915 interesting Pattern: 1. Create fresh wallets 2. Fund the wallet on july 11 3. Buy random meme tokens to establish wallet history 4. Leave the wallets dormant 5. Fund them shortly before the solana:5erj4fz47YLFZc677GNipfaK1G8UrwwPTyy9HPaMtLmk launch 6. Accumulate solana:5erj4fz47YLFZc677GNipfaK1G8UrwwPTyy9HPaMtLmk 7. Hold for roughly four hours 8. Compromise shivon’s X account and publish the promotional post 9. Token price surges, generating $6M+ in profit it kind of look coordinated, suggesting considerably more preparation than a simple opportunistic token launch. Of course, none of this by itself proves who controlled the wallets or that the X compromise and token launch were coordinated but it all kind of interesting. The attacker(s) still appear to hold the majority of the proceeds, only $123K has been sent to Railgun so far. Stay Smart
4
1
26
5,501
Looking into the @shivon X hack & solana:5erj4fz47YLFZc677GNipfaK1G8UrwwPTyy9HPaMtLmk launch Interestingly, Most of these bundle wallets appear to have been initially funded around July 11 by: 0xc39Ed9da17210ee1F6a1649204ac08c8e51220F4 After receiving their initial funding, the wallets bought random/unknown meme tokens something that could potentially make the wallets appear less “fresh” and create an artificial transaction history. Then they went silent...Until yesterday. The bundle wallets were subsequently funded by the addresses below and used to buy solana:5erj4fz47YLFZc677GNipfaK1G8UrwwPTyy9HPaMtLmk. 0xB353c51AEd42DCcC729D9115A44d2E3b3bFD7222 0xFb7D3b5fE5529AE9800c79F9B857863F0730a915 interesting Pattern: 1. Create fresh wallets 2. Fund the wallet on july 11 3. Buy random meme tokens to establish wallet history 4. Leave the wallets dormant 5. Fund them shortly before the solana:5erj4fz47YLFZc677GNipfaK1G8UrwwPTyy9HPaMtLmk launch 6. Accumulate solana:5erj4fz47YLFZc677GNipfaK1G8UrwwPTyy9HPaMtLmk 7. Hold for roughly four hours 8. Compromise shivon’s X account and publish the promotional post 9. Token price surges, generating $6M+ in profit it kind of look coordinated, suggesting considerably more preparation than a simple opportunistic token launch. Of course, none of this by itself proves who controlled the wallets or that the X compromise and token launch were coordinated but it all kind of interesting. The attacker(s) still appear to hold the majority of the proceeds, only $123K has been sent to Railgun so far. Stay Smart
4
1
26
5,501