Blockchain Intelligence at your fingertips. Crypto Tracing / AML Screening / Incident Response

Pinned Tweet
New Product: AI Tracer is Live 🔍 A self-serve crypto investigation tool, built for everyone. Paste a TxID and AI traces where the funds went — every wallet, bridge, and exchange along the path, across 14 chains. A visual map in minutes. No analyst skills needed. First Trace FREE → amlbot.com/ai-tracer
5
8
2,418
Update: It seems stolen funds from the @bitget hack have started to be laundered through Wasabi CoinJoin (mixer) Our tracing links ~4 BTC in a CoinJoin round back to a Bitget TRON wallet. The funds were swapped from TRX to USDT, bridged to Ethereum via @USDT0_to, swapped to ~145 ETH, then sent through @THORChain to ~4.59 BTC. The BTC was then split and prepared before entering the CoinJoin We have blacklisted the related addresses and are monitoring the attacker's BTC for further CoinJoin activity
~$343M (~88%) of the ~$389M stolen from @bitget has not moved Our tracing shows 13 attacker wallets are lying dormant: ~68.3K ETH across 8 wallets on ETH Mainnet, ~83M XRP across 4 wallets and ~18.9K ZEC in 1. None of them has sent a single transaction since being funded The laundering is running through one active XRP wallet and the smaller branches. ~5.2M XRP has been peeled off so far, and the TRON, BNB and stablecoin proceeds are being swapped into BTC via @THORChain, @Bridgersxyz and @near_intents Our team have blacklisted the related addresses and are actively monitoring them
1
8
51
8,935
Update: Tracing shows the exploiter behind @payy_link has moved almost all the funds to Tornado Cash The second batch of ~$90.2K in USDC remains parked in the attacker’s wallet, with no action from @circle in the past two days
It seems like @payy_link was exploited for ~$1.9M in USDC Our tracing shows the proceeds were swapped into ~683 ETH and split across four fresh wallets (~200 / ~280 / ~200 / 1 ETH). Those wallets have not moved since A second batch of ~90.2k USDC is still parked in the attacker's entry wallet. It remains there and was not blacklisted by @circle at our last check Worth noting: the attack wallet's gas was seeded through Railgun two days before the drain We are actively monitoring this case and will post updates if funds move
8
2,063
~$343M (~88%) of the ~$389M stolen from @bitget has not moved Our tracing shows 13 attacker wallets are lying dormant: ~68.3K ETH across 8 wallets on ETH Mainnet, ~83M XRP across 4 wallets and ~18.9K ZEC in 1. None of them has sent a single transaction since being funded The laundering is running through one active XRP wallet and the smaller branches. ~5.2M XRP has been peeled off so far, and the TRON, BNB and stablecoin proceeds are being swapped into BTC via @THORChain, @Bridgersxyz and @near_intents Our team have blacklisted the related addresses and are actively monitoring them
3
17
10,889
Our CEO @demchukvm spoke with @Incrypted about how AMLBot grew from a wallet checker into full AML infrastructure, what small compliance teams struggle with most, and where AI helps investigators and where it doesn't. Read the full interview ⬇️
1
2
286
It seems like @payy_link was exploited for ~$1.9M in USDC Our tracing shows the proceeds were swapped into ~683 ETH and split across four fresh wallets (~200 / ~280 / ~200 / 1 ETH). Those wallets have not moved since A second batch of ~90.2k USDC is still parked in the attacker's entry wallet. It remains there and was not blacklisted by @circle at our last check Worth noting: the attack wallet's gas was seeded through Railgun two days before the drain We are actively monitoring this case and will post updates if funds move
3
19
5,131
We’re marking a year of working with @SimpleSwap_io with a guide for anyone whose swap goes under review. When funds are already in motion, clear next steps matter most. Read it below ⬇️
A year ago we plugged @AMLBotHQ screening layer into the swap flow. The usual way to mark that is a press release with two logos. We wrote a guide instead, because the anniversary isn't the interesting part – what a year of reviews taught us is. People get stuck at the status, not the documents. "Under review" reads like an accusation. It isn't. It's the system saying the transaction context needs clarifying before funds move on. Once that lands, the rest is procedure: official channel only, order ID ready, one ticket, timeline tied to what's missing rather than a calendar. If you've ever seen that status, this is the reference we wish we'd shipped on day one. Read it on @DefiantNews: bit.ly/3V3kmxH
3
290
Seems like the @Fetch_ai / @ASI_Alliance exploiter has started laundering the stolen funds 100 ETH was swapped to ~266K USDC, bridged via Circle CCTP to Arbitrum and deposited into Hyperliquid, then converted into "FXMR" which is likely a Monero variant The other 100 ETH was sent to @Chainflip, where the broker rejected the deposit. The attacker was refunded and pivoted to @THORChain, swapped into ~3.28 BTC and began peeling it through a chain of Bitcoin addresses The remaining ~433 ETH are still parked at the main address 0x2dcc1085fDCf418B421E45e86e4e54637cc21dfE
Multiple tokens in the @ASI_Alliance ecosystem were hit in an exploit on Ethereum - ethereum:0xaea46a60368a7bd060eec7df8cba43b7ef41ad85 drained and ethereum:0xf0d33beda4d734c72684b5f9abbebf715d0a7935 , $WMTX, ethereum:0x5b7533812759b45c2b44c19e320ba2cd2681b542 & $CGV minted Tracing shows most of the funds were swapped into ETH and stablecoins. The main wallet 0x2dcc1085fDCf418B421E45e86e4e54637cc21dfE holds ~$1.75M (632.9 ETH + 52.4K mUSD + 15.9 WETH). A second wallet 0x83F4424A401a9Bb75F90314f21ADAeA6a9cE09C5 holds ~$530K (92.4 ETH + 289.5K USDC) Another 40M AGIX was parked in three dormant stash wallets that hold no gas We are actively monitoring this case
2
26
3,708
Multiple tokens in the @ASI_Alliance ecosystem were hit in an exploit on Ethereum - ethereum:0xaea46a60368a7bd060eec7df8cba43b7ef41ad85 drained and ethereum:0xf0d33beda4d734c72684b5f9abbebf715d0a7935 , $WMTX, ethereum:0x5b7533812759b45c2b44c19e320ba2cd2681b542 & $CGV minted Tracing shows most of the funds were swapped into ETH and stablecoins. The main wallet 0x2dcc1085fDCf418B421E45e86e4e54637cc21dfE holds ~$1.75M (632.9 ETH + 52.4K mUSD + 15.9 WETH). A second wallet 0x83F4424A401a9Bb75F90314f21ADAeA6a9cE09C5 holds ~$530K (92.4 ETH + 289.5K USDC) Another 40M AGIX was parked in three dormant stash wallets that hold no gas We are actively monitoring this case
2
7,740
Starknet's @nostrafinance was drained of ~$3.5M after an oracle price manipulation attack Our tracing shows the funds were swapped and exited to Ethereum through Near Intents, CCTP and Layerzero OFT ~$1.6M is still parked at the Starknet address 0x6d48ef7ab62c26e3ef1987c322096cd508e9034c8048783a6b438fc1344bc3, with no bridge activity yet. Another ~$1.9M sits in this Ethereum EOA: 0xa059aaab82773caf622de9d9a0f2dbf9aa7f3c37 We are actively monitoring this case and will update if the funds move
1
2
29
2,969
AMLBot retweeted
Two Safes using Makina modules on Ethereum were drained on Sep 15 Safe #1 lost 2,900 rsETH ($7.7M). An MEV bot intercepted the extraction in-block - 2,882 rsETH is now dormant at 0xC70f00CD7E461686b04B0E912E309becA8b80ea0, likely the Yoink MEV address. The attacker got nothing from this one Safe #2 lost ~$125K in USDC and DUSD. Those funds were swapped to ETH, bridged to Hyperliquid and converted to XMR. The attacker profited around $58K Attacker wallet was seeded from Railgun and used to deploy the malicious contracts
1
2
626
AMLBot retweeted
On September 11, @symbiosis_fi syBTC was exploited. ~184.47B syBTC was minted to the attacker on each of BNB, Ethereum and Rootstock Tracing shows attacker dumped all the tokens and bridged to Ethereum. The funds are now consolidated at 0x7cd28D8E6210E6E4A8b1947FC9b44DC01C600192 ~309 ETH (~$748K) The attacker's gas was funded via @ChangeNOW We are actively monitoring this case and will post updates if the funds move
2
14
1,642
Liquid Network @Liquid_BTC was reportedly exploited for ~4,000 BTC, currently worth ~$315M The purpoted whitehat might have returned 3,400 BTC (~$268M) to the official Liquid Federation wallet, while retaining ~600 BTC (~$47M) as a potential bounty The return transaction is still waiting to be confirmed mempool.space/tx/a6d697a2526…
1
1
9
3,532
Project @cozyfinance was exploited for $160K on @Optimism The attacker bridged all the stolen proceeds (USDC) to Ethereum, swapped them to ETH, and deposited them into Tornado Cash Notably, the attacker's gas funding also came from Tornado Cash, withdrawn on 27 August, 11 days before the exploit
3
1
14
2,084
Project @TectonicFi on @CronosNetwork was exploited for ~$75M Tracing shows the attacker bridged ~$6.5M to Ethereum via @RelayProtocol before Cronos halted the chain, freezing the remaining ~$60M in place on Cronos On Ethereum, the attacker now holds ~2,592 ETH and ~182K USDC (~$6.4M) across two addresses. The USDC remains freezable by Circle We are actively monitoring this case
1
1
961
Crypto neobank @avici was exploited for ~$1.12M Our tracing shows the proceeds were bridged from Solana to Ethereum via @debridge and swapped into ETH Funds were effectively laundered, ~456 ETH was deposited into Tornado Cash
2
604
AMLBot retweeted
Replying to @MoonwellDeFi
Note: this is at least Moonwell's 5th incident since Dec 2024, with the latest (~$8.7M on Aug 27) the biggest yet
2
4
428
DeFi Protocol @MoonwellDeFi was exploited for ~$8.7M on Base Tracing shows the borrowed assets were swapped to USDC on Base, bridged to Ethereum via Circle CCTP in two ~$4.36M transfers, then consolidated into DAI on Ethereum mainnet All ~$8.7M in DAI now sits unmoved at a single Ethereum address 0xd71dd9b6e634412713c47fe7ae02c628e338c384 We are monitoring the case and will update if funds move
1
3
1,778
Note: this is at least Moonwell's 5th incident since Dec 2024, with the latest (~$8.7M on Aug 27) the biggest yet
2
4
428