ZachXBT
Pseudonymous blockchain investigator
About ZachXBT
ZachXBT, also identified as Zachary Wolk is a pseudonymous American blockchain investigator and open-source intelligence (OSINT) researcher known for independent forensic investigations into cryptocurrency fraud, scams, and thefts. He has been active on X (formerly Twitter) since 2021, publishing detailed investigative threads that trace stolen funds, expose rug pulls, and identify perpetrators of crypto-related crime. His work has contributed to the recovery of hundreds of millions of dollars in stolen digital assets and has assisted law enforcement agencies in arrests across multiple countries.
Wired has described ZachXBT as the most prolific independent crypto-focused detective in the world. In February 2025, he joined the cryptocurrency investment firm Paradigm as an incident response advisor.
Early life and identity ZachXBT maintains strict anonymity and has never publicly disclosed his full name or appearance.
According to his own account, ZachXBT entered the cryptocurrency space around 2017, during the initial coin offering boom. After losing money to multiple fraudulent projects, he began analyzing blockchain data and tracing the flow of stolen funds.
Investigative methods ZachXBT's investigative approach combines blockchain forensics with open-source intelligence (OSINT) techniques. His methods include tracing fund flows across wallets and exchanges, address clustering to identify related accounts, and cross-referencing on-chain data with public records such as domain registrations, court filings, and social media activity.
He publishes his findings primarily through detailed threads on X and maintains a Telegram channel for longer-form investigations.
$243 million Genesis creditor theft (2024) On August 19, 2024, ZachXBT received an alert about an unusually large Bitcoin transaction while preparing to board a flight.
The attackers had used social engineering to impersonate Google and Gemini support staff, convincing the victim to reset two-factor authentication settings and install remote desktop software, which allowed them to extract private keys from the victim's Bitcoin Core wallet. ZachXBT traced the stolen 4,064 BTC as it was split across more than 15 exchanges and converted between Bitcoin, Litecoin, Ethereum, and Monero to obscure the trail. ZachXBT identified three suspects and shared his findings with U.S. law enforcement. The United States Department of Justice subsequently charged Malone Lam and Jeandiel Serrano, who were arrested in Miami and Los Angeles on September 18, 2024. Cryptoforensic Investigators, zeroShadow, and Binance Security froze more than $9 million in stolen funds, with over $500,000 returned to the victim. Within hours, ZachXBT submitted evidence to blockchain analytics platform Arkham Intelligence identifying North Korea's Lazarus Group as the perpetrators, based on analysis of test transactions and connected wallets used ahead of the exploit, as well as forensic graphs and timing analyses linking the attack to prior Lazarus Group operations against other exchanges. The Federal Bureau of Investigation subsequently confirmed the Lazarus Group's responsibility.
U.S. Marshals Service seized crypto theft (2026) In late January 2026, ZachXBT published an investigation alleging that an individual operating under the online handle "Lick" had stolen more than $46 million in cryptocurrency from wallets managed by the United States Marshals Service (USMS). The investigation originated after ZachXBT obtained a recording of a dispute in a private Telegram group chat, in which two individuals attempted to prove who controlled more cryptocurrency. During the exchange, one participant screen-shared a wallet holding approximately $2.3 million and then transferred $6.7 million in ether in real time, inadvertently demonstrating control over addresses that ZachXBT traced back to government wallets.
ZachXBT identified the individual as John Daghita, the son of Dean Daghita, president of Command Services & Support (CMDSS), a Virginia-based firm awarded a USMS contract in October 2024 to manage and dispose of certain categories of seized digital assets. Law enforcement seized cash, hard drives, and security keys during the arrest. The case drew scrutiny to the USMS's reliance on outside contractors for custody of seized digital assets.
Don’t just read it —
keep it.
Full-length biographies made to live with: read them, listen on the way to work, watch them tonight.
- E-book
- Audio
- Video
Instant download · yours to keep · every purchase keeps this site free
Frequently asked questions
Who was ZachXBT?
pseudonymous blockchain investigator
Sources & further reading
Cite this page
APA: Biography.guide. (2026). ZachXBT. https://biography.guide/zachxbt/
MLA: "ZachXBT." Biography.guide, https://biography.guide/zachxbt/.
Chicago: "ZachXBT." Biography.guide. https://biography.guide/zachxbt/.
Data last updated: 2026-09-20 · Spot an error? Report a correction.
Page generated 2026-09-27 05:26 UTC