31 Jul 2026, 15:04 UTC≈1,220 views53 reactionsread 7 August 2026 Photo
Can someone tell them to remove "Sleep at night" from their bio? Because many of the victims certainly won't.
$38M+ in Bitcoin Drained from Coldcard hardwallet wallet users
Stolen funds by victim size:
2 victims lost >$1M
13 victims lost $500K–$1M
23 victims lost $250K–$500K
38 victims lost $100K–$250K
The remaining victims each lost less than $100K
Just two weeks ago, zach called all hardware wallets "garbage."
…
👍24😭14❤9😱5🤡1
26 Jul 2026, 06:49 UTC≈1,780 views30 reactionsread 7 August 2026 31 hours after Triple-A wallets first showed massive suspicious outflows, new deposits are still coming in and being drained.
An additional $1.8M has now been drained across the Bitcoin and TRON networks.
Addresses:
0x2d9E17Abd7fb0A5d0c429142c52C91F9272dc451
0x20f774Ae0C053CBc4fB12da30B0e15fcf02de245
The total loss has now reached $11.8M
Meanwhile, this was Triple-A's response:
"We confirm that customers' funds a…
🤣20🤝7❤2🍌1
25 Jul 2026, 04:57 UTC≈1,850 views44 reactionsread 7 August 2026 Photo
An onchain message from "A pastor" to the Triple A "Attacker" 😂
GM
🤣41🗿3
24 Jul 2026, 20:23 UTC≈2,480 views17 reactionsread 7 August 2026 There appears to be suspicious fund movements from a TRIPLE-A hot wallet on TRON and Ethereum
So far, more than $9M+ drained and currently sitting on Ethereum.
Related addresses:
0x8335D258438E47Cd8EB1532C04Cfe445E011aEf6
TRSr81kTZAL2zMoWBsjE4QBc9B4v8WpSkw
Edited: The total amount drained
Stay smart
😱11👏4🔥1🤣1
23 Jul 2026, 13:28 UTC≈1,860 views31 reactionsread 7 August 2026 Photo
A dormant PancakeSwap LP lost $2.96M via a malicious EIP-7702 signature.
The attacker removed $1.48M BSC-USD and $1.48M BUSD liquidity provided by the victim, and swapped the BUSD for ETH.
The attacker has so far deposited $1.46M to Tornado Cash, and is still holding the remaining 1.48M USDT.
Theft addresses:
0xd7d44BbDb2f61eD68116c897DDaDF207838E553e
0xff15Da5bC89665E3a34A1E96a2372629cE0926F2
0xadeb25c81Fe6d00266…
😭16😱7🤯4❤3👍1
10 Jul 2026, 09:02 UTC≈3,770 views37 reactionsread 7 August 2026 Photo
Yesterday, I posted a quick investigation into suspicious fund movements involving a BNB Chain project, Codexfield that has existed since 2023 and was heavily supported by BNBCHAIN .
Following my investigation, the project changed its X handle and shut down the subdomains it had been using to collect funds from users, with over $85M generated based on my on-chain tracing.
The timing of these changes raises further …
👍27🔥5💯4❤1
8 Jul 2026, 17:49 UTC≈3,060 views18 reactionsread 7 August 2026 Photo
An unknown HashKey user may have lost $3M, likely as the result of a social engineering attack.
The attacker withdrew the victim's assets across both the Bitcoin and Ethereum networks.
On Ethereum, the stolen funds were swapped for 702 ETH before being deposited into Tornado Cash.
Theft addresses:
0x5554BC4e8Ee1a1c70B333Ab11f4CDe0Deb5aC603
0x55a77410BB702f9045111d7d0DBA043ED10Fd602
bc1pckv8nmgw35f0nywgud72d5wqvw02…
❤12😢4💔2
4 Jul 2026, 13:52 UTC≈3,190 views16 reactionsread 7 August 2026 Photo
In the last five hours, the Tornado Cash 100 ETH pool has received $38.3M in deposits.
The deposits are proceeds from the Step Finance and UXLINK hacks.
Tornado Cash deposits:
Step Finance attacker: 15,998 ETH (~$28.2M)
UXLINK attacker: 6,000 ETH (~$10.5M)
Attacker addresses:
0x535dC505c9f8Adb4cb70D3E5f44cC5c9Caa6C2b6
0x5210BFdf0cFE6471322D597D16Cf440F5AC59309
0xDf3786773645fd737ff5764C06536e8908f5d1b7
Tornado Ca…
❤11👍3❤🔥2
3 Jul 2026, 00:57 UTC≈2,070 views18 reactionsread 7 August 2026 Photo
Hinkal Protocol may have been exploited, with a loss of $822K USDC.
The attacker swapped the stolen USDC for ETH and has already begun depositing the funds into Tornado Cash.
Theft address: 0xbB3f01a1b1C68F3DEB36C55342b5F5706c32fc20
Stay smart.
❤11💔4👍3
28 Jun 2026, 20:14 UTC≈2,310 views20 reactionsread 7 August 2026 Photo
A victim wallet may have been compromised, resulting in a loss of $5.6M.
The attacker drained the victim wallet's assets across BNB and Ethereum and swapped them for ETH and BNB. The funds were then consolidated to the address below.
0xF9d1b5B22b3D6a889140ca7A39b8d8B411F7f971
Other theft addresses:
0xaeBFef599DB35a9D817a477EF006033426f8C52A
0xa7429b5930806E8B23de8C4bCA1Df1aa1440B4d5
0xE90295115a10b91b45Ff87244D8da…
👍13❤4😭3
20 Jun 2026, 20:56 UTC≈3,230 views7 reactionsread 7 August 2026 jaredfromsubway Mev bot contract was exploited of $7.5M
Theft addresses:
0x5aF38735B215b00aa7C9f93fEd7ee415CeCB36e1
xd8C125efCBc99408eC8723E9BBd81d1E8D39D845
0xe3Da36E4bd1a5738fa5D6Ef4F0e4dF40bDeB5f17
0x74Dc5b93586D248D5Aec64b3586736FF0A0D0e65
0x71d4416A7A85e08a5Fe7227Ca3B44Fc639e94e97
0x3e37f4A10d771Ba9dE44b6d301410b1BEdeA65d0
This is not a usual contract exploits... you can check out blockaid analysis
👍6❤1
20 Jun 2026, 19:55 UTC≈2,870 views13 reactionsread 7 August 2026 SUSPICIOUS ACTIVITY ON THIS WALLET.
0x3e37f4A10d771Ba9dE44b6d301410b1BEdeA65d0
Trying to figure it out...
involving $7M+
Looks like it involves jared mevbot
❤12👏1
Showing the 12 most recent of 18 posts we hold for @specterinvestigation. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked ≈ was rounded by Telegram before we ever saw it — t.me prints views in full below 1,000 and to three significant figures above, so ≈1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.