Blockchain intelligence for investigating crypto-related financial crime and fraud

Joined June 2022
4 Photos and videos
Pinned Tweet
We’ve joined IVAN PPP! 💥 BlockchainUnmasked is now an official partner in a US-led initiative to combat illicit crypto activity and protect the future of digital finance. Read more from MITRE → 🔗 mitre.org/news-insights/news…
4
840
Permissionless ≠ powerless. THORChain has: • trading halts • validator control • governance votes And still processes North Korea laundering while collecting fees. That’s hardly “neutral.” Interestingly, they chose Switzerland as their HQ. Likely intentional.
49
Pre-2008, MBS were accepted as repo collateral at haircuts that assumed the underlying was liquid, diversified, and uncorrelated with broad stress. When that assumption broke, the haircut problem became a solvency problem almost overnight. DeFi just ran the same play with LRTs. Aave's contracts didn't break. Their risk perimeter did. One bridged LRT, 93% LTV, no velocity limits, shared liquidity pools, and a tail risk that everyone priced as negligible until it wasn't. Different instrument. Same failure. Same lesson nobody wanted to learn until it was expensive.
37
Mythos isn’t hype. The signal is simple: Bug discovery is becoming cheap. Exploit development is compressing. The bottleneck is now patching, triage, and response. If defenders don’t operationalize faster than attackers, the gap widens. Anything else is noise.
1
40
Security can’t be an afterthought, or state-sponsored actors will keep draining hundreds of billions that effectively fund hostile regimes. Typically we don’t claim we could’ve stopped something like this—and we won't here. We couldn’t have stopped this (though the 6 hours the funds sat on USDC is another story). I dislike when firms grave-dance and claim their sandbox or monitoring tool would’ve magically prevented a breach. This attack was much more than the typical. But we will say this: if you want to find the real holes before they’re exploited—we’ve built NSA-grade pen-testing and counterintelligence capabilities (mainly for use by Federal Law Enforcement) that can help you identify weaknesses and close them proactively. Tracing after the fact is too late. And tracing itself has become a common-place competency. Prevention is non-negotiable. If you’re a protocol or exchange and what to chat security, get in touch.
1
109
Excited to share that we have joined the @circle Alliance Program, a global community of teams focused on bringing the world on-chain, powered by USDC.
121
We've recently worked on violent crypto crimes alongside federal law enforcement. It's scary. When crypto fraud turns violent, strong chain-analysis and cross-border coordination matter more than ever.
12 Nov 2025
Russian Crypto Scammer and Wife Found Dead in UAE After Apparent Revenge Attack ► decrypt.co/348276/russian-cr… decrypt.co/348276/russian-cr…
222
People are calling the recent npm hack a “failure” because it only stole a few bucks. That’s the wrong take. This wasn’t designed to drain wallets, it was a show of force. The attackers proved they could compromise packages with billions of downloads, hijack crypto flows, and manipulate addresses. Instead of hiding it, they made it obvious. They barely touched funds. Why? To send a warning shot. Now every dev team infra provider has to patch holes, spend time, energy, and money fixing exposures. That’s the real impact. This wasn’t accidental. It was intentional. A message: “If we wanted to steal at scale, we could. You’re not ready.”
1
264
BlockchainUnmasked retweeted
ICYMI: APPLE PATCHED A ZERO-CLICK VULNERABILITY THAT ALLOWED SOPHISTICATED ATTACKERS TO COMPROMISE DEVICES AND COULD HAVE LED TO CRYPTOCURRENCY THEFT; IT URGED IMMEDIATE UPDATES - PER COINTELEGRAPH
95
159
806
177,774
Just when you think you've seen every type of attack, we just got this: Attacker hacks victim's email → hacks their MEXC account → swaps $90k of coins to USD → buys $90K of a low-price token (CAW/USDC) → the price pumps→ attacker dumps it from their own account. They hacked an account so they could front-run their own pump and then dump. No coins "stolen"—just market manipulation. Wild.
3
580
BlockchainUnmasked retweeted
We released an updated version of @tayvano_'s guide on what to do if you've been infected by malware, tailored specifically for crypto users. Take a look and save the link, it might come in useful one day securityalliance.org/go/malw…
8
54
173
18,871
Yep. We've even had a few NK applicants. They're everywhere.
7 Jun 2025
Your DeFi dev might be a North Korean operative. The DOJ dropped a bombshell complaint showing how DPRK IT workers infiltrated U.S. crypto startups, laundered millions, and funded North Korea's weapons programs. If you hire remote devs, you NEED to be careful about this. đź§µ
2
239
The dates on this coincide directly with the dates of the API breach we investigated for dozens of individuals. Coinbase denied all of them and closed all of their cases, informing them that it was the user's fault and Coinbase was not liable. news.bitcoin.com/69461-users… via @bitcoinnews

3
169
Yep. More often than not unfortunately.
9 May 2025
The unfortunate reality is victims of theft need to get lucky with regards to which LE opens a case. There's nothing more frustrating than wasting days spoonfeeding a case to LE, and then have them question my motives/qualifications/reliability instead of catching the bad guys
1
358
Good progress. Crypto companies (exchanges) need to implement better SOPs to protect users.
4 Apr 2025
Illinois State Senator's Bill Seeks to Claw Back $163 Million Lost to Crypto Fraud ► decrypt.co/313327/illinois-s… decrypt.co/313327/illinois-s…
9
498
This is a wild stat.
5 Mar 2025
For 25% of the Winter 2025 batch, 95% of lines of code are LLM generated. That’s not a typo. The age of vibe coding is here.
1
3
445