The post Crypto Scam Exposed After Hacker Flexed $23M in Stolen US Funds appeared on BitcoinEthereumNews.com. Key Insights: A crypto scam operator linked to overThe post Crypto Scam Exposed After Hacker Flexed $23M in Stolen US Funds appeared on BitcoinEthereumNews.com. Key Insights: A crypto scam operator linked to over

Crypto Scam Exposed After Hacker Flexed $23M in Stolen US Funds

Key Insights:

  • A crypto scam operator linked to over $90 million in suspected thefts was exposed after he bragged about his wealth in a recorded group chat.
  • On-chain investigator ZachXBT traced wallet addresses displayed during the argument directly back to US Government seizure addresses and multiple victims from late 2025.
  • The threat actor, known as John, immediately scrubbed his social media after the January 23 crypto news.

On-chain investigator ZachXBT published a detailed thread on X, exposing a threat actor identified as John, also known as “Lick”. He was displaying $23 million in cryptocurrency wallets when ZachXBT caught him.

The addresses directly link to over $90 million in suspected thefts from the US Government in 2024 and multiple other unidentified victims between November and December 2025. This exposure occurred after John participated in a heated argument with another threat actor, Dritan Kapplani Jr., in a group chat.

The discussion was a bragging competition to determine who controlled more cryptocurrency funds. This interaction is famous as a “band for band” or “b4b” competition in cybercrime circles.

The entire confrontation was recorded and provided the evidence ZachXBT needed to connect wallet addresses to the crypto scam operation.

Threat Actor’s Tron Address. Source: ZachXBT

In the first part of the recording, John screen-shared his Exodus Wallet. It displayed a TRON address containing $2.3 million, after Dritan mocked him. In the second part, John moved an additional $6.7 million in ETH to the wallet address 0xd8bc while Dritan continued taunting him.

By the end of the recorded exchange, John had moved approximately $23 million to the 0xd8bc address. The recording clearly showed that he controlled both wallet addresses. ZachXBT began tracing the funds backward through the blockchain to verify their source and discovered damning connections.

The 0xd8bc address received funds from 0x8924, which John confirmed owning during the recording. The 0x8924 address had received 1,066 WETH from address 0xc7a2 on November 20, 2025, in a specific transaction hash documented in the report.

The critical link emerged when ZachXBT traced the 0xc7a2 address. It had received $24.9 million from a US Government address in March 2024, in connection with the Bitfinex hack seizure.

ZachXBT previously reported this theft from the US Government in October 2024. As per the latest crypto news, $18.5 million are still sitting at the cv0xc7A2 address.

The blockchain evidence established a direct trail from government-seized funds to the wallets John controlled, as displayed during his bragging session.

Crypto Scam Operator Tied to $63M in Q4 2025 Inflows

ZachXBT’s analysis revealed that the 0xd8bc address received over $63 million in inflows from suspected victims and government-seized addresses during the fourth quarter of 2025 alone.

Crypto Scam Actor’s Wallet | Source: ZachXBT/DeBank

In December 2025, the address received $13.5 million from 0x77a7 and $15.4 million from 0xf51b. In November 2025, it received $3 million from the Tron address TACZPn and $1 million from the Solana address 6tMdWb.

An additional 4,170 ETH, valued at $12.4 million, was received from the MEXC exchange earlier on January 23. This fund was flowing to the 0xd8bc address via the intermediary address 0xe0f7.

ZachXBT noted that John maintained an extensive message history on Telegram flaunting his net worth and calling others broke. His Telegram ID is 8269661864. The pattern of behavior suggested a threat actor who prioritized social status within cybercrime communities over operational security.

Rumors circulating on cybercrime Telegram channels suggested John could be John Daghitia, who was previously arrested in September 2025. However, ZachXBT noted that further research will fully confirm the identity.

The investigator observed that threat actors continued to show off stolen funds in leaked recordings. He didn’t remain quiet after alleged thefts from the US Government. This pattern repeatedly provided law enforcement with evidence.

In this specific crypto scam case, Dritan ragebaited John into participating in a band-for-band competition. The recordings captured proof of wallet ownership, providing straightforward evidence for future law enforcement action.

John’s response to the public exposure was immediate and telling. He quickly removed all NFT usernames from his Telegram account and changed his screen name after ZachXBT’s thread went public, suggesting that he recognized the documented evidence posed a serious legal risk.

The case demonstrated how ego-driven behavior among cybercriminals could override basic operational security.

A recorded bragging session provided investigators with direct blockchain evidence linking a threat actor to over $90 million in suspected thefts. Those crypto scams span across government seizures and private victims from 2024 and 2025.

Source: https://www.thecoinrepublic.com/2026/01/24/crypto-scam-exposed-after-hacker-flexed-23m-in-stolen-us-funds/

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Trump’s 'desperate' push to rename landmarks for himself is a 'growing problem': analysis

Trump’s 'desperate' push to rename landmarks for himself is a 'growing problem': analysis

President Donald Trump's fixation on adding his name to major landmarks is presenting numerous problems both for himself and his party.That's according to a Friday
Share
Alternet2026/02/07 05:30
Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be

Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be

The post Why The Green Bay Packers Must Take The Cleveland Browns Seriously — As Hard As That Might Be appeared on BitcoinEthereumNews.com. Jordan Love and the Green Bay Packers are off to a 2-0 start. Getty Images The Green Bay Packers are, once again, one of the NFL’s better teams. The Cleveland Browns are, once again, one of the league’s doormats. It’s why unbeaten Green Bay (2-0) is a 8-point favorite at winless Cleveland (0-2) Sunday according to betmgm.com. The money line is also Green Bay -500. Most expect this to be a Packers’ rout, and it very well could be. But Green Bay knows taking anyone in this league for granted can prove costly. “I think if you look at their roster, the paper, who they have on that team, what they can do, they got a lot of talent and things can turn around quickly for them,” Packers safety Xavier McKinney said. “We just got to kind of keep that in mind and know we not just walking into something and they just going to lay down. That’s not what they going to do.” The Browns certainly haven’t laid down on defense. Far from. Cleveland is allowing an NFL-best 191.5 yards per game. The Browns gave up 141 yards to Cincinnati in Week 1, including just seven in the second half, but still lost, 17-16. Cleveland has given up an NFL-best 45.5 rushing yards per game and just 2.1 rushing yards per attempt. “The biggest thing is our defensive line is much, much improved over last year and I think we’ve got back to our personality,” defensive coordinator Jim Schwartz said recently. “When we play our best, our D-line leads us there as our engine.” The Browns rank third in the league in passing defense, allowing just 146.0 yards per game. Cleveland has also gone 30 straight games without allowing a 300-yard passer, the longest active streak in the NFL.…
Share
BitcoinEthereumNews2025/09/18 00:41
Why Ethereum’s long-term potential remains intact DESPITE 30% weekly drop

Why Ethereum’s long-term potential remains intact DESPITE 30% weekly drop

The post Why Ethereum’s long-term potential remains intact DESPITE 30% weekly drop appeared on BitcoinEthereumNews.com. On the macro side, the market’s risk-off
Share
BitcoinEthereumNews2026/02/07 05:18