The post ZachXBT cracks Railgun privacy to expose Bittensor hacker appeared on BitcoinEthereumNews.com. Crypto sleuth ZachXBT has managed to deanonymise withdrawals from crypto mixer Railgun while identifying a suspect linked to NFT wash trading and the $28 million Bittensor hack.  Decentralized protocol Bittsensor suffered a supply chain attack in 2024 that resulted in the theft of $28 million from 32 holders of its TAO token.  In an investigation revealed today, ZachXBT showed how he was able to trace these funds to instant exchanges where they were swapped for privacy-focused cryptocurrency monero.  5/ I deanonymized the Railgun withdrawals to three addresses (0x1d7, 0x87d8, 0x1fbc) by applying timing / amount heuristics. Total deposits: 1249.68 ETH, 277.2K USDC, 22.35 WETHTotal withdrawals: 1246.16 ETH, 276.4K USDC, 19.83 WETH The unique denominations and short deposit… pic.twitter.com/6jZ2yrqLQw — ZachXBT (@zachxbt) October 15, 2025 A snippet of ZachXBT’s full Bittsensor investigation. Read more: Did the US government hack a scam network for $15B in bitcoin? Almost $5 million worth of these funds was transferred to Railgun in batches of ether, USDC, and wrapped ether.  ZachXBT claims to have then deanonymized the withdrawals from Railgun by applying timing and amount “heuristics.” According to the sleuth, “The unique denominations and short deposit time makes the demix high confidence.” Railgun is a rival to Tornado Cash, and has seen the likes of Ethereum creator Vitalik Buterin use its service.  In some instances, Railgun has utilised protocol policy to return stolen funds, for example from the $9.5 million exploit of the Starknet network. On the flip side, it’s also popular with North Korean hacking collective Lazarus Group.  This is a solid demonstration of Railgun’s privacy pools mechanism ( https://t.co/DekkatsMR5 ) working in practice, allowing Railgun to avoid serving proceeds of crime without using any snooping / backdoors. How it works: * Anyone can deposit into Railgun.* After you deposit,… https://t.co/SqclMS3SzO — vitalik.eth (@VitalikButerin) February… The post ZachXBT cracks Railgun privacy to expose Bittensor hacker appeared on BitcoinEthereumNews.com. Crypto sleuth ZachXBT has managed to deanonymise withdrawals from crypto mixer Railgun while identifying a suspect linked to NFT wash trading and the $28 million Bittensor hack.  Decentralized protocol Bittsensor suffered a supply chain attack in 2024 that resulted in the theft of $28 million from 32 holders of its TAO token.  In an investigation revealed today, ZachXBT showed how he was able to trace these funds to instant exchanges where they were swapped for privacy-focused cryptocurrency monero.  5/ I deanonymized the Railgun withdrawals to three addresses (0x1d7, 0x87d8, 0x1fbc) by applying timing / amount heuristics. Total deposits: 1249.68 ETH, 277.2K USDC, 22.35 WETHTotal withdrawals: 1246.16 ETH, 276.4K USDC, 19.83 WETH The unique denominations and short deposit… pic.twitter.com/6jZ2yrqLQw — ZachXBT (@zachxbt) October 15, 2025 A snippet of ZachXBT’s full Bittsensor investigation. Read more: Did the US government hack a scam network for $15B in bitcoin? Almost $5 million worth of these funds was transferred to Railgun in batches of ether, USDC, and wrapped ether.  ZachXBT claims to have then deanonymized the withdrawals from Railgun by applying timing and amount “heuristics.” According to the sleuth, “The unique denominations and short deposit time makes the demix high confidence.” Railgun is a rival to Tornado Cash, and has seen the likes of Ethereum creator Vitalik Buterin use its service.  In some instances, Railgun has utilised protocol policy to return stolen funds, for example from the $9.5 million exploit of the Starknet network. On the flip side, it’s also popular with North Korean hacking collective Lazarus Group.  This is a solid demonstration of Railgun’s privacy pools mechanism ( https://t.co/DekkatsMR5 ) working in practice, allowing Railgun to avoid serving proceeds of crime without using any snooping / backdoors. How it works: * Anyone can deposit into Railgun.* After you deposit,… https://t.co/SqclMS3SzO — vitalik.eth (@VitalikButerin) February…

ZachXBT cracks Railgun privacy to expose Bittensor hacker

Crypto sleuth ZachXBT has managed to deanonymise withdrawals from crypto mixer Railgun while identifying a suspect linked to NFT wash trading and the $28 million Bittensor hack. 

Decentralized protocol Bittsensor suffered a supply chain attack in 2024 that resulted in the theft of $28 million from 32 holders of its TAO token. 

In an investigation revealed today, ZachXBT showed how he was able to trace these funds to instant exchanges where they were swapped for privacy-focused cryptocurrency monero. 

A snippet of ZachXBT’s full Bittsensor investigation.

Read more: Did the US government hack a scam network for $15B in bitcoin?

Almost $5 million worth of these funds was transferred to Railgun in batches of ether, USDC, and wrapped ether. 

ZachXBT claims to have then deanonymized the withdrawals from Railgun by applying timing and amount “heuristics.

According to the sleuth, “The unique denominations and short deposit time makes the demix high confidence.”

Railgun is a rival to Tornado Cash, and has seen the likes of Ethereum creator Vitalik Buterin use its service. 

In some instances, Railgun has utilised protocol policy to return stolen funds, for example from the $9.5 million exploit of the Starknet network. On the flip side, it’s also popular with North Korean hacking collective Lazarus Group. 

Vitalik Buterin praising the crypto mixer Railgun.

Read more: What does Roman Storm’s guilty verdict mean for the wider DeFi sector?

Crypto mixers are designed to make funds untraceable once they’ve been withdrawn. ZachXBT’s research, however, appears to undermine this completely.  

Wash trading NFT anime girls

Once the crypto was obfuscated, the suspects sent the funds to three more addresses and made various bridged transactions.

The funds were then used to purchase some anime-themed NFTs and, through various overpriced sales and fund transfers, they were laundered.

The crypto sleuth noted that, “It’s extremely rare to see exploits/hacks involve NFT wash trading.” 

The Killer GF NFT series in question.

One address that received the funds was funded by an address belonging to a Bittensor user who went by the alias “Rusty,” and created “Skrtt racing,” a crypto project that took bets on live-streamed Hot Wheels races.  

ZachXBT linked this individual to a lawsuit launched against suspects of the Bittensor hack, and noted that Rusty, giving a statement in the lawsuit as Ayden B, denies involvement in the scam, but admitted to owning the wallets ZachXBT managed to identify in his investigation.

Hopefully law enforcement eventually moves forward with a criminal case in the future,” he said. 

Protos has reached out to ZachXBT to find out more and will update this piece should we hear back.

Got a tip? Send us an email securely via Protos Leaks. For more informed news, follow us on X, Bluesky, and Google News, or subscribe to our YouTube channel.

Source: https://protos.com/zachxbt-deanonymizes-withdrawals-from-crypto-mixer-railgun/

Market Opportunity
null Logo
null Price(null)
--
----
USD
null (null) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Trump and Newsom seen engaging in 'friendly banter' backstage: 'Gavin, we're good'

Trump and Newsom seen engaging in 'friendly banter' backstage: 'Gavin, we're good'

President Donald Trump and California Gov. Gavin Newsom engaged in a public war of words this week in Davos, Switzerland, but a Washington, D.C., insider revealed
Share
Rawstory2026/01/23 19:55
Visa Direct Enhances Mercuryo’s Real-Time Crypto-to-Fiat Conversions

Visa Direct Enhances Mercuryo’s Real-Time Crypto-to-Fiat Conversions

TLDR Mercuryo has partnered with Visa to offer near real-time crypto-to-fiat conversions through Visa Direct. The integration enables users to off-ramp cryptocurrency
Share
Coincentral2026/01/23 20:10
Vitalik Buterin lays out new Ethereum roadmap at EDCON

Vitalik Buterin lays out new Ethereum roadmap at EDCON

The post Vitalik Buterin lays out new Ethereum roadmap at EDCON appeared on BitcoinEthereumNews.com. At EDCON 2025 in Osaka, Ethereum co-founder Vitalik Buterin delivered fresh details of Ethereum’s technical roadmap, delineating both short-term scaling goals and longer-term protocol transformations. The immediate priority, according to slides from the presentation, is scaling at the L1 level by raising the gas limit while maintaining decentralization. Tools such as block-level access lists, ZK-EVMs, gas repricing, and slot optimization were highlighted as means to improve throughput and efficiency. A central theme of the presentation was privacy, divided into protections for on-chain “writes” (transactions, voting, DeFi operations) and “reads” (retrieving blockchain state). Write privacy could be achieved through client-side zero-knowledge proofs, encrypted voting, and mixnet-based transaction relays. Read privacy efforts include trusted execution environments, private information retrieval techniques, dummy queries to obscure access patterns, and partial state nodes that reveal only necessary data. These measures aim to reduce information leakage across both ends of user interaction. In the medium term, Ethereum’s focus shifts to cross-Layer-2 interoperability. Vitalik described trustless L2 asset transfers, proof aggregation, and faster settlement mechanisms as key milestones toward a seamless rollup ecosystem. Faster slots and stronger finality, supported by techniques like erasure coding and three-stage finalization (3SF), are also in scope to enhance responsiveness and security. The roadmap also includes Stage 2 rollup advancements to strengthen verification efficiency, alongside a call for broader community participation to help build and maintain these improvements. The long-term “Lean Ethereum” blueprint emphasizes security, simplicity and optimization, with ambitions for quantum-resistant cryptography, formal verification of the protocol, and adoption of ideal primitives for hashing, signatures, and zero-knowledge proofs. Buterin stressed that these improvements are not just for scalability but to make Ethereum a stable, trustworthy foundation for the broader decentralized ecosystem. This is a developing story. This article was generated with the assistance of AI and reviewed by editor Jeffrey Albus before publication.…
Share
BitcoinEthereumNews2025/09/18 03:22