Blockchain detective: 3 real wallets — from Vitalik to the Lazarus hackers

2026-07-23 · AMLConsensus Blog

Blockchain detective: 3 real wallets — from Vitalik to the Lazarus hackers

The blockchain is public: every transfer is visible forever, and every address has a history. The problem is you can't read that history by eye — 40 characters like 0x996f4d… tell you nothing. But an AML check turns those characters into a dossier.

We took three real addresses and ran them through @amlconsensus_bot. Nothing invented — only what the blockchain actually shows. Let's go.

Wallet #1: "clean" — but what does that mean?

Address: 0xd8dA6BF26964aF9D7eEd9e03E95415023B0f24f5. This is the public wallet of Vitalik Buterin, Ethereum co-founder. The check:

Low risk — 12/100
• OFAC SDN — clean
• Tether/Circle blacklists — clean
• TRM Labs — no sanctions
• MistTrack — score 12, no flags

All sources agree: the address is safe. That's exactly how a wallet you can accept a transfer from should look. But "clean today" isn't "clean forever" — which is why the next example matters.

Wallet #2: an exchange deposit — and here it gets interesting

Address: 0x3d76e5229558b8f0e9a1140e29b29aad8ed4646a. At first glance, an ordinary address. The AML check immediately tells you whose it is:

Attribution: deposit address of the Bitget exchange (exchange, deposit)

Already useful: you know you'd be sending money straight to the counterparty's exchange account. But the real value is the "Counterparties" button. Here's who this address dealt with on Ethereum:

Counterparties (share of volume):
• Bitget — 50%
Rapira — 50% UK sanctions (2026)

That's a flag. Half the address's volume ran through Rapira, a Russian exchange under UK sanctions. On BNB Chain the same address had more counterparties, including HTX (also UK-sanctioned — other platforms flag inbound transfers from it).

The address itself isn't formally on any sanctions list. But the money on it is mixed with flows from sanctioned platforms — and that's exactly what gets deposits frozen. Would you accept such a transfer blind? Most P2P bots would just show "15% risk" and say nothing about Rapira.

Wallet #3: money you don't touch

Address: 0x098B716B8Aaf21512996dC57EB0615e2383E2f96. The check turns red instantly:

High risk — 100/100
Attribution: Ronin Bridge Exploiter
OFAC SDN — address on the US sanctions list
Chainalysis — Lazarus Group

This is one of the wallets the Lazarus Group (North Korea) used to move the $625M stolen in the 2022 Ronin bridge hack — the largest crypto hack in history. The counterparty breakdown shows where the money went:

Where the money went:
• Unknown — 52%
• Axie Infinity — 47.8%
• FixedFloat, Binance — fractions of a percent

Accept even a cent from such an address and you don't get "risk" — you get sanctioned funds and an almost guaranteed freeze on any exchange in the world. This isn't a heuristic, it's a fact: the address is on the official OFAC list.

What this means for your P2P deal

Three wallets — three completely different stories, and you couldn't tell them apart by eye. The takeaway:

The main point: "one risk number" hides the story. The real value is in the details: whose address it is, who it dealt with, whether there's a sanctioned trail. That's what separates a check you can trust from a pretty picture with a percentage.

All three checks in this article were done in seconds right inside the bot. Paste your counterparty's address and you'll see the same dossier for your deal.

Check your counterparty right now

Consensus of 4 sources · verdict across 17 chains · connection graph & full audit across 35+ networks · PDF with QR verification

Open @amlconsensus_bot — 1 free check