AMLConsensus · course
Programme · Lesson 11.10
Section 11 · Lesson 11.10 · case study

ZachXBT and On-Chain Detectives: How the Community Catches Fraudsters

All the previous case studies share one inconspicuous detail: to unravel a theft, you do not always need a warrant, a subpoena, or access to servers. You need an open blockchain and a person willing to patiently follow the trail. The best symbol of this approach is an anonymous investigator under the handle ZachXBT, who — alone and with the community — helped return hundreds of millions of dollars to victims.

▶ Video case study: on-chain detectives (English narration).

Who is ZachXBT

ZachXBT is an anonymous independent investigator working in the crypto space. He has no police badge and no state powers; his tool is the public data of the blockchain and the ability to read it. Since 2021 his investigations have helped return significant sums to victims: by various estimates — on the order of $500M (Paradigm co-founder Matt Huang cited a figure of more than $350M). Even the lower bound of these estimates is hundreds of millions returned to people through the efforts of, in essence, one person and the community around him.

Why is this even possible? Because the blockchain is public. In traditional finance, to trace a transfer you need access to banking secrecy — and that is granted only to investigators. In crypto the entire ledger of operations is open to everyone. This shifts the balance of power: investigation ceases to be a monopoly of the state and becomes available to anyone with the skill and the persistence.

The method: forensics plus OSINT

The work of an on-chain detective rests on two pillars. The first is blockchain forensics: reading the network itself. Here all the techniques you studied in the course are applied — tracing transactions, clustering addresses (grouping addresses that probably belong to a single owner), analyzing patterns like splitting or transit through a mixer. The second pillar is OSINT, open-source intelligence: matching on-chain traces with what a person leaves "off-chain" — social media posts, handles, domains, metadata, accidental slips.

The magic begins at the junction of these two worlds. The blockchain tells you what the addresses did. OSINT helps understand who stands behind them. Taken separately, each half is incomplete: an address without a name is just a string, and a rumor without on-chain confirmation is just a rumor. But when a chain of transactions matches the publicly known behavior of a specific person or group, a hunch turns into an evidence-based theory.

  1. Fixing the starting point. Identify the theft or scam address — where the victims' funds left from.
  2. Clustering. Gather the linked addresses into a single cluster of wallets controlled by the attacker.
  3. Tracing. Walk through the chain of hops, marking splitting, mixers, cross-chain transitions, and cash-out points.
  4. Stitching to off-chain. Overlay the on-chain picture onto open data (social media, handles, domains) and find the link to real people.
  5. Publication. Make the investigation public — this pressures the platforms, helps freeze funds, and warns other victims.

"It takes not only technology, but also people willing to follow every lead."

— a paraphrase of the idea about the work of on-chain detectives and ZachXBT's role (not a verbatim quote)

This idea (we present it as a paraphrase, not a verbatim quote) precisely describes the essence of the approach. The data lies out in the open, but on its own it reveals nothing — someone has to read it, correlate it, and carry every lead through to the end. Technology provides visibility; the result comes from a person's attention and persistence.

Why this works better than it seems

A skeptic will ask: how does a lone individual outrun attackers with their mixers and cross-chain schemes? The answer lies in the asymmetry of time and memory. The criminal needs the trail to break in at least one place. The investigator needs the trail to survive in at least one place — and it always survives, because the blockchain is immutable. Every attempt to confuse the trail leaves its own trail: transit through a mixer is itself visible, and splitting across thousands of addresses is a recognizable pattern too.

Moreover, the community has a collective memory and collective eyes. What one analyst missed, another notices; what seemed a dead end a year ago gets resolved when a new off-chain lead surfaces. This is exactly how the cases we examined earlier in this section are built: Mt.Gox was unraveled by independent researchers over years, and darknet trails surfaced years after the platforms were shut down. ZachXBT is the same philosophy of patient public tracing, only in real time and with the results published.

Public data turns into recovered funds

Theft / scam  →  On-chain forensics + OSINT  →  Publication of the investigation  →  Freeze / return to victims

What the AML specialist takes from this

The ZachXBT story is not about everyone becoming a famous detective. It is about the fact that the tool is open to everyone, and that the methodology you are learning in this course is the very same one that delivers results at the cutting edge of investigations. When screening a client's wallet, you apply exactly those techniques: you look at the history, cluster linked addresses, track exposure to risky sources, and cross-check with public labels and lists.

The limits of the method: where the on-chain detective ends

An honest analysis requires acknowledging the limits of the approach too. An on-chain investigator can, with high confidence, show the route of the funds and build a well-founded theory of who stands behind it — but he does not replace a court and does not deliver a verdict. The attribution "this address belongs to such-and-such person" is a theory resting on data correlation, and it still has to be confirmed procedurally. Therefore it is important to treat the results of public investigations as a strong working hypothesis and a reason to check, not as a final verdict of guilt.

There is a second limitation too — the risk of mistaken attribution. A coincidence in address behavior or in social media handles can be accidental, and attackers know how to deliberately "plant" someone else's trails to lead an investigation astray. Professional work is distinguished precisely by the fact that a theory is re-verified many times against independent data before it is made public. For the AML specialist this is a direct lesson: any attribution and any label should be treated as a signal of a certain weight, not as absolute truth, and a decision should be backed by several independent sources.

Finally, it is important to understand the division of roles. The investigator's job is to unravel the trail and bring it into the open. The job of platforms, exchanges, and regulators is to freeze the funds and return them to victims. Your job as a screener is not to let a dirty flow through at the entry point. These roles complement each other: a public investigation is useless if no one on the fund-receiving side checks against its conclusions — and conversely, your screening is stronger when it rests on the community's accumulated picture of risky addresses.

What this case teaches. Anyone can trace, given public data — not just state agencies. ZachXBT, an anonymous investigator without powers, helped return on the order of $500M to victims by combining blockchain forensics with OSINT and carrying every lead through to the end. For you this is both inspiration and confirmation: the methods of this course — tracing, clustering, working with labels and exposure — are the real toolkit with which the community catches fraudsters. The open blockchain levels the playing field; the rest is decided by attention and persistence.

The facts are presented from open sources. The materials are for educational purposes.