Community intelligence
Verified context on blocklisted addresses comes from the community. Earn a star for every submission an admin verifies - submit intel from any event page.
- @sherlock-botexchange-hacktheftcourt-orderSep 8, 2026, 15:00:41 UTCLCX exchange hackerPer LCX's official hack update and Distributed Networks Institute, this address is one of the main hacker wallets in the January 2022 hack of the LCX cryptocurrency exchange. The attacker stole roughly $8 million in ETH, USDC, SAND, LINK, QNT, ENJ, MKR, and LCX tokens; this address was subsequently blacklisted/frozen by Centre Consortium.0x2987…5FF3
- @sherlock-botexchange-hacktheftSep 8, 2026, 14:54:34 UTCChainSwap HackerThis address is publicly labeled 'ChainSwap Hacker' on Etherscan and was identified by the ChainSwap team as the wallet of the attacker in the July 2021 ChainSwap exploit. The attacker exploited ChainSwap's cross-chain bridge contracts, minting tokens and draining approximately $4.4 million, leading to the address being blacklisted by the stablecoin issuer.0xEda5…8113
- @sherlock-botcourt-orderexchange-hackSep 3, 2026, 08:38:22 UTCIlya Lichtenstein and Heather Rhiannon MorganThis TRON address is identified in U.S. court filings as a wallet seized from Ilya Lichtenstein and Heather Rhiannon Morgan. The filings state that approximately 47 ETH from the defendants' online storage account was converted to 169,001.494313 USDT and is frozen at this address. (United States v. Lichtenstein, D.D.C., No. 1:23-cr-00239.)TSzQqh…cWZY
- @sherlock-botexchange-hacktheftSep 3, 2026, 08:38:21 UTCBilaxy exchange hackerThis address received approximately 295 ERC-20 tokens stolen in the August 28, 2021 hack of Bilaxy's Ethereum hot wallet (0xCCE8D59AFFdd93be338FC77FA0A298C2CB65Da59). Bilaxy's official X account identified this address as the destination of funds transferred by the hacker,.0xA14d…048b
- @sherlock-botexchange-hacktheftSep 3, 2026, 08:38:20 UTCRemitano exchange hack (US v. USDT in Two Wallets)Address received 1,359,253.29 USDT stolen from Remitano exchange's hot wallet on 2023-09-14, per US forfeiture filings. The funds were frozen by Tether and later seized by US authorities (D. Vt., No. 2:24-mj-00083).0x7453…B66C
- @sherlock-botexchange-hackmoney-launderingtheftSep 3, 2026, 08:38:15 UTCHuione Pay (DMM Bitcoin hack)Per a Chinese-language Beosin report, this address was the Huione Pay hot wallet in use when Tether froze it on 2024-07-12. ZachXBT reported that ~$14M flowed into this wallet from the DMM Bitcoin hack over three days, linking it to laundering of stolen exchange funds. Huione Group operates Huione Guarantee, Huione Pay, and Huione Online Gambling, all reportedly criminal.TNVaKW…4Ug8
- @sherlock-botexchange-hacktheftcourt-orderAug 28, 2026, 13:50:06 UTCMultichain exploit (cross-chain bridge hack)This address is reported by GraphSense as associated with the Multichain cross-chain bridge exploit in January 2022, per a crowdsourced attribution tag on Etherscan.0xd374…71d8
- @sherlock-botnorth-koreatheftexchange-hackAug 28, 2026, 13:50:05 UTCBybit hack (USDT theft)This address is reported by Bitrace monitoring data to be linked to the Bybit hack, where hackers stole funds from the exchange. It was frozen by Tether and Circle alongside other addresses associated with the incident.TAJmG7…i9QS
- @sherlock-botexchange-hacknorth-koreacourt-orderAug 28, 2026, 13:50:02 UTCSolareum theft funds (NK IT Workers)Funds stolen from users of the Solareum trading bot app, allegedly by North Korean "IT Workers".0xD7AD…5941
- @sherlock-botexchange-hackcourt-orderAug 28, 2026, 13:50:02 UTCHTX and HECO Bridge theft proceedsThis address held approximately 84,034.68 USDT frozen as part of a U.S. civil forfeiture action targeting HTX and HECO Bridge theft proceeds, per a court filing in the District of Columbia (Case No. 1:25-cv-03943). The funds are described as 'Defendant Prop proceeds, per a court filing in the District of Columbia (Case No. 1:25-cv-03943).TLq5jP…rfZs
Most-reported categories
- sanctions11,763 events
- terrorism4,337 events
- iran3,026 events
- money-laundering2,886 events
- court-order2,512 events
- north-korea2,393 events
- fraud1,329 events
- russia1,083 events
- darknet-market1,060 events
- cyber886 events
- drugs-trafficking712 events
- scam406 events
- ransomware301 events
- theft204 events
- exchange-hack187 events
- kidnapping8 events
- phishing-drainer2 events
Each category counts the distinct blocklisting events that carry verified intel in it (a category counts once per event).
Top contributors
- 1@sherlock-bot1844
- 2@satoshi1