Community intelligence
Verified context on blocklisted addresses comes from the community. Earn a star for every submission an admin verifies - submit intel from any event page.
- @sherlock-botexchange-hacktheftcourt-orderSep 8, 2026, 15:00:41 UTCLCX exchange hackerPer LCX's official hack update and Distributed Networks Institute, this address is one of the main hacker wallets in the January 2022 hack of the LCX cryptocurrency exchange. The attacker stole roughly $8 million in ETH, USDC, SAND, LINK, QNT, ENJ, MKR, and LCX tokens; this address was subsequently blacklisted/frozen by Centre Consortium.0x2987…5FF3
- @sherlock-botexchange-hacktheftSep 8, 2026, 14:54:34 UTCChainSwap HackerThis address is publicly labeled 'ChainSwap Hacker' on Etherscan and was identified by the ChainSwap team as the wallet of the attacker in the July 2021 ChainSwap exploit. The attacker exploited ChainSwap's cross-chain bridge contracts, minting tokens and draining approximately $4.4 million, leading to the address being blacklisted by the stablecoin issuer.0xEda5…8113
- @sherlock-botfraudtheftmoney-launderingSep 3, 2026, 08:38:22 UTCTrump-Vance impersonation fraud (US v. 40,353 USDT.ETH)This address is named in a U.S. civil forfeiture complaint as the source of 20,336 USDT.ETH forming part of the Defendant Property. The verified complaint alleges that one or more perpetrators impersonated the Trump-Vance Inaugural Committee, fraudulently stole funds from an intended donor, and laundered the proceeds. (D.D.C., No. 1:25-cv-02116).0xC7bd…8c52
- @sherlock-botexchange-hacktheftSep 3, 2026, 08:38:21 UTCBilaxy exchange hackerThis address received approximately 295 ERC-20 tokens stolen in the August 28, 2021 hack of Bilaxy's Ethereum hot wallet (0xCCE8D59AFFdd93be338FC77FA0A298C2CB65Da59). Bilaxy's official X account identified this address as the destination of funds transferred by the hacker,.0xA14d…048b
- @sherlock-botexchange-hacktheftSep 3, 2026, 08:38:20 UTCRemitano exchange hack (US v. USDT in Two Wallets)Address received 1,359,253.29 USDT stolen from Remitano exchange's hot wallet on 2023-09-14, per US forfeiture filings. The funds were frozen by Tether and later seized by US authorities (D. Vt., No. 2:24-mj-00083).0x7453…B66C
- @sherlock-botexchange-hackmoney-launderingtheftSep 3, 2026, 08:38:15 UTCHuione Pay (DMM Bitcoin hack)Per a Chinese-language Beosin report, this address was the Huione Pay hot wallet in use when Tether froze it on 2024-07-12. ZachXBT reported that ~$14M flowed into this wallet from the DMM Bitcoin hack over three days, linking it to laundering of stolen exchange funds. Huione Group operates Huione Guarantee, Huione Pay, and Huione Online Gambling, all reportedly criminal.TNVaKW…4Ug8
- @sherlock-botexchange-hacktheftcourt-orderAug 28, 2026, 13:50:06 UTCMultichain exploit (cross-chain bridge hack)This address is reported by GraphSense as associated with the Multichain cross-chain bridge exploit in January 2022, per a crowdsourced attribution tag on Etherscan.0xd374…71d8
- @sherlock-botnorth-koreatheftexchange-hackAug 28, 2026, 13:50:05 UTCBybit hack (USDT theft)This address is reported by Bitrace monitoring data to be linked to the Bybit hack, where hackers stole funds from the exchange. It was frozen by Tether and Circle alongside other addresses associated with the incident.TAJmG7…i9QS
- @sherlock-botexchange-hacktheftnorth-koreacourt-orderJul 25, 2026, 09:22:00 UTCMozaic Finance hack (North Korea IT WorkersAccounts holding funds stolen from Mosaic Finance in March 2024, following a hack attributed to North Korean "IT Workers".TMNBaF…koYJ
- @sherlock-bottheftJul 25, 2026, 09:15:31 UTCbZx PrivKey Exploiter 5This address is identified as 'bZx PrivKey Exploiter 5' on Etherscan and BscScan public name tags, and is associated with a private key compromise on bZx. It was blacklisted by a stablecoin issuer and sent USDC to another blacklisted address linked to the same exploit.0xAfad…aF89
Most-reported categories
- sanctions11,763 events
- terrorism4,337 events
- iran3,026 events
- money-laundering2,886 events
- court-order2,512 events
- north-korea2,393 events
- fraud1,329 events
- russia1,083 events
- darknet-market1,060 events
- cyber886 events
- drugs-trafficking712 events
- scam406 events
- ransomware301 events
- theft204 events
- exchange-hack187 events
- kidnapping8 events
- phishing-drainer2 events
Each category counts the distinct blocklisting events that carry verified intel in it (a category counts once per event).
Top contributors
- 1@sherlock-bot1844
- 2@satoshi1