📈 Get daily crypto insights that make you smarter about your money

Social Engineering Attack Drains 3,520 BTC Worth $330.7 Million in Fifth-Largest Crypto Heist

On April 28, 2025, blockchain investigator ZachXBT flagged a suspicious transfer of 3,520 Bitcoin, valued at approximately $330.7 million, marking the fifth-largest cryptocurrency theft in history. Unlike most headline-grabbing crypto heists that exploit smart contract vulnerabilities or compromised private keys, this attack relied entirely on psychological manipulation — a sophisticated social engineering campaign that preyed on an elderly American investor who had held over 3,000 BTC since 2017.

The Exploit Mechanics

The attackers employed a multi-layered social engineering strategy that unfolded over an extended period. Posing as trusted entities — potentially law enforcement or technical support representatives — the scammers slowly built credibility with the victim through repeated phone interactions. They leveraged classic manipulation tactics: asserting false authority, manufacturing urgency around fabricated account issues, and exploiting the natural instinct to comply with perceived institutional figures.

The victim, who had no previous record of substantial on-chain transactions, was ultimately persuaded to share sensitive wallet credentials during one of these interactions. Once access was granted, the attackers swiftly transferred 3,520 BTC in a single movement, converting the stolen funds through a carefully pre-planned laundering pipeline.

Affected Systems

The laundering operation was remarkably sophisticated and premeditated. The attackers used pre-registered accounts across more than six instant exchanges and over-the-counter desks, suggesting the infrastructure was in place well before the theft. The stolen Bitcoin was processed through a peel chain method — splitting large amounts into smaller, harder-to-trace portions routed through hundreds of wallets.

A significant portion of the BTC was quickly converted into Monero (XMR), the privacy-focused cryptocurrency with untraceable architecture. This conversion caused XMR to surge roughly 50% to approximately $339 within hours. Some Bitcoin was also bridged to Ethereum and deposited into various DeFi protocols, adding layers of obfuscation to the forensic trail. Blockchain analytics firm Hacken traced $284 million of the stolen BTC, though by that point it had been diluted to approximately $60 million after extensive peeling through obscure platforms.

The Mitigation Strategy

Response efforts were swift but limited in their effectiveness given the attackers’ preparation. ZachXBT and Binance collaborated to freeze approximately $7 million of the stolen funds — a fraction of the total loss. Multiple exchanges were notified in real-time, and investigators worked to identify the perpetrators. Analysts ruled out involvement from North Korea’s Lazarus Group, instead pointing to skilled independent hackers. Two suspects emerged from the investigation: an individual using the alias “X,” allegedly operating from the United Kingdom and believed to be of Somali origin, and an accomplice known as “W0rk.” Both reportedly scrubbed their digital footprints shortly after the theft.

Lessons Learned

This incident delivers a sobering reminder that the most robust technical security measures can be rendered useless by human vulnerability. The victim’s long-term holding pattern — accumulating BTC since 2017 without active trading — may have made them particularly susceptible to sophisticated manipulation. The crypto industry must recognize that social engineering attacks represent a threat vector equal in severity to smart contract exploits and exchange breaches.

At the time of the attack, Bitcoin traded at approximately $94,978 while Ethereum held at $1,798, according to CoinMarketCap data. The broader market context — with April 2025 recording $5.9 billion in total crypto losses across 10 incidents according to DeFi’s REKT database — underscores that security threats continue to evolve faster than defensive measures.

User Action Required

Crypto holders should immediately review their operational security practices. Never share wallet credentials, seed phrases, or private keys with anyone — regardless of their claimed authority. Enable multi-signature authentication on significant holdings, consider using hardware wallets with passphrase protection, and verify any unusual requests through independent channels. If someone contacts you claiming to represent an exchange, wallet provider, or law enforcement, hang up and contact the organization directly through verified channels. The $330.7 million lost in this attack was not a failure of blockchain technology — it was a failure of human defenses.

Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always conduct your own research and consult qualified professionals.

🌱 FOR BUSINESSES BitcoinsNews.com
Reach 100K+ Crypto Readers
Sponsored content, press releases, banner ads, and newsletter placements. Put your brand in front of Bitcoin's most engaged audience.

26 thoughts on “Social Engineering Attack Drains 3,520 BTC Worth $330.7 Million in Fifth-Largest Crypto Heist”

  1. social_eng_skep_

    3520 BTC stolen from someone who held since 2017 and never made a large tx. the scammers did months of phone calls building trust. terrifying

    1. social_eng_skep_ the 5th largest crypto heist ever and no smart contract involved. humans are always the weakest link

    1. Aleksandra Petrov

      the multi week grooming process is what makes this so hard to prevent. no single red flag, just a slowly building relationship. your bank would flag a large transfer but crypto has no such circuit breaker

  2. posing as law enforcement to get an elderly persons wallet credentials. lowest of the low. but it worked because crypto has no fraud department

  3. seedphrase_er

    banks have wire transfer limits and waiting periods for exactly this scenario. crypto has nothing. your grandma could send her life savings to a stranger and the network just says confirmed

    1. 330M stolen through phone calls. no smart contract exploit, no key compromise, just talking to someone for weeks until they handed over credentials. social engineering is the meta

      1. whale_watch_ the worst part is the attacker probably found the wallet through public records or data brokers. chain analysis isnt the issue here, its off-chain doxxing

      2. posing as law enforcement over weeks of calls is brutal. no hardware wallet helps when the owner voluntarily hands over the seed phrase

      3. whale_watch_ 330M through phone calls over weeks. no exploit, no key compromise. the attacker just talked to the guy until he gave up his seed. hardware wallets dont fix human trust

  4. noor_hashimi

    3000+ BTC since 2017 and zero on-chain history. these scammers specifically target dormant wallets because they know the holder isnt crypto native

    1. grim_accountant

      an elderly holder since 2017 with 3000+ BTC and zero on-chain history. exactly the profile these attackers profile for. patient, isolated, trusting of authority figures

  5. social_engine_

    ZachXBT flagged it but the BTC was already moving by then. 3520 BTC through a series of rapid transfers. once the credentials were shared the attacker moved faster than any monitoring could catch

  6. 3000+ BTC held since 2017 with zero on-chain history. scammers specifically profile dormant early holders because they know the person isnt checking crypto twitter daily. patient evil

    1. circuit_breaker_

      Preda M. exactly this. dormant wallets are the perfect target. no chain activity means no behavioral baseline for fraud detection to flag

  7. 3520 BTC from one elderly person through phone calls alone. no smart contract exploit, no key theft, just social engineering. humans are always the weakest link

  8. callback_nobody_

    posing as law enforcement for weeks of calls until the victim hands over their seed phrase. no exploit needed when social engineering bypasses every technical control

    1. cold_wallet_grandma_

      callback_nobody_ the worst part is a simple time lock or multisig on wallets above 100 BTC would stop most of these attacks. nobody sets that up until its too late

    2. callback_nobody_ a simple 24 hour time lock on wallets holding over 100 BTC would have saved this person. the tech exists nobody uses it because convenience wins over security every time

  9. chain_halt_proposal_

    330M gone through phone calls alone. banks have waiting periods for wire transfers above 10k but crypto lets you drain 300M with zero friction. the gap is regulatory not technical

    1. wire_delay_kep_

      chain_halt_proposal_ banks have 3 day waiting periods on wires above 50k but crypto lets you move 330M in one tx. the regulatory gap isnt accidental its the product

  10. cold_call_reaper_

    data brokers selling wallet mappings to scammers is the unreported story here. these crews know exactly who holds what and target accordingly

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$77,386.00+0.3%ETH$2,537.51+3.1%SOL$102.98+3.0%BNB$727.19+1.9%XRP$1.37+0.9%ADA$0.2072-0.6%DOGE$0.0846+0.6%DOT$1.05-6.0%AVAX$7.49-1.3%LINK$11.63+0.6%UNI$6.09+0.8%ATOM$1.65-8.5%LTC$53.49+2.2%ARB$0.1411-4.2%NEAR$2.50-0.7%FIL$0.7831-1.8%SUI$0.7314-1.1%BTC$77,386.00+0.3%ETH$2,537.51+3.1%SOL$102.98+3.0%BNB$727.19+1.9%XRP$1.37+0.9%ADA$0.2072-0.6%DOGE$0.0846+0.6%DOT$1.05-6.0%AVAX$7.49-1.3%LINK$11.63+0.6%UNI$6.09+0.8%ATOM$1.65-8.5%LTC$53.49+2.2%ARB$0.1411-4.2%NEAR$2.50-0.7%FIL$0.7831-1.8%SUI$0.7314-1.1%
Scroll to Top