After extensive investigations by blockchain investigators, the digital asset industry learned over the weekend about one of the largest thefts involving an individual ever recorded in history (January 10th, 2026 around 11:00 PM UTC) when a wealthy investor had their funds stolen in less than an hour. By focusing on exploiting the human factor rather than inherent software vulnerabilities, the hacker bypassed high tech cryptography safeguards through the use of social engineering techniques. The investor suffered the loss of 205,000 Litecoin (LTC) and 1,459 Bitcoin (BTC) as a result of this attack.
According to blockchain investigator ZachXBT, an identity thief was posing as a Trezor support agent, and the identity thief was able to convince the investor to provide them with their seed phrase. This is an example of the changing tactics of cybercriminals. Instead of relying on breaching a computer system, they are focusing on tricking people into giving them access to their resources (the keys to their futures).
The “Trezor Support” Trap
The heist did not involve the complex hacking of either the Bitcoin Blockchain or via brute force the hardware wallet itself. Instead it was done by way of an old-school, yet quite effective, social engineering scheme. It was determined by the security company, ZeroShadow, that the user had been fooled into communicating with a “Trezor Value Wallet” support scammer. During this interaction the scammer was able to convince the victim to provide them with their 24-word seed phrase which is the master key that provides complete access to a crypto wallet. After receiving this information, the hardware wallet was no longer secure. The scammer then had remote access to all of the victim’s addresses as well as their assets.
Anatomy of the Launder: The THORChain Connection
The criminals quickly acted after accessing the wallet with the stolen cryptocurrency, beginning to enact their complex plan of laundering the currency to ensure the blockchain tracing would be more difficult.
The thief utilised decentralised infrastructures rather than moving stolen funds to centralised exchanges with “know your customer” (KYC) verification requirements. Much of the stolen Bitcoin was transferred from Bitcoin to Ethereum, Ripple, and Litecoin networks using THORChain, a decentralised liquidity protocol allowing cross-chain swaps without intermediaries. While the THORChain has advantages for legitimate users, it can also be a tool for criminals who seek anonymity while committing crimes.
Market Shockwaves: The Monero Spike
The second half of the getaway was marked by an increase in swapping Monero (XMR) aggressively; this cryptocurrency has been developed for those who wish to maintain their anonymity while making online payments through the use of a privacy coin. Instant exchange services allowed attackers to convert all stolen Bitcoin and Litecoin into Monero.
The size of these swaps created significant disruption in the marketplace. Generally, Monero has less liquidity than Bitcoin; as a result, there was a tremendous amount of buy pressure for Monero that created a spike in its value. Traders who monitored charts for investments were shocked at the way Monero jumped before they figured out it was the result of a massive robbery that was taking place.
A Glimmer of Hope: $700K Frozen
While the vast majority of the funds appear to be lost, quick action by security teams yielded a small victory. ZeroShadow stated in a LinkedIn post that their blockchain monitoring tools flagged the illicit flow in real time.
By partnering up with their compliance departments they were able to track down some of the money before it was completely laundered. In this instance they managed to freeze approx $700K in assets which helped stop the attacker from completing the very last part of laundering that particular batch of funds. Though this amount is a very small percentage of the total lost (less than 0.3%) it is an important lead for law enforcement and also shows the increasing capabilities of on-chain response teams.
A Recurring Nightmare
This incident has similarities to another case of a theft that happened just last year. In 2025, an elderly U.S. citizen lost $330 million worth of Bitcoin as a result of a social engineering scheme that was similar to this incident. In that case, the victim had held over 3,000 BTC dormant since 2017, only to lose it all after being manipulated by scammers.
ZachXBT noted that despite the scale and efficiency of the Jan. 10 attack, there is no evidence currently linking it to state-sponsored groups like North Korea’s Lazarus Group. “It’s not North Korea,” he wrote, suggesting that highly organized criminal syndicates or even lone-wolf actors are now capable of executing nine-figure heists by exploiting human psychology rather than software bugs.
As the crypto industry matures, the “human firewall” remains its most vulnerable point. Security experts continue to warn that no amount of hardware encryption can protect users who are tricked into voluntarily sharing their private keys.




