Case studies

CredScore scores behavior, not labels. The same wallet, on the same chain, produces the same verdict every time, and the verdict reflects what the wallet did, not whether the actor later did the right thing. The case studies below test that design choice on real attacker wallets.

Each study runs an actual attacker wallet through the engine and publishes the unedited structured output. Same engine paying analysts use on the desk. No marketing claims, no narrative shaping. Read the methodology →
Pig butchering / DEX launderingLoss $19M alleged2026-06-20
Pig-Butchering Wallet: Catching the DEX-Routed Pass-Through Shape Sanctions Lists Miss

ZachXBT publicly named this Ethereum address in May 2026 as part of an alleged $19M social-engineering theft operation. Zero sanctions exposure, 100% mainstream attribution (Metamask Swaps, Uniswap V3 Router, WETH Token). CredScore now flags it Medium Risk, Review, on the new DEX-routed pass-through pattern shipped the same day.

Read the case study →
Behavior over labelsLoss $197M2026-06-20
Euler Finance Hack: Score 12, Escalate, Three Years After the Funds Were Returned

In March 2023, an attacker drained $197M from Euler Finance, apologized on-chain, and returned most of the funds within thirty days. Fifteen months dormant, the wallet still scores High Risk, Escalate, at 72% confidence. CredScore also surfaces one historical interaction with a Lazarus Group-sanctioned address. Behavior doesn't unhappen.

Read the case study →
Behavioral / Pump SignatureLoss $36M2026-06-16
Humanity Protocol Hack: Exploiter Wallet Flagged on Behavior Alone

An attacker drained $36M from Humanity Protocol on June 8, 2026 after stealing seven private keys from a developer laptop. The primary destination wallet, eight days old, ran through CredScore with no sanctions data and no entity attribution and returned High Risk, Escalate, on behavior alone.

Read the case study →
DPRK / BehavioralLoss $286M2026-05-22
Drift Hack: Four DPRK Wallets, Flagged on Behavior Alone

Drift Protocol publicly named four Ethereum wallets holding the proceeds of the $286M April 2026 exploit. With no sanctions data and no entity attribution, CredScore returned the same verdict on all four: High Risk, Escalate, on behavior alone.

Read the case study →
DPRK / SanctionsLoss $1.5B2026-04-18
Bybit Hack: Scoring the Lazarus Wallet Tree

The largest crypto hack in history, analyzed wallet by wallet. How CredScore's deterministic engine flags the Bybit exploiter address, traces the Lazarus laundering path, and produces an audit-ready briefing in under 15 seconds.

Read the case study →
Run your own wallet through the engine

The best way to evaluate a deterministic risk engine is to point it at a wallet whose risk profile you already know and see whether the verdict matches your read. One free analysis, no signup. If a publicly known attacker, mixer-funded wallet, or exploit address you want analyzed in a future case study comes to mind, email wade@credscore.us and we will consider it.

Try CredScore freeHow the engine works