Case studies
CredScore scores behavior, not labels. The same wallet, on the same chain, produces the same verdict every time, and the verdict reflects what the wallet did, not whether the actor later did the right thing. The case studies below test that design choice on real attacker wallets.
ZachXBT publicly named this Ethereum address in May 2026 as part of an alleged $19M social-engineering theft operation. Zero sanctions exposure, 100% mainstream attribution (Metamask Swaps, Uniswap V3 Router, WETH Token). CredScore now flags it Medium Risk, Review, on the new DEX-routed pass-through pattern shipped the same day.
Read the case study →In March 2023, an attacker drained $197M from Euler Finance, apologized on-chain, and returned most of the funds within thirty days. Fifteen months dormant, the wallet still scores High Risk, Escalate, at 72% confidence. CredScore also surfaces one historical interaction with a Lazarus Group-sanctioned address. Behavior doesn't unhappen.
Read the case study →An attacker drained $36M from Humanity Protocol on June 8, 2026 after stealing seven private keys from a developer laptop. The primary destination wallet, eight days old, ran through CredScore with no sanctions data and no entity attribution and returned High Risk, Escalate, on behavior alone.
Read the case study →Drift Protocol publicly named four Ethereum wallets holding the proceeds of the $286M April 2026 exploit. With no sanctions data and no entity attribution, CredScore returned the same verdict on all four: High Risk, Escalate, on behavior alone.
Read the case study →The largest crypto hack in history, analyzed wallet by wallet. How CredScore's deterministic engine flags the Bybit exploiter address, traces the Lazarus laundering path, and produces an audit-ready briefing in under 15 seconds.
Read the case study →The best way to evaluate a deterministic risk engine is to point it at a wallet whose risk profile you already know and see whether the verdict matches your read. One free analysis, no signup. If a publicly known attacker, mixer-funded wallet, or exploit address you want analyzed in a future case study comes to mind, email wade@credscore.us and we will consider it.