Skip to main content
Sign in
AVOID.NET

Entity Graph

Browse extracted entities, relationships, and potential duplicates.

Total entities
22,461
Relationships
17,889
Potential duplicates
0

Entities

Bybit publicly announces the civil lawsuit and preliminary injunction. Reports $48.4 million recovered and $30.5 million frozen across 28+ exchanges -- approximately 5.26% of stolen funds. Case described as a landmark first in crypto civil litigation against a nation-state.(2026-08-07:bybit-v-dprk-lazarus-group-1-5b-hack-civil-lawsuit-august-2026)event
95db8080
U.S. District Court for the District of Columbia grants partial preliminary injunction prohibiting transfer or dissipation of identified stolen assets held by John Doe defendants; court finds Bybit 'demonstrated a likelihood of success on the merits.'(2026-07-30:bybit-v-dprk-lazarus-group-1-5b-hack-civil-lawsuit-august-2026)event
f8e6da20
Bybit files civil lawsuit under seal in U.S. District Court for the District of Columbia naming DPRK, RGB, and Lazarus Group as defendants; court grants a temporary restraining order (TRO) the same day.(2026-06-18:bybit-v-dprk-lazarus-group-1-5b-hack-civil-lawsuit-august-2026)event
78f21851
Swiss and German authorities dismantle Cryptomixer.io following coordinated actions in Zurich, seizing approximately 25 million euros in Bitcoin. Cryptomixer was linked to laundering proceeds from the Bybit hack.(2025-11-28:bybit-v-dprk-lazarus-group-1-5b-hack-civil-lawsuit-august-2026)event
ed42312f
German federal authorities (BKA) and Frankfurt's Public Prosecutor's Office shut down cryptocurrency mixer eXch, seizing approximately $38.2 million and 8+ terabytes of data. Elliptic estimates more than $200 million in Bybit stolen funds were laundered through eXch.(2025-04-30:bybit-v-dprk-lazarus-group-1-5b-hack-civil-lawsuit-august-2026)event
311f4c7d
FBI issues public advisory (IC3 PSA250226) attributing the theft to TraderTraitor (Lazarus Group), listing 50 Ethereum wallet addresses and requesting assistance from exchanges and analytics firms to block transactions.(2025-02-26:bybit-v-dprk-lazarus-group-1-5b-hack-civil-lawsuit-august-2026)event
93579d0d
Approximately $1.5 billion in Ethereum and stETH stolen from Bybit cold wallet at approximately 14:13 UTC during a routine transfer, in what becomes the largest recorded cryptocurrency theft in history.(2025-02-21:bybit-v-dprk-lazarus-group-1-5b-hack-civil-lawsuit-august-2026)event
d65298bb
Malicious JavaScript code replaces legitimate Safe{Wallet} app code at 15:29 UTC, targeting Bybit's Ethereum multisig cold wallet, per Verichains forensic analysis.(2025-02-19:bybit-v-dprk-lazarus-group-1-5b-hack-civil-lawsuit-august-2026)event
c8f522ef
Bybit v. DPRK Lazarus Group -- $1.5B Hack Civil Lawsuit (August 2026)token
088b172a
changehero.iodomain
e2e83e0b
7feaffbf
Coinsbuy replenished drained wallets to within 0.05% of pre-attack balances; BlockWatchdog interpreted this as evidence the attack exploited a withdrawal system weakness rather than compromised private keys.(2026-08-10:bridgers-cross-chain-swap)event
cc06ca85
Approximately $6.34 million (79% of stolen funds) routed through FixedFloat via roughly 50 single-use addresses. Additional 150 ETH moved through ChangeNOW, which froze a six-figure sum after being contacted by Specter Investigations.(2026-08-09:bridgers-cross-chain-swap)event
6dedff58
SWFT Blockchain, operator of Bridgers, founded in Silicon Valley. Backed by investors including Draper Dragon and Node Capital.(2017-01-01:bridgers-cross-chain-swap)event
ea084e63
Bridgers Cross-Chain Swapprotocol
cb9c9cdc
Malwarebytes threat researcher Stefan Dasic publishes a report on the active fake AML checker campaign, documenting AMLBot impersonation, 'AML Check' generic branding, fake progress indicators, fabricated scan results, small upfront verification fees, and wallet drainer mechanics. Report corroborated same day by Decrypt, Security Boulevard, Cryptopolitan, and Coin-Turk.(2026-08-19:fake-crypto-aml-checker-infrastructure)event
893d27b0
PCrisk updates its second removal guide, confirming the second domain cluster remains active.(2026-06-02:fake-crypto-aml-checker-infrastructure)event
5bf94c96
AMLBot updates its official warning blog post, indicating the impersonation campaign has persisted for at least seven months.(2025-11-10:fake-crypto-aml-checker-infrastructure)event
ce1852e2
PCrisk publishes second removal guide documenting a distinct cluster of fake AMLBot domains including amlbotchecking[.]com, aml-bot.co[.]com, aml-safety[.]one, amlnix[.]com, and amlbot[.]club, with IP 104.21.15.211.(2025-06-26:fake-crypto-aml-checker-infrastructure)event
d59dc132
PCrisk publishes removal guide for fake AMLBot website scam, identifying domains including amlbot.seize[.]report, amlbot[.]sale, amlbotchecks[.]com, and aml-safety[.]app, with IP 104.26.9.244.(2025-03-26:fake-crypto-aml-checker-infrastructure)event
a495b4b6
AMLBot publishes initial warning on its official blog about fraudulent sites and Telegram accounts impersonating its brand, requesting wallet access and upfront payments.(2025-04-16:fake-crypto-aml-checker-infrastructure)event
8f60c8b1
Fake Crypto AML Checker Infrastructureorganization
c974cf95
bittime.comdomain
d03fd3aa
bybit.comdomain
264b2c10
Step App permanently terminates all services. FITFI market cap at approximately $12,229. Roughly 63,850 token holders left with near-worthless positions.(2026-08-21:step-app-fitfi)event
1743c89e
Bithumb suspends FITFI trading; withdrawals to end September 18, 2026.(2026-08-18:step-app-fitfi)event
0b2207aa
Step App announces permanent shutdown via X, setting August 21, 2026 as the final operational date. FITFI crashes approximately 88% within 24 hours of the announcement.(2026-08-06:step-app-fitfi)event
4f8e5403
KuCoin delists FITFI with a withdrawal deadline of August 31, 2026.(2026-07-30:step-app-fitfi)event
276e558d
South Korean exchanges Upbit and Bithumb announce plans to end FITFI trading support.(2026-07-16:step-app-fitfi)event
d5856050
Bybit delists the FITFI/USDT spot trading pair, citing thin liquidity and low volume.(2026-04-01:step-app-fitfi)event
19601987
Step App records over 1 million downloads, reaching peak user base.(2022-10-01:step-app-fitfi)event
65a3e3de
Step App launches in Japan with Usain Bolt as global brand ambassador.(2022-07-01:step-app-fitfi)event
ddf28f40
FITFI reaches its all-time high of approximately $0.73, representing roughly a 148x return from IDO price.(2022-05-05:step-app-fitfi)event
eb08ad6b
FITFI IDO opens on DAO Maker at $0.0049 per token, raising a reported $3.43 million over the April 11–21 sale period.(2022-04-11:step-app-fitfi)event
f96bfee6
Step App (FITFI)protocol
e3950e81
sandboxgame.medium.comdomain
d9b5899c
Coinbase scheduled to delist SAND perpetual futures contracts, announced in connection with the exploit period.(2026-08-26:the-sandbox-sand)event
c0516626
Minting activity ceases at approximately 04:45:21 UTC after 329.24 trillion SAND minted across 703 events over five hours. Approximately 14.75 million SAND (~80 ETH, ~$675,000) drained from the Ethereum OFT Adapter in six transactions within 24 seconds. The Sandbox multisig zeros out LayerZero trusted peer settings at approximately 05:09:19 UTC, containing the exploit. Blockaid and PeckShield flag the incident publicly. The Sandbox disables bridging on Base and BNB Smart Chain and issues public disclosure. Upbit and Bithumb suspend SAND deposits and withdrawals.(2026-08-22:the-sandbox-sand)event
79c2cb93
SAND bridge exploit begins at approximately 23:42:05 UTC. Attacker exploits approveAndCall function on The Sandbox's SAND OFT contract on Base, hijacking LayerZero delegate permissions and initiating unauthorized minting.(2026-08-21:the-sandbox-sand)event
82d8e78b
KelpDAO rsETH OFT bridge exploited for approximately $292 million via forged LayerZero cross-chain message; LayerZero Labs later acknowledges it made a mistake. First major LayerZero OFT exploit of 2026.(2026-04-18:the-sandbox-sand)event
a647e71a
The Sandbox announces restructuring: over 50% of approximately 250 staff laid off, multiple offices closed, co-founders removed from executive roles, Animoca Brands CEO Robby Yung installed as CEO.(2025-08-28:the-sandbox-sand)event
dba20ab6
Unauthorized party gains access to an employee computer, obtaining user email addresses and sending phishing emails with malware links. The Sandbox discloses incident and implements response measures.(2023-02-26:the-sandbox-sand)event
f83794d6
SAND reaches all-time high price during metaverse investment cycle; first play-to-earn event hosted. Platform sells approximately $350 million in virtual LAND NFTs over subsequent months.(2021-11-01:the-sandbox-sand)event
5472a7c3
Animoca Brands acquires Pixowl, including The Sandbox IP; project transitions to blockchain-based 3D metaverse with SAND token.(2018-08-01:the-sandbox-sand)event
f8dd7112
Pixowl founded by Arthur Madrid and Sebastien Borget; original 2D Sandbox mobile game created.(2011-05-01:the-sandbox-sand)event
f49ec420
The Sandbox (SAND)organization
9abc7dbd
BounceBit announced the permanent shutdown of BounceBit Chain and confirmed BB will be reissued as a BEP-20 token on BNB Chain using balances from the pre-attack snapshot at block 20,697,260. The team cited the discontinued Evmos framework as making a rebuild infeasible.(2026-08-21:bouncebit)event
753b8234
BB token hit a record low of approximately $0.0079 following the exploit announcement.(2026-08-20:bouncebit)event
75e5674d
At 21:02:35 UTC, the first unauthorized transfer began. An attacker exploited an authorization flaw in BounceBit's Evmos-based vesting account module. Chain state at block 20,697,260 was later designated as the pre-attack snapshot for the BNB Chain reissuance.(2026-08-19:bouncebit)event
3464517b
Data refreshes every 5 minutes · All metrics derived from Supabase