SECURING CONNECTION
INITIALIZING BLOCKCHAIN ANALYSIS
SITE AVAILABLE TRUE
SECURITY LEVEL SECURE
NETWORK STATUS SECURE

Lazarus High Risk Bybit Hacking Investigation [CLADIOUS-[BYBIT_HACKER_LAZARUS_ITER]-2025-001] - Wallet Analysis Report - Very High Risk - 0x1f09...b4d4

Published 13 Jul 2025 10 views
Wallet Name Analysis Target Wallet (CLADIOUS-[BYBIT_HACKER_LAZARUS_ITER]-2025-001) - 0x1f09...b4d4
Login to view LLM Analysis

Overview

Project Scope

Analysis of wallet 0x1f091649634e8fd9517d67b37ff428a00877b4d4 - Lazarus High Risk Bybit Hacking Investigation

Suspicious Wallet Hash

0x1f091649634e8fd9517d67b37ff428a00877b4d4
This is the primary wallet address being investigated in this report.

Methodology

Research Methodology

Automated Analysis Methodology for Wallet 0x1f091649634e8fd9517d67b37ff428a00877b4d4 1. Data Collection - Automated transaction retrieval from blockchain - Historical transaction pattern analysis - Network connection mapping 2. Analysis Algorithms - Multi-algorithm approach using 41 detection methods - Statistical anomaly detection - Behavioral pattern analysis - Network-based risk assessment 3. Risk Scoring - Weighted risk factor calculation - Multi-dimensional analysis - Historical comparison baseline - Real-time pattern detection 4. Report Generation - Automated findings compilation - Risk level determination - Recommendation synthesis - Compliance-ready documentation

Data Collection

Data Collection Process for 0x1f091649634e8fd9517d67b37ff428a00877b4d4 1. Blockchain Data Retrieval - Retrieved 41 analysis data points - Collected complete transaction history - Gathered network connection data 2. Analysis Processing - Applied multiple detection algorithms - Performed statistical analysis - Generated risk indicators - Created behavioral profiles 3. Quality Assurance - Data validation checks - Algorithm consistency verification - Result accuracy confirmation

Data Preprocessing

Data Preprocessing Steps: 1. Data Cleaning - Removed duplicate transactions - Standardized timestamp formats - Validated transaction data integrity 2. Feature Engineering - Created time-based features - Calculated statistical metrics - Generated network features 3. Normalization - Applied consistent scaling - Handled missing values - Optimized for analysis algorithms

Design Pattern

No design pattern information is available for this report.

Analysis

General Analysis Summary for 0x1f091649634e8fd9517d67b37ff428a00877b4d4

Risk Level: Very High Risk Score: 100/100 Total Issues Identified: 164 Suspicious Transactions: 41

Key Findings: - Automated analysis detected 41 suspicious transactions - Risk assessment indicates very high risk level - 164 total suspicious patterns identified across all algorithms - Standardized risk score: 100/100

Analysis Confidence: High (automated multi-algorithm approach) Recommendation: Immediate investigation required

No suspicious patterns detected.
0xbaeeaa9a5c6ceba9317ba2751fa373abf97a963c1573f0b846069e9f44a2ae27: Very short time between transactions
0x18bbb0d3a808432adc224ca4b42163cf7abf1867f4cfd0d09b29c0695c61d82c: Transaction amount halved compared to previous transaction 0x09fe622ceb3bcc911a545f64893dfd7f7eb5b9e762023c6a747d9bb332bc81d2: Transaction amount halved compared to previous transaction 0x7089e2e266ed56cb56c9c9cc751313300b8b6ca0731c6d11d1fec60f953d87a9: Transaction amount doubled compared to previous transaction 0x66ecb404ef160c03715fab0c078293f4a9787c8a6bcd4d13cfa0b69cfe2f3f39: Transaction amount halved compared to previous transaction 0xb7bd14ab96530f6cd580896a7519ab85e81b627d35e49bd455f670224f42f244: Transaction amount doubled compared to previous transaction 0xbd8911a0302651b74273136fc7e75c2d50260f6d9a9ba60f484563238b32531f: Transaction amount doubled compared to previous transaction 0x093b614f723717b64ef6fabfd3f708e0f7cc2b90c052f45fbf92a99a72fa44a7: Transaction amount halved compared to previous transaction 0x68933794ed9a4c641146cbe44867050e3ec738e462a40bb8c0a86cfaf99b6775: Transaction amount doubled compared to previous transaction 0x9ba758a980b7eff352a171f3ea86d373575fc6327047540a3c3bd08e522a88a2: Transaction amount halved compared to previous transaction
0xbaeeaa9a5c6ceba9317ba2751fa373abf97a963c1573f0b846069e9f44a2ae27: High frequency transactions (less than 1 minute interval) 0x0420b1ecb9dba09d5674663f7d3b6bed58f1c0d2b3513e9717ffab1b31f20bb1: High frequency transactions (less than 1 minute interval) 0x145870df4b7b343c317ed16fee71df62e8d7f71d53d33edcb3b0b7ca417fbef5: High frequency transactions (less than 1 minute interval) 0xec6bfefe5404d881022b3e2a623f2a6100811c767bfd4f96ca332b9a97b02528: High frequency transactions (less than 1 minute interval) 0x865d79164fbe3eab912b27fd1db7de2286da33f8a79ee6e786b21f090e198ddd: High frequency transactions (less than 1 minute interval) 0x18bbb0d3a808432adc224ca4b42163cf7abf1867f4cfd0d09b29c0695c61d82c: High frequency transactions (less than 1 minute interval) 0x880672725f9ad3f34c8ac5c4fff441235d16ed6d4d74a72e61b80196d36e1032: High frequency transactions (less than 1 minute interval) 0x09fe622ceb3bcc911a545f64893dfd7f7eb5b9e762023c6a747d9bb332bc81d2: High frequency transactions (less than 1 minute interval) 0xc32d654e86d64236accada4295dfc9b65769fe69aba9c6eaea8a7c72d9f242d9: High frequency transactions (less than 1 minute interval) 0xc1d46b9a4230fe5ec32d2ef4f6a581992fdb74b6516da2ebfb025e85c0945b43: High frequency transactions (less than 1 minute interval) 0x4dc9646055d956cff0fc512cd9dd256be655d8fe0d42ef878daf7eadfc910018: High frequency transactions (less than 1 minute interval) 0x6894e9306407ab6afd67cff4639d733270073d96040873192936b4f83668b3c5: High frequency transactions (less than 1 minute interval) 0x7089e2e266ed56cb56c9c9cc751313300b8b6ca0731c6d11d1fec60f953d87a9: High frequency transactions (less than 1 minute interval) 0x5128c7708cfd3a981fcd4fc43d956cb919955e25860452d2906bfb7ac6c9b013: High frequency transactions (less than 1 minute interval) 0x6d545d563dde9af44cb4df4a3427d2d4e9c63a6481d09b637859d9d651a8a146: High frequency transactions (less than 1 minute interval) 0xee9b7216c8e7fa739a71a3e4a98e2688bb7bc2c31c772a24ad7a4defbef75729: High frequency transactions (less than 1 minute interval) 0x59d27aacec799eb0dc709dd1796aa09b556dceb5db4b454b38e6cf16c3366b7b: High frequency transactions (less than 1 minute interval) 0x66ecb404ef160c03715fab0c078293f4a9787c8a6bcd4d13cfa0b69cfe2f3f39: High frequency transactions (less than 1 minute interval) 0x75137c8a5bd2e10597ba62e5d6080bd6163a45cf10ed9d3237f557c56acb0d3e: High frequency transactions (less than 1 minute interval) 0xb7bd14ab96530f6cd580896a7519ab85e81b627d35e49bd455f670224f42f244: High frequency transactions (less than 1 minute interval) 0xbd8911a0302651b74273136fc7e75c2d50260f6d9a9ba60f484563238b32531f: High frequency transactions (less than 1 minute interval) 0xc6821cd93a325207af2184b831bbe25c2e4f64fbd38b37725db8ea5b7b827d77: High frequency transactions (less than 1 minute interval) 0x0afa50f26bbcadc7401412ac95058cea14f16f073481250cd0eff428c488c6a7: High frequency transactions (less than 1 minute interval) 0x755067584cad01dfa2544a02c7a7dc15693cce25c48101d4ffe4b31b9d18627e: High frequency transactions (less than 1 minute interval) 0x67732a90a2eedc0072936186d3e82a935ee83e63e748156371d3f75b60a7899c: High frequency transactions (less than 1 minute interval) 0xb8ceca0b2cc72190c92731b0d5e0cb60152284c9af942bed944f042f25a480c1: High frequency transactions (less than 1 minute interval) 0xf87dd404b9f2330bbb04a17cbef7e0f4fadf550975859a169fd8b340a4e759f8: High frequency transactions (less than 1 minute interval) 0xa6088e66e16e9336047eab1d45db78b1a9ac7969a160a4b0367682d2cd23c6ef: High frequency transactions (less than 1 minute interval) 0xe4166a09107a8ebb47ba7402f72bda8ff5730c106ae600d2d22cd68641d7a115: High frequency transactions (less than 1 minute interval) 0x093b614f723717b64ef6fabfd3f708e0f7cc2b90c052f45fbf92a99a72fa44a7: High frequency transactions (less than 1 minute interval) 0xa1f1ca9260f1948efa01757836a83222b25cbf8e883a9cf9e85fd550a776d112: High frequency transactions (less than 1 minute interval) 0xdc178446b737eac354a174bd6241bcc929863a19804650ee34e8c379f4db3213: High frequency transactions (less than 1 minute interval) 0x009e46f6bdfb8c607b7e40cfc7a0f216ce5ff67dc8af2b3c0c7eb9829a0dba09: High frequency transactions (less than 1 minute interval) 0x68933794ed9a4c641146cbe44867050e3ec738e462a40bb8c0a86cfaf99b6775: High frequency transactions (less than 1 minute interval) 0x7b7e5271c3295a96f4f109b77bfd7fefbc8ce719aeb499cad24b621b49110148: High frequency transactions (less than 1 minute interval) 0x085aa00dcb3609aedecaf74f18fc056f09e9f522d7c20540e22098951119c4b3: High frequency transactions (less than 1 minute interval) 0x9ba758a980b7eff352a171f3ea86d373575fc6327047540a3c3bd08e522a88a2: High frequency transactions (less than 1 minute interval) 0xa0509b7db1ad129b1a1b78ef1a86420dc210afec5b4b149c891678283cd16792: High frequency transactions (less than 1 minute interval) 0x65af729135a93766efecd86d3bd025e69adbb790d22f4a86c4d8cd1068da8540: High frequency transactions (less than 1 minute interval) 0x5d523741c9880ca5b70673130fe9dabe7193847ec19af3af3881748b3247c199: High frequency transactions (less than 1 minute interval) 0x21531e19d10316c85b0c9f5fa1e815f9f155feb2aca7c4a28f9dba507930360c: High frequency transactions (less than 1 minute interval)

Summary

Total Suspicious Transactions
41
Average Risk Score
49.07
Top Tags
No tags

Suspicious Transactions

Transaction Hash Risk Score Risk Factors Tags
0x865d791…
31 Medium
Short time frame between transactions
Multiple round number transactions
High frequency transactions (less than 1 minute interval)
Low transaction fee
Very short time between transactions
Transaction amount significantly lower than average
Transaction amount halved compared to previous transaction
No tags
0x6894e93…
40 High
Short time frame between transactions
Part of coordinated wallet cluster
Repetitive transaction amount
Low transaction fee
Very short time between transactions
Transaction amount significantly lower than average
No tags
0x7089e2e…
100 High
Short time frame between transactions
Transaction amount significantly higher than average
Transaction involves DeFi exploit address: Bybit Exploiter 30
Receives funds from exploit address: 0xaf620e...
Anomaly detected by Isolation Forest
Transaction amount significantly higher than user average
Large transaction amount
Low transaction fee
Transaction amount doubled compared to previous transaction
Related to 11 high-risk transactions (highest score: 100)
Rapid accumulation of large transactions
Very short time between transactions
No tags
0xb8ceca0…
100 High
Short time frame between transactions
Related to 29 high-risk transactions (highest score: 100)
Anomaly detected by Isolation Forest
Large transaction amount
Transaction involves DeFi exploit address: Bybit Exploiter 34
Low transaction fee
Receives funds from exploit address: 0x3a21f4...
Rapid accumulation of large transactions
Very short time between transactions
No tags
0xa1f1ca9…
39 Medium
Short time frame between transactions
Rapid accumulation of large transactions
Related to high-risk transaction ['0x956b72262c36be8b7086673ca59bd5431422245c3e797f84097bfa21e2bfc475'] (score: 76)
Large transaction amount
Low transaction fee
Transaction amount doubled compared to previous transaction
Very short time between transactions
No tags
0x65af729…
52 High
Short time frame between transactions
Anomaly detected by Isolation Forest
Large transaction amount
Low transaction fee
Transaction amount doubled compared to previous transaction
Rapid accumulation of large transactions
Very short time between transactions
No tags
0x5d52374…
43 High
Short time frame between transactions
Part of coordinated wallet cluster
Low transaction fee
Very short time between transactions
Transaction amount significantly lower than average
Transaction amount halved compared to previous transaction
No tags
0xa0509b7…
30 Medium
Short time frame between transactions
Multiple round number transactions
Low transaction fee
Very short time between transactions
Transaction amount significantly lower than average
Transaction amount halved compared to previous transaction
No tags
0x0420b1e…
43 High
Short time frame between transactions
Anomaly detected by Isolation Forest
Low transaction fee
Very short time between transactions
Transaction amount significantly lower than average
Transaction amount halved compared to previous transaction
No tags
0x4dc9646…
43 High
Short time frame between transactions
Part of coordinated wallet cluster
Low transaction fee
Very short time between transactions
Transaction amount significantly lower than average
Transaction amount halved compared to previous transaction
No tags
0xb7bd14a…
100 High
Short time frame between transactions
Rapid accumulation of large transactions
Transaction involves DeFi exploit address: Bybit Exploiter 30
Receives funds from exploit address: 0xaf620e...
Large transaction amount
Low transaction fee
Transaction amount doubled compared to previous transaction
Related to 11 high-risk transactions (highest score: 100)
Very short time between transactions
No tags
0x67732a9…
60 High
Short time frame between transactions
Anomaly detected by Isolation Forest
Large transaction amount
Transaction amount halved compared to previous transaction
Regular interval transactions between the same wallets
Low transaction fee
Part of cyclic transaction pattern: Part of cycle of length 4
Rapid accumulation of large transactions
Very short time between transactions
No tags
0xa6088e6…
39 Medium
Short time frame between transactions
Rapid accumulation of large transactions
Large transaction amount
Low transaction fee
Transaction amount doubled compared to previous transaction
Very short time between transactions
No tags
0x009e46f…
100 High
Short time frame between transactions
Transaction amount significantly higher than average
Related to 29 high-risk transactions (highest score: 100)
Anomaly detected by Isolation Forest
Large transaction amount
Transaction involves DeFi exploit address: Bybit Exploiter 34
Low transaction fee
Transaction amount doubled compared to previous transaction
Receives funds from exploit address: 0x3a21f4...
Rapid accumulation of large transactions
Very short time between transactions
No tags
0x085aa00…
30 Medium
Short time frame between transactions
Multiple round number transactions
Low transaction fee
Very short time between transactions
Transaction amount significantly lower than average
Transaction amount halved compared to previous transaction
No tags
0xe4166a0…
30 Medium
Short time frame between transactions
Multiple round number transactions
Low transaction fee
Very short time between transactions
Transaction amount significantly lower than average
Transaction amount halved compared to previous transaction
No tags
0x145870d…
50 High
Short time frame between transactions
Large transaction amount
Rapid multi-hop layering pattern detected
Low transaction fee
Transaction amount doubled compared to previous transaction
Very short time between transactions
No tags
0xec6bfef…
47 High
Short time frame between transactions
Rapid multi-hop layering pattern detected
Low transaction fee
Very short time between transactions
Transaction amount significantly lower than average
Transaction amount halved compared to previous transaction
No tags
0x8806727…
50 High
Short time frame between transactions
Large transaction amount
Rapid multi-hop layering pattern detected
Low transaction fee
Transaction amount doubled compared to previous transaction
Very short time between transactions
No tags
0xc32d654…
46 High
Short time frame between transactions
Rapid multi-hop layering pattern detected
Low transaction fee
Transaction amount doubled compared to previous transaction
Very short time between transactions
Transaction amount significantly lower than average
No tags
0x18bbb0d…
42 High
Short time frame between transactions
Part of coordinated wallet cluster
Low transaction fee
Transaction amount doubled compared to previous transaction
Very short time between transactions
Transaction amount significantly lower than average
No tags
0x09fe622…
30 Medium
Short time frame between transactions
Multiple round number transactions
Low transaction fee
Very short time between transactions
Transaction amount significantly lower than average
Transaction amount halved compared to previous transaction
No tags
0x5128c77…
40 High
Short time frame between transactions
Rapid accumulation of large transactions
Large transaction amount
Low transaction fee
Very short time between transactions
Transaction amount halved compared to previous transaction
No tags
0x6d545d5…
47 High
Short time frame between transactions
Rapid multi-hop layering pattern detected
Low transaction fee
Very short time between transactions
Transaction amount significantly lower than average
Transaction amount halved compared to previous transaction
No tags
0xee9b721…
31 Medium
Short time frame between transactions
Multiple round number transactions
High frequency transactions (less than 1 minute interval)
Low transaction fee
Very short time between transactions
Transaction amount significantly lower than average
Transaction amount halved compared to previous transaction
No tags
0x59d27aa…
39 Medium
Short time frame between transactions
Rapid accumulation of large transactions
Large transaction amount
Low transaction fee
Transaction amount doubled compared to previous transaction
Very short time between transactions
No tags
0x66ecb40…
43 High
Short time frame between transactions
Part of coordinated wallet cluster
Low transaction fee
Very short time between transactions
Transaction amount significantly lower than average
Transaction amount halved compared to previous transaction
No tags
0x75137c8…
40 High
Short time frame between transactions
Part of coordinated wallet cluster
Repetitive transaction amount
Low transaction fee
Very short time between transactions
Transaction amount significantly lower than average
No tags
0xbd8911a…
100 High
Short time frame between transactions
Transaction amount significantly higher than average
Transaction involves DeFi exploit address: Bybit Exploiter 30
Receives funds from exploit address: 0xaf620e...
Anomaly detected by Isolation Forest
Transaction amount significantly higher than user average
Large transaction amount
Low transaction fee
Transaction amount doubled compared to previous transaction
Related to 11 high-risk transactions (highest score: 100)
Rapid accumulation of large transactions
Very short time between transactions
No tags
0xc6821cd…
53 High
Short time frame between transactions
Anomaly detected by Isolation Forest
Large transaction amount
Transaction amount halved compared to previous transaction
Low transaction fee
Part of cyclic transaction pattern: Part of cycle of length 4
Rapid accumulation of large transactions
Very short time between transactions
No tags
0x0afa50f…
30 Medium
Short time frame between transactions
Multiple round number transactions
Low transaction fee
Very short time between transactions
Transaction amount significantly lower than average
Transaction amount halved compared to previous transaction
No tags
0x7550675…
39 Medium
Short time frame between transactions
Rapid accumulation of large transactions
Large transaction amount
Low transaction fee
Transaction amount doubled compared to previous transaction
Very short time between transactions
No tags
0xf87dd40…
43 High
Short time frame between transactions
Part of coordinated wallet cluster
Low transaction fee
Very short time between transactions
Transaction amount significantly lower than average
Transaction amount halved compared to previous transaction
No tags
0x9ba758a…
39 Medium
Short time frame between transactions
Rapid accumulation of large transactions
Large transaction amount
Low transaction fee
Transaction amount doubled compared to previous transaction
Very short time between transactions
No tags
0x093b614…
42 High
Short time frame between transactions
Part of coordinated wallet cluster
Low transaction fee
Transaction amount doubled compared to previous transaction
Very short time between transactions
Transaction amount significantly lower than average
No tags
0xdc17844…
43 High
Short time frame between transactions
Part of coordinated wallet cluster
Low transaction fee
Very short time between transactions
Transaction amount significantly lower than average
Transaction amount halved compared to previous transaction
No tags
0x6893379…
100 High
Short time frame between transactions
Transaction amount significantly higher than average
Related to 29 high-risk transactions (highest score: 100)
Anomaly detected by Isolation Forest
Large transaction amount
Transaction involves DeFi exploit address: Bybit Exploiter 34
High frequency transactions (less than 1 minute interval)
Low transaction fee
Receives funds from exploit address: 0x3a21f4...
Rapid accumulation of large transactions
Very short time between transactions
No tags
0x7b7e527…
53 High
Short time frame between transactions
Related to high-risk transaction ['0x7a2dfefe03a1a94858eac73781abe9d1cc7e8cc55cd2a80e8628d39476712a51'] (score: 85)
Anomaly detected by Isolation Forest
Large transaction amount
Transaction amount halved compared to previous transaction
Low transaction fee
Rapid accumulation of large transactions
Very short time between transactions
No tags
0x21531e1…
40 High
Short time frame between transactions
Part of coordinated wallet cluster
Repetitive transaction amount
Low transaction fee
Very short time between transactions
Transaction amount significantly lower than average
No tags
0xbaeeaa9…
59 High
Transaction amount significantly higher than average
Anomaly detected by Isolation Forest
Transaction amount significantly higher than user average
Large transaction amount
Local Outlier Factor (LOF) detected as anomaly
High frequency transactions (less than 1 minute interval)
Low transaction fee
Very short time between transactions
No tags
0xc1d46b9…
46 High
Short time frame between transactions
Anomaly detected by Isolation Forest
Large transaction amount
Low transaction fee
Transaction amount doubled compared to previous transaction
Very short time between transactions
No tags
Showing 1 to 10 of 0 transactions

Advanced Analysis Findings

No Local Outlier Factor analysis data is available for this report.
No wallet community detection data is available for this report.
No transaction layering pattern data is available for this report.
No address clustering data is available for this report.
No sanctioned address connection data is available for this report.

Suspicious Activities

Suspicious Activities Summary: High Risk Activities: 41 Medium Risk Activities: 0 Total Flagged Transactions: 41 Pattern Categories: - Network-based anomalies - Behavioral inconsistencies - Statistical outliers - Temporal irregularities Automated Detection Results: - Algorithm coverage: Comprehensive - Detection confidence: High - Risk classification: Validated

Conclusions & Recommendations

Conclusions

Analysis Conclusions for 0x1f091649634e8fd9517d67b37ff428a00877b4d4: 1. Risk Assessment - Overall Risk Level: Very High - Standardized Risk Score: 100/100 - Average Transaction Risk Score: 50.54 - Total Suspicious Patterns: 41 2. Key Findings - Automated analysis completed successfully - Multiple detection algorithms applied - Comprehensive risk evaluation performed - Standardized scoring methodology applied (score: 100/100) 3. Confidence Level - Analysis Quality: High - Data Coverage: Complete - Algorithm Performance: Validated 4. Summary The automated analysis has identified significant concerns. Immediate action recommended.

Recommendations

Immediate Action Recommendations: 1. Priority Actions - Escalate to compliance team immediately - Implement enhanced monitoring - Consider transaction restrictions - Document all findings 2. Investigation Requirements - Detailed transaction review required - Source of funds investigation - Enhanced due diligence protocols - Regular monitoring updates 3. Compliance Measures - File suspicious activity reports if required - Implement know-your-customer procedures - Apply enhanced monitoring protocols - Document risk mitigation measures

Severity Assessment

Very High

Appendices & References

Appendices

Appendix A: Automated Analysis Results Appendix B: Algorithm Details and Methodology Appendix C: Risk Assessment Matrix Appendix D: Transaction Pattern Analysis Appendix E: Network Connection Analysis Appendix F: Case Reference Documentation - CLADIOUS-[BYBIT_HACKER_LAZARUS_ITER]-2025-001 Appendix G: Investigation Team Notes - Cladious Forensics Team

References

1. Blockchain Analysis Framework - Cladious Platform 2. Risk Assessment Guidelines - Financial Action Task Force (FATF) 3. Automated Analysis Documentation - Internal Methodology

Contact Information

Primary Analyst: Cladious Auto
Email: [email protected]
Generated: 2025-07-13 23:38:56 UTC
Investigation Team: Cladious Forensics Team
Case Reference: CLADIOUS-[BYBIT_HACKER_LAZARUS_ITER]-2025-001

Platform: Cladious Security Analysis Platform
For questions or additional analysis requests, please contact the investigation team.

This report contains confidential information and should be handled according to your organization's data protection policies.

Report Information

Author Cladious Auto
Published Date July 13, 2025
Views 10
Likes 0