SECURING CONNECTION
INITIALIZING BLOCKCHAIN ANALYSIS
SITE AVAILABLE TRUE
SECURITY LEVEL SECURE
NETWORK STATUS SECURE

Lazarus High Risk Bybit Hacking Investigation [CLADIOUS-[BYBIT_HACKER_LAZARUS_ITER]-2025-001] - Wallet Analysis Report - Very High Risk - 0xf223...0c0a

Published 16 Jul 2025 6 views
Wallet Name Analysis Target Wallet (CLADIOUS-[BYBIT_HACKER_LAZARUS_ITER]-2025-001) - 0xf223...0c0a
LLM Analysis

Overview

Project Scope

Analysis of wallet 0xf223587db52bcddc7986f80f095e2572c3d80c0a - Lazarus High Risk Bybit Hacking Investigation

Suspicious Wallet Hash

0xf223587db52bcddc7986f80f095e2572c3d80c0a
This is the primary wallet address being investigated in this report.

Methodology

Research Methodology

Automated Analysis Methodology for Wallet 0xf223587db52bcddc7986f80f095e2572c3d80c0a 1. Data Collection - Automated transaction retrieval from blockchain - Historical transaction pattern analysis - Network connection mapping 2. Analysis Algorithms - Multi-algorithm approach using 22 detection methods - Statistical anomaly detection - Behavioral pattern analysis - Network-based risk assessment 3. Risk Scoring - Weighted risk factor calculation - Multi-dimensional analysis - Historical comparison baseline - Real-time pattern detection 4. Report Generation - Automated findings compilation - Risk level determination - Recommendation synthesis - Compliance-ready documentation

Data Collection

Data Collection Process for 0xf223587db52bcddc7986f80f095e2572c3d80c0a 1. Blockchain Data Retrieval - Retrieved 22 analysis data points - Collected complete transaction history - Gathered network connection data 2. Analysis Processing - Applied multiple detection algorithms - Performed statistical analysis - Generated risk indicators - Created behavioral profiles 3. Quality Assurance - Data validation checks - Algorithm consistency verification - Result accuracy confirmation

Data Preprocessing

Data Preprocessing Steps: 1. Data Cleaning - Removed duplicate transactions - Standardized timestamp formats - Validated transaction data integrity 2. Feature Engineering - Created time-based features - Calculated statistical metrics - Generated network features 3. Normalization - Applied consistent scaling - Handled missing values - Optimized for analysis algorithms

Design Pattern

No design pattern information is available for this report.

Analysis

General Analysis Summary for 0xf223587db52bcddc7986f80f095e2572c3d80c0a

Risk Level: Very High Risk Score: 100/100 Total Issues Identified: 84 Suspicious Transactions: 22

Key Findings: - Automated analysis detected 22 suspicious transactions - Risk assessment indicates very high risk level - 84 total suspicious patterns identified across all algorithms - Standardized risk score: 100/100

Analysis Confidence: High (automated multi-algorithm approach) Recommendation: Immediate investigation required

No suspicious patterns detected.
0xad3f10811500ef47e7ec03e7b8bd8a1162b604ab58c3346af6672009673187b0: Very short time between transactions 0x84e56a521dec7ad6206c16b51f00e91d6a36bdec97460ad00d77c9a67fbb8fdc: Very short time between transactions 0x3404d66739b07a2d601d6f71cecd6d360ff76577c812ac150af3dffeac72ae01: Very short time between transactions 0xed4a291467c816e184984da1b345370c84b5f9371fe0fcf9fc70f246bf1eea99: Very short time between transactions 0x3aae892024fe0657fec064a165122df31fd4c2a0143a2eb1ea28ce2bdb338ab6: Very short time between transactions 0xe1e241bf7eefebb86e80271f99e16892dd9c0bab31b485734ae58e5e1f0e5586: Very short time between transactions 0x4cc1af0c8611af7a173b8ceb032e1df6ec552e323591032046905924a30e490c: Very short time between transactions 0x13a053fbe2f5d66f14b80af12d1b75bb1139be3de960255c6c3c62e0d7db97e2: Very short time between transactions 0x71a653649d6a9c1960592585e6531ab905b4ac0bec36aa72569eeae6134fbfcd: Very short time between transactions 0x8e60369849efab7493730892a43c02443fb3d4c4a84dd98c8afbaaadfc655069: Very short time between transactions 0x1fc65b977a640d0c5d14bf589809b1657712b123d0b828aa506bb58d351aa77f: Very short time between transactions 0x748ff0569ed982f0af8abe7744f42f9c382d22d21a20ec2e9d1f822ed7806436: Very short time between transactions 0x10ce5a4d8f0d413f8eadf8e694c4c13c735a68219c65396d367c7bf2c8f8b7dd: Very short time between transactions 0xfc97479751a17b90e7f97fb174e518d1cfe15c2e60de9574d3cd8405240dff7f: Very short time between transactions 0x06ef3698178bb94968e42a43ecb16fc4446684ab7298862279236aa7a3941df7: Very short time between transactions 0xacb7411abfe0fb1d869212d846569370b6a462533e24e0c96d35e9b48229d27b: Very short time between transactions 0x3026c556b5c7d9555795a7db94416d92b775567ea88abd407b7ed4b463cb608d: Very short time between transactions 0xf8ff292ebf52d9552a6c95842bd17e1d1e81ddca5cbb4c7fc19f87e90245846c: Very short time between transactions 0x71d231637f1f9791d9b0f90a44037ac1c280faac23ad4cef00e7fc5c8f123f95: Very short time between transactions 0x4020dad0b27311dbb4d058a2488c40a87e4cd41591dc81dcc3da237829558265: Very short time between transactions 0x8f6665a05f9245f77c70659524e07f9da26959e0d5e274ed057d6e6ec5f82ad3: Very short time between transactions
0xad3f10811500ef47e7ec03e7b8bd8a1162b604ab58c3346af6672009673187b0: Transaction amount doubled compared to previous transaction 0x3404d66739b07a2d601d6f71cecd6d360ff76577c812ac150af3dffeac72ae01: Transaction amount halved compared to previous transaction 0x4cc1af0c8611af7a173b8ceb032e1df6ec552e323591032046905924a30e490c: Transaction amount halved compared to previous transaction 0x4020dad0b27311dbb4d058a2488c40a87e4cd41591dc81dcc3da237829558265: Transaction amount halved compared to previous transaction
0xad3f10811500ef47e7ec03e7b8bd8a1162b604ab58c3346af6672009673187b0: High frequency transactions (less than 1 minute interval) 0x3aae892024fe0657fec064a165122df31fd4c2a0143a2eb1ea28ce2bdb338ab6: Regular interval transactions between the same wallets 0xe1e241bf7eefebb86e80271f99e16892dd9c0bab31b485734ae58e5e1f0e5586: High frequency transactions (less than 1 minute interval) 0x4cc1af0c8611af7a173b8ceb032e1df6ec552e323591032046905924a30e490c: High frequency transactions (less than 1 minute interval) 0x13a053fbe2f5d66f14b80af12d1b75bb1139be3de960255c6c3c62e0d7db97e2: High frequency transactions (less than 1 minute interval) 0x71a653649d6a9c1960592585e6531ab905b4ac0bec36aa72569eeae6134fbfcd: High frequency transactions (less than 1 minute interval) 0x8e60369849efab7493730892a43c02443fb3d4c4a84dd98c8afbaaadfc655069: High frequency transactions (less than 1 minute interval) 0x1fc65b977a640d0c5d14bf589809b1657712b123d0b828aa506bb58d351aa77f: High frequency transactions (less than 1 minute interval) 0x748ff0569ed982f0af8abe7744f42f9c382d22d21a20ec2e9d1f822ed7806436: High frequency transactions (less than 1 minute interval) 0x10ce5a4d8f0d413f8eadf8e694c4c13c735a68219c65396d367c7bf2c8f8b7dd: High frequency transactions (less than 1 minute interval) 0xfc97479751a17b90e7f97fb174e518d1cfe15c2e60de9574d3cd8405240dff7f: High frequency transactions (less than 1 minute interval) 0x06ef3698178bb94968e42a43ecb16fc4446684ab7298862279236aa7a3941df7: High frequency transactions (less than 1 minute interval) 0xacb7411abfe0fb1d869212d846569370b6a462533e24e0c96d35e9b48229d27b: High frequency transactions (less than 1 minute interval) 0x3026c556b5c7d9555795a7db94416d92b775567ea88abd407b7ed4b463cb608d: High frequency transactions (less than 1 minute interval) 0xf8ff292ebf52d9552a6c95842bd17e1d1e81ddca5cbb4c7fc19f87e90245846c: High frequency transactions (less than 1 minute interval) 0x71d231637f1f9791d9b0f90a44037ac1c280faac23ad4cef00e7fc5c8f123f95: High frequency transactions (less than 1 minute interval) 0x4020dad0b27311dbb4d058a2488c40a87e4cd41591dc81dcc3da237829558265: High frequency transactions (less than 1 minute interval) 0x8f6665a05f9245f77c70659524e07f9da26959e0d5e274ed057d6e6ec5f82ad3: High frequency transactions (less than 1 minute interval)

Suspicious Transactions

Transaction Hash Risk Score Risk Factors Tags
0xed4a291…
100 High
Local Outlier Factor (LOF) detected as anomaly
Low transaction fee
Large transaction amount
High frequency transactions (less than 1 minute interval)
Transaction involves DeFi exploit address: Bybit Exploiter 31
Anomaly detected by Isolation Forest
Very short time between transactions
Receives funds from exploit address: 0xcd1a4a...
Related to 118 high-risk transactions (highest score: 100)
Transaction amount significantly higher than average
Transaction amount significantly higher than user average
No tags
0x84e56a5…
46 High
Low transaction fee
Large transaction amount
Transaction amount doubled compared to previous transaction
Short time frame between transactions
Anomaly detected by Isolation Forest
Very short time between transactions
No tags
0x1fc65b9…
62 High
Outgoing structuring detected: 4 similar amounts totaling 86.28
Low transaction fee
Large transaction amount
Transaction amount doubled compared to previous transaction
Short time frame between transactions
Anomaly detected by Isolation Forest
Very short time between transactions
Rapid multi-hop layering pattern detected
High frequency transactions (less than 1 minute interval)
No tags
0xfc97479…
67 High
Outgoing structuring detected: 4 similar amounts totaling 86.28
Outgoing structuring detected: 3 similar amounts totaling 64.28
Low transaction fee
Large transaction amount
Transaction amount doubled compared to previous transaction
Rapid accumulation of large transactions
Short time frame between transactions
Anomaly detected by Isolation Forest
Very short time between transactions
Rapid multi-hop layering pattern detected
High frequency transactions (less than 1 minute interval)
No tags
0x3404d66…
39 Medium
Outgoing structuring detected: 4 similar amounts totaling 86.28
Outgoing structuring detected: 3 similar amounts totaling 64.28
Low transaction fee
Large transaction amount
Transaction amount doubled compared to previous transaction
Rapid accumulation of large transactions
Short time frame between transactions
Very short time between transactions
High frequency transactions (less than 1 minute interval)
No tags
0x3aae892…
85 High
Low transaction fee
Transaction amount significantly lower than average
Round amount consistent with mixer
Short time frame between transactions
Standard mixer amount detected
Anomaly detected by Isolation Forest
Very short time between transactions
Transaction amount halved compared to previous transaction
No tags
0x748ff05…
47 High
Low transaction fee
Transaction amount significantly lower than average
Short time frame between transactions
Very short time between transactions
Transaction amount halved compared to previous transaction
Rapid multi-hop layering pattern detected
Multiple round number transactions
High frequency transactions (less than 1 minute interval)
No tags
0x3026c55…
29 Medium
Low transaction fee
Transaction amount significantly lower than average
Transaction amount doubled compared to previous transaction
Short time frame between transactions
Very short time between transactions
High frequency transactions (less than 1 minute interval)
No tags
0xf8ff292…
47 High
Low transaction fee
Transaction amount significantly lower than average
Short time frame between transactions
Very short time between transactions
Transaction amount halved compared to previous transaction
Rapid multi-hop layering pattern detected
Multiple round number transactions
High frequency transactions (less than 1 minute interval)
No tags
0x71d2316…
53 High
Low transaction fee
Transaction amount significantly lower than average
Transaction amount doubled compared to previous transaction
Regular interval transactions between the same wallets
Short time frame between transactions
Very short time between transactions
Rapid multi-hop layering pattern detected
High frequency transactions (less than 1 minute interval)
No tags
0x4133153…
100 High
Low transaction fee
Transaction amount significantly lower than average
Short time frame between transactions
Transaction involves known exploit address: Fake_Phishing1298303
Very short time between transactions
Transaction amount halved compared to previous transaction
Multiple round number transactions
Receives funds from exploit address: 0x84106b...
No tags
0x4020dad…
27 Medium
Low transaction fee
Transaction amount significantly lower than average
Short time frame between transactions
Very short time between transactions
Repetitive transaction amount
High frequency transactions (less than 1 minute interval)
No tags
0x13a053f…
30 Medium
Low transaction fee
Transaction amount significantly lower than average
Short time frame between transactions
Very short time between transactions
Transaction amount halved compared to previous transaction
High frequency transactions (less than 1 minute interval)
No tags
0xe1e241b…
30 Medium
Low transaction fee
Transaction amount significantly lower than average
Short time frame between transactions
Very short time between transactions
Transaction amount halved compared to previous transaction
Multiple round number transactions
No tags
0x4cc1af0…
29 Medium
Low transaction fee
Transaction amount significantly lower than average
Transaction amount doubled compared to previous transaction
Short time frame between transactions
Very short time between transactions
High frequency transactions (less than 1 minute interval)
No tags
0x8e60369…
100 High
Low transaction fee
Transaction amount significantly lower than average
Short time frame between transactions
Transaction involves known exploit address: Fake_Phishing1298303
Very short time between transactions
Transaction amount halved compared to previous transaction
Receives funds from exploit address: 0x84106b...
High frequency transactions (less than 1 minute interval)
No tags
0x10ce5a4…
29 Medium
Low transaction fee
Transaction amount significantly lower than average
Transaction amount doubled compared to previous transaction
Short time frame between transactions
Very short time between transactions
High frequency transactions (less than 1 minute interval)
No tags
0xad3f108…
65 High
Outgoing structuring detected: 4 similar amounts totaling 86.28
Outgoing structuring detected: 3 similar amounts totaling 64.28
Low transaction fee
Large transaction amount
Rapid accumulation of large transactions
Short time frame between transactions
Anomaly detected by Isolation Forest
Very short time between transactions
Rapid multi-hop layering pattern detected
No tags
0xacb7411…
31 Medium
Low transaction fee
Transaction amount significantly lower than average
Short time frame between transactions
Very short time between transactions
Transaction amount halved compared to previous transaction
Multiple round number transactions
High frequency transactions (less than 1 minute interval)
No tags
0x8f6665a…
27 Medium
Low transaction fee
Transaction amount significantly lower than average
Short time frame between transactions
Very short time between transactions
Repetitive transaction amount
High frequency transactions (less than 1 minute interval)
No tags
0x71a6536…
51 High
Low transaction fee
Large transaction amount
Transaction amount doubled compared to previous transaction
High frequency transactions (less than 1 minute interval)
Short time frame between transactions
Anomaly detected by Isolation Forest
Very short time between transactions
Transaction amount significantly higher than average
No tags
0x06ef369…
52 High
Low transaction fee
Transaction amount significantly lower than average
Regular interval transactions between the same wallets
Short time frame between transactions
Very short time between transactions
Rapid multi-hop layering pattern detected
Multiple round number transactions
High frequency transactions (less than 1 minute interval)
No tags
Showing 1 to 10 of 0 transactions

Advanced Analysis Findings

No Local Outlier Factor analysis data is available for this report.
No wallet community detection data is available for this report.
No transaction layering pattern data is available for this report.
No address clustering data is available for this report.
No sanctioned address connection data is available for this report.

Suspicious Activities

Suspicious Activities Summary: High Risk Activities: 22 Medium Risk Activities: 0 Total Flagged Transactions: 22 Pattern Categories: - Network-based anomalies - Behavioral inconsistencies - Statistical outliers - Temporal irregularities Automated Detection Results: - Algorithm coverage: Comprehensive - Detection confidence: High - Risk classification: Validated

Conclusions & Recommendations

Conclusions

Analysis Conclusions for 0xf223587db52bcddc7986f80f095e2572c3d80c0a: 1. Risk Assessment - Overall Risk Level: Very High - Standardized Risk Score: 100/100 - Average Transaction Risk Score: 52.09 - Total Suspicious Patterns: 22 2. Key Findings - Automated analysis completed successfully - Multiple detection algorithms applied - Comprehensive risk evaluation performed - Standardized scoring methodology applied (score: 100/100) 3. Confidence Level - Analysis Quality: High - Data Coverage: Complete - Algorithm Performance: Validated 4. Summary The automated analysis has identified significant concerns. Immediate action recommended.

Recommendations

Immediate Action Recommendations: 1. Priority Actions - Escalate to compliance team immediately - Implement enhanced monitoring - Consider transaction restrictions - Document all findings 2. Investigation Requirements - Detailed transaction review required - Source of funds investigation - Enhanced due diligence protocols - Regular monitoring updates 3. Compliance Measures - File suspicious activity reports if required - Implement know-your-customer procedures - Apply enhanced monitoring protocols - Document risk mitigation measures

Severity Assessment

Very High

Appendices & References

Appendices

Appendix A: Automated Analysis Results Appendix B: Algorithm Details and Methodology Appendix C: Risk Assessment Matrix Appendix D: Transaction Pattern Analysis Appendix E: Network Connection Analysis Appendix F: Case Reference Documentation - CLADIOUS-[BYBIT_HACKER_LAZARUS_ITER]-2025-001 Appendix G: Investigation Team Notes - Cladious Forensics Team

References

1. Blockchain Analysis Framework - Cladious Platform 2. Risk Assessment Guidelines - Financial Action Task Force (FATF) 3. Automated Analysis Documentation - Internal Methodology

Contact Information

Primary Analyst: Cladious Auto
Email: [email protected]
Generated: 2025-07-16 01:11:13 UTC
Investigation Team: Cladious Forensics Team
Case Reference: CLADIOUS-[BYBIT_HACKER_LAZARUS_ITER]-2025-001

Platform: Cladious Security Analysis Platform
For questions or additional analysis requests, please contact the investigation team.

This report contains confidential information and should be handled according to your organization's data protection policies.