SECURING CONNECTION
INITIALIZING BLOCKCHAIN ANALYSIS
SITE AVAILABLE TRUE
SECURITY LEVEL SECURE
NETWORK STATUS SECURE

Lazarus High Risk Bybit Hacking Investigation [CLADIOUS-[BYBIT_HACKER_LAZARUS_ITER]-2025-001] - Wallet Analysis Report - Very High Risk - 0x22c1...b96c

Published 13 Jul 2025 9 views
Wallet Name Analysis Target Wallet (CLADIOUS-[BYBIT_HACKER_LAZARUS_ITER]-2025-001) - 0x22c1...b96c
Login to view LLM Analysis

Overview

Project Scope

Analysis of wallet 0x22c1d4debaa91fd08de109408f5ac8d5f171b96c - Lazarus High Risk Bybit Hacking Investigation

Suspicious Wallet Hash

0x22c1d4debaa91fd08de109408f5ac8d5f171b96c
This is the primary wallet address being investigated in this report.

Methodology

Research Methodology

Automated Analysis Methodology for Wallet 0x22c1d4debaa91fd08de109408f5ac8d5f171b96c 1. Data Collection - Automated transaction retrieval from blockchain - Historical transaction pattern analysis - Network connection mapping 2. Analysis Algorithms - Multi-algorithm approach using 23 detection methods - Statistical anomaly detection - Behavioral pattern analysis - Network-based risk assessment 3. Risk Scoring - Weighted risk factor calculation - Multi-dimensional analysis - Historical comparison baseline - Real-time pattern detection 4. Report Generation - Automated findings compilation - Risk level determination - Recommendation synthesis - Compliance-ready documentation

Data Collection

Data Collection Process for 0x22c1d4debaa91fd08de109408f5ac8d5f171b96c 1. Blockchain Data Retrieval - Retrieved 23 analysis data points - Collected complete transaction history - Gathered network connection data 2. Analysis Processing - Applied multiple detection algorithms - Performed statistical analysis - Generated risk indicators - Created behavioral profiles 3. Quality Assurance - Data validation checks - Algorithm consistency verification - Result accuracy confirmation

Data Preprocessing

Data Preprocessing Steps: 1. Data Cleaning - Removed duplicate transactions - Standardized timestamp formats - Validated transaction data integrity 2. Feature Engineering - Created time-based features - Calculated statistical metrics - Generated network features 3. Normalization - Applied consistent scaling - Handled missing values - Optimized for analysis algorithms

Design Pattern

No design pattern information is available for this report.

Analysis

General Analysis Summary for 0x22c1d4debaa91fd08de109408f5ac8d5f171b96c

Risk Level: Very High Risk Score: 100/100 Total Issues Identified: 90 Suspicious Transactions: 23

Key Findings: - Automated analysis detected 23 suspicious transactions - Risk assessment indicates very high risk level - 90 total suspicious patterns identified across all algorithms - Standardized risk score: 100/100

Analysis Confidence: High (automated multi-algorithm approach) Recommendation: Immediate investigation required

No suspicious patterns detected.
0x276f1756e2bb44436510d9bada98eafbcab37a1b14edcaace258c13d96cee587: Very short time between transactions 0xbb10591e9f183aae6c05a198ea69056eb2a2fad28ee60a1a1c88ccd10c8cba84: Very short time between transactions 0x973c15dc693b33e08f32717f25a8c1d901ed2abf6f28a521b049cc651ee3eae3: Very short time between transactions 0xa47848bd188a85c0d65354fd01b27496ba95768ebc6ceecfea48eb681c5e8a5e: Very short time between transactions 0x1540595744bbf75b2f8b8de7ef0c1f5f708c9c917745665ce27caee38bafb546: Very short time between transactions 0x6d8f6a00bf89e3571e70ca1cb076e008434471f2e260fff061ecbd66e353dae7: Very short time between transactions 0x41e2bfb9f4e372f582adef89ba92d188b1ef30fb8af68292427b6f148b1b6349: Very short time between transactions 0x0a3b5e48d6f0520affebf40a1b35729c3197a36cf6d8e026f9a106c28edefa96: Very short time between transactions 0x4707a2bbf6eb5968c16b290eb69be85462255ef8910fd74be8b9ba4cc6fc8fd8: Very short time between transactions 0x53175a36adcd5fdbed06e5ab4fcc5a9f0da98972d558bc962ae9d3bde8df788e: Very short time between transactions 0x72347ee4727ec461182dcab19726dd6d10abe284852ddcd65fcac63b5b457847: Very short time between transactions 0xf5f25c9233035561b38b474500fac4f29a247fc8859aa06ca3ba2de0ec997f1e: Very short time between transactions 0xdf20b205ef69209bdd40154b3c90af62b9ded9e0b8d58432da17a1a26fc924ce: Very short time between transactions 0x609ae87e2635b052dee93d142370cf8f64923f2527ec52a8241a5b1faf934ad8: Very short time between transactions 0xe61389c9cbf651fe22613e30ca55b3f6f26048016bb393c3cbee6fef3e2fdfa4: Very short time between transactions 0xbef2c7cd3b72240bc1aaae260fd9c7a880361c299c6cec101b09940d58f9cde2: Very short time between transactions 0x67b0abf0a0f292f9ca9ae3e1f01d7effec0cb2c44bfb75123437319a50f5087d: Very short time between transactions 0x97110981e72258bc325003cd382c2abaaf6e5afef863004370014b90fd9739d1: Very short time between transactions 0x0f71f4376e9c586e23228e4a161f050c0b4861f5123bd595a7f8ada0ccdc58b2: Very short time between transactions 0x3cd56a39faef4ffeacdfd9b281d1d43985ba8c5c12ba7a6c2cf448406e3f8010: Very short time between transactions 0x2678b8cb149f01ca5453fdc9e7792995690693055ea8b7f2c64b74b7b43ac911: Very short time between transactions
0x973c15dc693b33e08f32717f25a8c1d901ed2abf6f28a521b049cc651ee3eae3: Transaction amount doubled compared to previous transaction 0x67b0abf0a0f292f9ca9ae3e1f01d7effec0cb2c44bfb75123437319a50f5087d: Transaction amount halved compared to previous transaction 0xfa2ea91eb9855cf99b99966bf63723ccd6ac520ee7819d0f09af6f6d5d5d21d7: Transaction amount significantly lower than average, Transaction amount halved compared to previous transaction
0x276f1756e2bb44436510d9bada98eafbcab37a1b14edcaace258c13d96cee587: High frequency transactions (less than 1 minute interval) 0xbb10591e9f183aae6c05a198ea69056eb2a2fad28ee60a1a1c88ccd10c8cba84: Regular interval transactions between the same wallets, High frequency transactions (less than 1 minute interval) 0x973c15dc693b33e08f32717f25a8c1d901ed2abf6f28a521b049cc651ee3eae3: High frequency transactions (less than 1 minute interval) 0xa47848bd188a85c0d65354fd01b27496ba95768ebc6ceecfea48eb681c5e8a5e: Regular interval transactions between the same wallets, High frequency transactions (less than 1 minute interval) 0x1540595744bbf75b2f8b8de7ef0c1f5f708c9c917745665ce27caee38bafb546: High frequency transactions (less than 1 minute interval) 0x6d8f6a00bf89e3571e70ca1cb076e008434471f2e260fff061ecbd66e353dae7: High frequency transactions (less than 1 minute interval) 0x41e2bfb9f4e372f582adef89ba92d188b1ef30fb8af68292427b6f148b1b6349: High frequency transactions (less than 1 minute interval) 0x0a3b5e48d6f0520affebf40a1b35729c3197a36cf6d8e026f9a106c28edefa96: High frequency transactions (less than 1 minute interval) 0x4707a2bbf6eb5968c16b290eb69be85462255ef8910fd74be8b9ba4cc6fc8fd8: High frequency transactions (less than 1 minute interval) 0x53175a36adcd5fdbed06e5ab4fcc5a9f0da98972d558bc962ae9d3bde8df788e: High frequency transactions (less than 1 minute interval) 0x72347ee4727ec461182dcab19726dd6d10abe284852ddcd65fcac63b5b457847: High frequency transactions (less than 1 minute interval) 0xf5f25c9233035561b38b474500fac4f29a247fc8859aa06ca3ba2de0ec997f1e: High frequency transactions (less than 1 minute interval) 0xdf20b205ef69209bdd40154b3c90af62b9ded9e0b8d58432da17a1a26fc924ce: High frequency transactions (less than 1 minute interval) 0x609ae87e2635b052dee93d142370cf8f64923f2527ec52a8241a5b1faf934ad8: High frequency transactions (less than 1 minute interval) 0xe61389c9cbf651fe22613e30ca55b3f6f26048016bb393c3cbee6fef3e2fdfa4: High frequency transactions (less than 1 minute interval) 0xbef2c7cd3b72240bc1aaae260fd9c7a880361c299c6cec101b09940d58f9cde2: High frequency transactions (less than 1 minute interval) 0x67b0abf0a0f292f9ca9ae3e1f01d7effec0cb2c44bfb75123437319a50f5087d: High frequency transactions (less than 1 minute interval) 0x97110981e72258bc325003cd382c2abaaf6e5afef863004370014b90fd9739d1: High frequency transactions (less than 1 minute interval) 0x0f71f4376e9c586e23228e4a161f050c0b4861f5123bd595a7f8ada0ccdc58b2: High frequency transactions (less than 1 minute interval) 0x3cd56a39faef4ffeacdfd9b281d1d43985ba8c5c12ba7a6c2cf448406e3f8010: High frequency transactions (less than 1 minute interval) 0x2678b8cb149f01ca5453fdc9e7792995690693055ea8b7f2c64b74b7b43ac911: High frequency transactions (less than 1 minute interval)

Summary

Total Suspicious Transactions
23
Average Risk Score
48.52
Top Tags
No tags

Suspicious Transactions

Transaction Hash Risk Score Risk Factors Tags
0x1540595…
53 High
Short time frame between transactions
Anomaly detected by Isolation Forest
Large transaction amount
Transaction amount halved compared to previous transaction
Outgoing structuring detected: 5 similar amounts totaling 166.27
Low transaction fee
Rapid accumulation of large transactions
Very short time between transactions
No tags
0xfa2ea91…
25 Medium
Multiple round number transactions
Related to 17 high-risk transactions (highest score: 83)
Low transaction fee
Very short time between transactions
Transaction amount significantly lower than average
Transaction amount halved compared to previous transaction
No tags
0xbb10591…
54 High
Short time frame between transactions
Transaction amount significantly higher than average
Anomaly detected by Isolation Forest
Transaction amount significantly higher than user average
Large transaction amount
Low transaction fee
Part of cyclic transaction pattern: Part of cycle of length 4
Very short time between transactions
No tags
0x9711098…
56 High
Short time frame between transactions
Fan-in structuring detected: 3 similar amounts from different addresses totaling 0.00
Rapid multi-hop layering pattern detected
Part of coordinated wallet cluster
Low transaction fee
Transaction amount doubled compared to previous transaction
Very short time between transactions
Transaction amount significantly lower than average
No tags
0xa47848b…
60 High
Short time frame between transactions
Transaction amount significantly higher than average
Related to 53 high-risk transactions (highest score: 100)
Anomaly detected by Isolation Forest
Transaction amount significantly higher than user average
Large transaction amount
Local Outlier Factor (LOF) detected as anomaly
Very short time between transactions
No tags
0x41e2bfb…
52 High
Short time frame between transactions
Anomaly detected by Isolation Forest
Large transaction amount
Outgoing structuring detected: 5 similar amounts totaling 166.27
High frequency transactions (less than 1 minute interval)
Low transaction fee
Outgoing structuring detected: 4 similar amounts totaling 132.77
Transaction amount doubled compared to previous transaction
Rapid accumulation of large transactions
Very short time between transactions
No tags
0x0a3b5e4…
45 High
Short time frame between transactions
Multiple round number transactions
High frequency transactions (less than 1 minute interval)
Part of coordinated wallet cluster
Low transaction fee
Very short time between transactions
Transaction amount significantly lower than average
Transaction amount halved compared to previous transaction
No tags
0x53175a3…
45 High
Short time frame between transactions
Multiple round number transactions
High frequency transactions (less than 1 minute interval)
Part of coordinated wallet cluster
Low transaction fee
Very short time between transactions
Transaction amount significantly lower than average
Transaction amount halved compared to previous transaction
No tags
0x609ae87…
54 High
Short time frame between transactions
Anomaly detected by Isolation Forest
High frequency transactions (less than 1 minute interval)
Part of coordinated wallet cluster
Repetitive transaction amount
Low transaction fee
Very short time between transactions
Transaction amount significantly lower than average
No tags
0xe61389c…
66 High
Short time frame between transactions
Anomaly detected by Isolation Forest
Large transaction amount
Outgoing structuring detected: 5 similar amounts totaling 166.27
High frequency transactions (less than 1 minute interval)
Rapid multi-hop layering pattern detected
Low transaction fee
Outgoing structuring detected: 4 similar amounts totaling 132.77
Transaction amount doubled compared to previous transaction
Outgoing structuring detected: 3 similar amounts totaling 99.37
Rapid accumulation of large transactions
Very short time between transactions
No tags
0x4707a2b…
43 High
Short time frame between transactions
Anomaly detected by Isolation Forest
High frequency transactions (less than 1 minute interval)
Low transaction fee
Transaction amount doubled compared to previous transaction
Very short time between transactions
Transaction amount significantly lower than average
No tags
0xf5f25c9…
50 High
Short time frame between transactions
Anomaly detected by Isolation Forest
Large transaction amount
Outgoing structuring detected: 5 similar amounts totaling 166.27
High frequency transactions (less than 1 minute interval)
Low transaction fee
Outgoing structuring detected: 4 similar amounts totaling 132.77
Outgoing structuring detected: 3 similar amounts totaling 99.37
Rapid accumulation of large transactions
Very short time between transactions
No tags
0xdf20b20…
57 High
Short time frame between transactions
Anomaly detected by Isolation Forest
High frequency transactions (less than 1 minute interval)
Part of coordinated wallet cluster
Low transaction fee
Very short time between transactions
Transaction amount significantly lower than average
Transaction amount halved compared to previous transaction
No tags
0x2678b8c…
57 High
Short time frame between transactions
High frequency transactions (less than 1 minute interval)
Rapid multi-hop layering pattern detected
Repetitive transaction amount
Low transaction fee
Part of coordinated wallet cluster
Very short time between transactions
Transaction amount significantly lower than average
No tags
0xbef2c7c…
60 High
Short time frame between transactions
Multiple round number transactions
High frequency transactions (less than 1 minute interval)
Rapid multi-hop layering pattern detected
Low transaction fee
Part of coordinated wallet cluster
Very short time between transactions
Transaction amount significantly lower than average
Transaction amount halved compared to previous transaction
No tags
0x67b0abf…
28 Medium
Short time frame between transactions
Multiple round number transactions
High frequency transactions (less than 1 minute interval)
Repetitive transaction amount
Low transaction fee
Very short time between transactions
Transaction amount significantly lower than average
No tags
0x4dd526b…
55 High
Local Outlier Factor (LOF) detected as anomaly
Rapid multi-hop layering pattern detected
Low transaction fee
Part of coordinated wallet cluster
Transaction amount significantly lower than average
Transaction amount halved compared to previous transaction
No tags
0x973c15d…
100 High
Transaction amount significantly higher than average
Related to 32 high-risk transactions (highest score: 100)
Anomaly detected by Isolation Forest
Transaction amount significantly higher than user average
Large transaction amount
High frequency transactions (less than 1 minute interval)
Low transaction fee
Receives funds from exploit address: 0xfc9266...
Very short time between transactions
Transaction involves DeFi exploit address: Bybit Exploiter 22
No tags
0x276f175…
55 High
Short time frame between transactions
Transaction amount significantly higher than average
Anomaly detected by Isolation Forest
Transaction amount significantly higher than user average
Large transaction amount
Low transaction fee
Transaction amount doubled compared to previous transaction
Part of cyclic transaction pattern: Part of cycle of length 4
Very short time between transactions
No tags
0x6d8f6a0…
56 High
Short time frame between transactions
Anomaly detected by Isolation Forest
Part of coordinated wallet cluster
Low transaction fee
Very short time between transactions
Transaction amount significantly lower than average
Transaction amount halved compared to previous transaction
No tags
0x72347ee…
51 High
Short time frame between transactions
Anomaly detected by Isolation Forest
Large transaction amount
Outgoing structuring detected: 5 similar amounts totaling 166.27
Low transaction fee
Outgoing structuring detected: 4 similar amounts totaling 132.77
Transaction amount doubled compared to previous transaction
Outgoing structuring detected: 3 similar amounts totaling 99.37
Rapid accumulation of large transactions
Very short time between transactions
No tags
0x0f71f43…
55 High
Short time frame between transactions
Fan-in structuring detected: 3 similar amounts from different addresses totaling 0.00
High frequency transactions (less than 1 minute interval)
Rapid multi-hop layering pattern detected
Repetitive transaction amount
Low transaction fee
Part of coordinated wallet cluster
Very short time between transactions
Transaction amount significantly lower than average
No tags
0x3cd56a3…
62 High
Short time frame between transactions
Fan-in structuring detected: 3 similar amounts from different addresses totaling 0.00
Regular interval transactions between the same wallets
High frequency transactions (less than 1 minute interval)
Rapid multi-hop layering pattern detected
Repetitive transaction amount
Low transaction fee
Part of coordinated wallet cluster
Very short time between transactions
Transaction amount significantly lower than average
No tags
Showing 1 to 10 of 0 transactions

Advanced Analysis Findings

No Local Outlier Factor analysis data is available for this report.
No wallet community detection data is available for this report.
No transaction layering pattern data is available for this report.
No address clustering data is available for this report.
No sanctioned address connection data is available for this report.

Suspicious Activities

Suspicious Activities Summary: High Risk Activities: 23 Medium Risk Activities: 0 Total Flagged Transactions: 23 Pattern Categories: - Network-based anomalies - Behavioral inconsistencies - Statistical outliers - Temporal irregularities Automated Detection Results: - Algorithm coverage: Comprehensive - Detection confidence: High - Risk classification: Validated

Conclusions & Recommendations

Conclusions

Analysis Conclusions for 0x22c1d4debaa91fd08de109408f5ac8d5f171b96c: 1. Risk Assessment - Overall Risk Level: Very High - Standardized Risk Score: 100/100 - Average Transaction Risk Score: 53.87 - Total Suspicious Patterns: 23 2. Key Findings - Automated analysis completed successfully - Multiple detection algorithms applied - Comprehensive risk evaluation performed - Standardized scoring methodology applied (score: 100/100) 3. Confidence Level - Analysis Quality: High - Data Coverage: Complete - Algorithm Performance: Validated 4. Summary The automated analysis has identified significant concerns. Immediate action recommended.

Recommendations

Immediate Action Recommendations: 1. Priority Actions - Escalate to compliance team immediately - Implement enhanced monitoring - Consider transaction restrictions - Document all findings 2. Investigation Requirements - Detailed transaction review required - Source of funds investigation - Enhanced due diligence protocols - Regular monitoring updates 3. Compliance Measures - File suspicious activity reports if required - Implement know-your-customer procedures - Apply enhanced monitoring protocols - Document risk mitigation measures

Severity Assessment

Very High

Appendices & References

Appendices

Appendix A: Automated Analysis Results Appendix B: Algorithm Details and Methodology Appendix C: Risk Assessment Matrix Appendix D: Transaction Pattern Analysis Appendix E: Network Connection Analysis Appendix F: Case Reference Documentation - CLADIOUS-[BYBIT_HACKER_LAZARUS_ITER]-2025-001 Appendix G: Investigation Team Notes - Cladious Forensics Team

References

1. Blockchain Analysis Framework - Cladious Platform 2. Risk Assessment Guidelines - Financial Action Task Force (FATF) 3. Automated Analysis Documentation - Internal Methodology

Contact Information

Primary Analyst: Cladious Auto
Email: [email protected]
Generated: 2025-07-13 23:59:05 UTC
Investigation Team: Cladious Forensics Team
Case Reference: CLADIOUS-[BYBIT_HACKER_LAZARUS_ITER]-2025-001

Platform: Cladious Security Analysis Platform
For questions or additional analysis requests, please contact the investigation team.

This report contains confidential information and should be handled according to your organization's data protection policies.

Report Information

Author Cladious Auto
Published Date July 13, 2025
Views 9
Likes 0