With crypto hacks on the rise, stealing millions or even billions, blockchain forensics is crucial for ensuring transparency and traceability in this largely anonymous space. Using investigative tools, analysts can track illicit transactions, identify malicious actors, and assist law enforcement in recovering stolen assets.
In the crypto space, one of the most well-known names in web3 investigations is ZachXBT, a renowned blockchain investigator and on-chain sleuth. He is known for exposing scams, hacks, and fraudulent activities.
In this article, BitPinas will expound on the tools ZachXBT shared as his personal toolkit for tracing wallets, analyzing on-chain data, performing OSINT, and more.
Who is ZachXBT?

ZachXBT has been an anonymous blockchain investigator since 2021, known for exposing crypto scams, tracking stolen funds, and holding fraudsters accountable. As a victim of crypto fraud himself, he turned to blockchain’s transparency and his pattern-recognition skills to track down Ponzi schemes, phishing schemes, pump-and-dumps, and rug pulls.
Often called the “Sherlock Holmes of crypto,” he uses blockchain analytics and social media intelligence to uncover fraudulent projects. Frequently working for free as a “crypto fighter for the people,” ZachXBT primarily relies on donations, reportedly earning around $1.3 million a year. However, in August 2024, he took his first paid case, helping authorities track down cybercriminals who stole $243 million in Bitcoin—solving the case within a month.
Despite his impact, ZachXBT remains anonymous. Currently, ZachXBT has 838.7K followers on X and 73.6K subscribers on Telegram.
Notable Investigations
- BitBoy Crypto
- Exposed influencer Ben Armstrong (BitBoy) for allegedly promoting scam projects for hefty fees, some up to $40,000. Many of these projects collapsed shortly after his endorsement.
- Logan Paul
- Investigated Paul’s involvement in pumping and dumping low-market cap coins like ElonGate and DinkDoink. He also highlighted the failure of Paul’s NFT project, CryptoZoo, which stalled despite raising over $1 million.
- Bored Ape Phishing Scam
- Tracked down a five-person phishing ring that stole over $2.5 million worth of Bored Ape Yacht Club (BAYC) NFTs.
- His research contributed to real-world arrests by French authorities.
ZachXBT has also shared a list of 34 NFT projects he investigated.
Wallet Tracking and Transaction Analysis

- Cielo
- TRM Labs
- Creates graphs for addresses and transactions, identifying relationships and transaction flows.
- Tool link: https://www.trmlabs.com/
- MetaSleuth
- Arkham
- Multi-chain block explorer with entity labels, alert creation, and visual graphs.
- Tool link: https://intel.arkm.com/
Enhanced Blockchain Data Viewing

- MetaSuites
- Etherscan/Solscan
- Block explorers for Ethereum and Solana.
- Tool link:
- Blockchair
Bridge and Cross-chain Tracking

Blockchain Data Analytics

- Dune Analytics
- Platform for querying blockchain data sets to identify trends, transactions, and wallet histories.
- Tool link: https://dune.com/
Open-Source Intelligence (OSINT)

- OSINT Industries
- LeakPeek & Snusbase & Intelligence X
- Databases for leaked information searches.
- Tool link:
- Spur
- Cavalier by Hudson Rock
- TelegramDB Search Bot
- Discord.ID:
Historical and Archival Tools

- Wayback Machine & Archive Today
- Tools to archive web pages for future reference.
- Tool link:
- Mugetsu
Utility and Workflow Management

- Obsidian
- Software for creating detailed flow charts and diagrams to visualize investigative findings.
- Tool link: https://obsidian.md/
- CryptoTaxCalculator
Security and Testing

By applying these tools, users can improve their security, make informed decisions, and contribute to a safer blockchain ecosystem.
For Beginners:
- Track Wallets Easily – Use MetaSleuth or Cielo to follow wallet transactions across multiple chains and detect suspicious activity.
- Analyze Transactions – Start with Etherscan or Solscan to view blockchain transactions and understand how funds move.
- Check for Scams – Use OSINT Industries to verify usernames, emails, or phone numbers before engaging in crypto deals.
- Basic Security Check – Use Impersonator to test dApp security before connecting your wallet.
For Advanced Users:
- Deep Blockchain Analysis – Use TRM Labs or Arkham to conduct in-depth transaction mapping and entity tracking.
- Cross-Chain Investigations – Leverage Pulsy or Socketscan to analyze fund movements across different blockchains.
- Big Data Insights – Query blockchain datasets using Dune Analytics to detect trends and anomalies.
- Cybersecurity Investigations – Utilize LeakPeek, Snusbase, and Spur to check for leaked credentials and potential security threats.
- Visualize Investigations – Organize findings with Obsidian to create structured reports and flowcharts.
Conclusion
ZachXBT has played a crucial role in exposing crypto fraud, setting a high standard for transparency in blockchain investigations. His work has not only uncovered scams but also empowered the community by openly sharing investigative tools and techniques.
By using these tools responsibly, both beginners and advanced users can enhance their security, track suspicious activity, and contribute to a safer crypto ecosystem.
As blockchain adoption grows, community-driven investigations will remain essential in holding bad actors accountable and strengthening trust in the space.
Disclaimer
In his Telegram announcement where he shared these tools, ZachXBT explicitly stated that he has no financial incentives, sponsorships, or referral links associated with the tools mentioned. He emphasized that his recommendations are purely based on their utility in blockchain investigations.
Users should conduct their own research and exercise caution when using these tools.
This article is published on BitPinas: ZachXBT Shares the Full List of Tools Used for Blockchain Investigations
What else is happening in Crypto Philippines and beyond?