Blockchain investigator ZachXBT says he helped freeze roughly $800,000 in ransom proceeds after French streamer TeufeurS paid about $2 million in cryptocurrency to secure the release of his father, who was kidnapped in France in 2023. According to the disclosure, the recovery effort was carried out in coordination with Binance Security, and the case remained private for an extended period because of its sensitivity.
How the kidnapping unfolded
The abduction took place in August 2023 in Sarthe, a department in northwestern France. The attackers reportedly approached the victim while posing as Amazon delivery workers, then forced him into a vehicle. During the captivity, TeufeurS’s father was filmed at gunpoint, and the footage was sent directly to the streamer as pressure to make a ransom payment.
TeufeurS ultimately transferred around $2 million in crypto to obtain his father’s release. The case illustrates how digital assets can be used in extortion schemes that move quickly across wallets and jurisdictions, complicating traditional law enforcement response times.
Tracing and freezing the ransom funds
ZachXBT later said on X that he worked with the Binance Security team to track the ransom onchain and coordinate a freeze of approximately $800,000. In crypto-related extortion cases, ransom funds are often dispersed rapidly through multiple addresses, making any meaningful intervention difficult once the transfer is complete. Against that backdrop, freezing a substantial portion of the payment stands out as a notable result.
The investigator also indicated that the matter had not been discussed publicly earlier because of the risks tied to an active and highly sensitive criminal case. French authorities have since arrested six suspects connected to the kidnapping. Public reporting suggests fuller details of the case first emerged in April 2026.
France’s growing exposure to crypto-linked violent crime
The TeufeurS case is part of a wider pattern in France, where criminals have increasingly targeted people believed to hold significant digital assets. Reports cited in the source material say attackers often identify victims through social media visibility, public status, or other signals of wealth. The resulting crimes range from direct robbery attempts to organized kidnappings designed to force immediate crypto payments.
Local agencies have reportedly recorded more than 40 kidnappings and abductions tied to crypto since the start of this year, compared with 30 cases documented in 2025. The trend suggests that as crypto ownership becomes more visible, operational security is becoming a real-world issue rather than only a digital one.
Other incidents mentioned in the report reinforce that concern. In February, three armed suspects allegedly attempted to target Binance France head David Princay. In March, a couple reportedly suffered a home invasion and were forced to hand over €900,000—about $1 million—in bitcoin to attackers impersonating local authorities.
The role of onchain investigators
ZachXBT has become one of the most visible figures in the overlap between blockchain forensics and criminal investigations involving digital assets. His work in this case highlights how private-sector tracing and exchange compliance teams can sometimes help disrupt illicit fund flows after an incident has already occurred.
At the same time, he has noted separately that he generally avoids cases in jurisdictions where cooperation with law enforcement is limited and asset recovery is close to impossible. That comment underscores a broader reality: the effectiveness of tracing and freezing stolen or extorted crypto still depends heavily on timing, exchange involvement, and the willingness of authorities to act.
For the crypto industry, the case is another reminder that the risks associated with digital wealth are no longer limited to hacks, phishing, and protocol exploits. In some environments, public visibility around holdings can translate into physical danger. The combination of onchain transparency and offline coercion has created a new class of threat—one where wallet security, personal privacy, and real-world safety are increasingly interconnected.

