Odaily reported that on-chain investigator ZachXBT published a case analysis involving an alleged Indian scam group and a frozen crypto asset trail. The unusual detail in the case is that after the assets were frozen, the relevant person reportedly filed a police complaint with law enforcement in an attempt to trace and recover the frozen funds. The case began when a user contacted ZachXBT for help, saying that about 5.73 BTC had been frozen at Changelly in March 2025. The amount was described as being worth roughly $475,000.
Frozen 5.73 BTC Traced to Multiple Social Engineering Cases
According to ZachXBT’s on-chain analysis, the frozen funds were not presented as a simple or isolated transfer. The asset trail was traced back to multiple social engineering attacks targeting users in the United States, as well as theft cases connected to Bitcoin ATMs. The total amount involved in the broader set of cases has exceeded $1 million, and the victims included several elderly individuals. ZachXBT used the case to show how frozen exchange funds, victim-linked transfers, and cross-border asset movement can appear in the same investigative chain.
The investigation also found that the person’s explanation of the source of funds changed several times. The stated sources included “loans,” “transfers from a boss,” and “investments from 2014–2015.” However, ZachXBT said the evidence chain contained clear contradictions. The shifting explanations did not align cleanly with the on-chain fund flow and the information presented through email data analysis.
Police Report in India and Conflicting Identity Materials
A further point in the case was that the user had filed a police complaint in India in December 2025 to try to recover the frozen funds. The case number was listed as 3207-P/2025. This meant the person who claimed to be seeking help over the frozen assets had also used a local police process to pursue the same funds, moving the matter from blockchain tracing into offline law-enforcement records.
Follow-up on-chain forensics and email data analysis indicated that the user was suspected of acting as a “mule,” or a fund mover, in the transfer chain. ZachXBT also said that some bank documents did not match the person’s identity information. He stated that cases of this type show social engineering attacks and cross-border fund transfers are still taking place, and reminded users to avoid interacting with funds from suspicious sources in order to reduce the risk of compliance freezes or legal exposure.

