ChainCatcher reported that on-chain investigator ZachXBT published a case analysis involving crypto assets connected to an Indian scam group. In the case, individuals linked to the matter reportedly approached law enforcement after their assets had been frozen, a detail that made the incident stand out. The case began when a user contacted ZachXBT for help, claiming that about 5.73 BTC had been frozen at Changelly in March 2025. The amount was estimated in the source at roughly $475,000.
Frozen 5.73 BTC Traced to Theft-Related Activity
According to the on-chain analysis described in the case, the funds were not treated as an isolated transfer. The transaction history was traced back to multiple social engineering attacks targeting users in the United States, as well as thefts connected to Bitcoin ATMs. The total amount involved across the related cases had exceeded $1 million, and several elderly victims were among those affected.
The investigation also noted that the user’s explanation for the source of funds changed more than once. Different accounts included claims that the funds came from a “loan,” a “boss transfer,” and an “investment from 2014–2015.” ZachXBT’s analysis said these explanations conflicted with the available materials, leaving clear inconsistencies in the evidentiary chain.
Police Report in India and Mule Allegation
One of the more unusual elements was that the same user filed a police report in India in December 2025 in an attempt to recover the frozen funds. The case number cited was 3207-P/2025. In other words, after the assets were frozen, the relevant party attempted to use a law enforcement channel to seek the return of the funds.
Further on-chain forensics and email data analysis indicated that the user was considered to be possibly acting as a “mule,” or a funds mover, within the transfer chain. The case analysis also said that some bank documents did not match the user’s identity information. ZachXBT said cases of this type show that social engineering attacks and cross-border fund transfers are still taking place, and he warned users to avoid interacting with funds from suspicious sources in order to reduce the risk of compliance freezes or legal exposure.

