At 23:07:55 UTC on January 10, 2026, the Litecoin blockchain recorded a transaction sending approximately 1.831 million LTC into an address later identified by blockchain investigator ZachXBT as part of a major wallet theft. Whale Alert’s transaction record valued that transfer at approximately $148.49 million using a displayed Litecoin price of $81.08.
The transaction became part of a larger cluster that ZachXBT publicly described on January 16. The investigator said three addresses received a combined 2.05 million LTC and 1,459 BTC in a hardware-wallet social-engineering scam, estimating the assets’ aggregate value at more than $282 million.
The distinction between those two records is essential. The blockchains verify that the transactions occurred and show their assets, addresses and confirmation history. They do not independently establish who controlled the addresses, whether the transfers were authorized or how access was obtained. The theft and social-engineering characterizations depend on subsequent investigative attribution rather than information encoded in the transactions.
What the ledgers establish
The identified Bitcoin addresses are publicly inspectable through Bitcoin block explorers, while the Litecoin transaction has the hash beginning `8d29bb42` and a January 10 timestamp. These records make the asset movements reproducible without relying solely on a news report.
Whale Alert’s approximately $148.49 million valuation applies only to the identified 1.831-million-LTC transaction at its recorded time. Its displayed $81.08 price is rounded, and the page does not provide a consolidated market-wide pricing methodology. Cryptocurrency prices vary by venue, pair and moment, so the figure is a transaction-page estimate rather than an audited dollar loss.
The broader $282 million figure is ZachXBT’s January 16 estimate for 2.05 million LTC and 1,459 BTC. The investigator did not publish a complete valuation calculation or specify the exact exchange prices and timestamps used. Coinburn therefore treats $282 million as an attributable estimate, not a precisely reproducible accounting value.
Why the incident mattered
The available record did not identify a defect in Bitcoin, Litecoin or a hardware wallet’s cryptographic implementation. Instead, ZachXBT attributed the loss to social engineering involving a hardware wallet. That distinction separates compromise of a person’s credentials or decisions from exploitation of consensus code or a smart contract.
Hardware wallets are designed to keep signing keys isolated from an internet-connected computer. They cannot protect funds if an attacker obtains the wallet backup or persuades its owner to authorize a malicious transfer. The incident consequently illustrated a central limitation of self-custody: strong cryptography can secure keys against technical extraction while leaving the owner exposed to impersonation and manipulation.
The scale also made the transfers relevant beyond one unidentified holder. Moving large quantities through instant exchanges can strain available liquidity, while cross-chain routing complicates tracing and recovery. ZachXBT reported that the actor converted Bitcoin and Litecoin into Monero and routed some Bitcoin through THORChain. Those routing claims were reported after January 10 and were not independently visible in full because Monero obscures transaction details.
What was knowable on January 10
On January 10, observers could verify the public-chain transfers, including the large Litecoin transaction shortly after 23:00 UTC. The surviving record does not show that the recipient addresses had been publicly labeled as theft addresses that day. No contemporaneous victim statement, law-enforcement finding or hardware-wallet provider report reviewed for this reconstruction established the alleged attack method on January 10.
Accordingly, the event-day record supports describing unusual, exceptionally large asset movements—not asserting that a confirmed theft was already public knowledge.
Later context
ZachXBT disclosed the alleged theft on January 16, and subsequent coverage connected the transfers with large Monero conversions. Hacken’s later first-quarter security report classified a $282 million incident as social engineering rather than a code exploit. That later analysis clarifies the January 10 transfers but does not change what market participants could verify on the event date.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

