A fake tax app. A drained crypto wallet. And a swift freeze that gave one victim a real shot at recovery.
When a victim's HashPack wallet was drained through a fake tax application, ChangeNOW's AML systems caught the funds mid-transfer. What followed was a swift cooperation with the FBI that ended with the assets successfully handed over to investigators.
Incident Overview
The victim downloaded what appeared to be a legitimate tax preparation application. It wasn't. The app was a spoofed lookalike, designed to mimic a trusted tool and trick users into installing malware. Once on the device, it gained access to the victim's HashPack wallet credentials and drained the funds.
HashPack is a widely used non-custodial wallet for the Hedera (HBAR) network. The attacker made off with 497,000 HBAR and quickly began moving the funds to obscure their origin.
Early Detection and Fast Action
Shortly after the theft occurred, ChangeNOW received intelligence flagging the addresses associated with the stolen funds. Our AML team acted immediately:
- The flagged addresses were added to our internal blocklist
- Incoming transactions from those addresses were placed under monitoring
- A large transfer attempt, approximately $44,498.90 USD worth of HBAR, was identified and held before it could be completed
The speed of the response was critical. Stolen funds that pass through exchanges undetected are often broken up and converted within hours, making tracing extremely difficult.
Cooperation with the FBI
After the funds were secured, we notified the reporting source that assets had been frozen pending further action.
Shortly afterward, an FBI representative contacted us with a formal seizure request.
Following all necessary reviews and compliance checks in accordance with our AML/KYC procedures and law enforcement guidelines, the funds were successfully transferred to the FBI. We're glad this case had an outcome that gave the victim a real chance at recovery, and we're proud to have been part of making that happen.
How the Attack Worked: Spoofed Apps and Wallet Drainers
This type of attack is more common than most people expect, and it's effective precisely because it targets human behavior rather than blockchain infrastructure.



