Key Highlights
- About $1 million in stolen Walix-Wallet crypto has reportedly been moved through different infrastructures linked to Xhash.cash and NEAR Intents.
- Three Solana addresses were identified, while some related transactions were reportedly blocked or suspended.
- Match Systems said it is still tracing the stolen funds.
Around $1 million worth of cryptocurrency stolen in the Walix-Wallet hack that happened on July 25, 2026, may have moved through systems potentially linked to Xhash.cash and NEAR Intents, according to blockchain analysis shared with The Crypto Times by Match Systems.
The company, which helps in recovering stolen crypto funds, said that stolen funds moved across several blockchains as investigators followed their trail.
More than $1M in stolen crypto funds were traced
Match Systems said the attack led to theft of several million dollars worth of crypto assets. The company found that more than $1 million of the stolen assets may have passed through infrastructure associated with Xhash.cash, a crypto exchange service that allows users to convert different cryptocurrencies into Monero (XMR).
According to their on-chain analysis, the transaction pattern appears consistent with the way Xhash.cash may process “Any Crypto → XMR” swaps. In this process, deposits may first pass through addresses connected to NEAR Intents using its 1Click API.
After the deposits and cross-chain swaps, the assets were moved through Solana addresses that Match Systems said appear to be connected to Xhash.cash.
Match Systems identifies three different addresses with tags “2WJ98iXf8DwBzhQeL6zsXq9Tze8VjN6zNUijHAdrPCrJ, BTm25S9wbLdvU64K5dGBPsAVxnPRhSJnPB3XCf6mq6bc and 2giAscgqYx8U5teiQ78NrmmcmYJHFGHtZofe8kBW9nhX.”
The company said the assets were later sent from these addresses to several centralized crypto exchanges that support Monero trading pairs.
This means the funds did not simply move from one wallet to another. Instead, the trail crossed several networks and services before reaching other wallets and exchanges.
Why the funds became harder to track
Match Systems said this type of movement can make stolen crypto harder to track. Assets can enter through different blockchains, move through cross-chain swap services and then pass through privacy-focused conversion services before reaching another destination.
However, the findings do not establish that Xhash.cash or NEAR Intents knowingly took part in the theft or knowingly helped move stolen funds. The information shared with The Crypto Times only attributes the identified transaction pattern and infrastructure links to Match Systems’ blockchain analysis.
Some transactions are already blocked
The investigation has also helped block further movement of the funds. Match Systems said it worked with law enforcement agencies to identify the addresses involved.
It said these three found addresses have already been labeled on blockchain analytics platforms and added to blocklists used by NEAR Intents. Following the action, Match Systems said some transactions connected to infrastructure potentially linked to Xhash.cash have started to be blocked or suspended within NEAR Intents.
One recent transaction involving about 5 BTC has remained in “PROCESSING” status for more than three days, according to Match Systems. The company said the transaction status can be checked through the NEAR Intents 1Click API.
Investigation into the stolen funds continues
Match Systems said its work on the case is still continuing. The company is now looking for other services and infrastructure that may have been used along the route while trying to trace the stolen assets to their final destinations.
The Crypto Times has reached out to Walix-Wallet for comment on the hack and the findings shared by Match Systems, and is awaiting a response from them.
Meanwhile, the Walix case comes as crypto security losses remain high across the industry. Blockaid’s first-half 2026 security report said there are already about 212 on-chain exploits and more than $1.1 billion in losses during the first six months of the year.
The report also found that governance and process failures are playing a bigger role in crypto attacks, which means some losses are linked to weaknesses in how projects manage access, permissions and important decisions.
Several major attacks this year have also involved infrastructure used to move or manage crypto. KelpDAO lost $292 million in a bridge drain, while AFX Trade lost about $24.15 million after an attack involving a third-party bridge. B² Network also lost about $3.86 million after an attacker gained control of the upgrade authority over its staking contract.
So far, the investigation remains ongoing, with Match Systems continuing to look for other services and infrastructure that may have been used along the route and to trace the stolen assets to their final destinations.
Also Read: XRP Whales Accumulate 72M Tokens as Price Trades Near $1
