On-chain investigator ZachXBT has linked an operator using the online handle M1llionz to the laundering of $667,000 stolen in two violent home invasion robberies in France in April 2026, in an investigation he says produced a Tether freeze of 93,507.51 USDT.
M1llionz and RichMilly666 are handles used across Telegram and TikTok accounts. No arrest, charge, or conviction has been announced in connection with either robbery.
The Two Incidents
ZachXBT said five attackers carried out a home invasion in France on April 17, 2026, taking approximately 7.2 BTC, which he valued at $557,000. He identified the theft address as bc1qrdq5acl9nw4gt3cjte2629lw9qcg9xxkf3x02k and said several people were hospitalized.
On April 20, 2026, ZachXBT said multiple attackers bound and threatened a second victim until roughly $110,000 in crypto was surrendered from the address 0x3000d2a2ef9bd8b614b368408768a6e25bf4de0f.
The Crypto Times has not independently verified either incident with French authorities. No charges have been announced in connection with either robbery, and the individual named in the thread has not been arrested or convicted.
How the Funds Moved
The April 17 proceeds were bridged from Bitcoin to Ethereum through Chainflip, according to ZachXBT, with $317,000 subsequently routed through three KuCoin deposit addresses. He said he matched corresponding withdrawals through timing analysis, arriving at a consolidation address, 0xe744d8890792eb4b51ac6565e3d409076b62b302. A further portion was converted to Monero through two instant exchanges and Wagyu.
The April 20 proceeds followed a comparable path. ZachXBT said roughly 46 ETH, valued at $107,000, passed through a KuCoin deposit address, with the matching withdrawal landing at 0x5fb7194cc893cdc8339fa1bd7e8b52cdb3d3d075 and again consolidating at 0xe744. ZachXBT has previously published findings on stolen funds moving through KuCoin deposit addresses opened with purchased mule KYC
Timing analysis matches deposits to withdrawals by correlation rather than by direct on-chain linkage, and its conclusions are inferential where an exchange sits between the two legs.
The Tether Freeze
Approximately $108,000 moved from 0xe744 to 0x3c4f6ca9bea79432eaf8d98c3be4570064f1fde8, where ETH was swapped for USDT, ZachXBT said. He noted that the address had been funded for gas by 0x7e73, the April 20 victim address—the link he used to tie the swap back to the theft.
ZachXBT said he reported the movements to Tether and to law enforcement. A monitoring bot record shows 0x47967fe27f07fb54e9f4daa2541c0f75e27ddde7 blacklisted on April 24, 2026, at 13:09:11 UTC, carrying a balance of 93,507.51 USDT on ERC-20. Tether has not issued a public statement on the freeze.
The Channel and the Accounts
ZachXBT said the operator runs a Telegram channel named EMPIRE, with channel ID 2401432371 and user ID 8051285277, which openly advertises bank fraud services. Screenshots reviewed by The Crypto Times show posts soliciting accounts at named French retail banks, messages recruiting what the operator describes as spammers and scammers, and a post offering payment for what it calls physical accounts.
According to ZachXBT, wallets displayed in that channel received approximately $84,000 traceable to the robberies. He cited three instances: an Exodus address posted on March 12 that later received 1.44 ETH linked to the April 17 incident; a video posted June 8 showing an outbound transfer of 22.37 ETH connected to the April 20 incident; and screenshots posted June 11 showing an address that had received roughly 12.28 ETH from the consolidation address on May 9.
ZachXBT said he conducted open-source analysis and identified several email addresses and aliases he described as potentially associated with social media accounts linked to M1llionz. The aliases he listed are Mamane Kante and Yadali Kouyate. A relationship graph he published also maps accounts on TikTok, Instagram, Snapchat, Dropbox, PayPal, and Microsoft services to a common email address, with names including Daouda Danso and Jeremy Lefevre appearing against individual services.
ZachXBT did not state that he had confirmed the identity behind the accounts and characterized the linkage as potential. No arrest, charge, or conviction has been announced in connection with either robbery, and the presumption of innocence applies to every person named.
ZachXBT said the accounts have gone quiet in recent weeks, and the associated TikTok profile was set to private. He said he has identified two further attacks within two hops of the same OTC addresses.
Context
France recorded a series of violent incidents targeting crypto holders through 2026. In March, a couple in Le Chesnay near Paris were forced to transfer roughly €900,000 in bitcoin to attackers posing as police officers, according to the Versailles prosecutor’s office. In February, three suspects were arrested after a home invasion attempt targeting Binance France head David Princay.
ZachXBT disclosed on April 22 that he had worked with Binance’s security team to freeze approximately $800,000 of a $2 million ransom paid in the 2023 kidnapping of French streamer TeufeurS’s father, in which six suspects were later arrested.
Also Read: France Unveils Crypto Security Plan After 77 Kidnapping Cases in H1 2026
