ZachXBT Latest Survey: How Did 'Fortnite' Esports Pros Use a Meme Scam to Steal $3 Million?
Original Author: zachxbt, On-chain Detective
Original Translator: zhouzhou, BlockBeats
Editor's Note: This article analyzes how the hacker Serpent took control of accounts belonging to McDonald's, Kabosu, and others on X and Instagram, initiated a Meme Coin scam, stole approximately $3.5 million, and used it for casino gambling. Serpent was a professional player of "Fortnite" who was dropped due to cheating. In 2022, a rug pull occurred in the NFT project DAPE, co-founded by him. In 2024, the ERROR project he launched also faced a rug pull and was ultimately banned by X.
The following is the original content (slightly reorganized for better readability):
Over the past few months, I have been tracking a series of related data breaches involving McDonald's, Usher, Kabosu's owner, Andy Ayrey, Wiz Khalifa, SPX 6900, etc., which resulted in approximately $3.5 million in theft through the release of Pump Funmeme Coin.

On August 21, 2024, McDonald's Instagram account was hacked, and a promotional post for the meme coin GRIMACE was published, after which the hacker began to engage in mischief. Over $690,000 was transferred to two wallets from this pump and dump event.
4RiNhTwBxYWgb4MSCtt9vXgVk2yuPhoQR3DR9pMVPU1W
2vjnmxwTYNJvTmFhtqxZkPiuCHkaKZK5rcxTLuoC2dPB

On September 3, 2024, the McDonald's attacker moved 101.5 SOL to two addresses, and after actor Dean Norris's X account was compromised by the hacker, these two addresses were deployed to and targeted SCHRADER.

4s9Uz9pTBXcEaEtcjs8eg98r2TVte3rq3JUm3rVTFMudfewGbNKmqNyYs9bSAMDUaTbTcuA1v39sWr7GRqkDJ6EM
1gxo1pjTqjbee7rHW4cGvuNffX1qP4F8fP17g6SSC5EYbQrnktDrKSFB1uh4ju7PxQjprWFin37WUsAe225b9c6

On September 6, 2024, funds from a McDonald's APT (Account Takeover) were transferred to a casino deposit address.
CuNzegC9DE4CxCMn31ZcYLvtDaYsLD9RX8eRvmtZQrnB
Through timeline analysis, subsequent withdrawals shortly after the deposit can be identified.
B2fwZt5nTbdrnJ2CPsgrYMPuB4UnhN82EAM34dXDARLh

On September 12, 2024, B2fw transferred 110 SOL to two addresses involved in a meme coin presale promoted during the Usher leak event.
4FUrwoHz1fuUf4eR6YEAYSG9d9rN5fzbowMXtbjwJAhTDtHXjpnTb1sz6aeF6T79JaiMFyT2xX2EuTxqT5UhFfKD
427zpHF1WWgYgKxcSiUzwXLg2UqsF6xq7K13PU3mh6Wr99mipiVA6GcDTwi7EY93RJeRuEUDZAK9BnoMeki7sU6C

Subsequently, B2fw transferred 4868 SOL to the casino deposit address ECb5v, which is directly linked to other APT events, including the Andy Ayrey and Enoshima Aquarium leaks.
Ecb5vsomUG3MEnLCgiFvkdnnqpggTEXtN17z62iDPuU3

On October 15, 2024, Enoshima Aquarium's X account was breached, promoting a bundled meme coin. On the same day, 84 SOL obtained from this scam was transferred to ECb5v.
5PDjh74JTLMPW4dXr6fKm3Yue2j3vhbxLSK5dPbQ3oEGK4axE7fua1ngBMas4xpRY6dBr92Ccps7b1WwcLdnxXWL

On October 29, 2024, Andy Ayrey (Founder of Truth Terminal) had his X account compromised, which lasted for several days and promoted 6 meme coin scams. 3GVUs was one of the addresses involved in buying the tokens.
3GVUs2gNr161ohqnVXjUeoNQmf3cELxKSiPrxyQu6pjd
On October 30, 2024, 3GVUs transferred 169 SOL to Ecb5vs.
67nwsLLE3aGua4VeH8p6qHc3SL3rpxi9omMxRnfpeyZVsBpZawnUHo4Pt4tdT5Vxny2uRNRDH3vSZ1fzvKkNCML4

Out of the $2.178 million obtained from Andy Ayrey's ATO, $750,000 was deposited into a casino deposit address Apc3e.
Apc3eA9ScQksuZvfURQswZwVkusEYRaqeKEv4eXXbRZm
0.1 SOL from the Kabosu ATO funded an address that participated in the Andy Ayrey ATO.

On October 17, 2024, the owner of Kabosu's Instagram account was hacked and promoted a meme coin scam.
That day, 191 SOL from the scam was transferred to a casino deposit address:
6kwZ7tz8Xs7jaVqVJXZSRrZ2FtS2PPChEVuLXKrmMgCm

The APT (Account Takeover) events of Kabosu and Andy Ayrey are directly related to Wiz Khalifa's APT event.
On November 3, 2023, an attacker posted a wallet address on Wiz Khalifa's account. 29 SOL was transferred to 6kwZ7, similar to what happened in the Kabosu ATO.
NFCs23ddXQc9Zff2VJotEn2zaSAh4tvw6U6kb7fdXovZ8YPQgJMGQkXmtWiTutqnoBf6wR2khaKvFpyEKNhHfjJ

WIZ's deployer funds came from Andy Ayrey's ATO. Other addresses involved in the exploit redirected all gains obtained through instant swaps to a casino deposit address 0x83ee.
0x83ee6b53a0ae76b71bed0c32721a451776dbdb3a

On October 16, 2024, 0x83ee received 0.54 ETH from the scam's deployer, while SPX 6900 was compromised on October 11, 2024.
On Solana, another scam promoted by the compromised SPX 6900 account received backing from the Ken Carson attacker.

To further demonstrate the relationship between Kabosu's owner, SPX 6900, Ken Carson, and Enoshima ATO, each meme coin's deployer provided funds to the previous deployer's address through instant swap funds, attempting to obscure the origin of the funds.

Investigate how threat actor Serpent transitioned from a professional Fortnite player to aiding in a memecoin scam initiated through leaks from 9+ accounts on X and IG to steal $3.5M and use the proceeds for online casino gambling.

Serpent (SerpentAU) is a former professional Fortnite player from Australia, who was released by the esports organization "Overtime" in June 2020 after being found cheating. He then co-founded the NFT project DAPE in March 2022, which later rug-pulled.

In March 2024, Serpent launched another project called ERROR, but the project rug-pulled, leading to his ban from platform X.
Deployer Address:
0x8233873ee35547097ccb9098adbab955d7120ee8

On October 23, 2024, the ERROR deployer moved a total of 29 ETH to two instant exchanges.
Through time analysis, it was observed that these funds were received on Solana and transferred to the same gambling deposit address.
Ecb5vsomUG3MEnLCgiFvkdnnqpggTEXtN17z62iDPuU3

Multiple ATO (Aggressive Transaction Outcomes) directly linked to the deposit address Ecb5vs include: McDonald's, Usher, Andy Ayrey, Dean Norris, and Enoshima Aquarium. (For detailed tracking, please refer to the beginning of the document.)

Serpent gambles monthly on Roobet, Stake, BC Game, and Shuffle with stakes of millions of dollars, often screen sharing with friends on Discord.
I obtained recordings of his gambling sessions, where he inadvertently disclosed multiple deposit and withdrawal addresses.
Discord ID: 1269557350486904945

During a screen sharing session on November 1, 2024, Serpent shared a $100K deposit and $200K withdrawal, transferred to the following address.
When plotting the transaction graph, it was discovered that this address had high exposure to addresses associated with McDonald's, Andy Ayrey, and Usher ATO.
0xb8c9c8a5756a7992df65f949b7c1423eeb435aa5

During Andy Ayrey's security breach incident, another threat actor participated in hijacking these fraudulent projects, using the alias "Dex" (from Massachusetts, USA).
After I mentioned him in my Telegram channel last week, he started to panic and fabricated a story about being extorted, claiming to have lost $700K. 
The funds currently related to these security breaches are stored in the following addresses:
0xeb60a5242c1c97eb54195ec83de43bb26813c0d1
0x2355ac2929bb7051814de3c48670fccbb515d8be
4jjWZ8RaXZBqntnhu2JFidXEQWXgfKRbJQZdTHrdaqbv
Today, following the release of the first part of my investigation, Serpent started deleting all his posts on the new X account. I suspect there are still some ATO (Attack Transaction Activity) incidents related to this that I have not been able to directly trace on-chain. Regarding one of the breached accounts, I have shared a detailed investigation report with one of the victims I am collaborating with.

You may also like

Russia’s Largest Bitcoin Miner BitRiver Faces Bankruptcy Crisis – What Went Wrong?
Key Takeaways BitRiver, the largest Bitcoin mining operator in Russia, faces a bankruptcy crisis due to unresolved debts…

Polymarket Predicts Over 70% Chance Bitcoin Will Drop Below $65K
Key Takeaways Polymarket bettors forecast a 71% chance for Bitcoin to fall below $65,000 by 2026. Strong bearish…

BitMine Reports 4.285M ETH Holdings, Expands Staked Position With Massive Reward Outlook
Key Takeaways BitMine Immersion Technologies holds 4,285,125 ETH, which is approximately 3.55% of Ethereum’s total supply. The company…

US Liquidity Crisis Sparked $250B Crash, Not a ‘Broken’ Crypto Market: Analyst
Key Takeaways: A massive $250 billion crash shook the cryptocurrency markets, attributed largely to liquidity issues in the…

Vitalik Advocates for Anonymous Voting in Ethereum’s Governance — A Solution to Attacks?
Key Takeaways Vitalik Buterin proposes a two-layer governance framework utilizing anonymous voting to address collusion and capture attacks,…

South Korea Utilizes AI to Pursue Unfair Crypto Trading: Offenders Face Severe Penalties
Key Takeaways South Korea is intensifying its use of AI to crack down on unfair cryptocurrency trading practices.…

Average Bitcoin ETF Investor Turns Underwater After Major Outflows
Key Takeaways: U.S. spot Bitcoin ETFs hold approximately $113 billion in assets, equivalent to around 1.28 million BTC.…

Japan’s Biggest Wealth Manager Adjusts Crypto Strategy After Q3 Setbacks
Key Takeaways Nomura Holdings, Japan’s leading wealth management firm, scales back its crypto involvement following significant third-quarter losses.…

CFTC Regulatory Shift Could Unlock New Opportunities for Coinbase Prediction Markets
Key Takeaways: The U.S. Commodity Futures Trading Commission (CFTC) is focusing on clearer regulations for crypto-linked prediction markets,…

Hong Kong Set to Approve First Stablecoin Licenses in March — Who’s In?
Key Takeaways Hong Kong’s financial regulator, the Hong Kong Monetary Authority (HKMA), is on the verge of approving…

BitRiver Founder and CEO Igor Runets Detained Over Tax Evasion Charges
Key Takeaways: Russian authorities have detained Igor Runets, CEO of BitRiver, on allegations of tax evasion. Runets is…

Crypto Investment Products Struggle with $1.7B Outflows Amid Market Turmoil
Key Takeaways: The recent $1.7 billion outflow in the crypto investment sector represents a second consecutive week of…

Why Is Crypto Down Today? – February 2, 2026
Key Takeaways: The crypto market has seen a downturn today, with a significant decrease of 2.9% in the…

Nevada Court Temporarily Bars Polymarket From Offering Contracts in the State
Key Takeaways A Nevada state court has temporarily restrained Polymarket from offering event contracts in the state, citing…

Bitcoin Falls Below $80K As Warsh Named Fed Chair, Triggers $2.5B Liquidation
Key Takeaways Bitcoin’s price tumbled below the crucial $80,000 mark following the announcement of Kevin Warsh as the…

Strategy’s Bitcoin Holdings Face $900M in Losses as BTC Slips Below $76K
Key Takeaways Strategy Inc., led by Michael Saylor, faces over $900 million in unrealized losses as Bitcoin price…

Trump-Linked Crypto Company Secures $500M UAE Investment, Sparking Conflict Concerns
Key Takeaways A Trump-affiliated crypto company, World Liberty Financial, has garnered $500 million from UAE investors, igniting conflict…

Billionaire Michael Saylor’s Strategy Buys $75M of More Bitcoin – Bullish Signal?
Key Takeaways Michael Saylor’s firm, Strategy, has significantly increased its Bitcoin holdings by acquiring an additional 855 BTC…
Russia’s Largest Bitcoin Miner BitRiver Faces Bankruptcy Crisis – What Went Wrong?
Key Takeaways BitRiver, the largest Bitcoin mining operator in Russia, faces a bankruptcy crisis due to unresolved debts…
Polymarket Predicts Over 70% Chance Bitcoin Will Drop Below $65K
Key Takeaways Polymarket bettors forecast a 71% chance for Bitcoin to fall below $65,000 by 2026. Strong bearish…
BitMine Reports 4.285M ETH Holdings, Expands Staked Position With Massive Reward Outlook
Key Takeaways BitMine Immersion Technologies holds 4,285,125 ETH, which is approximately 3.55% of Ethereum’s total supply. The company…
US Liquidity Crisis Sparked $250B Crash, Not a ‘Broken’ Crypto Market: Analyst
Key Takeaways: A massive $250 billion crash shook the cryptocurrency markets, attributed largely to liquidity issues in the…
Vitalik Advocates for Anonymous Voting in Ethereum’s Governance — A Solution to Attacks?
Key Takeaways Vitalik Buterin proposes a two-layer governance framework utilizing anonymous voting to address collusion and capture attacks,…
South Korea Utilizes AI to Pursue Unfair Crypto Trading: Offenders Face Severe Penalties
Key Takeaways South Korea is intensifying its use of AI to crack down on unfair cryptocurrency trading practices.…