The $3 Billion Click: How a Programmer Robbed the Darknet and Lost It All to the State
The James Zhong case shows that blockchain anonymity is an illusion, and that bugs in code have no statute of limitations.
In November 2021, the U.S. Internal Revenue Service (IRS) seized 50,676 bitcoins worth roughly $3.36 billion from James Zhong, a resident of Georgia. It was the largest cryptocurrency seizure in history at the time, and the culmination of a scheme set in motion almost a decade earlier.
How the theft worked
In the autumn of 2012, Zhong found a vulnerability in the withdrawal system of Silk Road, the darknet marketplace that traded illegal goods for bitcoin. The platform failed to correctly check an account balance during rapid, repeated requests: several withdrawals fired milliseconds apart were all treated as valid, and the balance was effectively doubled.
According to the U.S. Department of Justice, the actions were deliberate. Zhong created about nine fake seller accounts without ever listing anything for sale, funded each with between 200 and 2,000 BTC, and triggered a flood of instant repeated withdrawals. Over a few days he pulled roughly 50,000 bitcoins off the platform, worth about $700,000 at the time.
A decade of waiting
After Silk Road was shut down in 2013, the funds sat untouched for seven years. During that time the price of bitcoin climbed many times over, and by 2020 Zhong's holdings were worth approximately $3.3 billion.
His bet that the theft had been forgotten proved wrong. By court order, all bitcoins that had passed through Silk Road were subject to forfeiture to the state; investigators were simply waiting for the owner to slip.
Deanonymization
The decisive blunder came down to the nature of the blockchain as a permanent, public ledger. Alongside the "dirty" coins, Zhong also held legally mined funds that he had sold on an exchange under his real name. While reorganizing his assets, splitting 10,000 coins across ten wallets, he linked that legitimate chain of transactions to the stolen funds. Blockchain analysis established his identity, which gave grounds for a warrant and a search.

The search and the sentence
During the search in November 2021, the bulk of the assets was found on a single-board computer hidden inside a popcorn tin in a bathroom cabinet. Investigators also seized cash, gold and silver bars, and physical Casascius coins.
At first, investigators did not have the access key (the seed phrase) to the wallet, which Zhong kept in his memory. After several months he agreed to cooperate, and in March 2022 the assets were moved to a Department of Justice address.
Given his cooperation, Zhong was sentenced to a year and a day in prison (the sentence was handed down in 2023, and he was released in 2024). All of the assets, both stolen and later acquired, were forfeited to the state.
Takeaways
The case illustrates three principles that matter for information security and crypto assets:
- Vulnerabilities have no statute of limitations. A bug in 2012 code produced consequences a decade later.
- The blockchain does not provide anonymity. A public ledger turns deanonymization into a matter of a single mistake when linking addresses.
- Time cuts both ways. It multiplied the value of the assets many times over, and it also gave investigators long enough to identify their owner.
Source: U.S. Department of Justice, IRS Criminal Investigation.
Written by
Read next
Ill Bloom: A Weak Seed-Phrase Generator Drained Over $5M From Crypto Wallets
Researchers at Coinspect have disclosed Ill Bloom, a vulnerability in how several cryptocurrency wallets generate their mnemonic recovery phrases (seed phrases). Exploiting it, attackers emptied hundreds of wallets in a single pass and made off with more than $5.1 million. The problem is not one specific wallet but the phrase-generation method used by a handful of lesser known apps, mobile and browser extensions, some dating back to 2018. These wallets relied on a weak random number generator,
ChocoPoC: Fake Exploits on GitHub Are Hunting Security Researchers
A malware campaign flips the script on bug hunters: fake proof-of-concept exploits on GitHub secretly install the ChocoPoC remote access trojan.
$643M in Six Months: How Lazarus Operates and Where the Evidence Runs Out
In the first half of 2026, analysts at TRM Labs attributed roughly $643 million to groups linked to North Korea, about 66% of everything stolen from the cryptocurrency industry, out of some $972 million lost across 207 incidents. Almost all of it came from two April attacks on DeFi protocols: the roughly $292 million breach of KelpDAO and the $285 million hit on Drift Protocol. A year earlier the shape was similar but the scale was not. Chainalysis put 2024 losses to DPRK-linked hackers at $1.34
Microsoft Patches a Record 570 Flaws, Two Zero-Days Already Under Attack
On Tuesday, July 14, Microsoft shipped the largest set of fixes in Patch Tuesday history, closing 570 vulnerabilities at once. Attackers are already exploiting two of them in the wild, and a third was publicly disclosed before the patch landed. The most serious of the exploited bugs is CVE-2026-56164 in Microsoft SharePoint Server. A missing authentication check in a critical function lets an unauthenticated attacker escalate privileges across the network, with no password at all. Researchers a
LegacyHive: Unpatched Windows Zero-Day PoC Dropped Hours After Patch Tuesday
Within hours of July's Patch Tuesday, a researcher going by Nightmare Eclipse (also seen as Chaotic Eclipse) published a proof-of-concept exploit for a new Windows vulnerability dubbed LegacyHive. No patch existed at the time of release, and the exploit works on the latest build of the system, assembled with July's updates already applied. The vulnerability lives in the Windows User Profile Service (ProfSvc) and its registry hive loading mechanism. When a user signs in, Windows mounts the UsrCl