ZachXBT traces $667K from French home invasion robberies to a laundering network
Blockchain investigator ZachXBT alleges that a French cybercriminal known as M1llionz (RichMilly666) laundered crypto stolen in two violent home invasions - netting roughly 7.2 BTC ($557K) and about $110K in other crypto.
According to his investigation, the stolen funds were moved through bridges, KuCoin deposits and a chain of swaps designed to obscure their origin. ZachXBT says the trail led to a $93K USDT freeze by Tether, linked to the stolen funds.
The case is a reminder that "violent crypto crime" is not a hypothetical: when attackers know holders' addresses, the weakest link is the person, not the key. Physical security and operational privacy go hand in hand.
A headphone glitch uncovered hidden tracking on AliExpress
A strange Bluetooth headphone behavior led to the discovery of a hidden tracking system running on AliExpress, the Alibaba-owned shopping site. The person behind the find wasn't looking for anything unusual - they just wanted their headphones to switch cleanly from their computer to their phone.
The headphones refused to switch audio output while an AliExpress tab was open in the background. As soon as the tab was closed, everything worked normally again. That small inconsistency was enough to make the user suspicious, so they dug into the site's code.
What they found were two obfuscated scripts - collina.js and fireyejs.js - quietly keeping the computer's audio system active behind the scenes. Because the audio pipeline stayed open, the Bluetooth connection couldn't switch devices properly, even though nothing was actually playing. The technique is a known anti-fingerprinting arms race trick: keep the audio context alive to probe the environment, and detect automation or collect signals most users would never notice.
Both stories share one thread: information you didn't know you were leaking. Whether it's a home address tied to a wallet or a browser quietly humming to itself, the leak usually starts where convenience meets opacity. On Vulpine the default is the opposite - no phone number, no email, end-to-end encrypted messages and metadata kept to the bare minimum, so there is simply less to track in the first place.