
ZachXBT plans fraud-intake site that may auto-reject cases from seven countries
The proposed filter would exclude Canada, the UK, India, Nigeria, Morocco, Algeria, and Bangladesh based on expected law-enforcement follow-through.
Blockchain investigator ZachXBT is preparing a new website to handle crypto-fraud investigations, and the intake flow may “likely automatically reject” submissions depending on where the victim or case is located. The proposed exclusion list names seven countries, a blunt signal that recovery odds can hinge on jurisdiction as much as on-chain evidence.
ZachXBT’s fraud-intake site plans jurisdiction-based auto-rejections
ZachXBT, a pseudonymous American blockchain investigator, is planning a new website to handle crypto-fraud investigations with an intake system that may “likely automatically reject” cases based on the country tied to the victim or the case.
The countries listed for exclusion are Canada, the United Kingdom, India, Nigeria, Morocco, Algeria, and Bangladesh. The framing is not that the underlying on-chain tracing is impossible, but that the workflow breaks later, when a case needs an exchange freeze, a custodian restriction, or a law-enforcement request that actually gets processed.
The stated rationale is operational: in some jurisdictions, ZachXBT says his investigative work has repeatedly failed to translate into meaningful action from local authorities, making cooperation with law enforcement the limiting factor. The packet’s description points to prior attempts to provide information in Canada and India that did not result in authorities taking action.
India is singled out as particularly significant in the exclusion list because ZachXBT claims he interacted with Indian law enforcement on cases involving frozen cryptocurrency and funds allegedly connected to the Lazarus Group. He also alleged investigative mistakes, including authorities confusing a phishing website with a legitimate crypto platform.
Why jurisdiction is becoming a practical constraint on recoveries
For traders and on-chain participants, the uncomfortable reality is that “recovery” is rarely a purely technical question. Tracing can identify flows and counterparties, but freezes and restitution typically require an institution to act, and that action is often gated by local procedure, local capacity, and whether a report turns into a case that someone is willing to push.
A jurisdiction-based intake filter would formalize that constraint. If the site does implement automatic rejections, it effectively turns country-of-case into a first-pass eligibility rule, which could shift where victims seek help when something goes wrong, whether that means going directly to exchanges and custodians, paying private investigators, or using alternative reporting channels that can route requests into more responsive venues.
The fairness debate is baked into the design. Supporters argue triage makes investigations more effective by focusing limited resources on jurisdictions where authorities are more likely to act on blockchain evidence and help freeze or recover stolen funds. Critics argue victims should not be penalized for the performance of their country’s law-enforcement system.
The packet also frames the move against a backdrop of rising fraud pressure, pointing to a “recent Coldcard exploit” described as affecting 192 individuals and compromising roughly 714.8 BTC in a few days. The incident is used as context for why faster intake and faster freeze pathways are becoming central to incident response narratives, even though the packet does not provide timing, attribution, or methodology details for independent verification.
The near-term signals are procedural, not rhetorical. The thresholds that matter are whether ZachXBT publishes the site URL and launch date, whether the intake rules are explicit about how jurisdiction is determined (self-reported location versus technical checks), and whether rejected submissions can be appealed or rerouted. The other open loop is documentation: the packet relays claims about prior Canada and India interactions, but does not include primary-source posts or supporting records, and the Coldcard exploit reference needs more verifiable detail beyond the 192-victim and ~714.8 BTC figures.
My read: this is a triage signal for where freezes and restitution are most realistic
The jurisdiction list is being read as a moral judgment, and I don’t think that survives contact with how post-theft recoveries actually happen. The choke point is not tracing, it’s getting a real-world actor to restrict funds or advance a case, and the proposed auto-reject language is basically an admission that some pipelines have been dead ends often enough to justify hard filtering.
The real test is whether the site ships with clear, enforceable intake rules and a transparent way to handle edge cases, because without that, “likely automatically reject” is more of a sentiment catalyst than a durable change in recovery mechanics. If the filter becomes operational and stable, it matters in practical terms by shifting which jurisdictions can realistically trigger freezes and restitution on a timeline that still intersects with where stolen funds move.