TL;DR:
- Two armed home invasions carried out in France during April resulted in the theft of approximately $667,000 in crypto assets.
- On-chain investigator ZachXBT tied the stolen funds to the online persona M1llionz after mapping deposits and public wallets.
- Issuer Tether executed the freeze of $93,000 in USDT associated with the addresses under investigation.
On-chain investigator ZachXBT ties M1llionz to crypto robberies following the release of a forensic investigation on Monday, August 24, detailing the laundering of assets violently stolen in France.
1/ Meet M1llionz (RichMilly666), a French cybercriminal allegedly laundering assets from two violent home invasion robberies in France in April 2026 that netted $667K total, with a history of openly posting about bank and retail fraud on social media.
My work has led to a $93K… pic.twitter.com/0jIhg89aEW
— ZachXBT (@zachxbt) August 24, 2026
Key Points of the Robberies and the Financial Trail
The criminal incidents occurred three days apart during April. On April 17, five assailants broke into a residence on French territory and stole 7.2 BTC—worth roughly $557,000 at the time—inflicting injuries that required hospitalizations. Three days later, on April 20, a second armed robbery involving threats and unlawful detention resulted in the theft of an additional $110,000 in digital assets.
The combined sum of both criminal events amounted to $667,000 in illicit funds. According to ZachXBT’s report, the attackers sought to disperse the capital through cross-chain bridges and centralized platforms.
Part of the Bitcoin taken in the first robbery was bridged to the Ethereum network via the Chainflip protocol. Records indicate that approximately $317,000 moved through three KuCoin deposit addresses before pooling into a consolidation wallet.
In the second attack, around 46 ETH was also routed into KuCoin deposits before joining the same consolidation path. The investigative findings note that several tranches were subsequently converted into USDT and privacy-focused assets.

Forensic Mapping and Asset Freezing Actions
The individual identified under the alias M1llionz, also known across digital platforms as RichMilly666, operated a Telegram channel called EMPIRE and posted content across social media. These channels were used to promote fraudulent services and showcase screenshots of wallet balances.
On-chain analysis revealed that wallets publicly shared by M1llionz received nearly $84,000 directly from the stolen fund routes. Evidence from the investigation indicates that screenshots and open-source metadata enabled investigators to link his digital identity to the receiving addresses.
Following the submission of forensic dossiers to authorities and centralized issuers, Tether moved to block an Ethereum address holding $93,000 in USDT.
The freezing of this $93,000 in USDT marks the first technical asset containment measure in the case. French judicial authorities maintain an active investigation to establish criminal liability and issue potential arrest warrants.





