SCAM Hide.cash Steals Customer Funds!

TrêvoidTrêvoid is verified member.

No KYC / AML
Staff member
Administrative
This report presents evidence that the cryptocurrency swap service hide.cash has misappropriated a user's deposit of 49.35 SOL (~$4,000). Despite the service's public denials, blockchain analysis confirms that the user’s funds were routed directly into wallets controlled by the hide.cash infrastructure.

The Conflict​

On July 17, 2026, a user attempted to swap 49.35 SOL for Monero via hide.cash. The transaction confirmed on the Solana blockchain, but the user received no payout. When confronted, the service operator, verified via DNS-protected ownership, claimed that the order never existed and that the deposit address used by the victim did not belong to them.

Uh0gNc.png

Forensic Evidence​

To bypass potentially forged communications, this investigation relied solely on immutable blockchain data and independent tests of the service’s own infrastructure. By creating new swap orders on hide.cash, it was confirmed that the service’s automated systems return deposit addresses that are directly linked to the wallets holding the victim’s stolen funds. Specifically, the wallet 6ZnB8mg, which the hide.cash site served as a valid deposit address, was responsible for funding the account BxYcm. Blockchain records show BxYcm receiving the vast majority of the victim's SOL just minutes after the deposit was cleared.

Furthermore, the victim’s ownership of the sending wallet was cryptographically verified. The victim successfully signed a custom message with the private key corresponding to the deposit, proving the legitimacy of the claim and the transaction path.

Analysis of the Operator​

The investigation identified a centralized pattern in how hide.cash manages its funds. A single signing key, EbsUZEFAU, controls the movement of assets across the wallets that received the victim's money. Additionally, these wallets are consistently drained down to a specific leftover balance and routed through a collection wallet that operates on a precise hourly schedule. This "fingerprint" confirms that all these wallets are managed by a single operator or automated program.

Conclusion​

The claim from hide.cash that the deposit address does not belong to them is demonstrably false. The service’s own website generates these addresses for customers, and those same addresses feed into a clearly defined, operator-controlled pipeline. Whether the theft was an intentional act of fraud, an internal exploit, or a systemic failure, the responsibility lies with the hide.cash operator. The service’s subsequent decision to take the site offline with a "503 maintenance" error immediately following these findings further undermines their credibility.

For those seeking to verify these findings, tracing the path of deposit addresses generated by the site and examining the transaction history of the associated wallets provides conclusive proof of the funds' destination.

Full investigation contains full evidence: https://kycnot.me/service/hide-cash/case/o5a43vn6yb88tu5an6his8pj