An Ethereum address connected to HashFlare, the defunct cloud-mining platform that collapsed amid fraud allegations, moved 10,600 ETH worth roughly $18.5 million on Monday morning. Blockchain investigator ZachXBT spotted the transfer, the first transaction from the address in approximately three and a half years.
HashFlare operated as a cloud-mining service, allowing users to rent computing power for cryptocurrency mining without owning physical hardware. The platform shuttered in 2021 after regulatory scrutiny and user complaints that it was unable to deliver promised returns. The address in question had been untouched since the collapse, making Monday's movement notable to investigators who monitor fraud-linked wallets.
ZachXBT did not publicly specify the destination of the transferred ETH or offer immediate insight into who controlled the wallet at the time of movement. Such reactivations of dormant fraud addresses typically prompt questions about whether the funds are being recovered by law enforcement, claimed by the original wallet holder, or moved by another party with access. Without additional on-chain clues or public statement from investigators or regulators, the intent behind the transfer remained unclear.
The reemergence underscores a quirk of blockchain forensics: even when a platform collapses and user funds are locked or lost, the addresses holding those assets remain visible and traceable indefinitely. Investigators can flag unusual activity, but determining who initiated a transaction and why requires either further chain analysis, regulatory disclosure, or voluntary communication from parties involved.