1/ Recently an unnamed source shared data exfiltrated from an internal North Korean payment server containing 390 accounts, chat logs, crypto transactions.
I spent long hours going through all of it, none of which has ever been publicly released.
It revealed an intricate ~$1M/month scheme of fraudulent identities, forged legal documents, and crypto-to-fiat conversion.
Enjoy the findings!
11/ This cluster of DPRK IT worker activity is less sophisticated compared to groups like AppleJeus and TraderTraitor, which operate far more efficiently and present the greatest risks to the industry.
I previously estimated DPRK IT workers generate multiple seven figures per month in revenue, and the data here supports that.
Unpopular opinion: threat actors are leaving an opportunity on the table by not targeting low-tier DPRK groups. The risk of repercussions is low, competition is minimal, and the targets are arguably deserving.
I plan to continue building out https://t.co/1Cvwh1L18Z with future findings.
Special thanks to @domain for helping me purchase two premium domains.
1/ Welcome to the Circle $USDC files.
$420M+ in alleged compliance failures since 2022, including fifteen cases of the US-regulated stablecoin issuer taking minimal action against illicit funds.
17/ On February 21, 2025, Bybit was hacked by Lazarus Group for $1.5B, widely reported across mainstream media.
On February 28, 106K USDT and 338K USDC consolidated to theft address 0xDa2.
Law enforcement, Bybit, and private sector experts submitted freeze requests to both Tether and Circle.
Tether froze the address within hours. Circle took 24 hours longer to act.
Theft address:
0xDa2e12E94060720581994eEc870F83d9C7200c2c
18/ Circle builds good products and I hold USDC myself. This isn't a post about hoping they collapse.
But the decisions they've made around compliance have had real consequences for real people.
Nine figures lost from the ecosystem because of repeated inaction across three years, law enforcement requests, private sector requests, and their own infrastructure.
The $420M+ figure only accounts for major public cases. The real figure is likely significantly higher.
They have every tool and resource available to do better. They just haven't.
So I'll leave you with one question: who is Circle actually serving?
A US-regulated public company owes it to its users and the broader community to do better than this.
1/ I uncovered a coordinated network of 10+ accounts manufacturing viral panic about war and politics to drive traffic to crypto scams.
Strategy:
>Purchase accounts with followers
>Doompost multiple times per day
>Repost content from alt accounts
>Promote fake giveaway or scam
>Change username
1/ Meet Aleksandr (Aleks) Khinkis, a Russian OTC broker who has allegedly helped a ransomware group launder $4.7M+ via a single crypto exchange account since July 2025, across three suspected ransom payments totaling 796 BTC.
10/ Hopefully law enforcement will prosecute Aleks, but given it likely involves multiple jurisdictions that adds a lot of complexity for a case.
73 BTC remains dormant at 1ECrX6LiBhuGLGgJYB6mtacEEhzNSS9xdP, which will likely be laundered in the future.
When I first began researching this ransom cluster in early Oct 2025, few of the addresses were reported in compliance tools by third party providers.
While a number of ransom payments go unreported, they are easy to identify onchain and freeze. My recommendation to victims is to always report addresses.
Special thanks to @bax1337 for OSINT assistance and to @TobyFrei4 for Russian translation.
John Daghita (Lick) was arrested in the Caribbean yesterday as a direct result of my investigation.
In late January 2026, I exposed how John stole $ 46M+ in seized crypto assets from the US government by abusing access at CMDSS, his father's company, which held a USMS contract.
John then taunted me multiple times via his Telegram channel and dust attacked my public wallet address with stolen funds.
Thanks for the last laugh, John.
1/ Meet @WheresBroox (Broox Bauer), one of the multiple @AxiomExchange employees allegedly abusing the lack of access controls for internal tools to lookup sensitive user details to insider trade by tracking private wallet activity since early 2025.
9/ During the February 2026 recorded call, Broox outlined a plan to help Gowno profit $200K quickly by abusing his access at Axiom which is consistent with similar illicit activity he had been conducting with others since early 2025.
In private chats he also shared screenshots of his exchange balances, suggesting the scheme had already been generating returns.
10/ I was retained to independently investigate alleged misconduct at Axiom and these findings are the result of that investigation.
Earlier today I reached out to the Axiom team for comment. Their statement is attached.
Regardless of whether Cal or Mist were aware, there was little to no monitoring or access controls in place to mitigate this abuse from happening in the first place.
The extent of data granted to employees in an easily accessible dashboard is unusual for BD roles, including a user's entire wallet list with date/time, the wallets they are tracking, transaction history, the nickname of wallets, and linked accounts.
Given Broox is based in NYC I think the case presents itself as a good opportunity for SDNY since it may fall within their jurisdiction.
Whether or not criminal charges are filed, I hope the Axiom co-founders further investigate the abuse and consider taking legal action against the employees involved.
NEW: Major investigation dropping February 26 on one of crypto’s most profitable businesses where multiple employees abused internal data to insider trade over a prolonged period of time.
1/2 In June 2024 a victim was brutally robbed for $4.3M+ of crypto assets at gunpoint via home invasion in the UK after the attackers posed as delivery drivers.
I am proud to share that Faris & his two other accomplices were just sentenced and nearly the full amount of stolen funds was seized by MET Police.
I previously published my investigation identifying Faris and worked closely with the victim to communicate all findings to law enforcement.
Due to minor protection laws certain details about the case remain sealed.
Court: Sheffield Crown Court
Case reference number: 01GD1223024