Archive · Declassified
← Return to HQ

Dossier Archive

16 Documented Investigations · Read at your own discretion

CW-001

Exchange Insider Trading Ring

1/ An investigation into how Greavys (Malone Iam), Wiz (Veer Chetal), and Box (Jeandiel Serrano) stole $243M from a single person last month in a highly sophisticated social engine

Open File →
CW-002

Cross-Chain Laundering Network

1/ Meet Haby (Havard), a Canadian threat actor who has stolen $2M+ via Coinbase support impersonation social engineering scams in the past year blowing the funds on rare social med

Open File →
CW-003

On-Chain Investigation Report

[Image]I am pleased to share that the threat actor ‘Ronald Spektor’ (Ron) was recently arrested in New York. In November 2024 I published my investigation detailing his involvement

Open File →
CW-004

Scam Token Cluster Uncovered

1/2 In June 2024 a victim was brutally robbed for $4.3M+ of crypto assets at gunpoint via home invasion in the UK after the attackers posed as delivery drivers. I am proud to share

Open File →
CW-005

Wallet Tracing Operation

1/ An investigation into how I identified one of suspects tied to the $28M Bittensor hack from 2024 by identifying anime NFT wash trades linked to a former employee and earned a wh

Open File →
CW-006

NFT Wash Trading Investigation

File pending declassification. Dossier content not yet available.

Open File →
CW-007

Crypto Ponzi Scheme Bust

1/ An unnamed source recently compromised a DPRK IT worker device which provided insights into how a small team of five ITWs operated 30+ fake identities with government IDs and pu

Open File →
CW-008

Bridge Exploit Analysis

1/ An investigation into how @cryptobeastreal scammed followers by lying they were not behind the $190M - $3M $ALT market cap crash where 45+ connected insider wallets sold $11

Open File →
CW-009

Rug Pull Documentation

1/ Multiple projects tied to Pepe creator Matt Furie & ChainSaw as well as another project Favrr were exploited in the past week which resulted in ~$1M stolen My analysis links bot

Open File →
CW-010

Money Laundering Trail

1/ My recent investigation uncovered more than $16.58M in payments since January 1, 2025 or $2.76M per month has been sent to North Korean IT workers hired as developers at various

Open File →
CW-011

Influencer Promo Scam Exposure

File pending declassification. Dossier content not yet available.

Open File →
CW-012

DeFi Exploit Investigation

1/ An investigation into how the New York based social engineering scammer Daytwo/PawsOnHips (Christian Nieves) stole $4M+ from Coinbase users by impersonating customer support, bo

Open File →
CW-013

Phishing Ring Takedown

1/ In late 2023 a former Yuga Labs security researcher was stopped at the airport after law enforcement mistakenly linked them to a $1.1M phishing theft from a Bored Ape owner. Her

Open File →
CW-014

Celebrity Token Scam

1/ An investigation into the alleged identity of the mysterious Hyperliquid whale tied to illicit activity that profited ~$20M via highly leveraged positions over the past couple w

Open File →
CW-015

Marketplace Fraud Analysis

Lazarus Group just connected the Bybit hack to the Phemex hack directly on-chain commingling funds from the intial theft address for both incidents. Overlap address: 0x33d057af7477

Open File →
CW-016

Cross-Chain Money Flow

1/3 A threat actor has stolen ~$500K over the past month by compromising 15+ X accounts (Kick, Cursor, Alex Blania, The Arena, Brett, etc) from sending targeted phishing emails whi

Open File →