CASE FILE · CW-012

DeFi Exploit Investigation

Entries
10
Evidence
11
01/Entry

An investigation into how the New York based social engineering scammer Daytwo/PawsOnHips (Christian Nieves) stole $4M+ from Coinbase users by impersonating customer support, bought luxury goods, and lost most of the funds gambling at casinos.

Dossier evidenceDossier evidenceDossier evidence
02/Entry

Daytwo operates a small call centre group and also works as a caller. His group primarily coerced targets into setting up Coinbase wallet with a compromised seed on phishing sites.

03/Entry

In Nov 2024 $240K was stolen from an elderly victim with Daytwo’s worker Paranoia (Justin). A private recording of the theft exists and was obtained Theft address bc1q35tw4f5qrfxrjy2v8g8d3majtujv28audm6yvp AJU5yh4kDahLak4uq5n4ehJDVs2w2Lbhw9UHoseaBwV7

04/Entry

I went and traced out the theft and noticed the $240K was split three different ways. A portion was deposited to Roobet and the rest was converted to XMR.

Dossier evidenceDossier evidenceDossier evidence
05/Entry

Daytwo likes to gamble on Discord calls with friends. The recording below shows his Roobet username ‘pawsonhips’ where he leaks his deposit address in a browser tab. 0x940970549037634c517deb741b16112b52e0ced1

06/Entry

I traced out his casino deposit address which links onchain to 30+ suspected thefts. I expect there’s many additional victims I am unable to directly link. While there’s potentially overlap between multiple threat actors the vast majority of activity pertains to Daytwo.

Dossier evidenceDossier evidence
07/Entry

Daytwo has a gambling problem and you’ll see onchain how casino deposits get smaller as he loses funds. Recently this escalated to the point where he started stealing cuts from accomplices. Recent casino deposit addresses 0x42442a16300c78288ee8ba5c9da611089fcc42bc 0x55153e2826e93e4fda0245ac8af296b41abcf05b 0x359ef3aa8b757e9c63e90dc1783531e58ef91ed5

Dossier evidence
08/Entry

During Discord calls with his friend group they openly talk about laundering funds and regularly show their face.

Dossier evidence
09/Entry

Recently Daytwo got a corvette using stolen funds and added a sticker with his IG username ‘daytw00000’ linking him irl to his Com alias.

10/Entry

It’s rare we see a social engineering scammer with such blatant disregard to mask their identity while flexing stolen funds all over social media. As Daytwo is not a minor it’s a rather easy case for law enforcement to pursue. Sadly any recovery for victims is likely a small amount given the funds were mostly gambled away after thefts.

Dossier evidence