CASE FILE · CW-014

Celebrity Token Scam

Entries
11
Evidence
23
01/Entry

An investigation into the alleged identity of the mysterious Hyperliquid whale tied to illicit activity that profited ~$20M via highly leveraged positions over the past couple weeks.

Dossier evidenceDossier evidence
02/Entry

A trader opened multiple highly leveraged positions on Hyperliquid and GMX from Jan - Mar 2025. They gained lots of attention this month after two onchain trades: -Large ETH & BTC long position on 50X leverage just before Trump’s crypto reserve announcement by 0xe4d3 ($10M profit) -Large BTC short position on 40X leverage by 0xf3F4 ($9M profit)

Dossier evidenceDossier evidenceDossier evidence
03/Entry

I went and identified the main counterparties of 0xf3f: 0x7ab8c59db7b959bb8c3481d5b9836dfbc939af21 0x312f8282f68e17e33b8edde9b52909a77c75d950 0xab3067c58811ade7aa17b58808db3b4c2e86f603 0xe4d31c2541a9ce596419879b1a46ffc7cd202c62 This cluster is to tied to Roobet, Binance, Gamdom, ChangeNOW, Shuffle, Alphapo, BC Game, & Metawin accounts.

Dossier evidence
04/Entry

0xf3f signed a messaged for the X account @qwatio and stated they made $20M on GMX & HL. This means he would have to control the related wallets in this cluster for the $20M number to be accurate. I replied to him yesterday on X but the posts were deleted after.

Dossier evidenceDossier evidence
05/Entry

An analysis for the X account used by 0xf3f indicates it was likely purchased at a point in time (recent name change, years of inactivity, aged account) I saw they follow @CryptxxCatalyst who posted links to multiple phishing sites + replied to people trying to trick them.

Dossier evidenceDossier evidenceDossier evidence
06/Entry

I reach reached out to @realScamSniffer about the phishing sites who regularly tracks them. A public address for the HL whale was set as the drainer fee receiver on the projection[.]fi phishing site in Jan 2025. 0x7ab8c59db7b959bb8c3481d5b9836dfbc939af21 0x7ab also directly received $17.1K in Jan 2025 from another phishing draining customer prior to where his wallets became tracked this month.

Dossier evidenceDossier evidenceDossier evidence
07/Entry

As 0x7ab was the first EVM address used by 0xf3f I traced the source to withdrawals on Solana from four casinos. 83Dumvk6pTUYjbGrC1fizBziRzDqcyNx73ieJcVbp56b I reached out and one of them clarified the funds came from an input validation exploit on a casino game. I was provided with a now deleted TG account: 7713976571 they had negotiated with the exploiter from.

Dossier evidence
08/Entry

I performed OSINT to find posts by the account in TG groups. I found three posts in the GMX group from the same TG ID asking for the help. To also verify it was the same person I saw the posts were around the same time 0xe4d3 was trading on-chain.

Dossier evidenceDossier evidenceDossier evidence
09/Entry

I tracked down a recent payment from 0xe4d3 to an unnamed person who confirmed they had been paid by the HL trader. They provided a UK phone number used to communicate with them. Public record reveals the name William Parker is likely tied to this number.

Dossier evidenceDossier evidence
10/Entry

Who is William Parker? Last year WP was arrested for stealing ~$1M from two casinos in 2023 and was sentenced in Finland. Prior to this WP was known as Alistair Packover (William Peckover) before later changing his name. In the early 2010s AP made multiple news headlines in UK for fraud charges related to hacking and gambling. (match the ages in the articles)

Dossier evidenceDossier evidence
11/Entry

It is abundantly clear WP/AP has not learned his lesson over the years after serving time for fraud and will likely continue gambling. Currently the funds primarily sit here: 0x51d99A4022a55CAd07a3c958F0600d8bb0B39921 Here’s a quick TLDR for those people who have a short attention span: In January 2025 after exploiting a casino game and phishing victims, a person previously charged for multiple crimes gambled 6 figs into $20M using high leverage onchain.

Dossier evidence