OmegaPro founder arrested for allegedly running crypto Ponzi

Turkish authorities arrested Andreas Szakacs, also known as Emre Avci, for his role in the OmegaPro cryptocurrency Ponzi scheme. Victims were invited to make small investments in the "Omega Invest" application, which made quick returns. They were enticed to invest more and more, but when they attempted to withdraw funds, they discovered the money had been taken. Altogether, victims have claimed around $103 million in losses.

The OmegaPro Ponzi scheme was reportedly linked to the OneCoin crypto Ponzi, whose operators stole at least $4 billion from millions of victims since 2019. Multiple people associated with OneCoin have been arrested, including its co-founder Karl Sebastian Greenwood, but its "Cryptoqueen" co-founder Ruja Ignatova was one of Europol's most wanted fugitives and remains the subject of an Interpol red notice.

Doja Cat's Twitter account hacked to promote meme token

Tweet by Doja Cat: "buy $DOJA or else" followed by a Solana address. There's a photo of her brandishing a toy scimitar and she's wearing a chainmail hood.Tweet from Doja Cat's hacked account (attribution)
The Twitter account belonging to rapper Doja Cat was compromised on July 8, tweeting to her 5.6 million followers that they should "buy $DOJA or else", and various other messages to that effect. Doja Cat quickly posted on her Instagram account to say that the Twitter account had been compromised.

The attacker appeared to have only marginal success, as the token reached a market cap of around $500,000 before collapsing by 96%.

Hackers have compromised a string of celebrity Twitter accounts to promote memecoins recently, including those of Hulk Hogan and Metallica.

Bittensor wallets drained

Some users of the Bittensor wallet software suffered wallet drains as thieves emptied their cryptocurrency wallets of the project’s TAO token. Around 32,000 TAO, notionally worth around $8 million, was siphoned. Although blockchain sleuth zachxbt hypothesized that the attack may have been thanks to a private key leak, Bittensor later claimed that affected users had in fact been compromised by a malicious Bittensor package that had been uploaded to Python's PyPi package manager. It's not yet clear how the malicious package made it onto the package manager.

Bittensor is among the artificial intelligence-focused cryptocurrency projects that have become popular recently amid the AI hype. Although the project website boasts that "Bittensor is creating a new future for humanity, where new economies and new commodities are decentralized by design and where no single entity is a sole authority," the group unilaterally halted the chain in the wake of the attack.

Silvergate Bank pays $63 million to settle charges from multiple agencies

More than a year after the crypto-friendly Silvergate Bank collapsed, its parent company has agreed to pay $63 million in fines to the Federal Reserve and California Department of Financial Protection and the Innovation. The SEC also imposed a $50 million fine, though the terms of the settlement noted this "may be offset" by the other penalties.

According to the regulators, Silvergate "had serious deficiencies" in its anti-money laundering programs, including in its intra-customer crypto transfer product. In particular, the SEC highlighted $9 billion in suspicious transfers among FTX entities that should have been detected by compliance programs. The SEC also alleged that Silvergate misrepresented its financial state during the post-FTX collapse bank run.

Yield App declares insolvency, citing FTX losses

Yield App, a crypto investment platform, has announced that it will be entering liquidation proceedings. Citing "significant financial challenges", the project announced that the platform would be suspended pending liquidation.

In the immediate aftermath of the FTX collapse in November 2022, Yield App CEO Tim Frost had assured customers that "Yield App has no exposure to Alameda or the FTT token, and no signifiant exposure to FTX". However, Yield is now — going on two years after the FTX collapse — claiming to be suing "several hedge funds" that had lost money on FTX.

SEC sues Consensys, maker of MetaMask wallet

As expected, the SEC has filed a lawsuit against Consensys, the maker of the popular MetaMask cryptocurrency wallet. Although Consensys had recently gloated about the SEC completing an investigation into the company's offering of ETH, and determining not to pursue action over it, a Wells notice sent to the firm in April suggested that some legal action was impending. Shortly afterwards, Consensys filed a lawsuit against the SEC, alleging regulatory overreach.

The SEC's lawsuit claims that Consensys violated securities laws by acting as an unregistered securities broker, and by offering staking services that constituted unregistered securities offerings. The SEC has previously cracked down on staking offerings by other firms, including Coinbase and Kraken.

Logan Paul files defamation lawsuit over Coffeezilla's coverage of his failed CryptoZoo project

Logan PaulLogan Paul (attribution)
A year and a half after threatening to sue YouTuber Coffeezilla for his series of videos exposing influencer Logan Paul's (alleged) role in (allegedly) scamming his large following with a failed blockchain game, Paul has followed through on the threat. Although he acknowledges in the lawsuit that the project was definitely a scam, Paul says that he too was duped by several "conmen" who he'd brought on as advisers.

In the lawsuit, Paul claims that Coffeezilla knowingly falsely accused Paul of being in on the scam in hopes of getting more attention on his videos. Paul is seeking more than $75,000 in damages.

In January 2024, Paul filed suit against the advisers he's described as "conmen". He's also pointed the finger at them while defending a potential class action complaint from defrauded investors.

FBI busts group of crypto-seeking home invaders

The Department of Justice busted a group of more than a dozen people, led by a 24-year-old man named Remy St. Felix, who perpetrated a string of break-ins and violent assaults in hopes of obtaining their victims' cryptocurrency holdings. The group seems to have been far more successful with their hacking thefts than with their in-person attempts to obtain cryptocurrency, but that didn't stop them from committing a string of eleven break-ins where they assaulted, threatened, and kidnapped victims.

In one case, a victim was able to transfer $150,000 in cryptocurrency to the attackers before their cryptocurrency exchange blocked the suspicious transfers. However, in their other attempts to physically steal crypto, they were unsuccessful, with victims either refusing to hand over their crypto or successfully escaping.

In one case, St. Felix and his associates targeted a woman from whom his group had already stolen $3 million in a SIM swapping attack. When they broke in and held the woman at gunpoint to try to steal the $500,000 in crypto she had left, the woman refused to turn over her password to her cryptocurrency account, so dismayed by her earlier loss that she told the men just to shoot her.

St. Felix was convicted on nine counts by a federal jury, and faces a sentence of seven years to life in prison. Thirteen co-conspirators also pleaded guilty.

Farcana token plummets 60% amid murky explanations

The token for the Farcana blockchain shooting game plummeted in value by around 60%. First, the project team announced that one of the project wallets had been compromised. However, they later deleted that tweet, then claimed that one of their market makers had been compromised. They emphasized that their wallets had not been hacked, and that their smart contracts had not been exploited.

23.8 million FAR were taken from a wallet, and the majority were sold for around $164,000 in USDT. The exploiter still holds 3.4 million FAR, which are notionally worth $83,250 but not likely to be sellable for that amount.

Farcana raised $10 million in seed funding in November 2023 from investors including Animoca and Polygon Ventures.

Victim loses $11 million to permit phishing

A victim lost $11 million in Aave Ethereum (aEthMK) and Pendle USDe tokens after signing several permit phishing signatures. Permit phishing is a technique in which scammers convince a victim to sign a transaction that grants broad permissions, allowing the scammer to then drain assets from the wallets.

Sportsbet.io likely hacked for $3.5 million

It appears that the online crypto sports betting platform Sportsbet.io suffered a theft of around $3.5 million in USDT and Tron's TRX tokens. The theft was observed by crypto sleuth zachxbt, who noted that the theft seems to have been perpetrated by the same attacker who stole at least $55 million from the BtcTurk cryptocurrency exchange only hours earlier.

SportsBet has not yet disclosed any theft.

"Read-only" CoinStats crypto application enables wallet breaches

CoinStats, an application promising to help people track their cryptocurrency holdings, has suffered a breach impacting more than 1,500 user wallets.

The application asks its users to connect their wallets to allow it to track their holdings, but promises on the website that it offers "the ultimate security for your digital assets". "Since we ask for read-only access only, your holdings are perfectly safe under any conditions," the website promises, later touting its "military-grade encryption".

CoinStats shut down the platform while investigating the incident. Losses have been estimated at around $2.2 million.

50 Cent claims his accounts were compromised to promote a memecoin

Tweet by 50cent: "Get Rich or Die Tryin! 💪🏾 Get the official $GUNIT Now"Scam tweet from 50 Cent's account (attribution)
50 Cent has claimed his Twitter account and website were hacked to promote a memecoin called $GUNIT. "I have no association with this crypto," the rapper wrote on Instagram.

50 Cent also claimed in the post that "Who ever did this made $300,000,000 in 30 minutes." It's not clear where 50 Cent got this number, because the token has only done $19.8 million in volume. One wallet made around $722,000 off the token, and three others also made over $100,000.

BtcTurk exploited for at least $55 million

The Turkish cryptocurrency exchange BtcTurk has acknowledged that they suffered a hack that impacted ten hot wallets containing multiple cryptocurrencies. The exchange halted deposits and withdrawals while investigating, and said they are working with law enforcement.

It appears that assets notionally worth around $55 million were stolen. Furthermore, the exploiter sold substantial amounts of some cryptocurrencies, including Luna Classic, causing major price movements in those tokens.

According to newly installed Binance CEO Richard Teng, Binance froze $5.3 million of the stolen assets.

CertiK and Kraken accuse each other of misconduct over bug report and $3 million "testing"

Prominent blockchain security firm CertiK has accused American cryptocurrency exchange Kraken of threatening them after they reported a bug. According to CertiK, they discovered a bug in the exchange software, which they tested with multiple transactions over several days. Some of these were large transactions, which CertiK said they performed to test whether Kraken had alerting in place to detect higher-value transfers. When they reported the vulnerability to the exchange, they say the exchange patched the bug, but then threatened CertiK employees and demanded they repay a "mismatched" amount of crypto allegedly taken during the testing period.

However, others have noted that the number of transactions and amount of cryptocurrency taken by CertiK while "investigating" the bug seems to far exceed the norm for whitehat security researchers, and that they took cryptocurrency amounting to millions of dollars — making their "testing" look a lot more like a blackhat theft. Furthermore, CertiK made several transfers to Tornado Cash as part of their "testing" — an entity that is sanctioned by the United States.

Kraken alleged that CertiK did not disclose the full extent of their employees' transactions, and refused to return the $3 million they had taken. They also alleged that CertiK had attempted to extort them. Kraken said they had been in contact with law enforcement, and were "treating this as a criminal case".

Ultimately, CertiK returned the funds. However, it's not clear if criminal action may be ongoing.

Martin Shkreli claims to have been behind a Donald Trump memecoin

Martin Shkreli sits at a table, arms crossed and smirkingMartin Shkreli (attribution)
After Arkham Intelligence announced a $150,000 bounty for anyone who could prove the identity of the person behind a Donald Trump memecoin called $DJT, blockchain sleuth zachxbt quickly rose to the occasion. He submitted evidence that Martin Shkreli, the "pharma bro" who spent years in federal prison for financial fraud and who was previously known for hiking the price of an anti-malaria drug 56×, was behind the token. This wouldn't have been Shkreli's first foray into the blockchain world, after he launched a "web3 drug discovery platform", and then later dubiously claimed to have been hacked for over $450,000 after his computer was infected by a trojan after he torrented a porn video.

Shkreli attempted to frontrun the news in a Twitter space, and came out with his own claims that he had collaborated with Barron Trump to create the token, and with Andrew Tate to pump its price. However, fellow felon and memecoin pumper Roger Stone subsequently crawled out of the woodwork to claim that neither Barron nor Donald Trump was involved with $DJT.

Shkreli has yet to provide solid proof that he created the memecoin, though zachxbt's research tends to be very strong. If true, Shkreli faces potential legal repercussions, as he is still on parole after his release in 2022. The terms of his parole require him to "refrain from engaging in self-employment which involves access to client's assets, investments, or money, or solicitation of assets, investments, or money", and to make financial disclosures to the courts. Shkreli was also banned from the securities industry in 2018, as part of a settlement with the SEC.

Holograph exploited for more than $1.2 million

The Holograph tokenization project was exploited on June 13 after they took advantage of a flaw in a smart contract that allowed them to mint 1 billion HLG tokens. Notionally worth $14.4 million at the time the tokens were minted, relatively low liquidity meant that the introduction of a billion additional tokens crashed the token price by 80%. The attacker ultimately was able to cash out around 348 ETH (~$1.2 million).

One of the addresses involved in the exploit appears to have contributed to the Holograph protocol, though it's not clear if they took advantage of insider knowledge to pull off the heist.

UwU Lend re-enables protocol after hack, immediately gets hacked again

After suffering a $20 million loss in a June 10 hack, the UwU Lend defi lending protocol has now seen another $3.7 million in suspicious outflows only days later. Although UwU Lend paused the protocol after the attack, they re-enabled it on June 12, claiming to have identified and resolved the vulnerability. This apparently wasn't the case, given the same attacker quickly repeated their exploit.

UwU Lend was created by Michael Patryn, aka Omar Dhanani, aka "0xSifu", who has been behind several cryptocurrency projects that have suffered major exploits. This is not exactly helping concerns among some observers that perhaps Sifu is the common denominator in these suspicious losses.

Phishing scammers impersonate Andreessen Horowitz employee to drain crypto wallets

DMs from a person impersonating Peter Lauten:
Impersonator: "hi 👋"
Victim: "Hello Peter"
Impersonator: "It's great connecting with you here. I'm from @a16z, and we're on the lookout for compelling stories in the web3 space for our "My First 16" podcast. We love diving into the early stages of innovative projects - the ups, the downs, and everything in between."Messages from a scammer impersonating Peter Lauten (attribution)
Attentive phishers noticed when Andreessen Horowitz partner Peter Lauten changed his Twitter username from @peter_lauten to @lauten, and snapped up the previous username. They then began contacting various targets in the cryptocurrency world, asking to set up meetings to arrange appearances on the venture capital firm's crypto podcast.

The scammers followed a familiar playbook in which they asked their targets to download video call software called "Vortax", which was actually wallet draining malware. However, these scammers had a leg up on some others who have been running that scheme: the Andreessen Horowitz website still listed Lauten's old username on their website, giving even skeptical victims some reassurance that the account was legitimate.

According to crypto sleuth zachxbt, who first reported on this incident, one victim lost $245,000 when his wallets were drained by the malware.

Terraform Labs, Do Kwon reach $4.5 billion settlement with the SEC

Terraform Labs and its former CEO Do Kwon have agreed to settle the SEC's civil action against them with a $4.5 billion payment of disgorgement, interest, and penalties. Kwon and the company were behind the collapsed Terra/Luna stablecoin project, which imploded in May 2022. It was among the first dominoes in what ended up being an industry-wide collapse.

If the settlement is approved by the judge, Kwon will personally be responsible for around $200 million of the settlement payment, with Terraform Labs shouldering the rest. Although the settlement is among the largest the SEC has received in a securities fraud lawsuit, it's unlikely the company will ever pay anything close to the total amount, as it is in bankruptcy and claims to have only around $150 million in assets remaining. Both the company and Kwon will be banned from trading crypto asset securities.

The substantial fine is among the lesser of Kwon's worries at the moment, as he is still in jail in Montenegro pending extradition to either South Korea or the United States to face serious criminal charges for his role in the fraud.

UwU Lend suffers almost $20 million hack

The defi lending protocol UwU Lend was hacked for around $20 million. After various blockchain security firms observed suspicious outflows of funds, the protocol acknowledged there had been a "situation" on their Twitter account, and wrote that they had paused the protocol while they were investigating.

UwU Lend was founded by Michael Patryn, aka Omar Dhanani, aka "0xSifu" — a co-founder of the ill-fated QuadrigaCX exchange and ex-con. He also pseudonymously ran the defi cryptocurrency project Wonderland until his identity was revealed after the protocol suffered a meltdown.

Loopring's "most secure" wallet hacked for at least $5 million

Although Loopring markets its wallet application as "Ethereum's most secure wallet", that's evidently a pretty low bar. They disclosed that they had suffered a breach in their wallet recovery service, which allows individuals to designate trusted entities to recover assets or freeze compromised accounts. An attacker was able to "recover" assets from wallets that had only designated a single Loopring guardian, pilfering at least $5 million.

Loopring announced that they had suspended their account recovery operations, and were working with law enforcement to trace the attackers.

New York Attorney General sues over $1 billion NovaTech and AWS Mining crypto pyramid schemes

Cynthia and Eddy Petion, with a car behind them printed with the NovaTech brandingCynthia and Eddy Petion (attribution)
The New York Attorney General’s office has sued Cynthia and Eddy Petion over two allegedly fraudulent cryptocurrency pyramid schemes called AWS Mining and NovaTech. They particularly targeted victims of Haitian descent, promoting their schemes in Creole, leveraging their victims’ religion, and promising them “financial freedom” and “freedom from the plantation”.

In reality, the schemes were pyramid schemes in which investors earned crypto for recruiting others to buy in. NovaTech also used the funds from newer investors to pay out the supposed “returns” from the investment scheme, in a classic Ponzi fashion. From August 2019 – April 2023, victims deposited more than $1 billion into NovaTech. Though it was described as a trading operation, only about $26 million ever went into crypto trading.

In June 2022, the couple secretly sold their Florida house and moved to Panama, while continuing to pretend they were in the state. Speaking to another operator of the scheme, Cynthia Petion advised: “leave the country…they can’t serve you if they can’t find you lol.”

Blockchain developer loses over $48,000 after posting private key to Github

A blockchain developer posted on Twitter that he had lost almost $50,000 after his cryptocurrency wallet was drained. He explained that he had been working on a software project on Github in a private repository that contained his wallet's private key. In order to apply for a funding grant from the Optimism project, he had to make the repository public. However, he forgot that the secret key was in the repository.

Generally, it is very bad practice to store sensitive secrets in Github, even when projects are set to private.

"Got drained of everything," he wrote on Twitter. A commenter asked how long it took for the attacker to steal the money after the private key became publicly visible. "2 min", he replied.

Lykke exchange hacked for over $23 million

The UK-based Lykke crypto exchange suffered an exploit that saw more than $23.6 million stolen from the platform. The platform shut down trading two days later, and some customers reported seeing balances of 0 in their accounts.

The theft was first noticed by outside researchers, who saw the suspicious outflows and accused the platform of not communicating the security breach to its customers. The following day, Lykke acknowledged the attack and informed customers via email.

DOJ indicts Epoch Times executive for crypto scam

Widong "Bill" Guan, Chief Financial Officer of the far-right Epoch Times media company, has been indicted on money laundering conspiracy and bank fraud charges for his alleged involvement in a cryptocurrency scam and money laundering operation. According to the Justice Department, Guan used cryptocurrency to purchase prepaid debit cards that were loaded with fraudulently obtained unemployment insurance benefits. Guan and others then laundered the funds through bank accounts they'd fraudulently opened using stolen personal information.

According to the DOJ, banks became suspicious when the revenue for the Epoch Times increased 410% — from around $15 million to around $62 million — from the previous year.

Velocore decentralized exchange exploited for $6.8 million, Linea blockchain halts in response

The Velocore DEX, built on the Linea Ethereum layer-2 blockchain, was exploited for around $6.8 million in ETH. The hacker was able to take advantage of a bug in the project's smart contract in the logic to calculate swap fees. Using a flash loan attack funded through Tornado Cash, the attacker drained most of the tokens from the pool, bridged the tokens back to the Ethereum mainnet, and then tumbled the stolen funds back through Tornado.

In an unusual move, the operators of the Linea layer-2 blockchain chose to unilaterally halt the chain in order to stop the outflow of stolen assets. Because Linea — like many layer-2 chains — is highly centralized, it was possible for the Linea team to unilaterally stop the production of blocks.

This was very controversial, as a single operator being able to unilaterally control the operation of a blockchain goes against much of the cryptocurrency ethos. Following their action, they tried to explain that "Linea's goal is to decentralize our network - including the sequencer. When our network matures to a decentralized, censorship-resistant environment, Linea's team will no longer have the ability to halt block production and censor addresses - this is a primary goal of our network".

Japanese crypto exchange DMM Bitcoin loses $308 million

A Japanese cryptocurrency exchange called DMM Bitcoin has announced that they suffered an "unauthorized leak" of 4,502.9 bitcoin (~$308 million) from a company wallet. They've provided very little in additional details around how the loss occurred, or who may have been involved. They have taken some of their services offline as they investigate the incident.

The company claims it will replace the lost funds with help from other companies in their group.

This is one of the largest cryptocurrency thefts in recent history, rivaling the roughly $320 million theft from the Wormhole bridge in February 2022 and the $477 million theft from FTX in November 2022.

FTX executive Ryan Salame sentenced to 7.5 years imprisonment

Ryan SalameRyan Salame (attribution)
Ryan Salame was the CEO of FTX Digital Markets which was the Bahamian portion of the FTX business. In September 2023, just before Sam Bankman-Fried's trial began, Salame pleaded guilty to one count each of conspiracy to operate an unlicensed money transmitting business and conspiracy to make unlawful political contributions and defraud the Federal Election Commission. He was the only co-conspirator of four to not plead under a cooperation agreement, and he did not testify at Bankman-Fried's trial.

In his sentencing memo, Salame asked for a sentence of no more than 18 months imprisonment, claiming that "he was duped, as was everyone else, into believing that the companies were legitimate, solvent, and wildly profitable." Judge Kaplan didn't seem to agree, ultimately passing down a sentence greater than the five to seven years requested by prosecutors. He also will pay $6 million in forfeiture, $5 million in restitution, and spend three years on supervised release.

Salame is the first of Bankman-Fried's co-conspirators to be sentenced.

Memecoin team accused of hacking influencer Twitter account to manipulate markets

According to crypto sleuth zachxbt, the team behind the Solana-based $CAT memecoin hacked the Twitter account of "Gigantic-Cassocked-Rebirth" (@GCRClassic) crypto influencer.

First, the team sniped their own $CAT token launch to obtain 63% of the token supply, ultimately selling a portion of it for around $5 million. Then, they took out $2.3 million and $1 million long positions on the ORDI and ETHFI tokens, respectively. Finally, they posted from the compromised influencer account to shill the ORDI and ETHFI tokens to his massive following. Ultimately, their gambit doesn't appear to have been incredibly successful: they made around $34,000 on the ORDI position, but lost $3,500 on the ETHFI position. However, as zachxbt noted, it's possible they also opened positions on centralized exchanges where the outcomes aren't publicly visible.

"Normie" memecoin plummets 99% after exploit

An attacker perpetrated a flash loan attack on the "Normie" memecoin on the Base layer-2 blockchain to drain millions of NORMIE tokens. The vulnerability was evidently discovered in March, but never patched.

Although the token claimed to have a market cap of $42 million, the attacker was only able to cash out around 224 wETH (~$882,000). However, the losses to some holders of the token were much more substantial. One individual had put around $1.16 million into $NORMIE, and those holdings are now priced at around $150.

The attacker has been negotiating the possible return of funds to the project team, who has expressed interest in relaunching the token.

Caitlyn Jenner launches memecoin amid deepfake confusion

Tweet by Caitlyn Jenner: "make america great again!!! 🇺🇸 and we love crypto! @pumpdotfun 🫡" with a photo of Jenner grasping hands with Donald TrumpJenner's launch tweet (attribution)
Olympic athlete-turned-Trumpworld media personality Caitlyn Jenner has confused many by apparently launching a memecoin on pump.fun and heavily promoting it on her Twitter account with more than 3 million followers. Her original post featured a photo of her grasping hands with Donald Trump, with the text "make america great again!!! 🇺🇸 and we love crypto!".

At first, people widely believed her account had been hacked, given how frequently celebrity token promotions turn out to be compromised Twitter accounts. Then, she began joining Twitter spaces and posting videos about the token, but with the emergence of more and more convincing deepfakes, even those didn't convince people that it was truly Jenner behind the token.

Despite the confusion — or perhaps because of it — the token has been popular.

The token launch was linked to Sahil Arora, a person allegedly connected to multiple celebrity rug pulls and pump-and-dumps. However, Jenner quickly turned on Arora shortly after the token's launch, posting on Twitter "FUCK SAHIL! He scammed us! BIG TIME!" and that "Sahil appears to be fully out".

Jenner is not the first in her family to get mixed up with crypto. In October 2023, her stepdaughter Kim Kardashian was fined over $1 million for unlawful touting of a crypto security.

Gala Games suffers $21 million hack

Someone was able to mint 5 billion $GALA tokens, the native token of the Gala Games blockchain gaming project. The tokens would be notionally worth around $200 million based on their paper value, although such a massive amount wouldn't be sellable without impacting the token price. Furthermore, the Gala Games team was able to add the attacker's address to a blocklist shortly after the theft a few hours after the attack began, preventing them from swapping more of the tokens.

Altogether, the attacker was able to swap around $21 million of the GALA tokens into ETH before the address was frozen.

The attacker was able to perform the exploit because they had access to a wallet with admin access to the Gala Games smart contract. It's not clear if the attacker is a rogue employee, or if an admin wallet was compromised.

As of writing, Gala Games has not publicly acknowledged the attack.

Crypto scam money launderers charged for laundering more than $73 million through Deltec

Two people were charged in California for laundering money obtained from cryptocurrency and fiat "pig butchering" scams. After receiving the money from the investment scammers, the launderers then allegedly helped to obfuscate at least $73 million in transactions by moving the money through Deltec Bank in The Bahamas and converting it into the Tether stablecoin.

Deltec is a well-known bank in the cryptocurrency world, mostly for its ties to Tether and to FTX. In July 2023, US authorities seized tens of millions from Deltec accounts in connection to a cryptocurrency money laundering investigation. It's not clear if that was the same investigation.

"Crypto King" Aiden Pleterski arrested

Aidan Pleterski and a woman with her face blurred stand in front of a lime green Lamborghini in what appears to be an upscale suburbAiden Pleterski (attribution)
Aiden Pleterski, a 25-year-old who goes by "Crypto King", has finally been arrested and charged with fraud and money laundering. In 2022, he was sued by a group of investors who have lost at least CA$41.5 million (~US$30.5 million) they entrusted to him to invest on their behalf. He had promised massive profits, and told them that any losses on their initial investments would be repaid in full. A judge froze his assets in July 2022, and the court ordered him and his company into bankruptcy the following month. The bankruptcy proceedings have so far recovered around CA$3 million (US$2.2 million).

Investigators for the bankruptcy proceedings found that Pleterski had invested less than 2% of customer funds. Around $16 million instead went to personal expenses, including luxury cars, a $45,000-a-month lakefront mansion, private jets, and vacations.

Even after being sued, filing for bankruptcy, and being kidnapped and beaten by angry investors, Pleterski flaunted his supposed wealth online. Much to the indignation of the creditors in his bankruptcy, he has continued to regularly livestream himself gambling for hours, spending $150,000 on Legos, and driving luxury cars.

Pleterski was released the same day he was arrested, thanks to a CA$100,000 (~US$75,000) surety bond posted by his parents.

Pump.fun suffers $2 million loss to former employee who claims he wanted to "kill" the project for "inadvertently hurt[ing] people"

Pump.fun is a Solana-based memecoin generator that soared to popularity recently amid a resurgence in memecoin trading. On May 16, the project suffered a $2 million exploit by an attacker who then began airdropping the money to somewhat random wallets.

A former employee — whose real identity is known — brazenly took credit for the theft on Twitter. They wrote: "everybody be cool, this is a r o b b e r y. ... I'm about to change the course of history. n then rot in jail. am I sane? nah. am I well? v much not. do I want for anything? my mom raised from the dead n barring that: life without parole."

In a Twitter Spaces chat, the attacker stated that he had worked for the company briefly, and that he had grievances against its management. "I just kind of wanted to kill Pump.fun because it's something to do... It's inadvertently hurt people for a long time," he said.

Pump.fun paused trading shortly after the attack, and stated that they were "cooperating with relevant parties, including law enforcement, to minimize the damage." The attacker responded to the post: "Neener neener neener".

Brothers indicted for $25 million MEV bot exploit

Two brothers, Anton and James Peraire-Bueno, were indicted for a theft involving MEV — maximal extractable value. MEV involves previewing upcoming transactions on a blockchain and taking actions to extract additional profits — which can sometimes be substantial — based on that information.

According to the Justice Department, the Peraire-Buenos exploited a flaw in popular MEV software called "MEV-boost", which is used by most Ethereum validators. By creating their own validators and "bait transactions", they were able to trick MEV bots into proposing transactions involving illiquid cryptocurrencies, which the brothers then frontran. They were able to create false signatures that tricked a MEV-boost relay into releasing information about upcoming blocks that they were able to tamper with.

The brothers were charged with conspiracy to commit wire fraud, wire fraud, and conspiracy to commit money laundering, and face up to 20 years in prison for each charge.

The Justice Department is describing the case as a "first-of-its-kind manipulation of the Ethereum blockchain". The case is an interesting one, as some believe the practice of MEV itself exploits Ethereum users. Others believe anything you can do with code should be allowed — "code is law". However, by signing false transactions and tricking the relay into releasing private information, the brothers' actions do seem to go beyond simply making profits in a "code is law" Wild West, and into the realm of actual fraud.

$2 million stolen from ALEX's XLink bridge by bumbling exploiter

An attacker tried to pull off what could have been a ~$12 million heist from ALEX Lab's XLink bridge after a private key was compromised. However, the sloppy work by the attacker enabled an apparent whitehat hacker to step in.

The attacker was successfully able to transfer around 13.8 million STX (~$2 million) on the Stack BTC layer-2 chain. However, their attempts to steal assets notionally worth around $4.3 million from the project's BNB Chain implementation failed when they upgraded the project contract to a malicious version, but failed to prevent other people from calling the withdraw function. The attacker's first transactions to withdraw the funds themself failed, and an apparent whitehat hacker was able to step in and complete the withdrawal ahead of the exploiter. They later negotiated a deal for the funds' return, after offering a 10% "bounty".

The exploiter had also tried, and failed, to steal assets notionally worth around $5 million on the Ethereum blockchain, but failed to do so. ALEX Lab later announced they were able to recover or secure around $4.5 million of those assets. ALEX also later announced that they believed the attackers were part of the North Korean Lazarus Group.

Tornado Cash developer sentenced to more than five years imprisonment in the Netherlands

Alexey Pertsev, one of the developers of the Tornado Cash mixing service, was found guilty of money laundering and sentenced to 64 months imprisonment in the Netherlands. Prosecutors claimed that Pertsev knew the service was being used to launder money, but "chose not to intervene". They argued that, although the developers could not necessarily prevent bad actors from laundering money through the service directly, they could have done more to prevent people from using the web interface to wash funds from known criminal wallets.

The case is a concerning one, as sanctioning software developers for how the code they write is used — particularly when it comes to software intended to protect privacy — has frightening implications. Although there is some precedent in the United States that "code is speech", and merely writing and publishing code is protected by the First Amendment, that obviously does not apply to the Netherlands. A collaborator to Pertsev, Roman Storm, is set to be tried on charges of money laundering and sanctions violations in the United States in September, and that case is likely to grapple with this exact issue.

Sonne Finance hacked for at least $20 million

The Sonne Finance lending protocol was exploited for at least $20 million as an attacker was able to exploit a vulnerability in some of their smart contracts. Sonne is a fork of the Compound Finance project, which has known vulnerabilities that are sometimes not properly addressed by people who reuse the code — as has happened with Radiant Capital and Rari.

After being alerted to the theft by several security companies, Sonne announced they had paused the contract on the Optimism Ethereum layer-2 chain.

Cypher contributor admits to stealing over $300,000 due to "crippling gambling addiction"

After the founder of the Solana-based Cypher futures trading protocol publicly accused a core contributor of stealing funds, the contributor — publicly known only as "hoak" — has confessed to the thefts.

Cypher was hacked for $1 million in August 2023, but was able to recover around $600,000 of the stolen funds, which they promised to distribute to impact users via a redemption fund. However, over a period of months and unbeknownst to the rest of the team, hoak had been dipping into the recovered funds — taking around half of what was in the fund for himself.

After he was accused, hoak fessed up in a public statement where he wrote that his actions were a "culmination of what snowballed into a crippling gambling addiction and probably multiple other psychological factors that went by unchecked for too long." He continued: "I know likely nothing I say or do will make things better - perhaps other than rotting in jail. To address the elephant in the room, the allegations are true, I took the funds and gambled them away. I didn’t run away with it, nor did anyone else."

SEC sends Wells notice to Robinhood Crypto

Robinhood has disclosed that they received a Wells notice from the US Securities and Exchange Commission in relation to their "Robinhood Crypto" product. This indicates that the SEC believes that some of the assets that can be traded via Robinhood Crypto are securities.

In the past, Robinhood has removed cryptocurrencies from trading after they were alleged to be securities by the SEC, such as Solana (SOL), Cardano (ADA), and Polygon (MATIC) in the wake of the lawsuits against Binance and Coinbase. However, given the SEC's stance that most cryptocurrencies are securities, it seems likely that the SEC believes one or more of the 14 non-bitcoin cryptocurrencies Robinhood offers may also be a security.

Robinhood's Chief Legal Officer issued a statement that "We firmly believe that the assets listed on our platform are not securities and we look forward to engaging with the SEC to make clear just how weak any case against Robinhood Crypto would be."

GNUS.ai exploited for $1.27 million

An exploiter was able to create a fake version of the $GNUS token on the Fantom blockchain, then bridge the tokens to Ethereum and Polygon where they were then sold as though they were authentic. They were able to drain $1.27 million from the project's liquidity pools.

GNUS.ai (short for "Genius", not a reference to the animal) is one of many AI-related blockchain projects that has sprung out of the recent AI hype. This particular one promises to allow people to "utiliz[e] unused cycles" on various computing devices for computation-intensive AI systems, using cryptocurrency for payments.

Cred executives indicted

The former CEO, CFO, and CCO of the cryptocurrency lending service Cred have been indicted on multiple charges involving wire fraud and money laundering. They were charged in connection with their operation of the Cred platform, which went bankrupt in November 2020 after hiding its insolvency for several months.

Cred had claimed to customers that they engaged in only "collateralized or guaranteed lending", hedged their investments, and "comprehensive insurance", but hid that "virtually all the assets to pay the yield were generated by a single company whose business was to make unsecured micro-loans to Chinese gamers." Furthermore, they did engage in uncollateralized lending, did not hedge their investments, and did not hold insurance as they had claimed.

Around $150 million in customer funds were lost in the collapse based on prices at the time, though those crypto assets would have been priced substantially higher at various times since.

Wallet loses over $72 million to address poisoning

An Ethereum wallet was apparently drained of 1,155 wrapped bitcoin (~$72.7 million) when they transferred it to a malicious address that had been operating an address poisoning scheme.

Address poisoning is a scam tactic that takes advantage of crypto traders' tendencies to copy and paste wallet addresses from their transaction histories, since the addresses are long strings of characters that are not practical to type from memory. By creating a new wallet address with identical start and/or ending character strings to addresses used by the victim, and spamming the victim with transactions from that similar address, scammers are sometimes able to get victims to erroneously copy the spoofed address for future transfers.

That's what appears to have happened in this case, when a victim transferred 1,155 wrapped bitcoin — tokens pegged to the bitcoin price meant for use on the Ethereum blockchain — to the malicious address.

The victim and the exploiter later reached an agreement for the return of most of the funds, with the exploiter keeping $7.2 million as a "bounty".

Pike Finance exploited for $2 million in two separate attacks

Pike Finance, a cross-chain lending protocol, was exploited twice in four days as attackers discovered vulnerabilities in the project's smart contracts.

The first attack, on April 26, was enabled by a flaw in the security measures related to transfers of the USDC stablecoin. An attacker was able to change the recipient address and amount, ultimately making off with almost $300,000 in the stablecoin. Pike released a postmortem two days later, acknowledging that the bug had been identified by a third-party auditor but had not been rectified by their team.

When the Pike team went to patch the smart contracts to thwart this attack, they introduced new, even worse vulnerabilities. As a result, on April 30, an attacker was able to upgrade the project's smart contracts to malicious ones, then withdraw $1.68 million in ETH, ARB, and OP tokens.

Pike Finance has offered a 20% reward for the return of the funds or information pertaining to the attacker, and has promised "a plan to make users whole". Pike, which launched in early 2024, is backed by Circle and Wormhole.

Roger Ver arrested for $50 million tax fraud

Portrait of Roger VerRoger Ver (attribution)
Roger Ver, an early bitcoin investor who later became an outspoken evangelist for the fork Bitcoin Cash, has been arrested on tax fraud charges. According to the Department of Justice, Ver evaded almost $50 million in owed taxes by concealing income and lying to tax preparers about his bitcoin assets as he attempted to renounce his US citizenship and become a citizen of the tax haven St. Kitts and Nevis.

Ver was arrested in Spain, and the United States will seek his extradition.

Besides his tax woes, Ver has also been caught up in accusations by CoinFLEX that he owed the platform around $84 million after failing to meet a margin call. Ver has in turn claimed that CoinFLEX owed him money. CoinFLEX filed for restructuring in August 2022.

Changpeng Zhao sentenced to four months imprisonment

Changpeng ZhaoChangpeng Zhao (attribution)
Former Binance CEO Changpeng "CZ" Zhao has been sentenced to four months in prison after pleading guilty to money laundering-related charges. The charges were filed in November, and Zhao entered a guilty plea, resigned from the company, and agreed to pay a $50 million fine.

Prosecutors sought a three year sentence for Zhao, while Zhao requested to serve no time. The judge ultimately decided on a sentence closer to the five-month sentence that was being recommended by the Probation Office.

Rain cryptocurrency exchange hacked for $14.8 million

Bahrain-based cryptocurrency exchange Rain was exploited for around $14.8 million dollars on April 29. The exchange did not publicly disclose the hack until the suspicious outflows across wallets on multiple blockchains were noticed by blockchain investigator zachxbt.

After zachxbt sounded the alarm on May 13, Rain admitted that they had had a "security incident", but stressed that customer funds were safe, and stated that the Rain Group had "covered any potential losses resulting from this incident".

ZKasino scam suspect arrested by Dutch police

In the wake of the $33 million ZKasino rug pull, Dutch police have arrested an as yet unnamed 26-year-old who is likely "Derivatives_Ape", the creator of the project. The police also seized assets estimated at more than €11.4 million (~US$12.3 million) including real estate, a luxury car, and crypto. According to police, they began investigating the project only days earlier, after hearing reports of the rug pull on Twitter.