1/ Here’s how KongBTC, a Dubai based influencer fraudulently mislead 100+ people into losing 49.114 BTC
👇
2/ Back in Fall of 2018 Kong & his partner VJ frequented a number of different crypto servers eventually opening up three different investment pools (TCD, CTH, Solo pool)
3/ At first they opened a ETH based trading pool in The Crypto Den (TCD) that Kong & his partner claim turned a 30% profit when it was in fact a loss.
Here’s the contract that was agreed to by a TCD pool members.
4/ Simultaneously they ran another pooled fund of 17.514 from a Discord community called The Crypto Hub (CTH). They paid out members of the TCD ETH pool with these proceeds.
(Video call held with Kong after funds were all lost)
1/ I uncovered a coordinated network of 10+ accounts manufacturing viral panic about war and politics to drive traffic to crypto scams.
Strategy:
>Purchase accounts with followers
>Doompost multiple times per day
>Repost content from alt accounts
>Promote fake giveaway or scam
>Change username
2/ Example: @wanglaurentceo
They started by purchasing an account with followers and use AI to create a fake Asian version of Mario Nawfal.
(User ID 1804235884826333184)
3/ Here’s related accounts reposting to boost the reach of posts about exaggerated or fake news.
This causes them to go viral each day with millions of views and thousands of likes / replies.
1/ Meet @WheresBroox (Broox Bauer), one of the multiple @AxiomExchange employees allegedly abusing the lack of access controls for internal tools to lookup sensitive user details to insider trade by tracking private wallet activity since early 2025.
2/ Axiom is a crypto trading platform founded by Mist & Cal in 2024. After going through Y-Combinator's Winter 2025 batch, it quickly became one of the most profitable companies in the space, generating $390M+ in revenue to date.
I was retained to investigate allegations of misconduct at Axiom after receiving reports.
3/ Broox is a current Axiom senior BD employee based in New York.
In the clip Broox states he can track any Axiom user via ref code, wallet, or UID and claims he can "find out anything to do with that person".
He also describe researching 10-20 wallets initially and slowly increasing over time "so it does not look that suspicious"
In a separate clip from the same recording, Broox sets ground rules for how to request lookups from him and then says he'll send the full list of wallets.
The full recording is a private call of the group members strategizing.
1/ Meet the threat actor John (Lick), who was caught flexing $23M in a wallet address directly tied to $90M+ in suspected thefts from the US Government in 2024 and multiple other unidentified victims from Nov 2025 to Dec 2025.
2/ Earlier today John got into a heated argument with another threat actor known as Dritan Kapplani Jr. in a group chat to see who had more funds in crypto wallets.
In 'The Com' this is known as a band for band (b4b).
However the entire interaction was fully recorded.
3/ In part 1 of the recording Dritan mocks John however John screenshares Exodus Wallet which shows the Tron address below with $2.3M:
TMrWCLMS3ibDbKLcnNYhLggohRuLUSoHJg
1/ Meet Haby (Havard), a Canadian threat actor who has stolen $2M+ via Coinbase support impersonation social engineering scams in the past year blowing the funds on rare social media usernames, bottle service, & gambling.
2/ On Dec 30, 2024 Haby posted a screenshot in a group chat showing off a 21K XRP ($44K) theft from a Coinbase user.
rN7ddvk4DrGHZUrBfNARJEEAbPkky9Mwcz
3/ On Jan 3, 2025 Haby posted a screenshot from his Exodus wallet showing his Telegram & IG accounts.
I matched up the historical balances to the screenshot and found the XRP address linked to two other Coinbase user thefts for ~$500K total.