CrYptOG
5 LIVE

Avengers Anti-Fraud Alliance

CrYptOGOn-chain forensic investigations into cryptocurrency investment fraud

I trace stolen money on-chain, and publish the evidence while the schemes are still taking deposits.

I follow stolen money on the blockchain. I publish the proof while the scheme is still taking people’s money.

150+Investigations
100k+Wallets scanned
$2.29B+Value of schemes investigated
$400M+Exposed before charges were filed

$1.89B HyperFund (DOJ) · $400M Goliath Ventures (U.S. Attorney’s Office, M.D. Fla.) · $4M measured on-chain across the Aurum / NEYRO reports. Eight further cases carry no published figure.

trace — aurum/neyro — bsc mainnet

What do you want to do?

Before anything else: if somebody has offered to get your money back, be careful. Real recovery never asks you to buy anything. Read why →

Case files

Investigations, and where they ended up

The investigations

Each file states what was claimed, what the chain showed, and what happened next. Status reflects the public record, not my opinion — where a matter is before a court, the court's language is used.

Each report shows three things: what the scheme promised, what the blockchain actually shows, and what happened next. Where there is a court case, I use the court’s own words.

Aurum

Aurum / NEYRO — the exit drain

BSC · Ethereum · Base · Arbitrum
New Still draining

When the fake trading bot stopped paying, Aurum didn’t just vanish. Under cover of an “airdrop season 2”, users were walked into signing a single token approval — and a purpose-built contract has been pulling USDT and USDC straight out of their wallets ever since. If you connected a wallet to Aurum or NEYRO, revoke your approvals today.

A contract is still taking USDT and USDC out of people’s wallets. It uses a permission they signed for a fake “airdrop”. So far $2.88M has gone, from 4,411 wallets. If you ever connected a wallet to Aurum or NEYRO, cancel your token approvals today.

Drained so far
$2.88M — a floor, not a total
Victim wallets
4,411 across three chains
Method
Approval phishing; 49 batch sweeps
Concentration
~98% on BNB Smart Chain
Cash-out
Relay bridge; Binance a lead, unconfirmed
Identification lead
One Coinbase withdrawal to the operator
Status
Live — pulls continuing at publication
Published
28 Aug 2026
Open the full report →
Companion to the Aurum / NEYRO brief, which covered the Ponzi phase. This report covers what came after: outright theft from wallets that had already been emptied of deposits. The drainer contract hard-codes a single collector address and a single permitted caller, and BSCScan independently labels both wallets “Aurum Foundation 2”. The Binance endpoint sits beyond a cross-chain bridge and is treated as a lead to confirm rather than an observed deposit. No individual is named; identification rests with exchange records under lawful request.
RIFT Protocol

RIFT Protocol

Hyperliquid · Arbitrum · Base
New Taking deposits

Sold as an automated engine paying a daily return out of “the protocol’s market-making flow”, with a live feed of real trades as proof. The trades are real. During the exact 24-hour cycle in which one New Zealand investor was credited $1.67, the trading account behind that feed closed two positions for a realised loss of $14.26 — while $131,419 of new deposits arrived at the same address.

It pays a small amount every day and shows you real trades as proof. The trades are real, but they lost money during the same day it paid out. New deposits are still coming in.

That cycle
−$14.26 traded, +$1.67 credited
Peak ever at risk
$5,844.88 — 0.217% of balance
Pool advertised
$8.92M; $2.7M locatable
The quiet period
50 days, $892 traded, paid daily throughout
Undisclosed fee
0.5% each way, 4 collection addresses
Recorded claims tested
8 of 8 contradicted by the trade record
Operator
Marida Limited, Hong Kong BR 76783901
Published
22 Aug 2026
Open the full report →
Shares treasury infrastructure with 3FO / Alpha AI, documented separately here — the same deposit address, and one corporate wallet paying both platforms’ promoters in multiples of a single unit price. The Terms of Service name Marida LTD four times and disclose no company number, country or address; the jurisdiction was found in the operator’s own card product. The trade hashes are genuine — the claim circulating elsewhere that they are fabricated is wrong, and is corrected in the report. No allegation of criminal conduct is made against any named individual.
Northcrest Capital

NexusX / Northcrest Capital

TRON · USDT TRC-20
New Taking deposits

Sold as an SEC-regulated platform paying 1.2% a day, with member funds “not pooled, not shared”. One investor's $500 was swept out of its deposit address in eight and a half hours and batched with other people's money four minutes after that. The platform also states it has nothing to do with cryptocurrency; the investor was given four crypto deposit addresses.

It promises 1.2% a day and says your money is kept separate from everyone else’s. One person’s $500 was moved out within nine hours and mixed with other people’s money four minutes later. Payments to members stopped in July. Deposits did not.

Through one wallet
$1,477,325 / 6 months
Peak balance held
~$67,000
Reached members
$150,762 to 390 addresses
Out the other route
$618,277 in 16 transfers
Payments to members
Stopped after 25 Jul
Deposits
Heaviest volumes of its life to 15 Aug
Published
16 Aug 2026
Open the full report →
The depositor was recruited out of BG Wealth Sharing / DSJ Exchange — documented separately here — on the basis that this would recover those earlier losses. No SEC registration for Northcrest Capital was located; it is unconnected to the SEC-registered NorthCrest Asset Management, LLC of Plymouth, Minnesota, which is a genuine firm. That these addresses were issued by the platform rests on the depositor's contemporaneous account, not on the chain, and is stated as such in the report.
Goliath Ventures

Goliath Ventures

M.D. Fla. · 6:26-cr-158-GAP-NWH
Guilty plea

Marketed as a crypto liquidity-pool and DeFi fund paying 3–8% monthly. Prosecutors for the U.S. Attorney's Office reported that almost none of the money reached a crypto liquidity pool.

Sold as a crypto fund paying 3–8% a month. More than $400 million came in. About $1 million was actually invested. The person behind it has pleaded guilty and is waiting to be sentenced.

Raised
$400M+ (DOJ)
Actually deployed
~$1M
Admitted losses
$250M+
Outcome
Pleaded guilty; sentencing 8 Oct
The investigation that exposed it →
First investigated and exposed by Danny de Hek, the New Zealand investigative journalist who leads the Avengers — long before any charges were filed. Charges, plea and figures per U.S. Attorney's Office, M.D. Fla. Company entered Chapter 11; receiver appointed.
Aurum

Aurum Foundation / NEYRO

BNB Smart Chain · TRON
Collapsed

Sold as a non-custodial AI trading agent earning 12–18% monthly. The verified contract contained no withdrawal function a depositor could call. Nine days after this report published, the platform collapsed and announced it had been hacked.

Sold as an AI trading bot paying 12–18% a month. The contract had no way for a depositor to take money out. Nine days after this report, the platform shut down and said it had been hacked.

Through one wallet
$31.7M / 17 days
Layering
422 wallets, 352 × $50k
Real pool yield
~0.5% / year
21 Jul
Report published — still taking deposits
29 Jul
neyro.network seized by registrar
30 Jul
Wallets drained; “cyberattack” announced
Open the full report →
Company attributes the losses to a sophisticated cyberattack during a Web3 migration. BehindMLM's reading of the DNS and wallet timeline is that this was an exit scam. Regulator warnings preceded the collapse in Belgium, France, Poland, Hong Kong, Australia, New Zealand, Greece, Nigeria and Russia. On-chain groundwork by the investigator known as “Onchainmlm” / “Dana”, independently re-verified here. What happened after the collapse — the wallet drain that is still running — is documented in the companion report at the top of this page.
Boomerang

Boomerang

Polygon · flash-loan arbitrage
Collapsed

Sold as a flash-loan arbitrage bot paying daily returns. Users noticed the same trade size always paid the same profit — a dynamic market does not do that. The chain showed why: the trades lost money, and the payouts came from somewhere else.

Sold as a trading bot. The same trade size always paid the same profit, which a real market never does. The trades lost money, and the payouts came from a wallet someone topped up by hand. It collapsed while the investigation was running.

The $899 trade
Flash loan returned a loss
Profit source
Separate, manually topped-up wallet
V4 contract
0x…8400, funded via 0x…64F3
Hardcoded payouts
250,000-char string in their own source
Creator wallet
0x…EFDF — Zoom-verified
Outcome
Collapsed during the series
Watch Busted No 2 →
Wallet ownership established from the operators' own public Zoom calls, then verified against Polygonscan. The hardcoded payout table was found in the platform's front-end source by fellow Avenger Rob. Co-founder “Powell” was never publicly identified.

HyperVerse / HyperFund

HyperTech group
Charged

The scheme that built the playbook: rebrand, reissue, repeat. The interesting question was never one collapse — it was who carried the wallets across every rebrand.

One scheme, renamed again and again. The same wallets followed it through every new name. Sam Lee has been charged by the US Department of Justice — charged is not convicted, and he is presumed innocent unless a court decides otherwise. A promoter, R. Burton, was sentenced to 32 months.

Investor losses
~$1.89B alleged
Principal
Sam Lee — charged, DOJ
Promoter
R. Burton — 32 months
Chain
HyperFund → HyperNation → HyperVerse → HyperOne → Boomerang
Wallets tagged
750+ across rebrands
Method
Zoom-verified ownership, then on-chain
The King's Gambit →
Charges against Sam Lee per U.S. DoJ, District of Maryland; defendants are presumed innocent unless and until convicted. The link between the Boomerang CEO and the HyperTech programmes rests on wallet ownership he disclosed himself on public Zoom calls, traced from a July 2020 HyperFund deposit address through HyperNation withdrawals into Boomerang funding wallets. No charges have been filed in relation to Boomerang.
BG Wealth Sharing

BG Wealth Sharing / DSJ Exchange

GitHub · OSINT
Documented

The exchange's own source code was published to a public repository. It showed the backend was never what the marketing described. The repo came down; the evidence didn't.

The exchange’s own code was published online where anyone could read it. It showed the system did not work the way the marketing said. The UK regulator, the FCA, issued a warning in May 2025.

Method
Repo + domain analysis
Regulator
FCA warning, May 2025
Published
dehek.com, Apr 2026
Watch the on-chain deep dive →
Joint work with Danny de Hek's Avengers community; prior documentation by BehindMLM. A depositor who lost money here was later recruited into NexusX / Northcrest Capital, on the basis that it would recover those losses — see that case file.
MHT Trade

MHT Trading

BNB Smart Chain · MHTtrade.io
Rug-pulled

An “AI arbitrage” bot promising up to ~30% monthly. The staking contract that was meant to hold user funds held about fifteen dollars. Documented in April 2025; the scheme pulled its liquidity four months later.

An “AI trading” bot promising up to about 30% a month. The contract meant to hold everyone’s money held about fifteen dollars. Four months after this was documented, it took the remaining funds and shut down.

In the contract
~$15 against staked deposits
Where funds went
Split 97/3 to corporate wallets
Bot profit per trade
$0–$0.02
Aug 2025
PancakeSwap LP pulled, USDT swept
Were you affected? →
Per-trade profits orders of magnitude below the promised return is the structural signature of paying earlier users from newer deposits.

PlayGlobal Digital

Luxembourg · PLAYGLOBAL SA
Active offering

An invitation-only pre-sale of “11 million master tokens”, promising access to a fund described in the same conversation as both $100 billion and $100 million. No white paper, no contract address, no named chain, no audit. And it is being marketed to the victims of MHT under a recovery banner.

An invitation-only token sale. In one conversation the fund behind it was described as both $100 billion and $100 million. There is no white paper, no contract address and no audit. It is being sold to people who lost money in MHT as a way to get it back.

Entity
RCS Luxembourg B289162
MiCA status
No CASP authorisation located
Transition closed
1 July 2026
Referred to
CSSF · FCA · ESMA
Read the warning →
A Luxembourg company number confirms incorporation, not a licence. The promoter fronting the recovery narrative is the same person who recruited investors into MHT, which he confirms on the recorded call. Corroborated independently by Danny de Hek, 3 July 2026. Findings are assessments of cited evidence, not assertions of proven criminal conduct.
3FO

3FO / Alpha AI

Base · BTCC
Taking deposits

Yield “credited every Wednesday for life” against a token users cannot sell elsewhere. The credit appears on a web dashboard, not on any chain. There is no staking contract to inspect, because there is no staking contract.

It promises a payment every Wednesday “for life”, on a token you cannot sell anywhere else. The payment only appears on their own website, never on a blockchain. There is no staking contract to check, because there is not one.

Payout wallet
Funded solely by the deposit wallet
Trading activity
None visible on-chain
Entry
$500 of ETH paired to BTCC
Pattern
Same circular flow as HyperFund
Watch the breakdown →
Deposits in, corporate wallet, payouts back out to the same users. When the corporate wallet empties, withdrawals stop — that balance is the thing to watch. The same corporate addresses reappear in RIFT Protocol, documented separately here: one deposit address receives from both platforms, and a single payout wallet pays both sets of promoters.
MetaTronics

MetaTronics

BNB Smart Chain
Open — interim

An “algorithmic investing” platform whose payout hub is topped up by the same handful of addresses it pays out from, holds almost no standing balance, and disperses small amounts to hundreds of recipients.

The wallet that pays people out is refilled by the same addresses it pays. It holds almost nothing and sends small amounts to hundreds of people. Still being investigated. The only link to a person so far is what a promoter said on camera, and I have not been able to confirm that independently, so nobody is named here.

Payout recipients
214 addresses, 549 payments
Hub peak balance
~$3,279
Funding rail
No-identity cross-chain swaps
Status
Attribution not yet closed
How attribution works →
Interim working product. Wallet attribution currently rests on statements made by a promoter on camera and has not been independently confirmed, so no findings about any named individual are published here.

Promoter network mapping

Cross-scheme · ongoing
Continuous

The schemes die; the promoters don't. Tracking which recruiters reappear across rebrands is often the earliest available warning.

Schemes shut down, but the same people start the next one. Following who turns up again is often the earliest warning anyone gets.

Signals
Wallet reuse, Zoom records
Shared with
AAA, regulators
Submit a tip →
Individuals are named publicly only where supported by documentary or on-chain evidence.

Separately, I keep track of which promoters turn up again under a new scheme name. That is usually the earliest warning anyone gets. Submit a tip →

Contract audit

What they promise, next to what they deployed

A scheme controls what it says about itself. It does not control what its code does, and once a contract is deployed anyone can read it. So for each case below: on the left, what they told investors, quoted from their own site or call. On the right, what the contract they deployed actually does. Every contract here was published and verified by the operators themselves — this is their code, not my reconstruction of it. Pick a case.

The claim
You stay in control. Your capital stays on-chain and you retain full control at all times. NEYRO “Control” page — verbatim
Without custody — withdraw anytime. NEYRO “Control” page — verbatim
Contradicted. The verified contract exposes no function a depositor can call to withdraw. Only the operator can move funds — confirmed by pulling the public ABI, not inferred.
The code
// Verified "Exact Match" on BSCScan.
// Excluding imported libraries, the whole
// "AI trading bot" is these three functions:

setTokenId(uint256 _tokenId) onlyRole(ADMIN)
   // admin picks the pool position

increaseLiquidity(uint256 amt) internal
   // one-way: amount1Desired = 0

loop() onlyRole(OPERATOR)
   // pushes ALL user USDT into the pool

// NO withdraw()  NO deposit()  NO redeem()
// Nothing a depositor can call.

AAA bot — deployed

Intelligence, structured at the point of entry

The Avengers Anti-Fraud Alliance runs an off-chain Discord intelligence pipeline. Members file structured intelligence on scam projects and persons of interest; the bot validates each submission, awards Intel Credits (IC), and routes it to the right channel. Intel Credits (IC) drive a nine-level role ladder. Everything is a slash command — pick one to see what a member sees.

AAA-Submissions-Bot
AAA-Submissions-Bot BOT
Pick a command to see what a member sees.

Also registered: /extract · /amend · /cap-adjust. Two further personas run alongside the submissions bot — a stream transcript ingester, and Judge deHek, who presides over the Jury Room.

Join the Alliance.
There is nothing to buy. No deposit, no package, no entry fee, no token on sale. Intel Credits (IC) cannot be purchased at any price — the only way to hold any is to file intelligence that stands up to checking.

Wallet tags, promoter documentation, a recording from a Zoom you sat through: submit it, and if it holds, your Intel Credits (IC) move you up the nine-level ladder. Under the proposed STINK/BOUNTY protocol, the rank you hold when Phase 1 closes would set your bracket in any future $BOUNTY distribution.

Proposed is the operative word — no date, no promise, no valuation, and nothing owed to anyone. But the ledger starts the day you register, and backdating is not a feature. Zoom raiders welcome.
Join the AAA Discord

Video & writing

The work, in public

Everything is published with the chain data attached so it can be checked independently. If a finding can't be reproduced from public sources, it doesn't go out.

Recent investigations

All 24 videos →

Written reports

28 AUG 2026

After the Ponzi collapsed, an “airdrop” harvested wallet approvals. $2.88M pulled from 4,411 wallets, and still running. Revoke your approvals.

22 AUG 2026

One investor’s $200 followed through a single earning cycle. He was credited $1.67; the trading account behind the feed lost $14.26 in the same hours.

16 AUG 2026

Sold as SEC-regulated and paying 1.2% a day, with member funds “not pooled, not shared”. One depositor’s $500 left its deposit address in eight and a half hours and was batched with other people’s money four minutes later.

21 JUL 2026 · UPDATED

Deposits pooled, extracted by the operator, layered across 422 wallets into a no-identity swap service. Nine days later the platform collapsed and announced a hack.

APR 2026

What the repository showed before it was deleted, and why the timing of the deletion matters.

APR 2025
MHTtrade.io — on-chain analysis report

The staking contract held about fifteen dollars against user deposits. Published four months before the scheme pulled its liquidity.

Method

Start with what can be proved

How I check things

Chain data is public but anonymous. An address only becomes evidence once you can show whose it is — and the most reliable source for that has repeatedly been the operators themselves.

Anyone can see blockchain records, but they do not have names on them. A wallet only becomes evidence once you can show who it belongs to. Usually the operators show us themselves.

1 · Establish ownership

The first thing I do is search the wallet address itself. People publish their own wallets more often than you would think. After that: promoters share their screens on public calls, and a wallet shown that way belongs to them by their own admission, so there is nothing to argue about.

Step zero is searching the identifier. Self-publication is the strongest attribution evidence there is, and it is frequently sitting in a search index before any chain analysis begins. Beyond that: promoters share their screens on public calls, and wallets disclosed that way are self-identified — no attribution guesswork, no heuristics to argue with.

2 · Follow the funding

Find the wallet that pays users, then find the wallet that fills it. If the profits were real, nobody would need to keep topping it up.

Work backwards from the wallet that pays users to the wallet that fills it. If returns are real, that upstream wallet should not need topping up.

3 · Close the arithmetic

Check the sums inside a single block, where prices cannot move. Then the numbers either add up or they do not.

Settle everything inside one block, where prices are fixed. Then the sums either balance or they don't, and no amount of marketing changes the answer.

4 · Publish it checkable

Every claim comes with the wallet address or transaction behind it, so you can look it up yourself instead of taking my word for it. In a commissioned report the links are built in by the software, not added by hand, and printed copies carry the web address beside each one.

Every claim ships with the address or hash behind it, so a reader with a block explorer can reproduce the finding rather than take it on trust.

Report a scheme

If you've lost money, start here

If you have lost money, start here

Send me whatever you have: wallet addresses, transaction numbers, screenshots, and the name of whoever got you into it. Reporting a scheme is free and always will be. I will read it and add it to the record. It may become a report on this site, but I cannot promise that, and I cannot say when.

Paying is for something different: a written answer about your money, by an agreed date, in a document you can hand to a solicitor, your bank or the police. Only pay if somebody is waiting for that document. If you are not sure, send the free report and I will tell you which one you need. Nothing that identifies you is published unless you say so.

Send what you have — wallet addresses, transaction hashes, screenshots, the name of whoever recruited you. Reporting a scheme is free and always will be: it puts the scheme on the record, and it may end up as a published report — no promise either way, and no timescale. If instead somebody is waiting on a document about your money — a solicitor, your bank’s fraud team, a compliance desk — that is commissioned work, answered to a stated date. Not sure which you need? Send the free report and I will tell you. Nothing identifying you is published without your say-so.

If someone has offered to recover your losses, read this first.
Very often the people who took your money are the same people who come back offering to get it returned. It always looks the same: the paperwork is a few days away, there is a lawyer or a confidentiality agreement in the way, and somewhere there is a new coin, a membership, or a fee to pay.

Real recovery never asks you to buy anything. If getting your money back is tied to putting more money in, that alone is the warning.
The people who took the money are frequently the people who come back offering to get it returned. The pattern is consistent: a recovery group forms around a collapsed scheme, the paperwork is always days away, it is always gated behind lawyers or an NDA — and somewhere in the process there is a new token, a membership, or a fee.

Legitimate recovery never requires you to buy anything. If a recovery route is coupled to a fresh investment, treat that coupling itself as the warning, whatever else is true about the people involved.
What a regulated route looks like.
One HyperFund investor got money back through the UK banking system, using Wealth Recovery Solicitors, a law firm in Manchester. Most fraud cases are taken on with no fee if they lose.

The point is not that firm. The point is the type. A regulated solicitor can be checked before you hand over anything: their SRA number is 8000728 and their Companies House number is 11325165. Look both up yourself, the same way you would check a wallet on a blockchain explorer. Somebody who is not regulated gives you nothing to check, and no protection if it goes wrong.

I am not paid anything for pointing you there, and no recovery is ever guaranteed. Go to their website yourself — criminals pretend to be them.
One HyperFund investor known to me recovered capital through the UK banking system with Wealth Recovery Solicitors, an SRA-regulated law firm in Manchester working on a no-win-no-fee basis for most fraud cases.

The point is not the firm — it is the category. A regulated solicitor is checkable before you hand over anything: SRA 8000728 · Companies House 11325165. Verify both on the SRA and Companies House registers yourself, exactly as you would verify a wallet against a block explorer. An unregulated “recovery agent” offers you none of that, and no professional indemnity if it goes wrong.

Signposted, not endorsed — no recovery is guaranteed, and I take nothing for the referral. Note that WRS publish their own warning about fraudsters impersonating them, so approach them through their own site rather than an inbound message.
Support this work Ko-fi