The song didn't play for long, the scammer didn't enjoy it for long: the theft of $243 million in BTC and OSINT

Man

Professional
Messages
3,088
Reaction score
631
Points
113
The story of the investigation into how Greavys (Malone Iam) Wiz (Veer Chetal), and Box (Jeandiel Serrano) stole $243 million from one person on August 19, 2024 using a sophisticated social engineering attack, and the efforts of ZachXBT that helped lead to multiple arrests and the freezing of those millions of dollars.

aff640eac6ea10313a348bd0bd6f225d.jpeg


So, a quick introduction to the incident that happened: On August 19, 2024, threatening individuals attacked one Genesis creditor by:
  • Calls on behalf of Google support service to a spoofed number with the aim of compromising personal accounts;
  • They called as Gemini support, claiming that the account was hacked;
  • By deception (various social engineering techniques), the victim was forced to reset 2FA and send funds to a hacked wallet;
  • Forced the victim to use AnyDesk to provide screen sharing, which resulted in the loss of Bitcoin core private keys.

Gemini Transaction Hash Link: 59.34 BTC - Aug 19 at 1:48 am UTC

Transaction Hash Link: 14.88 BTC - Aug 19 at 2:30 am UTC

5cbfab2e96ecca7b62435e869afbf1e9.png
a0bef3647186798afd985356657ac53d.jpeg


Here is a private video showing live reactions from several participants upon receiving $238 million.


Transaction hash link: 4064 BTC - Aug 19 at 4:05 am UTC

Initial tracking showed that $243 million was split between each party, after which the funds quickly moved across more than 15 exchanges, instantly swapping between Bitcoin, Litecoin, Ethereum, and Monero.

f90c655287ee110f7f3cef974ad7bf69.jpeg


Wiz (Veer) got a big % from the heist and messed up during the screenshot by giving his full name while stealing.

3357d062f4041a3f39b5359d2694ba36.png


Additional comfort in the investigation was achieved by the fact that during numerous recordings, accomplices called him Veer in audio and chats ($35.5 million of his funds are located here)

Wiz's friend Light/Dark (Aakaash) helped launder money for him using eXch and Thorswap.
  • Like Wiz, he also leaked his name during a screenshot exchange.

The destination address is also confirmed in the video.


Greavys (Malone) lives a flamboyant lifestyle, buying 10+ cars with stolen funds, clubbing with friends in LA and Miami, spending $250K-500K a night and giving girls Birkin bags.

e8586b8e4430fbdf3ba7635a79d4553a.png


By the way, in the central screenshot our Greavys a/k/a Malone gave his beloved a Lamborghini Urus worth about $241,843 and 3 Birkin bags worth about $63,000. But she didn't buy it and didn't even say thank you...

She only wrote that she was kidnapped again for lovemaking 😆

Greavys was discovered through OSINT in Los Angeles/Miami due to friends/girlfriends posting his location on social media every night.

a277531614f529b11c409d86bd03ea19.png


He also has an Instagram account, where he posted photos of himself under his own name earlier this year (malone.lv).

Box (Jeandiel Serrano) played his part by calling the victim as a representative of the Gemini exchange.

Box uses the same pfp on Discord, Telegram and other platforms.

4120a63a746c9af03f79284f8e671cd6.png


Currently $19.5M tied to Box is here

Danny Trauma (Dane) was active in the internal Telegram chat as Meech, although his exact role is unclear, although he is known to have access to several databases.

However, his ex-girlfriend leaked all his photos on social media, so information about him became public knowledge.

A group of eth addresses associated with Box/Wiz raised $41M+ from two exchanges, mostly funneling it to luxury goods brokers to buy cars, watches, jewelry, and designer clothing.

07c2ec74269535a39040490682eed933.jpeg


This is also supported by what was said in the chats about spending funds.

63be43205a867f99086f09e31680185a.png


While most of the funds were converted to XMR, both Box and Wiz accidentally linked laundered funds to dirty funds in several cases.

Wiz showed during the screenshot the address to which he sent funds for the purchase of designer clothes and which had million-dollar connections with the above cluster (this address).

ca57b384301c9c16d3620ad6c1795eea.png


4c70a4552cacc6f1e529ff4606a16cc6.jpeg


With the assistance of CFInvestigators & zeroshadow_io and the Binance Security Team, over $9M+ have been frozen and $500K+ have already been returned after investigating the incident in close cooperation with the victim.

As a result, Box and Greavys were arrested on September 18 in Miami and Los Angeles.


Source
 
Top