Skip to main content
Sign in
AVOID.NET

Entity Graph

Browse extracted entities, relationships, and potential duplicates.

Total entities
22,711
Relationships
18,089
Potential duplicates
0

Entities

At 21:30 UTC, Blockaid detects an exploit targeting AFX Trade's custodial bridge on Arbitrum. Attackers with five compromised hot-validator keys withdraw 24.15 million USDC. Stolen USDC is converted to approximately 12,467.5 ETH and bridged to Ethereum.(2026-07-22:h1-2026-bridge-hack-cluster-same-day-35-6m-attack-wave-july-22-23)event
9738f83b
Assets recovered following the May 2026 Verus exploit are redeposited to the bridge, re-exposing user funds while the underlying vulnerability remained unpatched.(2026-07-08:h1-2026-bridge-hack-cluster-same-day-35-6m-attack-wave-july-22-23)event
081cea19
Verus-Ethereum bridge suffers its first exploit, losing approximately $11.58 million. Attacker forges Merkle proof exploiting a validation gap between source-chain committed value and Ethereum-side payout. Assets converted to approximately 5,402 ETH.(2026-05-18:h1-2026-bridge-hack-cluster-same-day-35-6m-attack-wave-july-22-23)event
6bb07494
H1 2026 Bridge Hack Cluster — Same-Day $35.6M Attack Wave July 22-23token
4d924ba4
As of this investigation date, kaneta.cc and monblare.com infrastructure retains valid SSL certificates and is assessed to be staged for active or imminent deployment(2026-08-01:castleloader-needlestealer-crypto-wallet-malware-campaign)event
2d8e03a5
GBHackers and CyberPress report on the NeedleStealer connection and MOTW-stripping via signed installers, noting staged infrastructure with SSL certificates valid into August 2026(2026-07-28:castleloader-needlestealer-crypto-wallet-malware-campaign)event
ba6bc303
Arctic Wolf Labs publishes expanded CastleLoader analysis identifying three new campaigns (Urutyka, Garrigin, Noidret) and the NeedleStealer framework with Rust wallet spoofer and Golang browser extension components(2026-07-27:castleloader-needlestealer-crypto-wallet-malware-campaign)event
33946fca
Huntress publishes BackgroundFix campaign analysis documenting ClickFix chain delivering CastleLoader, CastleStealer, and NetSupport RAT via fake background-removal websites(2026-04-30:castleloader-needlestealer-crypto-wallet-malware-campaign)event
e6869401
CastleLoader begins delivering LummaStealer; Bitdefender observes surge in infections peaking in India, the US, and Europe through January 2026(2025-12-01:castleloader-needlestealer-crypto-wallet-malware-campaign)event
541b557f
Recorded Future attributes campaign cluster to TAG-150, documenting four sub-clusters and four-tier C2 infrastructure(2025-09-01:castleloader-needlestealer-crypto-wallet-malware-campaign)event
b9c3f8f6
CastleRAT Python variant first identified; TAG-150 expands from loader to full RAT capability(2025-08-01:castleloader-needlestealer-crypto-wallet-malware-campaign)event
8b5ce3cd
CastleLoader campaigns actively targeting U.S. entities observed by PolySwarm; 469 of 1,634 attempted compromises succeed (28.7% infection rate)(2025-05-01:castleloader-needlestealer-crypto-wallet-malware-campaign)event
00603ca5
TAG-150 (GrayBravo) earliest confirmed activity, deploying CastleLoader infrastructure(2025-03-01:castleloader-needlestealer-crypto-wallet-malware-campaign)event
4025dd74
CastleLoader / NeedleStealer Crypto Wallet Malware Campaignorganization
40184273
As of this date, no confirmed victim counts, financial losses, arrests, or indictments related to the DACP campaign had been publicly disclosed. The August 10 enrollment deadline cited in the fraudulent letters had not yet passed.(2026-08-01:irs-fake-digital-asset-compliance-portal-phishing-campaign-2026)event
2fea8715
Multiple crypto and mainstream news outlets including The Block, Crypto Briefing, Crypto Times, and Gate News published coverage of the IRS warning. Coinbase Support posted a public advisory on X (Twitter).(2026-07-31:irs-fake-digital-asset-compliance-portal-phishing-campaign-2026)event
36d519a5
IRS Criminal Investigation (IRS-CI) issued a formal public warning confirming the campaign. IRS-CI Chief Jarod Koopman stated criminals were creating convincing fake websites and official-looking correspondence. The IRS confirmed it operates no Digital Asset Compliance Portal.(2026-07-30:irs-fake-digital-asset-compliance-portal-phishing-campaign-2026)event
38ed9f6d
Coinbase and threat intelligence firm DarkTower issued a consumer alert identifying the fake DACP letter campaign.(2026-07-28:irs-fake-digital-asset-compliance-portal-phishing-campaign-2026)event
200d0f21
IRS Fake Digital Asset Compliance Portal Phishing Campaign 2026organization
51928a3f
McGuireWoods publishes legal analysis of SEC v. Morocoin raising the 'Schrodinger's Asset' securities classification question. No court orders or judgments publicly reported as of this date.(2026-02-27:morocoin-berge-blockchain-cirkor)event
d46482d8
SEC files civil complaint (Case No. 25-cv-04102) in U.S. District Court for the District of Colorado against all seven defendants for securities fraud violations, alleging $14 million in investor losses.(2025-12-22:morocoin-berge-blockchain-cirkor)event
16bc042a
Berge Blockchain and Cirkor allege regulatory investigation, demand additional fees, then cut off investor access. AIIEF and Zenith cease operations. Scheme ends.(2025-01-01:morocoin-berge-blockchain-cirkor)event
25dd757e
AI Investment Education Foundation Ltd. (AIIEF) and Zenith Asset Tech Foundation begin operating, directing investors to Berge Blockchain and Cirkor platforms.(2024-07-01:morocoin-berge-blockchain-cirkor)event
237ad7a2
Morocoin alleges to investors that it is under regulatory investigation and that accounts will be frozen for three years, then demands expedited withdrawal fees. AI Wealth and Lane Wealth clubs cease operations.(2024-06-01:morocoin-berge-blockchain-cirkor)event
b5d426a1
AI Wealth Inc. and Lane Wealth Inc. begin operating WhatsApp investment clubs, directing investors to fake Morocoin trading platform.(2024-01-01:morocoin-berge-blockchain-cirkor)event
43c32c83
Morocoin / Berge Blockchain / Cirkortoken
f21cb217
On-chain analysts (Lookonchain, Polysights) identify 12 wallets that allegedly profited over $1 million on Polymarket before ZachXBT's reveal, with on-chain researchers alleging some wallet addresses are connected to Broox Bauer.(2026-02-27:axiom-exchange-employee-insider-trading-scandal)event
625a4c93
Axiom issues public statement expressing shock and disappointment, removes affected internal tool access, and pledges ongoing investigation.(2026-02-26:axiom-exchange-employee-insider-trading-scandal)event
840dbf2e
Polymarket prediction market launches — 'Which crypto company will ZachXBT expose for insider trading?' — drawing over $39.7 million in cumulative trading volume before settlement.(2026-02-23:axiom-exchange-employee-insider-trading-scandal)event
2bd9a7db
Recorded call allegedly captures Broox Bauer describing internal lookup capabilities to moderator 'Gowno' and outlining a plan for the associate to earn $200,000 via privileged access.(2026-02-01:axiom-exchange-employee-insider-trading-scandal)event
413234df
Alleged incident: Registration details and linked wallet addresses for a trader known as 'Monix' allegedly shared; internal lookups on AURA meme coin traders discussed.(2025-08-01:axiom-exchange-employee-insider-trading-scandal)event
26b00acc
Alleged incident: Broox Bauer allegedly distributes a screenshot of private wallets connected to a trader identified as 'Jerry' obtained via internal dashboard.(2025-04-01:axiom-exchange-employee-insider-trading-scandal)event
7c8bfe4d
Axiom launches in early access on Solana. Alleged internal tool abuse begins shortly after launch, according to ZachXBT's investigation.(2025-01-01:axiom-exchange-employee-insider-trading-scandal)event
334a377e
Axiom Exchange founded by Henry Zhang (Mist) and Preston Ellis (Cal); accepted into Y Combinator Winter 2025 batch.(2024-01-01:axiom-exchange-employee-insider-trading-scandal)event
13e67f0a
Axiom Exchange — Employee Insider Trading Scandalexchange
7ccb0d7a
Basse-Terre Court of Appeal approves extradition of John Daghita to the United States.(2026-05-28:john-daghita-aka-lick-us-marshals-crypto-theft)event
a8aab4b3
Daghita appears before the indictment chamber of the Court of Appeal in Basse-Terre, Guadeloupe. He reportedly requests his own extradition to the United States, stating he wants to explain himself in U.S. courts. Magistrates reserve decision until May 28.(2026-05-21:john-daghita-aka-lick-us-marshals-crypto-theft)event
838a55ea
Federal grand jury in Alexandria, Virginia, returns a 15-count indictment against John Daghita in the Eastern District of Virginia, charging wire fraud, theft of public money, money laundering, and unlawful monetary transactions.(2026-03-26:john-daghita-aka-lick-us-marshals-crypto-theft)event
be4a22e1
FBI Director Kash Patel publicly announces arrest via X and shares photos of Daghita in custody and the seized suitcase of cash and hardware wallets.(2026-03-05:john-daghita-aka-lick-us-marshals-crypto-theft)event
d0e2fa8c
John Daghita arrested at Villa Sun Reset on the island of Saint Martin by French Gendarmerie elite tactical unit in collaboration with the FBI Washington Field Office. Seized items include $239,348 in cash, a Rolex GMT Master, and multiple hardware wallets.(2026-03-04:john-daghita-aka-lick-us-marshals-crypto-theft)event
fa7cb12b
Wallet linked to the alleged theft deploys $LICK meme coin on Pump.fun (Solana). The token collapses approximately 97% within 24 hours. Pump.fun removes the ticker.(2026-01-01:john-daghita-aka-lick-us-marshals-crypto-theft)event
c7466a57
ZachXBT publishes findings publicly identifying the 'John/Lick' persona as John Daghita and alleging the son of a USMS contractor executive stole more than $40 million in government cryptocurrency. U.S. Marshals Service confirms investigation.(2026-01-26:john-daghita-aka-lick-us-marshals-crypto-theft)event
61c35951
During an online 'band-for-band' exchange, a participant using the handle 'John' or 'Lick' screen-shares wallet balances and moves approximately $23 million live; ZachXBT observes the recorded session and traces the wallets to U.S. government seizure addresses. An additional $41 million in transfers alleged to have occurred on January 22-23.(2026-01-23:john-daghita-aka-lick-us-marshals-crypto-theft)event
044c9995
USMS instructs CMDSS to return approximately $2 million in virtual currency to a USMS-owned address. Approximately 20 minutes later, Daghita allegedly diverts the assets to a non-USMS address instead.(2026-01-22:john-daghita-aka-lick-us-marshals-crypto-theft)event
dc851087
John Daghita allegedly initiates three transfers totaling approximately $5 million from USMS-controlled wallets to wallets he personally controlled — the first alleged theft transactions per the indictment.(2025-12-15:john-daghita-aka-lick-us-marshals-crypto-theft)event
9a7a25d4
CMDSS (Command Services & Support), owned by Dean Daghita, awarded a ~$4 million U.S. Marshals Service contract for custody and disposal of Class 2-4 seized digital assets.(2024-10-01:john-daghita-aka-lick-us-marshals-crypto-theft)event
42f602ca
Wallet address 0xc7a2 allegedly received $24.9 million from a U.S. government address tied to the 2016 Bitfinex hack seizure, per ZachXBT on-chain analysis.(2024-03-01:john-daghita-aka-lick-us-marshals-crypto-theft)event
69dcd23f
Data refreshes every 5 minutes · All metrics derived from Supabase