← AVOID.NET
Entity Graph
Browse extracted entities, relationships, and potential duplicates.
Total entities
22,711
Relationships
18,089
Potential duplicates
0
Filter by kind
Entities
↯9738f83b
At 21:30 UTC, Blockaid detects an exploit targeting AFX Trade's custodial bridge on Arbitrum. Attackers with five compromised hot-validator keys withdraw 24.15 million USDC. Stolen USDC is converted to approximately 12,467.5 ETH and bridged to Ethereum.(2026-07-22:h1-2026-bridge-hack-cluster-same-day-35-6m-attack-wave-july-22-23)event
↯081cea19
Assets recovered following the May 2026 Verus exploit are redeposited to the bridge, re-exposing user funds while the underlying vulnerability remained unpatched.(2026-07-08:h1-2026-bridge-hack-cluster-same-day-35-6m-attack-wave-july-22-23)event
↯6bb07494
Verus-Ethereum bridge suffers its first exploit, losing approximately $11.58 million. Attacker forges Merkle proof exploiting a validation gap between source-chain committed value and Ethereum-side payout. Assets converted to approximately 5,402 ETH.(2026-05-18:h1-2026-bridge-hack-cluster-same-day-35-6m-attack-wave-july-22-23)event
♦4d924ba4
H1 2026 Bridge Hack Cluster — Same-Day $35.6M Attack Wave July 22-23token
◎7eb3cdf8
blog.polyswarm.iodomain
◎803e30f3
arcticwolf.comdomain
↯2d8e03a5
As of this investigation date, kaneta.cc and monblare.com infrastructure retains valid SSL certificates and is assessed to be staged for active or imminent deployment(2026-08-01:castleloader-needlestealer-crypto-wallet-malware-campaign)event
↯ba6bc303
GBHackers and CyberPress report on the NeedleStealer connection and MOTW-stripping via signed installers, noting staged infrastructure with SSL certificates valid into August 2026(2026-07-28:castleloader-needlestealer-crypto-wallet-malware-campaign)event
↯33946fca
Arctic Wolf Labs publishes expanded CastleLoader analysis identifying three new campaigns (Urutyka, Garrigin, Noidret) and the NeedleStealer framework with Rust wallet spoofer and Golang browser extension components(2026-07-27:castleloader-needlestealer-crypto-wallet-malware-campaign)event
↯e6869401
Huntress publishes BackgroundFix campaign analysis documenting ClickFix chain delivering CastleLoader, CastleStealer, and NetSupport RAT via fake background-removal websites(2026-04-30:castleloader-needlestealer-crypto-wallet-malware-campaign)event
↯541b557f
CastleLoader begins delivering LummaStealer; Bitdefender observes surge in infections peaking in India, the US, and Europe through January 2026(2025-12-01:castleloader-needlestealer-crypto-wallet-malware-campaign)event
↯b9c3f8f6
Recorded Future attributes campaign cluster to TAG-150, documenting four sub-clusters and four-tier C2 infrastructure(2025-09-01:castleloader-needlestealer-crypto-wallet-malware-campaign)event
↯8b5ce3cd
CastleRAT Python variant first identified; TAG-150 expands from loader to full RAT capability(2025-08-01:castleloader-needlestealer-crypto-wallet-malware-campaign)event
↯00603ca5
CastleLoader campaigns actively targeting U.S. entities observed by PolySwarm; 469 of 1,634 attempted compromises succeed (28.7% infection rate)(2025-05-01:castleloader-needlestealer-crypto-wallet-malware-campaign)event
↯4025dd74
TAG-150 (GrayBravo) earliest confirmed activity, deploying CastleLoader infrastructure(2025-03-01:castleloader-needlestealer-crypto-wallet-malware-campaign)event
□40184273
CastleLoader / NeedleStealer Crypto Wallet Malware Campaignorganization
◎dec9bb7c
news.bloombergtax.comdomain
↯2fea8715
As of this date, no confirmed victim counts, financial losses, arrests, or indictments related to the DACP campaign had been publicly disclosed. The August 10 enrollment deadline cited in the fraudulent letters had not yet passed.(2026-08-01:irs-fake-digital-asset-compliance-portal-phishing-campaign-2026)event
↯36d519a5
Multiple crypto and mainstream news outlets including The Block, Crypto Briefing, Crypto Times, and Gate News published coverage of the IRS warning. Coinbase Support posted a public advisory on X (Twitter).(2026-07-31:irs-fake-digital-asset-compliance-portal-phishing-campaign-2026)event
↯38ed9f6d
IRS Criminal Investigation (IRS-CI) issued a formal public warning confirming the campaign. IRS-CI Chief Jarod Koopman stated criminals were creating convincing fake websites and official-looking correspondence. The IRS confirmed it operates no Digital Asset Compliance Portal.(2026-07-30:irs-fake-digital-asset-compliance-portal-phishing-campaign-2026)event
↯200d0f21
Coinbase and threat intelligence firm DarkTower issued a consumer alert identifying the fake DACP letter campaign.(2026-07-28:irs-fake-digital-asset-compliance-portal-phishing-campaign-2026)event
□51928a3f
IRS Fake Digital Asset Compliance Portal Phishing Campaign 2026organization
↯d46482d8
McGuireWoods publishes legal analysis of SEC v. Morocoin raising the 'Schrodinger's Asset' securities classification question. No court orders or judgments publicly reported as of this date.(2026-02-27:morocoin-berge-blockchain-cirkor)event
↯16bc042a
SEC files civil complaint (Case No. 25-cv-04102) in U.S. District Court for the District of Colorado against all seven defendants for securities fraud violations, alleging $14 million in investor losses.(2025-12-22:morocoin-berge-blockchain-cirkor)event
↯25dd757e
Berge Blockchain and Cirkor allege regulatory investigation, demand additional fees, then cut off investor access. AIIEF and Zenith cease operations. Scheme ends.(2025-01-01:morocoin-berge-blockchain-cirkor)event
↯237ad7a2
AI Investment Education Foundation Ltd. (AIIEF) and Zenith Asset Tech Foundation begin operating, directing investors to Berge Blockchain and Cirkor platforms.(2024-07-01:morocoin-berge-blockchain-cirkor)event
↯b5d426a1
Morocoin alleges to investors that it is under regulatory investigation and that accounts will be frozen for three years, then demands expedited withdrawal fees. AI Wealth and Lane Wealth clubs cease operations.(2024-06-01:morocoin-berge-blockchain-cirkor)event
↯43c32c83
AI Wealth Inc. and Lane Wealth Inc. begin operating WhatsApp investment clubs, directing investors to fake Morocoin trading platform.(2024-01-01:morocoin-berge-blockchain-cirkor)event
↯625a4c93
On-chain analysts (Lookonchain, Polysights) identify 12 wallets that allegedly profited over $1 million on Polymarket before ZachXBT's reveal, with on-chain researchers alleging some wallet addresses are connected to Broox Bauer.(2026-02-27:axiom-exchange-employee-insider-trading-scandal)event
↯840dbf2e
Axiom issues public statement expressing shock and disappointment, removes affected internal tool access, and pledges ongoing investigation.(2026-02-26:axiom-exchange-employee-insider-trading-scandal)event
↯2bd9a7db
Polymarket prediction market launches — 'Which crypto company will ZachXBT expose for insider trading?' — drawing over $39.7 million in cumulative trading volume before settlement.(2026-02-23:axiom-exchange-employee-insider-trading-scandal)event
↯413234df
Recorded call allegedly captures Broox Bauer describing internal lookup capabilities to moderator 'Gowno' and outlining a plan for the associate to earn $200,000 via privileged access.(2026-02-01:axiom-exchange-employee-insider-trading-scandal)event
↯26b00acc
Alleged incident: Registration details and linked wallet addresses for a trader known as 'Monix' allegedly shared; internal lookups on AURA meme coin traders discussed.(2025-08-01:axiom-exchange-employee-insider-trading-scandal)event
↯7c8bfe4d
Alleged incident: Broox Bauer allegedly distributes a screenshot of private wallets connected to a trader identified as 'Jerry' obtained via internal dashboard.(2025-04-01:axiom-exchange-employee-insider-trading-scandal)event
↯334a377e
Axiom launches in early access on Solana. Alleged internal tool abuse begins shortly after launch, according to ZachXBT's investigation.(2025-01-01:axiom-exchange-employee-insider-trading-scandal)event
↯13e67f0a
Axiom Exchange founded by Henry Zhang (Mist) and Preston Ellis (Cal); accepted into Y Combinator Winter 2025 batch.(2024-01-01:axiom-exchange-employee-insider-trading-scandal)event
△7ccb0d7a
Axiom Exchange — Employee Insider Trading Scandalexchange
↯a8aab4b3
Basse-Terre Court of Appeal approves extradition of John Daghita to the United States.(2026-05-28:john-daghita-aka-lick-us-marshals-crypto-theft)event
↯838a55ea
Daghita appears before the indictment chamber of the Court of Appeal in Basse-Terre, Guadeloupe. He reportedly requests his own extradition to the United States, stating he wants to explain himself in U.S. courts. Magistrates reserve decision until May 28.(2026-05-21:john-daghita-aka-lick-us-marshals-crypto-theft)event
↯be4a22e1
Federal grand jury in Alexandria, Virginia, returns a 15-count indictment against John Daghita in the Eastern District of Virginia, charging wire fraud, theft of public money, money laundering, and unlawful monetary transactions.(2026-03-26:john-daghita-aka-lick-us-marshals-crypto-theft)event
↯d0e2fa8c
FBI Director Kash Patel publicly announces arrest via X and shares photos of Daghita in custody and the seized suitcase of cash and hardware wallets.(2026-03-05:john-daghita-aka-lick-us-marshals-crypto-theft)event
↯fa7cb12b
John Daghita arrested at Villa Sun Reset on the island of Saint Martin by French Gendarmerie elite tactical unit in collaboration with the FBI Washington Field Office. Seized items include $239,348 in cash, a Rolex GMT Master, and multiple hardware wallets.(2026-03-04:john-daghita-aka-lick-us-marshals-crypto-theft)event
↯c7466a57
Wallet linked to the alleged theft deploys $LICK meme coin on Pump.fun (Solana). The token collapses approximately 97% within 24 hours. Pump.fun removes the ticker.(2026-01-01:john-daghita-aka-lick-us-marshals-crypto-theft)event
↯61c35951
ZachXBT publishes findings publicly identifying the 'John/Lick' persona as John Daghita and alleging the son of a USMS contractor executive stole more than $40 million in government cryptocurrency. U.S. Marshals Service confirms investigation.(2026-01-26:john-daghita-aka-lick-us-marshals-crypto-theft)event
↯044c9995
During an online 'band-for-band' exchange, a participant using the handle 'John' or 'Lick' screen-shares wallet balances and moves approximately $23 million live; ZachXBT observes the recorded session and traces the wallets to U.S. government seizure addresses. An additional $41 million in transfers alleged to have occurred on January 22-23.(2026-01-23:john-daghita-aka-lick-us-marshals-crypto-theft)event
↯dc851087
USMS instructs CMDSS to return approximately $2 million in virtual currency to a USMS-owned address. Approximately 20 minutes later, Daghita allegedly diverts the assets to a non-USMS address instead.(2026-01-22:john-daghita-aka-lick-us-marshals-crypto-theft)event
↯9a7a25d4
John Daghita allegedly initiates three transfers totaling approximately $5 million from USMS-controlled wallets to wallets he personally controlled — the first alleged theft transactions per the indictment.(2025-12-15:john-daghita-aka-lick-us-marshals-crypto-theft)event
↯42f602ca
CMDSS (Command Services & Support), owned by Dean Daghita, awarded a ~$4 million U.S. Marshals Service contract for custody and disposal of Class 2-4 seized digital assets.(2024-10-01:john-daghita-aka-lick-us-marshals-crypto-theft)event
↯69dcd23f
Wallet address 0xc7a2 allegedly received $24.9 million from a U.S. government address tied to the 2016 Bitfinex hack seizure, per ZachXBT on-chain analysis.(2024-03-01:john-daghita-aka-lick-us-marshals-crypto-theft)event
Data refreshes every 5 minutes · All metrics derived from Supabase