Skip to content

Commit 8ff3ca4

Browse files
iZonexclaude
andcommitted
[examples] second sweep pass: 2 more July incidents + un-stale the Genesis case (664 -> 666)
The first pass was exploit-shaped and missed the neighbouring categories. Going back over end-of-month, non-exploit events, and corpus freshness turned up three things. - Solido Cash (2026-07-23, ~293.7M SUPRA / ~$900K) - T9.001 in a stale-feed fallback shape. An oracle misassignment on SOLID (backstop collateral) meant a stale feed tripped fallback logic that priced it far above market; 809,052 CASH minted against the inflated collateral and sold. Two waves: an atomic transaction at 18:21:35 UTC, then a manual repeat across five wallets hours later - the gap between them was an unused detect-and-halt window. ~90% of the loss fell on the Solido Foundation, ~84% of proceeds traced to CEX infrastructure. Second SUPRA-adjacent oracle case this month after Bonzo Lend, and the entry says explicitly that they are NOT the same defect or component: Bonzo consumed Supra's verifier, Solido misconfigured its own feed. What they share is the missing deviation bound on the consuming mint path. - DPRK state-bank diversion (arrest 2026-07-12, reported 07-25) - T7.010 + T8.005, recorded at inferred-weak with a structural caveat header. Former military operators reportedly diverted Central Bank / Foreign Trade Bank funds into overseas crypto wallets and structured them out through Chinese brokers in Sinuiju and Hyesan. The whole account is Daily NK citing one anonymous Pyongyang source and is explicitly not independently verified - it is in the corpus because the shape (a national operator cohort stealing from its own state, caught by that state's internal controls) exists nowhere else in OAK, not because it is established. The intrusion leg is deliberately left unmapped per the Brazil central-bank precedent: "breached" with no vector is not a Technique. The T7.010 assignment is what distinguishes it from Brazil - there the crypto leg was an on-ramp purchase (no T7 primitive runs that direction), here it is a structured off-ramp of proceeds already on-chain. - 2024-08 Genesis creditor: the file had gone ~12 months stale on the legal axis. It still read "Wiz and Box at large". Since then the prosecution was recast as a RICO racketeering conspiracy; a Second Superseding Indictment (2025-12-08) added Dellecave, Ibrahim and Zulfiqar; twelve are charged with nine guilty pleas including Chetal; Evan Tangeman pleaded guilty to laundering >=$3.5M. DOJ now quantifies the theft as 4,100+ BTC - $263M in Aug 2024, >$368M by Dec 2025. Loss line now reconciles all three circulating figures ($230M charged / ~$243M at-theft market price / $263M DOJ) as BTC price movement rather than a disputed quantity. Also records the DOJ's "residential burglars targeting hardware virtual currency wallets" language, which is the T5.009 adjacency. Checked and deliberately not added: the $263M/12-defendant DOJ action is dated 2025-12-08, not July 2026 (one outlet misdated it); CertiK's H1 wrench-attack figures (52 incidents, $124.18M, 20 home invasions) are a report published 2026-07-23, not an incident; the DOJ's $25M civil forfeitures (2026-07-21) name no defendant. WEMIX Feb 2025 remains an open backfill - flagged, not written. Validators clean: citations, linkage, backlinks (0/0), tags, detect_ai_tells, markdownlint (CI-pinned 0.13.0, 0 errors). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
1 parent 7920bdc commit 8ff3ca4

7 files changed

Lines changed: 135 additions & 21 deletions

BACKLOG.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22

33
_Generated by `tools/build_backlog.py` on 2026-07-29. Regenerated on every `npm run site:data`._
44

5-
_Scope: 664 worked examples, 149 Techniques, 19 Threat Actors._
5+
_Scope: 666 worked examples, 149 Techniques, 19 Threat Actors._
66

77
This file is a prioritized contributor backlog. **P0** items close hard structural gaps (empty Tactics, placeholder actor cards). **P1** items lift per-Tactic coverage below the documented minimum. **P2** items anchor candidate sub-Techniques from `TAXONOMY-GAPS.md`.
88

SPECS.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -254,4 +254,4 @@ Maturity legend:
254254

255255
---
256256

257-
Updated automatically when `tools/build_specs_index.py` runs as part of `npm run site:data`. Last regenerated from corpus state at `2026-07-29T12:40:25+00:00`.
257+
Updated automatically when `tools/build_specs_index.py` runs as part of `npm run site:data`. Last regenerated from corpus state at `2026-07-29T14:42:20+00:00`.

STATS.md

Lines changed: 16 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,11 @@
11
# OAK — Stats Snapshot
22

3-
_Auto-generated by `tools/build_stats.py` at 2026-07-29 12:40 UTC._
3+
_Auto-generated by `tools/build_stats.py` at 2026-07-29 14:42 UTC._
44

55
## Catalogue
66

77
- **17** Tactics · **149** Techniques · **19** Threat Actors · **47** Mitigations · **41** Software · **12** Data Sources
8-
- **664** Worked Examples · **1555** bibtex entries
8+
- **666** Worked Examples · **1555** bibtex entries
99

1010
## Examples by Tactic
1111

@@ -15,11 +15,11 @@ _Auto-generated by `tools/build_stats.py` at 2026-07-29 12:40 UTC._
1515
| T2 (Liquidity Establishment) | 32 |
1616
| T3 (Holder Capture) | 38 |
1717
| T4 (Access Acquisition) | 77 |
18-
| T5 (Value Extraction) | 121 |
18+
| T5 (Value Extraction) | 122 |
1919
| T6 (Defense Evasion) | 55 |
20-
| T7 (Laundering) | 175 |
21-
| T8 (Operator Continuity / Attribution Signals) | 91 |
22-
| T9 (Smart-Contract Exploit) | 212 |
20+
| T7 (Laundering) | 177 |
21+
| T8 (Operator Continuity / Attribution Signals) | 92 |
22+
| T9 (Smart-Contract Exploit) | 213 |
2323
| T10 (Bridge / Cross-Chain) | 59 |
2424
| T11 (Custody / Signing) | 151 |
2525
| T12 (NFT-Specific) | 23 |
@@ -46,7 +46,7 @@ _Auto-generated by `tools/build_stats.py` at 2026-07-29 12:40 UTC._
4646
| 2023 | 102 |
4747
| 2024 | 151 |
4848
| 2025 | 77 |
49-
| 2026 | 85 |
49+
| 2026 | 87 |
5050

5151
## Examples by Year-Month (recent dense window)
5252

@@ -75,39 +75,39 @@ _Auto-generated by `tools/build_stats.py` at 2026-07-29 12:40 UTC._
7575
| 2026-04 | 11 |
7676
| 2026-05 | 16 |
7777
| 2026-06 | 20 |
78-
| 2026-07 | 17 |
78+
| 2026-07 | 19 |
7979

8080
## Attribution-strength Distribution
8181

8282
| Strength | Count |
8383
| --- | ---: |
84-
| pseudonymous | 321 (48.3%) |
84+
| pseudonymous | 322 (48.3%) |
8585
| unattributed | 149 (22.4%) |
86-
| confirmed | 126 (19.0%) |
86+
| confirmed | 126 (18.9%) |
8787
| inferred-strong | 65 (9.8%) |
88-
| inferred-weak | 3 (0.5%) |
88+
| inferred-weak | 4 (0.6%) |
8989

9090
## Threat Actors
9191

9292
- 19 of 19 actors have at least one attributed example
9393

9494
| Actor | Examples |
9595
| --- | ---: |
96-
| OAK-G01 (lazarus) | 120 |
96+
| OAK-G01 (lazarus) | 121 |
9797
| OAK-G02 (drainer-services) | 11 |
9898
| OAK-G03 (russian-laundering-infrastructure) | 6 |
9999
| OAK-G10 (alphv-blackcat) | 5 |
100+
| OAK-G04 (dprk-it-worker-scheme) | 4 |
100101
| OAK-G05 (lockbit) | 4 |
101-
| OAK-G04 (dprk-it-worker-scheme) | 3 |
102+
| OAK-G07 (apt43-kimsuky) | 2 |
103+
| OAK-G08 (bluenoroff) | 2 |
104+
| OAK-G09 (andariel) | 2 |
102105
| OAK-G14 (clop-cl0p) | 2 |
103106
| OAK-G12 (scattered-spider) | 2 |
104107
| OAK-G15 (ransomhub) | 2 |
105-
| OAK-G07 (apt43-kimsuky) | 1 |
106108
| OAK-G13 (iranian-crypto-operators) | 1 |
107109
| OAK-G06 (evil-corp) | 1 |
108110
| OAK-G19 (darkside) | 1 |
109-
| OAK-G08 (bluenoroff) | 1 |
110-
| OAK-G09 (andariel) | 1 |
111111
| OAK-G17 (blackbyte) | 1 |
112112
| OAK-G18 (karakurt) | 1 |
113113
| OAK-G11 (black-basta) | 1 |

examples/2024-08-genesis-creditor-social-engineering.md

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,8 @@
11
# Genesis Creditor — Multi-Stage Impersonation Social Engineering — 2024-08-19
22

3-
**Loss:** ~$243M in BTC, ETH, and other crypto assets from a single Genesis Global Capital creditor.
3+
**Loss:** ~\$243M in BTC, ETH, and other crypto assets from a single Genesis Global Capital creditor. Three figures circulate and each is correct for what it measures: **\$230M+** is the amount charged in the original 2024 indictment; **~\$243M** is the market-price valuation of the assets at the moment of theft; and **\$263M** is the DOJ's figure as of the 2025-12-08 RICO announcement, stated as **over 4,100 BTC** and worth **more than \$368M** by that date. The spread is BTC price movement, not a disputed quantity.
44
**OAK Techniques observed:** OAK-T4.007 (Native App Social Phishing / Engagement-Weighted Platforms) — primary; OAK-T7 (Laundering) — post-exploit.
5-
**Attribution:** **confirmed** — three threat actors: Malone Lam ("Greavys"; rendered "Malone Iam" in ZachXBT's original thread — a capital-I/lowercase-l transcription error. Full name Malone Lam Yu Xuan; the DOJ record and all subsequent reporting use **Lam**), Veer Chetal ("Wiz"), and Jeandiel Serrano ("Box"). Malone arrested in Miami (Sep 2024); Wiz and Box at large as of investigation date. A fourth associate, Aakaash ("Light/Dark"), assisted with laundering.
5+
**Attribution:** **confirmed** — originally three named threat actors: Malone Lam ("Greavys"; rendered "Malone Iam" in ZachXBT's original thread — a capital-I/lowercase-l transcription error. Full name Malone Lam Yu Xuan; the DOJ record and all subsequent reporting use **Lam**), Veer Chetal ("Wiz"), and Jeandiel Serrano ("Box"). Malone arrested in Miami (Sep 2024); Wiz and Box at large as of ZachXBT's investigation date. A fourth associate, Aakaash ("Light/Dark"), assisted with laundering. **The case has since expanded far beyond those three.** By the DOJ's announcement of **2025-12-08**, the prosecution had been recast as a **RICO racketeering conspiracy**, **twelve** individuals stood charged, and **nine had entered guilty pleas** — including **Veer Chetal**. A **Second Superseding Indictment** added **Nicholas Dellecave** ("Nic", "Souja"; arrested Miami 2025-12-03), **Mustafa Ibrahim** ("Krust"; arrested in Dubai), and **Danish Zulfiqar** ("Danny", "Meech"; arrested in Dubai). Separately, **Evan Tangeman** (Newport Beach, CA) pleaded guilty to RICO conspiracy, admitting he laundered **at least \$3.5M** for the enterprise, with sentencing set for **2026-04-24**.
66

77
**Key teaching point:** This is the largest known social engineering theft against a single individual in crypto history. The attack demonstrates the **multi-stage impersonation escalation** pattern: the attackers chained spoofed calls (Google Support → Gemini Support), each stage extracting credentials or authorizations that enabled the next. The victim was a sophisticated institutional creditor, not a retail user. The laundering used 15+ exchanges with rapid cross-asset swapping (BTC→LTC→ETH→XMR) to break traceability.
88

@@ -28,6 +28,9 @@ ZachXBT traced the full on-chain flow and identified the three principals throug
2828
| 2024-08-19~Sep | Laundering: funds split three ways, swapped BTC→LTC→ETH→XMR via 15+ exchanges, eXch, THORSwap | **T7 laundering** |
2929
| 2024-09 | Malone Lam (Greavys) arrested in Miami by FBI. Wiz (Veer Chetal) and Box (Jeandiel Serrano) remain at large | (legal action) |
3030
| 2024-09-19 | ZachXBT publishes full investigation with on-chain tracing of all three principals | (public disclosure) |
31+
| 2024-11 | Veer Chetal ("Wiz") secretly charged; later pleads guilty and forfeits ~30 designer watches, clothing, and \$36M+ in ETH; loses bond after a further ~\$2M crypto theft while awaiting sentencing | (legal action) |
32+
| 2025-12-03 | Nicholas Dellecave ("Nic", "Souja") arrested in Miami | (legal action) |
33+
| 2025-12-08 | DOJ announces a **Second Superseding Indictment** charging Dellecave, Mustafa Ibrahim ("Krust", arrested Dubai) and Danish Zulfiqar ("Danny", "Meech", arrested Dubai) with **RICO conspiracy**, bringing the total charged to **twelve**, of whom **nine have pleaded guilty**. Same announcement: **Evan Tangeman** pleads guilty to RICO conspiracy, admitting he laundered ≥\$3.5M for the enterprise (sentencing 2026-04-24). DOJ states the theft totalled **over 4,100 BTC**, worth **\$263M in August 2024** and **>\$368M** by the announcement date | (legal action) |
3134

3235
## What defenders observed
3336

@@ -48,6 +51,7 @@ ZachXBT traced the full on-chain flow and identified the three principals throug
4851
- [ZachXBT — Investigation Thread (X/Twitter)](https://twitter.com/zachxbt/status/1836752923830702392) — 14-part investigation with on-chain tracing of all three principals.
4952
- [DOJ / U.S. Attorney D.C. — "Indictment Charges Two in \$230 Million Cryptocurrency Scam"](https://www.justice.gov/usao-dc/pr/indictment-charges-two-230-million-cryptocurrency-scam) — the charging document. Malone Lam (20, Miami / Los Angeles; also used "Anne Hathaway" and "\$\$\$") and Jeandiel Serrano (21, Los Angeles; "VersaceGod", @Skidstar) charged with conspiracy to steal and launder over \$230M from a victim in **Washington, D.C.** The charged figure (\$230M+) and the market-price valuation at theft (~\$243M) differ; both are correct for what they measure.
5053
- [Wikipedia — Malone Lam](https://en.wikipedia.org/wiki/Malone_Lam) — biographical detail: Malone Lam Yu Xuan, born 2004-07-19, Singaporean, raised in Choa Chu Kang, attended Unity Secondary School, dropped out as a teenager. Co-founded the "Social Engineering Enterprise" with roommates in Texas; the network reached ~14 members across several states, working from hacked databases, dark-web data and phishing mail. Arrested by the FBI in Miami on 2024-09-18 after an off-duty police officer tipped him off; he threw his phone into Biscayne Bay en route. Proceeds spent on ~33 luxury cars, jewellery, travel and nightclubs.
54+
- [DOJ / U.S. Attorney D.C. — "Guilty Plea and Superseding Indictment Announced in Social Engineering Scheme that Stole \$263 Million in Cryptocurrency" (2025-12-08)](https://www.justice.gov/usao-dc/pr/guilty-plea-and-superseding-indictment-announced-social-engineering-scheme-stole-263) — the case's recasting as a **RICO racketeering conspiracy**. Evan Tangeman (Newport Beach, CA) pleads guilty, admitting he laundered ≥\$3.5M for the enterprise (sentencing 2026-04-24). The Second Superseding Indictment charges Nicholas Dellecave ("Nic", "Souja"; arrested Miami 2025-12-03), Mustafa Ibrahim ("Krust"; arrested Dubai) and Danish Zulfiqar ("Danny", "Meech"; arrested Dubai), bringing the total charged to **twelve**, with **nine guilty pleas** entered. Quantifies the theft as **over 4,100 BTC**, worth **\$263M in August 2024** and **>\$368M** as of the announcement. Also references **"residential burglars targeting hardware virtual currency wallets"** as a component of the enterprise — the physical-coercion adjacency that connects this case to OAK-T5.009. (Mirrored by IRS Criminal Investigation at <https://www.irs.gov/compliance/criminal-investigation/guilty-plea-and-superseding-indictment-announced-in-social-engineering-scheme-that-stole-263-million-in-cryptocurrency>, which is fetchable where justice.gov returns 403.)
5155
- [The Block — Chetal bond revocation](https://www.theblock.co/post/359078/teen-in-245m-bitcoin-heist-loses-bond-after-new-2m-crypto-theft-unsealed-court-docs-show) — Veer Chetal ("Wiz") was a **teenager** at the time of the theft; secretly charged 2024-11; pleaded guilty; forfeited ~30 designer watches, clothing, and \$36M+ in ETH. Lost bond after committing a further ~\$2M crypto theft while awaiting sentencing.
5256
- Theft BTC transaction: `4b277ba298830ea538086114803b9487558bb093b5083e383e94db687fbe9090`
5357
- Laundering addresses: documented in ZachXBT thread (15+ exchange deposit addresses, eXch, THORSwap).

0 commit comments

Comments
 (0)