# Questions from the community

## How we made this page

After Altilly went down, and again after Xeggex collapsed, people asked a lot of hard questions. Many of them were aimed at me. This page tries to answer all of them, including the ones I would rather not answer.

- **What we collected.** We collected every question and allegation we could find: on Reddit, on Bitcointalk, in news articles and forum posts, and in the user complaints that were forwarded into the management chat as screenshots or copied text (many of those came from Altilly's public Telegram groups, Discord and support tickets).
- **How we sorted them.** Many questions were asked again and again in different words. We merged the duplicates into 79 questions and grouped them by theme. Questions about Nayiem's other projects and businesses that are unrelated to Altilly are outside the scope of this page, which covers Altilly, Mike and Xeggex.
- **How we checked them.** We compared each question with the full management chat and with public records, such as Companies House, court records, archived web pages and news reports. Where the chat does not cover something, we say so.
- **How to read the verdicts.** Each answer starts with a label:
  - **Answered by the chat**: the chat answers the question.
  - **Partly answered**: the chat answers part of it; the rest stays open.
  - **Not in the chat**: the chat does not cover it, so we give what public records show and say what is still unknown.
  - **The critic is right**: the evidence supports the criticism.
  - **The critic is partly right**: the evidence supports some of the criticism, but not all of it.
- **Who wrote the answers.** The answers were written with AI assistance and then checked against the chat. You don't have to trust them: every number like [#1057] opens that message in the chat, so you can read it in context yourself.
- **My own view.** Where I disagree or want to add context, it appears separately as "Nayiem's note". That is my account, not a finding.

:::caveat
The public Altilly Telegram groups were not available as an export; questions from those groups are included where users repeated them on Reddit or where the team quoted them in the management chat.
:::

:::note
Where an answer or a note says "believes", that is a belief. No court or authority has confirmed that Mike is Paul Vernon, that "Karl" is Mike, or that Mike took the Altilly or Xeggex funds. Usernames of private people are left out.
:::

**Contents:** [The questions people ask most](#the-questions-people-ask-most) · [The hack](#the-hack) · [Mike and Paul Vernon](#mike-and-paul-vernon) · [Nayiem's role and money](#nayiems-role-and-money) · [Refunds](#refunds) · [Deleted messages and transparency](#deleted-messages-and-transparency) · [Xeggex and Dokdo](#xeggex-and-dokdo) · [Solar](#solar) · [Other](#other)

## The questions people ask most

These ten came up most often. We ranked the questions by how many separate sources are listed under "Where this was asked", then by how many of Reddit, Bitcointalk and the user complaints forwarded into the management chat they came up in. Most questions have two or three sources, so this is a rough guide, not a count of everyone who asked.

1. [Was Altilly negligent, with plain-text passwords and a hosting login without 2FA?](#was-altilly-negligent-examples-include-passwords-sent-in-plain-t)
2. [When would refunds actually happen?](#when-would-refunds-actually-happen-did-the-promised-april-2021-s)
3. [Was the hack real, or a staged exit scam?](#was-the-december-2020-altilly-hack-real-or-was-it-a-staged-exit-)
4. [How can an exchange lose its database with no usable backups?](#how-can-an-exchange-lose-its-database-with-no-usable-backups-no-)
5. [Why did the claim rules ask for a user's country, set a minimum balance and require a Google sign-in?](#why-did-the-claims-rules-include-a-users-country-with-users-in-c)
6. [Why were refunds only partial?](#why-were-refunds-only-partial-for-example-507-000-of-999-990-pac)
7. [Did Nayiem steal Altilly users' funds?](#did-nayiem-and-his-family-simply-steal-altilly-users-funds)
8. [Who controls altilly.com, and why did it redirect elsewhere?](#who-controls-altilly-com-why-is-its-whois-private-why-did-it-red)
9. [Were the servers deleted by an attacker, or cancelled for non-payment?](#were-the-servers-deleted-by-an-attacker-using-an-old-login-witho)
10. [How much was actually stolen, and where did it go?](#how-much-was-actually-stolen-about-1m-30-btc-and-12k-usdt-2-4m-9)

## The hack

### Was the December 2020 Altilly hack real, or was it a staged exit scam? There were no records afterwards, and the owning organisation was renamed just before it.

**Partly answered**

The chat cannot settle whether the loss was an outside attack or staged. There were two events. On 24 Dec, after an earlier intrusion that Mike put down to an insecure rescue port on "3 machines" (his report, forwarded by Chuck) [#1033-#1034], Mike suggested telling users it was an "outage" under investigation [#1057]. On 25 Dec, all servers at the host (Cherry Servers) were deleted, and the backups at Backblaze were gone too [#1103, #1108]. This happened while Mike was still moving wallets to a new host [#1121, #1297-#1299]. The host first said the servers were cancelled for non-payment, which Mike called "a lie" [#1110-#1111]. Later, as Mike relayed it, the host said the deletion request came from an old, inactive login email over a Tor IP [#1504, #1508]. Mike explained that portal access would allow rescue-mode access to the machines [#1510]. Almost all detail about the attack reached the group through Mike, and none of it was independently verified. The "no records" point is true: the database and the config needed for decryption were lost [#1348, #1352-#1353].

Points against staging: Chuck reported that Livecoin was hit the same day and used the same host [#1113-#1125]. Mike said about 0.8 of the 31 BTC was his, and that 1.2m PYRK of his was lost [#1663, #1745], though these are his own statements. 24 ETH in the Altilly wallet was not taken [#2861].

The chat records no organisation being renamed. It does show Nayiem saying in 2019 that Altilly was "still incorporated in Hongkong", with a plan to change that later [#759-#761], but a later message says no Hong Kong company was ever formed [#1778]. Separately, public Companies House records (outside the chat) show Qredit Ltd, a new company in Nayiem's name, incorporated on 11 Dec 2020.

The chat supports negligence: no audits and no cold storage [#215-#216], and backups were not protected against deletion [#1271, #1501]. Insider action is possible, but the chat does not prove it.

**Nayiem's note:** The author's account: he now believes the "hack" was an inside job by a developer. He says it happened just before the high-value assets were due to move to his Hetzner hosting, and that only low-value coins had been moved. He says this is his belief. The chat shows the migration pattern [#1297, #2518-#2519], but no message sets a date for moving BTC or ETH.

**Where this was asked:**

- [Reddit, r/Bitcoin](https://old.reddit.com/r/Bitcoin/comments/kn28kn/_/giel58l/): "Really funny how the owner renamed the organization right before the magical hack."
- [Bitcointalk](https://bitcointalk.org/index.php?topic=5166945.40): "the transfer process to new servers someone made a mistake and deleted important files...Exit Scam?"
- [Reddit, r/CryptoMarkets](https://old.reddit.com/r/CryptoMarkets/comments/ogw26p/_/h4o81ea/): "altilly claims a HACK at the server, no records available, I almost wonder if thats really what happened."

### Was the hack an inside job? In 2020 Altilly called that suggestion 'totally untrue and unfounded'. Why does Nayiem now say it was an inside job?

**The critic is partly right**

The critic is right that this is a change of position. In December 2020 Nayiem backed the official line and defended Mike ("It's not your fault" [#1256]). His inside-job view is a later reinterpretation, not a view he held at the time. The chat does not prove an inside job.

Points that raised questions later:
- Nayiem himself had no access to the Cherry servers that were wiped. He wrote that "Mike didn't allow me" [#1492-#1493].
- Mike said Cherry told him the deletion request came from an old login on his hosting account, over Tor [#1504, #1508].
- The wipe happened in the middle of a server migration. Mike said coins added in the last 30 days were already on the new host [#1297-#1298].
- Mike estimated the Bitcoin loss at about 31 BTC [#1600].
- A day earlier, after the first attack, Mike suggested telling users "we are still investigating the outage" [#1057].

Evidence for an outside attack:
- Mike reported signs of an attack through the host's rescue port the day before; Chuck forwarded his messages [#1033-#1034].
- Mike explained that the old login had no 2FA and that Cherry's portal had been breached before [#1504, #1507, #1510].
- Cherry's own first explanation was non-payment, which Mike disputed [#1110-#1111].
- Chuck reported that Livecoin used the same host and was hit the same day, which suggests a common vulnerability [#1113-#1124].
- Mike said he lost some of his own funds [#1663, #1745].
- 24 ETH in the Altilly wallet was not taken [#2861].

Our assessment is that the inside-job claim is possible but unproven. The chat also contains substantial evidence for an outside attack.

**Nayiem's note:** The author's account: he says he trusted Mike "like family" and was "too naive to believe that he could have orchestrated all of it." He says he changed his view only after going back through the team chat years later and finding what he calls hints. On 29 Sep 2026 he wrote publicly that he "believe[s]" the hack was an inside job by a developer. That is his belief, not a finding.

**Where this was asked:**

- [Quadriga Initiative](https://quadrigainitiative.com/casestudy/altillyhotwalletshackedandcoldwalletslost.php): "suggestions of the attack being an inside job are totally untrue and unfounded"
- [Bitcointalk](https://bitcointalk.org/index.php?topic=5166945.60): "Seems another inside job here...Wanting to get out of this altilly project"
- [Bitcointalk](https://bitcointalk.org/index.php?topic=5166945.60): "probably someone on the inside...the domain was basically stolen through an old inactive email"

### Were funds moved before the hack was announced? Deposits and withdrawals failed for days, the LTC wallet was already empty on 24 December, and the DIME and MOON wallets were emptied or moved.

**The critic is partly right**

Partly. Funds did move on 24 December, after the outage began but before the server deletion (25 Dec) was disclosed. The team was already talking about "the hack that happened" and an attack on three machines on the morning of 24 Dec [#1031, #1033-#1034]. That afternoon Mike asked the team to tell users "we are still investigating the outage, and we have full control of our systems" [#1057]. Asked whether the loss was under 10k, he said "might be 15" and "wont know for sure until i get everything moved" [#1059, #1060]. Mike called the move unplanned [#1065], but his later messages say some wallets had been moving for a while [#1371, #1447]. On 25 Dec he said he "was still in the process of moving stuff" [#1121]. For DIME, Chuck reported that the main Altilly wallet had been emptied around the time things froze [#1494]. Mike said DIME was one he was moving, confirmed the receiving wallet was "ours", and said the DIME deposit wallet had not been moved yet [#1495, #1497]. For MOON, Chuck flagged that all Mooncoin went to a new address on 24 Dec [#1278]. Mike did not call that a migration: he said it was "prob from withdraws, but can't check db" [#1284]. Only the Mooncoin deposit wallet appears on the saved-wallet list [#1454, #1457]. MOON and DIME refunds were later paid [#4720, #4788]. A later request from Chuck to Mike to "send some Moon to a user" got no reply in the chat [#6880-#6881]. The chat has nothing about the Litecoin wallet, and nothing about deposits failing for days before 23 Dec. Messages are missing from the 24 Dec exchange [#1058, #1061-#1064]. A public notice drafted on 24 Dec said services were being moved to "a more reliable source" [#1084]. It did not mention a hack or wallet funds being moved.

**Nayiem's note:** The author's account: servers and wallets were being moved to the author's Hetzner hosting. Mike moved the low-cap and newly listed coins first and never moved the high-value assets. Then the "hack" happened. In the chat, only the move itself and which coins were saved can be checked. No message gives a date for when the high-value assets were due to move.

**Where this was asked:**

- [Bitcointalk](https://bitcointalk.org/index.php?topic=5166945.60): "Litecoin address was already empty on december 24th"
- Chat [#1494] (forwarded from a coin developer): "So our Asset is not on the safe list. But our Main Altilly wallet was zero'd out yesterday."
- Chat [#1278, #1279] (forwarded, with explorer screenshot): "All mooncoin send to new adress the 24 December...."

### Nayiem's own timeline puts the first signs of the hack on 12 December 2020, but users were told on 26 December. What happened during those 13 days? Were funds being moved?

**The critic is partly right**

The "12 December" date in Nayiem's 2025 statement is wrong, and he now says so himself. He believes he confused it with the date Qredit Ltd was incorporated. The team chat has no messages at all between 2 and 18 December [#997-#999], and the messages from 18 to 23 December are about other topics [#1000-#1028]. The incident first comes up on 24 December, when Nayiem asks "can you give me more details about the hack that happened?" [#1031]. The reply is that the attack "came in from maybe an insecure recue port at the host level" and that "3 machines" were affected [#1033-#1034]. The way he phrases the question shows the team already knew about the hack from outside this chat. The public notice also says the suspicious activity was noticed "earlier this week", and that the servers had been rebooted and reinstalled before the activity came back [#1167, #1232]. So some things happened in the days before 24 December that the chat does not record. The chat does not support a 13-day gap, but it cannot account for every day either.

On 24 December Mike estimated the loss at under 10k, "might be 15", and added: "wont know for sure until i get everything moved" [#1056-#1060]. Assets were being moved to a new host at that point. Mike proposed telling users "we are still investigating the outage, and we have full control of our systems" [#1057]. The proposed user text also said "we felt it was best to remove data from those machines immediately" [#1065]. Chuck pointed out that the status page showed missing assets, and Mike replied "ill fix that soon" [#1077-#1079]. On 25 December the servers at the old host were gone. Mike said "somebody hacked into their systems. deleted all the servers" [#1103, #1132]. The host later replied that the data "was cleaned when they were deleted from your client portal. This a standard procedure when our clients decide to cancel the services" [#1564]. The chat does not show who deleted them.

Nayiem pushed to inform users, saying "it will backfire if we don't tell the truth" [#1162-#1163]. The notice went up on 25 December at 17:18 in the chat export's clock, which is 26 December 01:25 CET according to the notice's own timestamp [#1232-#1233]. On 27 December he replied to the host's message with "Don't share this with anyone yet until I have my stuff ready" [#1566]. The chat does not show where the lost funds went.

**Nayiem's note:** The author's account: he agrees the "12 December" date was an error. Qredit Ltd was incorporated on 11 December 2020 (Companies House no. 13077371), 12 days before the incident began on 23 December, and he thinks he mixed up the incorporation date with the incident date. He says the servers were being moved to his hosting provider, and that Mike moved the small, recently listed coins first and never moved the high-value assets. The chat supports part of this, but only in messages written after the outage. There is nothing about the move before 24 December.

**Where this was asked:**

- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ip0qha/): "What was happening during those 13 days of silence? ... Were you moving funds? Covering tracks? Delaying withdrawals?"

### How can an exchange lose its database with no usable backups, no cold-storage backups and backups kept on the same provider? Is 'no backup' just an excuse for not refunding people?

**The critic is partly right**

On backups, the critics are largely right. The chat shows no working disaster recovery. Backups did exist, but at Backblaze, a separate provider from the Cherry Servers host [#1269-#1271]. The problem was that the credentials used for them could delete as well as upload. When the loss was found, the developer suspected a hack but also raised a possible Backblaze billing issue, so the cause was unclear at the time [#1103, #1108]. Backblaze later said deleted files could not be recovered and that "object lock", which blocks deletion for a set period, had not been turned on [#1498, #1501]. The developer called the delete-capable keys his own mistake [#1271]. (Those Backblaze keys, including the one in Mike's server guide [#2587], were revoked long ago.) The backups of the "safe" wallets were lost as well [#1299]. The config file needed to decrypt the database had no copy anywhere [#1353, #3086]. Even a database backup would not have helped without those keys [#4103]. A critic's message, relayed into the team chat by a team member, called it "sloppy and amateur" [#2679], and that criticism holds up. Was "no backup" invented later as an excuse? The chat doesn't support that. The loss was reported in the internal team chat as it happened, 25-26 Dec 2020 [#1103-#1108, #1299]. In early January 2021 the developer asked the host whether a separate database SSD might still hold data [#2491-#2511]. Refunds of saved assets were started, but many other refunds were never completed (see the Refunds FAQ).

**Nayiem's note:** The author's account: many of the chains used for refunds in 2020-21 no longer exist. Together with the lost database, this makes the remaining claims (which he estimates at around $50,000–60,000) nearly impossible to verify, and many late claims were fake. He says he stopped doing refunds around 2022/2023.

**Where this was asked:**

- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ikt45d/_/mbpss8s/): "How the heck does an exchange not have hourly backups? ... They are rugging if there is any talks about lost database."
- [Bitcointalk](https://bitcointalk.org/index.php?topic=5166945.60): "you storage the backup in the same server where the Database is located?"
- [Bitcointalk](https://bitcointalk.org/index.php?topic=5385112.0): "Claiming you don't have backup...proves how incompetent your developer is...bullshit excuse."

### Were the servers deleted by an attacker using an old login without 2FA, or cancelled for non-payment, which is what Cherry Servers first said? Who was Cherry's client of record, and what came of the promised 'settlement' with the host?

**Partly answered**

Cherry Servers gave two different accounts. Its first email, as Mike relayed it on 25 Dec 2020, said the servers "were cancelled by the system due to non-payment and not by anyone accessing the systems". Mike replied that there were no overdue invoices and that this was "a lie" [#1110-#1111]. The next day Mike said Cherry had traced the deletion request to an old, inactive email login on the hosting account. It was an address he had used when first setting up the service, it had no 2FA, and the request came from a Tor IP [#1504, #1508]. He also said Cherry's portal had itself been breached about a year earlier [#1507]. Cherry later partly backed this up in writing. In a reply to Nayiem's email of 15 Feb 2021, which Nayiem posted in the chat, Cherry said it "was aware of the fact of the attacker accessing your account the year before". It said it had forced a systemwide password reset after that event. It also said its action logs were too limited "to double-check what might have happened" [#4353-#4354]. Cherry's formal letter of 5 March 2021 [#4349] (attached PDF) says the client "had access to his servers through his two accounts". It says all servers "were deleted using one of the Client's accounts" and refers to an "(il)legal login". It does not name who logged in. It adds that the client acknowledged the deletion came from its own account, and it blames the client for keeping no backups. On paper the client of record was Qredit, since the letter is addressed to Qredit. In the chat, though, Mike ran the Cherry servers, and Nayiem said he never had access to them [#1483, #1492-#1493]. Nayiem nevertheless corresponded with Cherry directly from his Qredit address. The critic is therefore right that Qredit was Cherry's client of record. On the settlement: Qredit emailed Cherry on 22 Feb 2021. It raised Cherry's liability and asked for a settlement "for the Qredit and/or for its clients", saying it had lost its business and "over 1mln usd in clients funds". Cherry's 5 March letter rejected any liability and any duty to compensate. Nayiem had earlier said he would "sue Cherry" [#2875]. The chat shows no lawsuit and no compensation after that.

**Nayiem's note:** The author's account: in a note added to the chat in 2026, the author calls Cherry's email the "first response ... after I reached out to them on behalf of Altilly" [#7587]. This would explain why the letter is addressed to Qredit. The same note claims Mike used the situation to "orchestrate" the hack. That is the author's belief, and the chat does not establish it.

**Where this was asked:**

- Cherry Servers liability notice (2021-03-05); PDF p.4
- [Reddit, r/Bitcoin](https://old.reddit.com/r/Bitcoin/comments/kn28kn/_/gief7eg/): "We are working on a settlement with the hosting provider without using any legal actions at this stage."
- Chat [#2714-#2729] (group screenshots): "cherryservers is shit isn't it"

### Was Altilly negligent? Examples include passwords sent in plain text, a hosting login without 2FA, and an ignored security-testing offer. Was it insured, and can victims claim against Willems Ventures?

**The critic is partly right**

On negligence, the critic is right. In 2019 the developer ("Mike") wrote "we are too small to worry about audits yet" and "heck we are too small to even start moving to safe storage" [#215-#216]. After the incident he said an old, inactive email address still had login access to the hosting account, while "the email i currently use has 2fa" [#1504]. According to Mike, the host told him the servers were deleted from that address over Tor [#1508]. The backups were set up so they could be deleted [#1271], and they were deleted as well [#1342]. At first Mike was not sure whether this was the hacker or a billing problem [#1108]. Outside critics said the same at the time. One message, which Chuck copied into the chat from another group, said: "Who runs a server without backups? Its sloppy and amateur" [#2679]. The chat does not show the plain-text password emails. Those come from a public forum post (bitcointalk). The security-testing offer appears only as a third party's claim in a screenshot from September 2021 [#7380]. The chat never shows the offer being made or turned down. The chat shows no evidence that Altilly was insured. Liability insurance comes up only as a question [#1309], and later talk of insurance is about future plans [#2873, #5030]. Whether victims can bring a claim against Willems Ventures is a legal question that this evidence cannot settle.

**Nayiem's note:** The author's account: Altilly was never registered as a company. Mike privately promised that the author would formally acquire it once Qredit Ltd was set up. Qredit Ltd and Willems Ventures Ltd were both incorporated on 11 Dec 2020, 12 days before the incident, and Companies House lists no role for Mike in either company. The author says he never earned anything from Altilly. He also admits to what he calls naive management at the time.

**Where this was asked:**

- [Reddit, r/altillyhack](https://old.reddit.com/r/altillyhack/comments/my9l2v/): "they were clearly negligent, and must be insured if they are operating a company. so I guess we must put forward a claim against the main company, which is still operating called Willems Ventures"
- [Bitcointalk](https://bitcointalk.org/index.php?topic=5166945.40): "I registered to this site and got an email WITH MY PASSWORD INSIDE IN PLAIN TEXT!"
- Chat [#7380] (Telegram screenshot): "if people see a asecurity company was wanting to test and help you before the issue happened it would not look good on altilly"

### Why did Altilly talk about everything except catching the hacker? Why was there no police report or legal action?

**The critic is right**

On the main point, the critic is right. The management chat records no police report, criminal complaint or legal action against whoever carried out the December 2020 hack. The chat's only calls to the police concern a separate break-in at the author's home in January 2021 [#2380-#2477]. Chuck suggested getting a statement from the hosting company for "any legal proceedings that might happen later" [#1319-#1322]. Nayiem noted "Lawyers are all on holiday" [#2183]. Nothing in the chat shows a lawyer being engaged over the hack or a report being filed.

Legal pressure that did come up was aimed at the hosting company, not at the hacker. Nayiem wrote "I'm still going to sue Cherry" and said the company would "receive an ultimatum" [#2875-#2876]. Days later he concluded "We are not going to get money from this shit company" [#3092]. In March 2021 he shared a "Notice regarding liability" from Cherry Servers, which he said contradicted an earlier email in which they admitted fault [#4349-#4356].

The technical trail was left mostly to Mike, who controlled the hosting account. He reported that the attacker used a Tor exit IP and logged in through an old, inactive email address on the account [#1450, #1504-#1508]. He asked the host for the login history but got only five days of it [#1509, #1749]. When Nayiem asked where the BTC went [#1511], Mike said he hadn't written it down [#1516]. He also said he couldn't remember the address of the wallet he had been "keeping some safe in" [#1615]. Nayiem himself asked around about who knew the company used Cherry [#2715, #3038] and looked into a Cherry employee [#3093-#3108]. When Nayiem asked what to tell users, Mike suggested: "just say we are investigating and information collected from user submissions will help in this" [#2124], and Nayiem agreed [#2125].

So there were informal inquiries and a dispute with the host. But neither Mike nor Nayiem, who both ran the company, took any formal step toward identifying or prosecuting the hacker at the time. That was a shared failure.

**Nayiem's note:** Author's account: in the 2025 write-up, the author says the FBI and the US Marshals were contacted. That tip was about the author's belief concerning Mike's identity, not a report filed over the hack in 2020. The author says the Marshals opened a two-way dialogue and issued tip reference 777-W77728, with no response beyond that. Nothing public confirms the tip or the reference.

**Where this was asked:**

- [Reddit, r/Bitcoin](https://old.reddit.com/r/Bitcoin/comments/kn28kn/_/giel79n/): "You dont find it funny theyre talking about everything BUT finding justice and identifying the hacker? As if it would be impossible?"

### How much was actually stolen: about $1M (30 BTC and 12k USDT), $2.4M, $900K or $6.7M? Where did it go? Will the compromised hot-wallet address and the trail of the 30 BTC be published?

**The critic is partly right**

About $1M is the only loss figure in the chat. On 27 Dec 2020 Nayiem told the team "1 million usd can be done" when he talked about paying users back [#1626]. Later that day he wrote "We lost 1mln, but we should know that it will be more. Not everyone will be honest about what they've deposited" [#1677]. The chat mentions 31 BTC ("How much of the 31 btc was ours?" [#1662]). The developer replied that about 0.8 BTC was his own and that the exchange's own share was only fees [#1663]. The developer appears as "Deleted Account" in the export and is understood to be Mike. For USDT, the only address anyone knew was the USDT withdraw wallet [#1616-#1617]. When it was checked after the hack it showed about $13.2k in tether [#1624]. Nayiem had guessed less than $2k [#1622]. So the chat does not confirm exactly how much USDT was taken. The public figure of roughly 30 BTC plus 12k USDT (Quadriga Initiative) is broadly consistent with the chat, but the chat does not prove it. The $2.4M is not a loss figure. The author says it was the team's final total of all claims, saved and non-saved assets together; his 2025 write-up wrongly called it "saved" assets and his personal website wrongly calls it a loss. Claims can exceed the loss because they include saved assets that still existed and were valued at a later date. The final claims sheet is not in the chat, so the $2.4M cannot be checked here; the chat shows only the valuation being set up [#2534, #2553] and the non-saved-asset and conversion sheets being built [#7426]. Nothing in the chat supports a $900K personal payout. The $900K figure comes from the author's own 2025 write-up and refers to refunds he says he later paid from his own income. We found no source at all for $6.7M.

The critic is right that the BTC trail was never published. A user asked the team to "post your now compromised hotwallet address and the location of the stolen 30 BTC" [#2112]. Nayiem said "We should really find out what the btc wallet was." Chuck agreed but said "im not sure how". He added that the BTC was not in the deposit or withdraw wallets but "in safe storage", with maybe 0.3 BTC in the withdraw wallet at a time [#2113-#2119]. Mike had said he kept the safe wallet's address in a database table but could not remember it [#1615]. He also said that even with the address, change outputs would make the funds hard to trace [#2121]. The team's agreed public answer was only that they were "investigating" [#2124]. The chat shows no BTC address for the stolen funds and no trace of where they went. It does not support the claim that the funds were routed to Exmo or Livecoin wallets. Some funds were not taken, for example 24 ETH in the Altilly wallet [#2861].

**Nayiem's note:** Author's account: in his Feb 2025 document the author says he paid about $900K of refunds "out of my own pocket". The chat does not show this. The author also says all XQR held on Altilly was lost in the hack. The chat backs that part: "All lost" [#1732-#1733].

**Where this was asked:**

- [Quadriga Initiative](https://quadrigainitiative.com/casestudy/altillyhotwalletshackedandcoldwalletslost.php): "The total amount stolen is circa 1mln USD… 30 BTC and 12,000 USDT"
- Chat [#2112] (forwarded user message): "please also post you now compromised hotwallet address and the location of the stolen 30 BTC on your site"
- [Reddit, r/Bitcoin](https://old.reddit.com/r/Bitcoin/comments/kn28kn/_/gid7raa/): "Folks waited 2 years for Bitcoin to jump...then exit scam 12k and 30 Bitcoin lolz...."

### Why did some stolen Altilly funds go to wallets linked to the Exmo/Livecoin hackers, and was the same-day Livecoin hack connected? Was that trail laid deliberately as cover?

**The critic is partly right**

The chat supports only part of this. EXMO and Livecoin were both hacked within days of the Altilly incident in late December 2020, and the team discussed both. The author posted CoinDesk's article on the EXMO hack [#1053]. Chuck, a co-founder, relayed that Livecoin "was hacked" [#1088]. He also passed on a report from a third person that Livecoin used "the same host" [#1113, #1124], and said it was hit the "same day" [#1122]. The author himself wrote that Livecoin used TransIP, Hetzner and Cherry [#1480]. Altilly was itself partly moving to Hetzner at the time [#1119]. The account the author identifies as Mike wrote "this is state sponsored for sure" [#1054].

Nothing in the chat shows Altilly funds reaching wallets linked to the EXMO or Livecoin attackers. There are no addresses, no tracing output and no screenshots. The 2025 Follow-Up PDF says the funds went there "as cover", but it gives no exhibits. The critic is right that this claim is unproven. Whether the trail was laid on purpose is not established either way.

The hosting evidence is mixed as well. Cherry's first email apparently blamed overdue invoices, which the Mike account called a lie [#1110, #1111]. That account was also unsure whether the backups were lost to the hacker or to a billing issue [#1108]. Later, Cherry sent a formal "Notice regarding liability" [#4349], which the author said contradicted an earlier Cherry email that had admitted fault [#4350]. A shared host and the timing fit a wider outside attack. They are also consistent with other explanations. The chat does not settle it.

**Nayiem's note:** In the author's account, he was told later that some Altilly funds reached wallets tied to those attackers. He has no addresses or tracing report, so this is hearsay. In 2020-21 it convinced him that Altilly was part of a wider attack, and he told Mike "It's not your fault" [#1256]. Only years later (he dates it to 2024) did he come to believe the link might have been used as cover. That is his hindsight belief. No authority has confirmed it.

**Where this was asked:**

- Nayiem's Follow-Up PDF (Feb 2025)
- Chat [#1088, #1124] (forwarded): "Maybe a hack attemp, livecoin was hacked"

## Mike and Paul Vernon

### Is 'Mike' real? Nobody had heard of him before February 2025. How do we know Nayiem is not Mike or Karl himself?

**Partly answered**

The chat shows that "Mike" existed long before February 2025. From July 2019, Chuck, a third team member, refers to him and tags him as @MrMike_O [#10, #17, #175]. Nayiem also addresses him directly [#794]. The same account links github.com/mrmikeo [#4380] and pastes a support ticket addressed "Hi Michael" [#3288]. In December 2020 Chuck asks "Does Michael have access to both TUSC wallets?" [#1796]. A "Michael Osullivan" was also publicly listed as the Altilly developer in the Bitcointalk AltillyCoin announcement of December 2018 (bitcointalk.org topic 5086735). Mike and Nayiem appear as two separate people talking to each other, and Chuck talks to both of them: Nayiem says "Mike didn't allow me" access to the servers [#1492-#1493], and Mike says he set up the hosting account [#1504].

There is counter-evidence too. In January 2021 Chuck relayed a message from an outside user who named "Michael Osullivan" and also suggested the team might be "an accomplice" [#2679]. Nayiem himself wrote in 2026 that he "always knew that Mike never used his real name" [#7595], so "Michael Osullivan" may itself have been an alias.

The critic has a fair point on several things. The export was published by Nayiem and redacted by him: some messages were deleted [#7598], and it includes notes he added in September 2026 [#7581-#7598]. Mike's account shows as "Deleted Account", so it can only be identified from context. "Karl" never appears in the chat, so the chat cannot show that Nayiem is not Karl. Chuck is the independent witness who could confirm that Mike and Nayiem were different people. Whether Mike and Karl are the same person, or whether either is Paul Vernon, remains an allegation that no court has ruled on.

**Nayiem's note:** The author's account: Mike suggested they work on Xeggex together and approach "Karl", and Nayiem publicly announced a plan for Dokdo to acquire Xeggex. The author says that around November 2022 he found out Mike was running Xeggex himself and that "Karl" never existed, so the acquisition was cancelled. He says he did not warn Xeggex users for more than two years. His reason is that he expected people would not believe him. He says the business relationship ended in late 2022, and that after that he stayed in contact with Mike only to get money back: the Solar funds, repaid in full by 19 March 2024, and later a promise Mike made to fund the remaining Altilly refunds for non-saved assets and to pay Chuck, which Mike never followed up on. He also says Mike deleted their private Telegram chat history, so the private conversations cannot be shown.

**Where this was asked:**

- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ikt45d/_/mbqduik/): "How do we know Mike is even real, and that you're actually not Mike like you say in your post?"
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ikt45d/_/mbrx2v3/): "'Mike' is just another story. ... no one knew about Mike before you made this post."
- [Reddit, r/XeggeX_Victims](https://old.reddit.com/r/XeggeX_Victims/comments/1imyfqw/_/mccvosd/): "Doesn't mean that Nayiem is off the hook though.  Why doesn't Nayiem = Mike?"

### Users publicly named Michael O'Sullivan as the culprit in January 2021, in Altilly's own channels. Why claim nobody knew about Mike? Was management his accomplice?

**The critic is partly right**

The critic is right on the core fact. On 6 Jan 2021 Chuck posted a photo [#2678] in the management chat, followed by text that appears to come from a user in a public channel [#2679]. The text named "Michael Osullivan", said he was trying to sell BTC, and called management "very likely" an accomplice. Chuck removed the user ("removing this guy and his idiot freind", [#2680]) and Nayiem answered with a thumbs-up [#2681]. Nayiem then asked him not to delete the messages because "It will make them look like fools" [#2682], which dismissed the accusation. Chuck replied "too late" [#2683], so the messages had already been removed. The chat records no follow-up on the name. The developer's name was not secret either: a 2018 Bitcointalk announcement lists "Michael Osullivan" as the developer ([Bitcointalk, Dec 2018](https://bitcointalk.org/index.php?topic=5086735)). The site should not say nobody knew who Mike was. What stayed unproven then, and in this chat, was whether he took the funds.

The chat does not show management working with him on the loss. Nayiem pressed for the missing BTC to be traced [#1511, #1599, #2113], and he said at the time that Mike held the server access and he did not [#1492-#1493]. The user's point about backups is backed only by Mike's own account: he wrote that the backups were gone and that it was unclear whether the hacker or a billing problem at Backblaze caused it [#1108, #1299]. Management, Nayiem included, kept working with Mike afterwards. In September 2021 Chuck was still assigning him work on the recovery with Nayiem tagged [#7421, #7435], and Mike was still posting in the chat [#7430-#7431].

**Nayiem's note:** Author's account: at the time, Nayiem saw Mike as family and was "too naive to believe that he could have orchestrated all of it." He says he only came to believe who Mike really was around Nov 2022, and he went public in Feb 2025. His reply in the chat was "Don't delete the messages" [#2682], and that points to embarrassment about the accusation, not to hiding it.

**Where this was asked:**

- Chat [#2679] (forwarded user message): "you want to know the guys name, its Michael Osullivan... Unless of course you are an accomplice in this"
- Chat [#2678, #2679] (group screenshot and forwarded text): "Their negligence is what got you in this position. Who runs a server without backups?"

### Where is the proof that Mike was part of Altilly: logs of GitHub backdoors, a legal document, proof he returned funds? Why would he refuse KYC yet offer full ownership? Did Nayiem ever meet him or verify his identity?

**The critic is partly right**

The chat clearly shows that someone called Mike worked on Altilly's technical side from 2019. His messages come from an account that now shows as "Deleted Account". We link that account to Mike from context: Nayiem calls him "Mike" [#3691, #3693], and Chuck addresses him as @MrMike_O [#17, #175]. In the chat he releases code [#22-#23], runs queries on user data [#416] and builds admin tools [#611]. He links a repository called altillypwa under the GitHub account mrmikeo [#4380]. He shares a whitepaper cover for a separate project, "Altfenix", that names "Michael Osullivan, @MrMikeO" as author [#5529]. None of this proves his legal identity.

On the other points, the critic is right:
- We have no logs of GitHub backdoors. That claim comes from one unnamed reviewer, and we hold no artifacts.
- No legal document ties Mike to Altilly, and we found no company register entry naming him.
- The chat contains no proof that he returned any funds.
- The chat contains no offer of "full ownership" (see the ownership questions under "Nayiem's role and money").
- No message shows Mike openly refusing KYC. [#7383] ("he wont KYC") follows a screenshot of a third party threatening legal action and appears to be about that person, but the chat does not say who "he" is.

What the chat does show: in March 2021, the Revolut Business team account that Nayiem had set up asked Mike to verify his ID. Mike put it off because his passport was "at the china visa office" [#4414-#4416]. Nayiem did not insist. Instead he let Mike use his own card details to pay for a service [#4417]. In hindsight that was a mistake.

We found no record of an in-person meeting, a video call or any identity check. Team Revolut cards were shipped to Nayiem's address for forwarding [#3647, #3657]. One Revolut envelope that arrived there was addressed to "PAUL Vernon" [#3833]. The thread around it shows it was the card Mike ordered [#3638-#3693, #3960]; see the Paul Vernon questions below. We do not treat the name as proof of who Mike is. No authority has confirmed Mike's identity.

**Nayiem's note:** The author's account (not verified by the chat): Mike privately promised that the author could acquire Altilly once Qredit Ltd was set up, which Companies House dates to 11 Dec 2020. The author says Mike later deleted their private chat history, so that promise cannot be shown. The author also says Mike repaid the 1,878,477 SXP fraudulently swapped in the Nov 2022 Solar incident ([Solar's statement of 30 Nov 2022, posted in the Solar validator group on Discord](/evidence/solar-statement-2022-11-30.png)). By the author's account, Mike repaid the full 1,878,477 SXP in 12 payments between 1 December 2022 and 19 March 2024, back to the Solar swap wallet involved in the theft. The final payments can be checked on the Solar blockchain (see the [Solar repayment ledger](/story#after-altilly)). The author confirms there are no screenshots of the GitHub/"Karl" episode.

**Where this was asked:**

- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ikt45d/_/mbrx2v3/): "show us proof that Mike existed during Altilly. Show us the logs of him installing 'backdoors' on GitHub."
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ip0qha/): "Mike refused to complete KYC, yet offered Nayiem 'full ownership' - how does that make sense?"
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ip0qha/): "Did you ever meet Mike in person, do a video call, or was this entire partnership just an online crypto bromance"

### Does the GitHub account mrmikeo belong to Nayiem, including a recent Xpense commit? Did he use the identity of a director registered as Michael O'Sullivan (Ecuadorian and Vanuatu passports, as critics put it) to register UK companies?

**Partly answered**

The chat does not support the claim that the GitHub account mrmikeo is Nayiem's. Nayiem posts under his own name throughout, and he talks about "Mike" as a separate person, for example "it's for mike" [#4385] and "Just need Mike to work on the account connector" [#7205]. A developer addressed as @MrMike_O joined the group in 2019 ([#17], [#190]), and his account has since been deleted. In March 2021 a now-deleted account posted a link to github.com/mrmikeo/altillypwa [#4380]. Every deleted account shows up with the same label in the export, so the chat alone cannot prove which person posted it. For completeness: Nayiem also once linked an mrmikeo repo (github.com/mrmikeo/qredit-dataserver, [#5196]) while asking a technical question. Linking to a repo does not show who owns it. From our own check of public sources (not the chat): GitHub metadata for mrmikeo ("MikeO") points to the Altilly developer email address, and the 2018 Bitcointalk Altilly announcement names "Michael Osullivan" as developer. We did not examine any "Xpense" commit and cannot confirm it. The newest mrmikeo commit we checked is in xeggex/hummingbot (1 Apr 2024). UK Companies House lists a director registered as Michael O'Sullivan, with non-UK nationality and residence, for Xeggex Software Services Ltd (14910559). Nayiem's own UK companies (13077371, 13078483) list him under his real name. Filings are self-declared, and nothing we hold shows whether that identity is real, borrowed or fake. We make no claim that any passport is fraudulent, and a real Michael O'Sullivan may be an unrelated person. In January 2021 an outsider named "Michael Osullivan" as the thief [#2679]. The same outsider also suggested Nayiem might be an accomplice. Both are unverified accusations.

**Nayiem's note:** The author's account: he believes "Mike" (mrmikeo), and later "Karl" at Xeggex, was Paul Vernon, and that the O'Sullivan identity was Mike's, not his. This is the author's belief, not an established fact. The author has no screenshots of the GitHub/"Karl" episode.

**Where this was asked:**

- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1immi9m/_/mc4a39b/): "the GitHub profile most likely belongs to Nayiem ... I'm guessing Nayiem is using a stolen identity and goes by Michael O'Sullivan to register companies in England"
- [UK Companies House](https://find-and-update.company-information.service.gov.uk/company/14910559/officers)
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1imsux4/): "Karl => NAYIEM !!! Mike_O => Michael O'Sullivan !!!"

### Is the XeggeX 'Mike' (Telegram MrMike_O, Qredit API contributor) the same person who ran Altilly's back end? Is Karl a separate person or just Mike?

**Partly answered**

Yes on the first question, with caveats. In the chat, the Telegram user @MrMike_O (whose account now shows as "Deleted Account") ran Altilly's back end. He talks about releasing new code [#22-#23] and explains the hosting account and its login emails after the December 2020 incident [#1503-#1504]. Chuck asks him to change admin rights in the Altilly group [#1263, #1317]. He links code in the github.com/mrmikeo repositories [#4380]. He posts a white-paper cover for a planned exchange, "AltFenix", signed "Michael Osullivan @MrMikeO" [#5529], and forwards a support email addressed "Hi Michael" [#3288]. Outside the chat, the public GitHub account mrmikeo has code for Altilly and Qredit and, according to our separate check, a commit to the xeggex organisation's repository in April 2024 ([GitHub commit d1479b80](https://github.com/xeggex/hummingbot/commit/d1479b80fe4003100502eea94d7142d3de54c7eb)). That links one developer to all three projects. It does not prove he ran XeggeX.

The chat cannot answer the Karl question. Its messages from the time end in October 2021, before XeggeX existed. Later replies in the group were added by Nayiem in 2025–2026 and are not evidence from the time. The claim that "Karl = Mike" comes from a single anonymous page (xeggex.cpuchain.org), which we could not load or check.

On the name Paul Vernon: in December 2020 Mike said an old login email for the hosting account was "paul@satotechlt.com", and that "history on that domain probably has my name" [#1324-#1328]. In February 2021 Nayiem posted a photo of a Revolut delivery addressed to "PAUL Vernon" [#3833]. The thread around it shows this was the card Mike ordered: Revolut did not ship to his country, so Nayiem had it sent to his own address to forward, Nayiem confirmed Mike had ordered his card, and on 19 February Mike said his Revolut card had arrived [#3638-#3693, #3960]. None of this proves that Mike and Paul Vernon are the same person. No court or authority has linked Paul Vernon to Altilly or XeggeX. It remains an allegation, and it reflects the author's belief.

**Nayiem's note:** The author's account: Mike suggested they work on XeggeX together and approach "Karl". Around November 2022 the author came to believe that Mike ran XeggeX himself, that "Karl" never existed, and that Mike was Paul Vernon. The author says there are no screenshots of the Karl episode and admits he did not warn XeggeX users until February 2025.

**Where this was asked:**

- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1iic1wh/): "This Mike guy from the xeggex Team worked on the qredit api which is connected to atillys native crypto."
- [change.org](https://www.change.org/p/demand-for-immediate-investigation-and-restitution-for-victims-of-xeggex-crypto-exchange-18ba0d68-051a-44fe-ac1a-8cbbf631f582)
- [xeggex.cpuchain.org](https://xeggex.cpuchain.org/) (page returned 403 when checked)

### Nayiem believed Mike stole almost $1M from Altilly. Why did he keep working with him afterwards (Altfenix, a gaming project, XeggeX talks) and still coordinate Dokdo references on XeggeX in December 2022?

**The critic is partly right**

The chat runs from Jul 2019 to Oct 2021. It also includes a few short replies from Feb 2025 and notes added in 2026. In 2020-2021 it mostly shows Nayiem relying on Mike and speaking warmly to him: "I just need you Mike" [#1885], "I believe in you Mike" [#3340], "I trust you with the hosting panel" [#5658]. The two planned Altfenix together in May 2021 [#5235-#5628]. They were still working together in Sep 2021, when Nayiem posted a plan with Mike working full time on Qredit Motion [#7428]. There is also a remark that cuts the other way. In May 2021 Nayiem handed Mike access to the hosting panel and added "It's not like something bad ever happened before" [#5658]. It reads as a sarcastic nod to the incident, so he was aware of it and trusted Mike anyway. Nothing in the chat mentions a gaming project, XeggeX or Dokdo, so the December 2022 coordination cannot be checked here.

The criticism is fair on several points. Nayiem's own 2025 PDF says Mike's story "made no sense" in Dec 2020 and that "we had our doubts" in 2021. So he kept working with Mike, including on Altfenix, after he had doubts. The PDF also gives two different dates for when he became convinced: once "2024" and once late 2022. He did not warn XeggeX users until Feb 2025. None of this establishes who Mike is or that he took the funds.

**Nayiem's note:** Author's account (not verifiable from the chat): after the loss he trusted Mike again, partly because he was told some of the stolen funds had been traced to wallets tied to the Exmo and Livecoin hackers. He saw Mike as "family". He says Mike brought him XeggeX in 2022 and presented it as a chance to repay Altilly users. Around Nov 2022, at the time of the Solar (SXP) loss that Mike later repaid, he concluded that "Karl" did not exist, and the Dokdo acquisition was cancelled. Any contact in Dec 2022 was about unwinding things, for example getting the Altilly domain handed over. After that, he says, he stayed in contact with Mike only to get money back: the Solar funds, and later a promise Mike made to fund the remaining Altilly refunds for non-saved assets and to pay Chuck, which Mike never followed up on. He stayed silent until 2025 because he expected not to be believed. He calls himself "super naive" for missing the hints.

**Where this was asked:**

- [publish0x.com](https://www.publish0x.com/crypto-musings-consumer-impacts/the-xeggex-drama-continues-xevwkno): "why Willem went back to working with Mike again, knowing he was already involved in heisting almost a $1 million from Altilly"
- Nayiem's Follow-Up PDF (Feb 2025) (2022-12-03 Dokdo references coordinated with Mike)

### Nayiem believed Mike had stolen before and was building XeggeX. Why did he warn nobody until after it collapsed? Does that make him an accessory with foreknowledge?

**The critic is partly right**

On the silence, the critic is right. The contemporaneous Telegram chat ends in October 2021 [#7571], before Xeggex existed, so it cannot answer this question. The only later entries are a few short replies posted on 8-9 Feb 2025, days after the collapse [#7572-#7575], and his 2026 annotations [#7576-#7598]. None of them is a warning from before the collapse.

The author admits that from about November 2022 he believed Mike was running Xeggex. He did not warn its users until after withdrawals stopped on 3 Feb 2025.

His own follow-up PDF (Feb 2025, p.15, an image), which he shared with investigators and initially posted on Reddit, shows him writing to Mike on Discord about the Solar (SXP) swap incident ([Solar's statement of 30 Nov 2022](/evidence/solar-statement-2022-11-30.png)): "Why did you do it Mike?" (29 Nov 2022, 22:45), then "We are not going to say anything if you can return the funds in 24hrs." (30 Nov 2022, 00:17). Silence was offered in exchange for repayment.

The same PDF shows that he stayed in contact with Mike afterwards. On 3 Dec 2022 Mike asked, "should I start removing references to Dokdo on Xeggex?", and Nayiem answered "Yes, please." By his own account, Mike repaid the full 1,878,477 SXP in 12 payments between 1 December 2022 and 19 March 2024, back to the Solar swap wallet involved in the theft. He has published transaction IDs only for the final five payments, which can be checked on the Solar blockchain ([Solar repayment ledger](/story#after-altilly)). So during the years he stayed quiet, he was also being repaid.

Over time he has given different reasons for not speaking out. In Feb 2025 he cited fear for his safety and a lack of proof. Now he also cites not wanting Solar associated with the matter and expecting not to be believed. He says that after the business relationship ended in late 2022, his only contact with Mike was about getting money back.

Xeggex users had a real stake in knowing what he suspected, and they have a fair complaint.

Whether any of this makes him an "accessory" is a legal question this record cannot settle. We found no public report of a court or law-enforcement body acting on Xeggex or naming anyone as responsible for it. The DOJ/IRS releases we reviewed concern Cryptsy only. Nayiem says he filed a tip with the US Marshals Service, but only after the collapse, in Feb 2025. That Mike is Paul Vernon is still an allegation, not an established fact.

**Nayiem's note:** The author's account: around November 2022, at the time of the Solar SXP loss, he came to believe that "Karl" did not exist and that Mike was running Xeggex himself. The planned Dokdo acquisition was then cancelled. He did not go public for two reasons. He was running a separate, legitimate project (Solar) and did not want to be associated with the matter. And he expected not to be believed, which he says the Reddit reactions in Feb 2025 later confirmed. He says the business relationship ended in late 2022, and that after that his only contact with Mike was about getting money back. He says Mike repaid the full 1,878,477 SXP by 19 March 2024. He accepts that he did not warn Xeggex users for more than two years. He gives these as reasons, not excuses.

**Where this was asked:**

- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ikt45d/_/mbrp780/): "You knew Mike the scammer ripped off users and stole funds, caught him in the midst of creating a new exchange ... and did and said nothing until after it happened again?"
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ikt45d/_/mbsikr3/): "What you have just admitted to is foreknowledge of a federal offense."
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ikt45d/_/mbqlc3s/): "If this is true it would of been nice to know 9 months ago and not today."

### If Nayiem knows the thief's identity and has evidence, why not go to the police instead of threatening him on social media? Has any authority acted on the FBI case ID he cites? Why is the man not in jail?

**The critic is partly right**

The critic is largely right. The management chat has no report of the December 2020 "hack" to police or any other authority. On 30 Dec 2020 the author tried to reach lawyers, but they were on holiday [#2183]. The police were contacted twice on 3 Jan 2021, both times about threats and intruders, not about the hack. After an angry user had called and emailed him [#2339] [#2341], someone had been on his property. Police treated it as not urgent and told him to come to the station [#2380] [#2389] [#2420]. That evening he called them again about two people with flashlights in his garden [#2471].

By his own account, the author came to believe Mike was Paul Vernon around November 2022. He did not report this until early 2025, after Xeggex stopped withdrawals in February 2025. "777-W77728" is not an FBI case ID. It is a US Marshals tip reference number. It confirms that a tip was received, not that anyone is investigating. By the author's account, a two-way dialogue was opened and the reference issued, with no response beyond that; his February 2025 wording made the dialogue sound like more than that. No authority has publicly acted on the tip. No court or agency has linked Vernon to Altilly or Xeggex, and none has confirmed that Mike is Vernon.

On "threatening him on social media": the author's 2025 posts did more than report. They published a private person's name and a property listing, and they offered to share Mike's details if people would visit him. The author now says that was wrong, and this site does not repeat it.

The public record on Vernon is a separate matter. Paul E. Vernon, the former Cryptsy CEO, was indicted on 17 counts in S.D. Fla. (case 1:19-cr-20509). The indictment was filed under seal in August 2019 and unsealed in January 2022. In September 2019 the court moved him to fugitive status. DOJ says he moved to China in or around November 2015. No arrest or extradition has been reported. The charges concern Cryptsy only and are allegations; he is presumed innocent.

**Nayiem's note:** In the author's words: he reported to the FBI and the US Marshals in early 2025. The Marshals opened a two-way dialogue and issued tip reference 777-W77728, with no response beyond that, and the FBI gave him no case number. He says that in 2022 he stayed silent because he was running a legitimate project (Solar) and did not want to be associated with Vernon. He also expected people would not believe him, and the Reddit reactions in 2025 confirmed that. He admits that publishing a private person's details in 2025 was wrong, and says the unredacted chat and the "PAUL Vernon" envelope are available to any authority. These are his beliefs and explanations. They have not been verified.

**Where this was asked:**

- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ip0qha/): "If you knew for months that 'Mike' was really Paul Vernon, why didn't you report him to authorities? Why did you only expose him when it became necessary to clear your own name?"
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ikt45d/_/mc24rqc/): "you know the identity of the person and have evidence of theft from your clients ... and your action us to threaten to make his name public!!"
- Nayiem's Follow-Up PDF (Feb 2025) (FBI / US Marshals case ID 777-W77728)

### Why did Paul Vernon appear only after Nayiem was questioned? Is Vernon a convenient scapegoat, a disappeared villain used to take the heat off Nayiem?

**The critic is partly right**

The critic is partly right about timing. Nayiem named Paul Vernon publicly only in February 2025, after Xeggex collapsed. In February 2021 he had received a Revolut envelope addressed to "PAUL Vernon" (photo attached to [#3833]) and said nothing about it in public at the time.

The name was not made up later, though. It shows up in the chat years before anyone accused Nayiem. The account shown as "Deleted Account" in the export is Mike's: Nayiem addresses Mike by name and that account replies [#3638-#3639, #3691-#3693]. In December 2020 that account gave "paul@satotechlt.com" as an old email address and said the domain's history "probably has my name" [#1324, #1326, #1328]. In February 2021 Revolut said its service was not offered in Mike's country [#3639, #3646]. Nayiem offered to have Mike's card sent to his own address in Sweden and to forward it [#3647, #3657], and Nayiem then wrote that Mike had registered and ordered his card [#3693]. Two days later a Revolut express envelope arrived at Nayiem's address, addressed to "PAUL Vernon" (photo attached to [#3833]). Mike later said his card was held up in customs, then that it had arrived [#3837, #3960].

Taken together, these messages make it likely that Mike used the name Paul Vernon. There is one limit. Nayiem administered the Revolut Business account [#3644-#3645], and the chat does not show who typed the cardholder name. It only shows that Mike registered and ordered the card himself [#3693].

No court has confirmed that Mike is Vernon, or that Mike or Vernon took part in the Altilly or Xeggex losses (Rekt News, Plisio). The original chat ends in October 2021 [#7571], so it cannot answer the Xeggex-ownership theory in either direction. Even if Mike is Vernon, Nayiem's own failures as CEO still stand.

**Nayiem's note:** The author's account: around November 2022 he concluded that Mike was running Xeggex, that "Karl" never existed, and that Mike was Paul Vernon. He says he kept quiet because he was running a legitimate project (Solar) and did not want to be linked to Vernon. He also expected people not to believe him, and they did not believe him when he went public in February 2025. He says he googled the name on the envelope in 2021 and found only a blues musician [#7585, #7595]. This cannot be checked.

**Where this was asked:**

- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ip0qha/): "At first, Nayiem never mentions Paul Vernon. ... He needed a bigger villain to take the blame"
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1inxb8g/_/mcgul9r/): "Paul has already disappeared, so it's easy to make him the scapegoat"
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ljmhjx/_/mzna6o5/): "there are theories Nayiem Willems was the owner of Xeggex and just using Paul Vernon as a Scape goat and it was actually Nayiem behind the hack."

### What hard proof is there that Paul Vernon was Mike/Karl and ran XeggeX? The evidence cited is a 'paulv' code signature, a GitHub slip, villa matching and a phone call. Is that strong enough?

**The critic is partly right**

On the four items named, the critic is right: none of them is hard proof. No screenshot of the "paulv" code signature exists, and Mike reportedly said the Mac was second-hand. There are no screenshots of the GitHub/"Karl" slip either. The villa match comes second-hand from a broker. The phone call is an inference drawn from how the person who answered reacted. No court or agency has linked Paul Vernon to Xeggex, and press coverage calls it an allegation. (see [Rekt News, 5 Mar 2025](https://rekt.news/plant-a-red-flag), [Quadriga Initiative](https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Xeggex_Exchange_Collapses_After_Suspicious_Withdrawals) and [Plisio](https://plisio.net/profiles/xeggex-exchange), which all describe the link as an allegation).

The chat log has two better pieces of material. Both date from 2020–2021, years before any public dispute:

- On 26 Dec 2020, right after the Altilly hack, Mike said the compromised old email address was "paul@satotechlt.com" and added "history on that domain probably has my name" [#1324] [#1326] [#1328]. Caveat: the author now thinks the domain was a typo for satotechltd.com; he says his own WHOIS lookup at the time showed nothing because of the missing letter [#7595]. A historical WHOIS record for satotechltd.com, which the author posted in 2026, lists Paul Vernon / Project Investors Inc [#7577], and a January 2016 Bitcointalk post lists a Hong Kong "Satotech Limited" linked to Vernon, with the same phone number as that WHOIS record ([Bitcointalk](https://bitcointalk.org/index.php?topic=1173703.msg13568578#msg13568578), [#7583]). Reading "satotechlt" as a typo for "satotechltd" is the author's interpretation, not a proven fact. See [Who is Mike?](/mike).
- In Feb 2021 Nayiem set Mike up with a card on the Altilly team's Revolut Business account. Revolut would not ship to China [#3639] [#3646], so Nayiem told Mike to have it sent to Nayiem's address [#3647]. Mike replied "ok, done" [#3653], and Nayiem confirmed Mike had registered and ordered his card [#3693]. Two days later a Revolut envelope arrived there addressed to "PAUL Vernon" (photo in [#3833], home address redacted). Mike later confirmed he had received his Revolut card [#3960]. Read together, the thread shows the envelope held the card Mike ordered [#3638-#3693, #3960]. Caveat: the chat does not show who entered the cardholder name, and it does not show Revolut checking anyone's ID.

The chat also shows Mike used the "mrmikeo" GitHub account [#4380] and the @MrMike_O handle [#3831].

Taken together, this makes it likely that the person we knew as "Mike" used the name Paul Vernon. The author says he always knew "Mike" was not his real name [#7595]. This is not proof of anyone's legal identity. It does not prove that the real person named Paul Vernon ran Xeggex or did anything wrong. Those points remain the author's belief and an allegation.

**Nayiem's note:** The author says that around Nov 2022 they came to believe that "Karl" never existed, that Mike ran Xeggex, and who Mike was. The author did not go public until Feb 2025. They expected people not to believe them. They say that after the business relationship ended in late 2022, their only contact with Mike was about getting money back. The author also confirms that no screenshots of the GitHub/Karl episode exist.

**Where this was asked:**

- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ip0qha/): "Do you have ANY proof that Paul Vernon was actually behind Xeggex? Why is there no FBI, Interpol, or financial crime agency interest"
- [Reddit, r/Bitcoin](https://www.reddit.com/r/Bitcoin/comments/1inqdx4/)
- [rekt.news](https://rekt.news/plant-a-red-flag): "'Karl' has been alleged to be Paul Vernon"

### Why did Nayiem's write-up say Vernon 'has never been criminally charged', when he was indicted on 17 counts in 2019 (unsealed in 2022)?

**The critic is right**

The critic is right. The February 2025 write-up said Paul Vernon "has never been criminally charged", and that was false. A sealed 17-count federal indictment against Paul E. Vernon, the founder of Cryptsy, was filed in the Southern District of Florida on 15 August 2019 (case 1:19-cr-20509). On 16 September 2019 the court placed him in fugitive status, according to the CourtListener docket. The indictment was unsealed and announced on 26 January 2022 (DOJ SDFL and IRS-CI press releases). The counts include wire fraud, money laundering, computer fraud, destruction of records and tax evasion. These are allegations, and there has been no conviction. No filing in that case mentions Altilly or Xeggex. The chat does not explain why the write-up used those words. No original chat message types the name "Paul Vernon", but the name does appear in the original record: the Revolut card envelope Nayiem photographed on 4 February 2021, the card Mike had ordered, is addressed to "PAUL Vernon" [#3833]. On 26 December 2020 Mike also shared the email address paul@satotechlt.com and said "history on that domain probably has my name" [#1326, #1328]. Nayiem's 2026 note on the envelope photo adds the full name in text [#7585]. Whether Mike is the indicted Cryptsy founder has not been legally established. Our review lists "never charged" among several factual errors in the 2025 statement, and the new story corrects it.

**Nayiem's note:** The author's account, from the revised story draft: he meant that Vernon "never faced justice", but he accepts that the words he used were false. The new story says plainly that Vernon was indicted in 2019, that the indictment was made public in 2022, and that he remains in fugitive status.

**Where this was asked:**

- [US Department of Justice](https://www.justice.gov/usao-sdfl/pr/ceo-major-online-cryptocurrency-exchange-company-indicted-defrauding-company-s)

### Is the story of Mike hiding in China under a false passport credible? If Nayiem feared him, why send people from the Chinese community to confront him and publish his address and villa location?

**The critic is partly right**

The critic is partly right. On the first point, the chat shows Mike living fairly openly in China on a visa rather than hiding there. He talks about extending his visa and the registration with the local police it required [#894] [#900], gives a mailing address in China (not shown on this site), and says his passport is "at the china visa office" [#4415]. Revolut told him its service was not offered in his country [#3646], so Nayiem offered to receive the card at his own address and forward it [#3647] [#3657]. The envelope that arrived was addressed to "PAUL Vernon" [#3833] (photo on file, with the address redacted), and Mike later confirmed he had got his card [#3960].

Separately, the US Department of Justice says Paul Vernon, the former Cryptsy CEO, moved to China in about November 2015. He was indicted in 2019 (the indictment was unsealed in 2022) and has not been tried. The US has no extradition treaty with China. The UK Companies House record for Xeggex Software Services Ltd lists a director registered as Michael O'Sullivan as a citizen of Vanuatu ([Companies House](https://find-and-update.company-information.service.gov.uk/company/14910559/officers)). That record says nothing about Vernon.

That Mike is Paul Vernon is Nayiem's conclusion, drawn largely from the card label. It is circumstantial and no court has confirmed it. Nothing we checked shows that any passport was false, so the "false passport" part of the story is unverified.

On the second point, the critic is right. In the 2025 PDF, Nayiem wrote that he would share Mike's personal details "if there was a 100% guarantee that people would visit his location". He also wrote that the "Chinese community has the resources to track down Paul" and that he was "the only person who knows exactly who Paul is, where he is". He had held Mike's China mailing address since 2021. The PDF also printed a villa address, while saying he was "genuinely afraid for my safety". The PDF says he feared Mike and also points toward Mike's location. The author describes this as a change over time rather than a contradiction (see his note below). This site redacts that address and all other home addresses, and asks readers not to contact or visit anyone.

**Nayiem's note:** He says he was afraid of Mike for a long time and kept quiet. After Xeggex collapsed, he was being threatened over something he had no control over, and he decided that Mike's identity and location should be known. He says members of the Chinese community later reported that the property matched the house in Mike's videos; this site cannot verify that and does not publish any address. In his own words, the author says he has been getting threatening messages for years, including threats linked to the Xeggex hack. He says that working through this material brings back fear, sleepless nights and PTSD. His 2025 PDF gives his reasoning at the time. He held back Mike's identity at first because of the risk to himself. Then, in February 2025, he was being threatened and publicly blamed for Xeggex, so he decided to go public together with community members who were Xeggex victims. That is his explanation, not a justification this site endorses.

**Where this was asked:**

- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ikt45d/_/mbsggmr/): "China doesn't let anyone hide unless they have paid 75M. ... Story comes across as bullshit to me"
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ip0qha/): "why would he send members of the Chinese community to track him down and confront him?"
- Nayiem's Follow-Up PDF (Feb 2025), pp.18, 26, 45

### Is Karl, Mike or Paul actually Nayiem's brother?

**Partly answered**

Nothing in the chat suggests it, and a few messages point the other way, though none of them settle it. When the team wishes Mike a happy birthday, Nayiem says it falls two days after his "youngest brother's" birthday [#3748-#3752]. That at least means Mike is not his youngest brother. Elsewhere Nayiem mentions a brother in the Netherlands in passing, with no link to anyone in the team [#6194]. A participant now shown as "Deleted Account", apparently Mike, talks about his military service and upstate New York [#6193, #6195]. He also gives an old email address, paul@satotechlt.com, and says that domain's history "probably has my name" [#1324-#1328]. That is the only identity trace in the original chat's text, and it gives a first name, not a surname. No 2019-2021 message types the full name "Paul Vernon"; it appears on the Revolut envelope Nayiem photographed in February 2021 [#3833] and in his own 2026 annotation [#7585]. Public reporting describes "Karl = Paul Vernon" as a community allegation that no court has confirmed. The name "Karl" never appears in the chat, so nothing there links Karl to Nayiem's family. The rumour, as the author's rebuttal PDF describes it, rested on a 2018 article about Nayiem working with his brother and on the word "brother" in Karl's Discord bio. That doesn't show the two are related. To be fair, a chat log can't prove a negative, the identity links above are inferences rather than proof, and Karl's time at Xeggex comes after the chat ends.

**Nayiem's note:** The author's account: in his Follow-Up PDF rebuttal, Nayiem calls the brother claim a rumour and says the only "proof" offered was a 2018 news article about him working with his brother and the word "brother" in Karl's Discord bio. He says he believes Mike/Karl is Paul Vernon, and that he saw Mike "as family" in the emotional sense, not as a relative. These are his own statements and have not been independently verified.

**Where this was asked:**

- Nayiem's Follow-Up PDF (Feb 2025), addendum rebuttal

## Nayiem's role and money

### Did Nayiem, and his family, simply steal Altilly users' funds?

**Partly answered**

None of the surviving messages shows that Nayiem, or any member of his family, took users' funds, and no family member plays any role in the chat. The servers and wallets that were wiped were run by the lead developer, "Mike". His account now shows as "Deleted Account", and the chat's context identifies it as his. He held the "safe" wallet keys and ran the sweeps by hand [#1299, #1615, #6717]. Nayiem wrote "I never had access to those servers" and "Mike didn't allow me, because I break things" [#1492-#1493]. No surviving message shows him receiving fees, a salary or any payout. He describes himself as "1mln usd in debt" [#1882] and having "no money at all" [#2805]. He also said he was "done paying for all those 3rd parties" [#6772], which suggests he had been covering some outside support costs, though at one point he said he had "zero cash" and the Freshdesk bill could wait [#5602]. The chat does not support the "several million euros" figure. Nayiem's own estimate was "We lost 1mln, but we should know that it will be more", because not every claim would be honest [#1677]. The critic does have a point. Users lost real money, and the saved-asset refunds were incomplete. The chat shows the keys for the unpaid saved coins, such as TUSC and HIVE, were with Mike, and Chuck's September request to him to send the pending saved assets got no reply in the chat [#4878, #3917, #7421]; Nayiem says Mike never completed those refunds. Nayiem also handled refund approvals himself, which means he could move at least some user funds [#3563-#3564]. He barely checked individual claims ("anything between 50-200 usd I don't check at all", [#3564]), checking only that each coin's total matched its wallet [#3558], and he approved stalling tactics ("Go for it", [#5017-#5020]; a refund-token plan followed the next day [#5201-#5203], but Altfenix never launched), followed by "This will be a multi million dollar baby" [#5021]. He also ordered one payout with "remove all traces" [#4029, #4032-#4033]; the users concerned were in countries on a banking partner's 139-country high-risk list, not a sanctions list, and by the author's account they were paid; the chat does not show the payments. Some messages were deleted [#7598], so the chat's silence proves nothing either way.

**Nayiem's note:** The author's account: he says he never drew a salary or any income from Altilly, and that all listing and trading fees went to Mike. He says he lost his own XQR in the hack ([#1732-#1733] record only that it was lost). He accepts that not every approved user got their saved assets back: the chat shows some still unpaid in September 2021 [#7180, #7421]. He says he stopped refunds around 2022/23 with around $50,000–60,000 in claims left that can no longer be verified. The chat does not confirm these points; they are his own statements.

**Where this was asked:**

- Reddit (post on a private user's profile; link and username left out): "User stolen at altilly.com by Mr Nayiem Willems on Twitter"
- [Reddit, r/banano](https://old.reddit.com/r/banano/comments/kr9tm9/_/gin5jqj/): "Altilly.com is a big scam by Mr Nayiem Willems"
- Chat [#2689, #2777] (@AltillyComScam tweets): "has been a successful scammer with a net worth of several million euros stolen from us"

### Who actually owned Altilly: Hodler Enterprises, 'the Qredit team', nobody officially, or Nayiem as founder? Nayiem later said he 'acquired it in 2018 for $175,000', and critics say he founded it rather than being asked by Mike to be CEO.

**The critic is partly right**

The chat does not settle who owned Altilly, and the public accounts contradict each other. Altilly's 2019 Bitcointalk post said it was "owned and operated by Hodler Enterprises". Its post-hack notice said it "was acquired in 2019" but also that there was no "official ownership by either of the 2 parties". Nayiem's personal site said he "acquired Altilly in 2018 and invested $175,000". None of these claims comes with documents, and the $175,000 figure does not appear anywhere in the chat. In the chat, Nayiem acts as Altilly's CEO and public face, but not clearly as its sole owner. In 2019 he edits Altilly's company text. He wants to cut the Hodler Enterprises wording ("nobody cares who Hodler Enterprises is") [#702]. When Chuck insists on calling Altilly "a Hodler Enterprises owned company", Nayiem agrees to put that on the About page [#705-#706]. In the same period he asks Mike to approve new listing fees and to push the changes live [#755]. He also writes that Altilly is "still incorporated in Hongkong, until I have the things sorted here" [#759]. In December 2020, Mike says he had meant to use a registration service "to form a company in hk" but "never did do that tho" [#1778]. Two days later Nayiem says "We are not incorporated in Sweden", and he and Chuck agree not to mention that to anyone [#2164, #2166-#2167]. After the hack, Chuck talks about the team "taking responsability and paying back" [#1690-#1694]. The chat starts in July 2019, so it cannot show who founded Altilly or whether Mike asked Nayiem to be CEO. The critics are right that Nayiem's own statements conflict: his claim of a 2018 acquisition and his Hong Kong incorporation claim are not supported by the chat. No message records a planned transfer of ownership.

**Nayiem's note:** The author's account: Altilly was never registered as a company. The author was CEO and the public face and handled the company formation, while Mike directed development. Mike privately promised that the author would get full ownership once the author had set up a company (Qredit Ltd, around December 2020). The author says Mike later deleted that private chat. The author also says that he never received a salary or fee income, and that he meant the Hong Kong incorporation claim [#759] in good faith but now believes it was untrue. This explanation does not account for the author's earlier public statement "acquired in 2018 for $175,000".

**Where this was asked:**

- [Reddit, r/Bitcoin](https://old.reddit.com/r/Bitcoin/comments/kn28kn/): "The exchange was acquired in 2019."
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ikt45d/_/mbrx2v3/): "He is the FOUNDER of Altilly, yet he claims Mike came to him and asked him to be CEO."
- [Quadriga Initiative](https://quadrigainitiative.com/casestudy/altillyhotwalletshackedandcoldwalletslost.php): "without any official ownership by either of the 2 parties"

### What was Altilly's legal entity? Nayiem says he registered it in the UK 12 days before the hack, but Companies House shows only Qredit Ltd. Why a Hong Kong address, a UK PO box, EUR 2,000 of capital and no board?

**The critic is partly right**

Largely, the critic is right. No evidence shows Altilly ever had a legal entity. In Sept 2019 the website mentioned Hodler Enterprises [#702], and Chuck wanted it to keep saying Altilly was owned by that parent company "for trust reasons" [#705]. At the same time Nayiem wrote that Altilly "operates out of Sweden" but was "still incorporated in Hongkong, until I have the things sorted here" [#759]. That statement does not hold up. In Dec 2020 Chuck asked about the Hong Kong (Mong Kok) address shown for Altilly [#1776-#1777]. Mike (who appears in the log as "Deleted Account") replied that it was probably from a registration service he had planned to use to form an HK company, but he "never did do that" [#1778-#1779]. Two days later Nayiem confirmed "We are not incorporated in Sweden" [#2164]. Nayiem's 2019 description of Altilly as an HK-incorporated company was therefore inaccurate. When Chuck asked about the company address, Nayiem answered that it was where his own business, Willems Ventures, is registered [#1578-#1579]. Companies House lists only QREDIT LTD (13077371), incorporated 11 Dec 2020, 12 days before the incident began. It is not Altilly. Its registered office is a London virtual-office address, and Nayiem is its only director and its 75%+ PSC. So "no board" is accurate. It never filed accounts and was dissolved by compulsory strike-off in May 2022. The register records its capital as GBP 100, not EUR 2,000. The "fake PO box" claim comes from a screenshot posted in the chat [#7418] and has not been verified. The chat never mentions the UK company. Nayiem's account is that Qredit Ltd was set up so it could take Altilly over, and that it never traded because its XQR was held on Altilly and lost [#1732-#1733]. No message in the chat confirms that takeover plan.

**Nayiem's note:** The author's account: Altilly was never registered as a company. Mike privately promised that the author would formally acquire Altilly once the author had set up Qredit Ltd, and the two were moving servers and wallets to the author's hosting when the 'hack' happened. According to the author, Qredit Ltd never traded because its XQR coins were held on Altilly and lost [#1732-#1733]. Willems Ventures Ltd was his resort business and was not connected to Altilly [#1579]. The chat has no message that confirms the acquisition promise.

**Where this was asked:**

- [UK Companies House](https://find-and-update.company-information.service.gov.uk/) (only Qredit Ltd, 11 Dec 2020)
- Chat [#1776] (forwarded): "are you based in hong kong, and operate in sweden ??"
- Chat [#7418] (Telegram screenshot): "You use fake post office box in england, started company with 2000 ueros, and have no board"

### How could Nayiem be CEO without access to the Cherry servers holding BTC, ETH, DASH and LTC, and why didn't he demand control?

**The critic is partly right**

The chat shows that Nayiem says he had no access, and nothing in it contradicts that. On 26 Dec 2020 he wrote "Mike uses cherry" [#1483], then "I never had access to those servers. Mike didn't allow me, because I break things" [#1492-#1493]. Nobody else in the chat confirms or disputes this. Mike (shown as "Deleted Account") said the hosting account had been set up about three years earlier using an old, inactive email he had used [#1504]. According to Mike, Cherry said the server deletion request came from that email [#1508]. Mike also held a VPS with the "safe" wallets [#1299]. The chat shows Nayiem did not know the setup: he asked which provider was used [#1105], what had been moved to Hetzner the day before [#1119], and whether any keys existed [#1285]. Mike said wallets were being moved to "the new host", but only "any bitcoin clone that was added in the last 30 days" had moved, and the move was still in progress [#1297-#1298]. BTC, ETH, DASH and DOGE wallets are reported lost [#1600, #4094-#4095]. The chat does not show what happened to LTC.

On the second half of the question, the critic is right. The chat has no message from before the loss in which Nayiem asks for control of the servers or keys. Even afterwards, on 4 Jan 2021, he wrote that he "could also reset the credentials my self.. but don't want to give you the feeling that I don't trust you" [#2571], and that he wished he had known earlier how things were set up [#2572]. A CEO letting high-value wallets sit under one person's sole control was a governance failure.

**Nayiem's note:** Author's account (not in the chat): Nayiem says he was CEO and the public face and handled the company formation. He says Mike decided what was built and which direction to take, and presented himself as not interested in money or in being seen in public. Nayiem believed that once he had set up Qredit Ltd, around December 2020, he would take over the whole exchange. He says that is why servers and wallets were being moved to his Hetzner account. The promise of a handover was made in private and does not appear in the chat. His view that the "hack" came just as the high-value assets were due to move is his own reading. No message in the chat gives a date for that move.

**Where this was asked:**

- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ip0qha/): "If he was the CEO, why did he allow high-value assets to be stored in a system he couldn't control?"

### Why would Nayiem pay refunds from his own pocket for a hack he says was not his fault? Was it to delay legal action?

**The critic is partly right**

The chat does not show refunds paid from Nayiem's own pocket. Through 2021 he says "I have no money at all" [#2805] and "I have zero cash" [#5602]. The saved-asset refunds that were paid were sent in kind from recovered exchange wallets, mostly by Mike [#4593, #4613-#4903]. The ones left unpaid, such as TUSC and HIVE, were also coins whose keys Mike held [#4878, #3917]; Nayiem says Mike never completed them. In some cases wallet contents were handed to the project's developers to distribute [#2145, #2149-#2151, #6760-#6761]. Refunds for non-saved assets were not paid within this record. They were put off ("Rest of the shit storm will come later" [#4582-#4583]; "We will deal with it once we have the funds" [#6754]). Proposed sources included selling leftover coins [#4738], future exchange profits [#5878] and QSLP tokens rather than cash [#6807]. Nayiem says that from late 2021 he paid refunds from his own income, about $900K by his count, but that falls outside this record and the chat cannot confirm it. Paying refunds does not prove he caused the loss, because an exchange operator faces pressure to make users whole whatever the cause of a hack. On the delay point, the critic is partly right. Chuck raised the risk of lawsuits when discussing how to hand out recovered assets [#2035] and pointed to another exchange's refund process as designed to prevent lawsuits [#3576]. Chuck said "I can drag it out forever" and Nayiem answered "Go for it." [#5017-#5020]. A refund-token plan followed the next day [#5201-#5203], but Altfenix never launched. Chuck also spoke of stringing the process out to "buy time" [#5962, #6027, #6811], though he also said the phased schedule was meant to spread the workload [#5960-#5961]. At Chuck's request, dated promises were replaced in public posts with "as quickly as possible" [#3418-#3421]. None of this shows Nayiem was responsible for the loss. It does show that buying time was one reason refunds were paced as they were.

**Nayiem's note:** Author's account: the author says that he and Chuck were both struggling financially while doing refunds between December 2020 and December 2021. They collected bottles to return for deposit money, which went back into refunds or bills (he says this was posted in the main Altilly Telegram group at the time: [message link](https://t.me/c/1308041716/180323), members only). He stopped refunds around 2022/2023, with a handful after that. He estimates the unpaid claims left at around $50,000–60,000, but these can no longer be verified because the chains are dead and the database was lost. Many refund chains from 2020-21, including the old Qredit chain, no longer exist, so txid proof often cannot be shown. The chat supports none of the specific personal-payment figures he has given elsewhere.

**Where this was asked:**

- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ip0qha/): "If he wasn't responsible for the hack, why did he take on the financial burden? ... Because Nayiem WAS responsible for the hack and was trying to delay legal action."
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ikt45d/_/mbz5rer/): "why u pay from ur own pocket.... sounds likly more scammy then ur story.."

### What did Nayiem mean in May 2021 by 'I can't pull this twice. Next time will be one way ticket to Russia or China'? Is that an admission of complicity?

**The critic is partly right**

The quote is accurate [#5354]. It was written on 17 May 2021, during a design discussion about a new exchange. In the messages just before it, Nayiem says he wishes withdrawals could run from something "disconnected from the internet", using a scheduled file and a script [#5334-#5340]. That way, "if someone hacks the platform. They will only get access to hot wallets" [#5344]. He says he means "the hack that happened", not a customer withdrawal [#5345-#5346]. Mike suggests letting the Oracle decide whether funds go to hot or cold wallets [#5350]. Nayiem adds "Just need to be careful in trying something new" [#5353]. Straight after the quote, Mike says "If there is a next time I'll probably have a heart attack". Nayiem replies "Same for me. I don't know what i will do to myself if it ever happens again" [#5356, #5361]. A few minutes later he writes "We have some sort of protection now with the insurance and licensing. But still.. need to be careful" [#5364].

A critic can read "I can't pull this twice" as "I can't get away with this twice". In context, we read it differently. The whole exchange is about stopping an outside attacker from draining wallets again. "Next time" refers to a second hack happening to them, and the reactions around it (heart attack, not knowing what he would do to himself) are about dread, not escape. We do not read the line as an admission of complicity, and nothing in this exchange suggests he took part in the theft. Readers can check the full context in the messages cited.

The critic has a fair point on tone, though. "Damage control" and "pull this twice" frame the Altilly loss mainly as a reputational problem the team had got through. That matches a dismissive, flippant tone towards affected users that the chat shows elsewhere [#2158, #6386]. It was a poor choice of words, but on its own it is not evidence of complicity.

**Nayiem's note:** The author's account: in his statement for the website, Nayiem says the years after the Altilly hack brought threats, sleepless nights, financial ruin and what he describes as PTSD. He also says he is ashamed of how naively he wrote at the time, and compares reading his old messages to "reading messages from a child pretending to run an exchange." Nothing in his statements speaks to this particular line.

**Where this was asked:**

- Chat [#5354]: "We managed so far with the damage control of Altilly. I can't pull this twice. Next time will be one way ticket to Russia or China"

### Was 'Charles' (Hodler Company / Hodler Enterprises, 'Altilly support') a fake persona run by Nayiem? Is Hodler Enterprises a real company?

**The critic is partly right**

The chat does not support the idea that "Charles" was a fake persona run by Nayiem. The group was created by the account "Chuck" (service message), and Chuck wrote its first message asking Nayiem to add managers [#2]. Across the chat he posted about 2,800 messages. He openly disagrees with Nayiem [#705], and Nayiem addresses him by his own Telegram handle [#1819, #4907]. He introduced himself to a KYC vendor by name, "from Altilly Exchange" [#661]. He was added to the team's Revolut Business account and ordered his own card [#3709-#3723], then reported receiving it [#3846]. He also describes personal hardship, such as going to a food bank [#3430]. All of this is consistent with a separate person, not an alias.

The critic is right that Hodler Enterprises links to Nayiem. Nayiem wanted to remove most references to Hodler Enterprises from the Altilly site ("nobody cares who Hodler Enterprises is") [#702]. Chuck objected that the site should still say Altilly was "a Hodler Enterprises owned company or a subsidary of" for trust reasons [#705], and Nayiem agreed to keep that on the About page [#706]. Chuck later asked about accounts that were "yours or hodler?" [#1489]. The only "HodlerCompany" handle in the chat belongs to another member close to Nayiem, not to Chuck [#5104, #5105].

The chat does not show whether Hodler Enterprises was ever a registered company. Nayiem said Altilly was "still incorporated in Hongkong" [#759]. That conflicts with a later message from a now-deleted account (apparently Mike): the Hong Kong address came from a registration service he had meant to use to form a company in HK, and he "never did do that" [#1776-#1779].

**Nayiem's note:** In the author's own account, Chuck is a real teammate who struggled alongside him during the refunds (food bank, collecting bottles), and Chuck agreed to let the food-bank detail be published. The author also says the arrangement was that he would get ownership of Altilly once he had set up a company. The chat has no ownership-transfer message; see [#702, #705] and [#759].

**Where this was asked:**

- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ikt45d/_/mbrx2v3/): "a user named Hodler Company (Hodler Enterprises), who introduces himself as Charles, Altilly support. Guess who created Hodler Enterprises? It was Nayiem."
- freebitcoins.com blog post (link left out because its address names a private person)
- [Reddit, r/ArkEcosystem](https://old.reddit.com/r/ArkEcosystem/comments/d26802/_/ezt65wu/): "Hodler Enterprises does exist, they're the company behind Qredit, Hodler Mining, Altilly, etc"

### Does Nayiem run multiple personas, such as the Karl/NeoSolarX avatars and Turkish-language accounts, with himself as the public face and a back-end persona he also controls? Why did he change his profile picture and remove 'CEO of Solar' from X after being named?

**Partly answered**

The chat supports one part of this. Nayiem was Altilly's public CEO, and Mike ran the back end. In Nayiem's own words: "I never had access to those servers... Mike didn't allow me" [#1492-#1493], and "Mike never gave me access to the database" [#6557]. Those are his own statements, not independent proof. They do fit the "public face / backend operator" split described on Reddit. The chat does not show Nayiem running a back-end persona. It also does not show him with no back-end access at all. After the December 2020 hack he asked for the Altilly.com server login [#1375], and on 4 January 2021 he wrote "Mike, I did a root password reset on cnserver02" and asked for the sudo passwords so he could check what had been saved [#2569-#2570]. His remark "I wish I knew earlier" [#2572] suggests he had not seen that setup before the hack.

The chat runs from 2019 to 2021. It has nothing about "Karl", NeoSolarX, Turkish-language accounts or changes to his X profile, so it can neither confirm nor rule out the multiple-persona claim. The avatar similarity is an observation, not evidence of who runs an account. We found no source tying Karl to Nayiem. Karl's link to Mike rests on public GitHub and WHOIS traces plus community allegations, and is unproven. The profile change is real by the critic's account. We have no documented reason for it.

**Nayiem's note:** The author says "Karl" was a persona Mike introduced in 2022. In the author's account, Mike proposed they approach Karl together about Xeggex, and around November 2022 the author concluded that Karl never existed and that Mike ran Xeggex himself. This is the author's own account and has not been independently verified. The author does not say why the X profile picture and the "CEO of Solar" line were changed. That still needs an answer.

**Where this was asked:**

- [Reddit, r/XeggeX_Victims](https://old.reddit.com/r/XeggeX_Victims/comments/1imyfqw/): "NeoSolarX & Karl share similar avatars, hinting that Nayiem may be using multiple online personas."
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1immi9m/_/mc5dyvd/): "At Altilly, Nayiem was the public face but a guy named Karl/Mike was working backend operations"
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ik58q6/_/mbked49/): "he changed the description of his profile on X (removing that he is CEO of 'solar network')"

### Were Altilly's team members and Nayiem's back-end developers real, verified people, or fake personas with stock photos?

**The critic is partly right**

The chat cannot settle whether the faces on Altilly's website were stock photos. It never shows the team page. By December 2020, when Chuck asked whether any team "faces/names" were still on any website, Nayiem answered "Nope, all removed long time ago" [#1264-#1265]. The management group shows a small core of real, active people: Nayiem as CEO and public face, Chuck on support and listings, and one lead developer, "Mike" (@MrMike_O). Mike pushed code, ran user payouts, built admin tools and was the person asked about stuck withdrawals [#22-#23, #416, #611, #790].

The critic is right about the developer's identity. Mike went by "Michael Osullivan". That name appears on a May 2021 whitepaper draft he posted for a later project, "AltFenix" [#5529], and a community member also named him that way [#2679]. But on 26 December 2020 Mike himself told the group that an old email of his was paul@satotechlt.com and that "history on that domain probably has my name" [#1324-#1328]. On 4 February 2021 Nayiem posted, with only the comment "That was really quick", a photo of a Revolut envelope addressed to "Paul Vernon" [#3833]. In 2026 Nayiem wrote that he "always knew that Mike never used his real name" [#7595]. So the team had signs of a different name at the time. The chat shows no public verification of who the developer was. Chuck had proposed that listed projects name a CEO with a verifiable public profile [#85], but no such check was ever applied to Altilly's own developer.

The link from "Mike" to the name "Paul Vernon" is a lead based on Mike's own email remark and the envelope. It is not proof of who he is, and no court or authority has confirmed it.

**Nayiem's note:** Author's account: Nayiem says he was told Mike used a pseudonym because he had hosted adult websites and did not want his real name to hurt the exchange's credibility, and that searching the name at the time turned up only a musician [#7595]. Nayiem says he now believes Mike is Paul Vernon. That is his belief, and no court or authority has confirmed it.

**Where this was asked:**

- [Reddit, r/Bitcoin](https://old.reddit.com/r/Bitcoin/comments/kn28kn/_/giel58l/): "they look like all of the generic stock photos every shit coin has on their .io page."
- [Reddit, r/XeggeX_Victims](https://old.reddit.com/r/XeggeX_Victims/comments/1lx6xie/): "Or are these back-end developers merely hidden or fake personas with stolen or faked photos?"

### If Mike handled Altfenix with no oversight from Nayiem, why is the Estonian Altfenix company (16269508) registered to Nayiem? Who got the exchange fees?

**The critic is partly right**

On ownership and oversight, the critic is right. The chat shows Nayiem leading Altfenix, not standing back from it. He came up with the name and the domain [#5235], checked the trademark [#5254, #5761], wrote the product plan [#5587-#5634] and posted the demo [#5771]. He was also applying for the Estonian crypto licence with his own e-residency [#5081, #5744-#5745] and said the licence required him to move to Estonia [#7276]. The build work was given to Mike [#7223, #7428]. Any "no oversight" wording should be corrected. The company number 16269508 does not appear in the chat, but a company registered in Nayiem's name is consistent with his role in this record.

On fees, the chat shows no Altfenix fee income at all. In the last plan in the chat (September 2021), Mike still needed "3 to 4 weeks to go live with Altfenix", so the exchange had not launched by then [#7428]. The fee splits discussed were plans only. In reply to a question about paying off non-saved assets, Nayiem said "25% of the fees" (apparently for refunds) and "50% operational … in case we get hacked", with the exact split shown in a screenshot [#5876-#5883].

For Altilly, the chat does not say who received the fee revenue overall. When Nayiem asked "How much of the 31 btc was ours?" [#1662], a now-deleted account (apparently Mike) replied "around 0.8 was mine … exchange fees, not much" [#1663]. That describes the speaker's own holdings. It does not describe where all fees went. The word "ours" in Nayiem's question also suggests that insiders, possibly including him, held funds on the exchange. Nayiem set Altilly's listing-fee policy [#178, #917], but no message shows fees being paid to him.

**Nayiem's note:** Author's account (2026): Nayiem says all Altilly listing and trading fees went to Mike, and that he himself never drew a salary or earned from Altilly. Listing fees were paid in XQR, which was already in circulation, so he says he did not profit from them. He says he did the company formation and acted as CEO, while Mike decided what was built. The chat does not confirm or disprove who received the fees, apart from [#1663].

**Where this was asked:**

- [Reddit, r/cryptsyinsolvency](https://old.reddit.com/r/cryptsyinsolvency/comments/1inrl5y/_/mdn1063/): "Your google docs says that Mike was handling Altfenix and you had no oversight. Why is it then registered to you?"
- Chat [#5876, #6443] (forwarded): "so the fees earned on the exchange will be shared by qredit and the partners 50/50 ?"

### Is Nayiem the one constant behind a string of failed or scam ventures (Willems Ventures, Qredit, Altilly, Altfenix, Voyager Park, SolarDAO, Bitilly), and is a 2026 project another attempt?

**The critic is partly right**

The critic is partly right. Nayiem does run through several of these ventures. He started the Qredit ICO, and by his own account in the chat he "lost everything again when dutch SEC came in" [#1882]. He led Altilly and posted its public hack statement [#1167]. His company Willems Ventures and his resort Voyager Park are registered at his address [#1579]. He set up and controlled a Revolut Business "company account" for the team, adding USD and EUR accounts and requiring his own approval for payments over 50 USD [#3603, #3644, #3645, #3723]. After the hack he planned Altfenix, a new exchange named after Altilly, with Mike [#5236, #5254, #5593]. The refunds for non-saved assets were to be paid in a refund token listed on that future exchange [#5201-#5203], and later in QSLP tokens [#6806, #6807]. One version of the plan had him buying tokens back at a discount from users willing to take "only half back" [#5203]. When the chat ends in 2021, the non-saved refunds were still being prepared [#7426]. There is no sign in the chat that they were ever finished. The chat also shows him telling Chuck to refund one pushy user from a country on the banking partner's 139-country high-risk list (not a sanctions list) "not by email and remove all traces" [#4028]-[#4029]; the author says the users were paid.

"Career scam artist", though, means profiting at customers' expense, and the chat does not show that. Nayiem held the company account and ran the refund wallets himself [#3558, #3570], but no message shows him taking a salary, fees or customer funds for himself. When Chuck expected him to sell what was left in the refund wallets, Nayiem replied it would not "buy a full tank of gasoline" [#4738, #4743]. The only fee balance anyone claims is Mike's [#1663]. Nayiem says he was "1mln usd in debt" [#1882] and had "zero cash" [#5602]. The chat does not mention Bitilly or SolarDAO. It also cannot say whether a 2026 project will be different; readers should judge that on how open it is from the start.

**Nayiem's note:** The author's account: Nayiem says he never earned anything from Altilly and that all listing and trading fees went to Mike. Mike's alleged theft is his belief, not an established fact. On the 2026 project, he says he cannot move forward until this chapter is closed, and that publishing the chat is part of closing it. He admits that from late 2022 he believed Mike was running Xeggex and did not warn its users for more than two years.

**Where this was asked:**

- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ixct4u/_/melnuxb/): "Nayiem and his team are career scam artist and they've done this before."
- Nayiem's Follow-Up PDF (Feb 2025), p.43
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1qx3ld9/_/o3vuz2j/): "It's Nayiem Willems trying to scam people again."

### Did Nayiem run an illegal high-yield investment scheme in Sweden (40% returns), and what happened to the Voyager Park investments offered to crypto contacts and to Altilly's 'Investbox'?

**Not in the chat**

The management chat does not mention a 40% high-yield scheme, so it can neither confirm nor rule out that part of the Bitcointalk claim. It remains an open allegation.

It does contain evidence on the Voyager Park investment question, and that evidence cuts against the author. At [#7494] the author posted a screenshot of a tweet asking about "the trailer park investments you offer fewer weeks earlier in December". The tweet includes images of a Willems Ventures page (willems.ventures/invest) that presents Voyager Park, the author's igloo tourist resort in northern Sweden [#1378, #1583-#1584, #6246, #7127]. The page says the author is "reaching out to my fellow crypto friends to invest as little as €12,50 in the business so we can reach our hard-cap". The same pitch names the author's crypto projects, Qredit and the Altilly Exchange. So the chat shows that Voyager Park investments were offered to crypto contacts. It does not show who invested, how much was raised, what investors were promised, or what happened to their money. In the chat, the author dismissed the person who posted the tweet as a troll [#7492, #7500-#7501] and did not answer the question there. Willems Ventures and Voyager Park were registered at the same address [#1579-#1580].

Investbox was a real Altilly feature. Asked by Chuck, a developer in the chat (shown as "Deleted Account", apparently Mike) said Investbox funds were not in a special wallet: they sat in the two normal hot wallets, held under a different account [#1784-#1785]. Chuck also suggested Investbox was funded from users' exchange balances rather than from a separate deposit address, but no confirmation appears in the chat [#3926-#3928]. The chat does not say what yield Investbox offered or how Investbox balances were treated after the hack. In May 2021 the author said Investbox "was working actually and was attracting users" but proposed dropping it from a relaunch "just to be safe" [#5319-#5321]. Investbox was still present in a June 2021 test build [#6581].

Readers should get a direct public answer from the author on the Voyager Park investment offer: how many people invested, how much, on what terms, and whether they were repaid.

**Nayiem's note:** The author's account: Willems Ventures Ltd was the company for Voyager Park, their tourist resort, and it had nothing to do with Altilly [#1579, #1583]. In the chat, the author also said they "Moved to Sweden. Made money again, started Voyager Park" and were about $1M in debt after the hack [#1882]. The author's statements provided so far do not deal with the 40% high-yield claim or with any Voyager Park investors.

**Where this was asked:**

- [Bitcointalk](https://bitcointalk.org/index.php?topic=5166945.40): "running an illegal investment scam in Sweden, High Yield with 40% returns"
- Chat [#7494] (tweet screenshot): "can the user claim the restored balances from your prev. exchange simple on your next project? and whats about the trailer park investments"

### Did Nayiem take public money for a historic building in northern Sweden (a Dokdo/Solar office promising 40 jobs) and then leave? Why is the county pursuing him over repairs?

**Not in the chat**

The Telegram record can't answer this. The chat runs from 2019 to 2021 and covers Altilly. It never mentions a historic building, a public grant, a Dokdo or Solar office, a promise of 40 jobs, or a county claim over repairs. On Sweden, the chat shows only a little. Nayiem ran a tourist resort called Voyager Park, which was receiving guests in late 2020 and 2021 [#1378, #5156]. His company Willems Ventures and Voyager Park were registered at the same address where he lived [#1579, #1580], and other messages point to that being in Sweden [#1776, #6194]. In December 2020 he said he expected to end up in "massive debt" [#1533]. That says nothing either way about whether he ever got public funding. The two Reddit comments are worded as speculation ("There are speculations...", "I know the county wants hold of him..."), and neither links to a source. We have not checked Swedish public records, such as municipal or county grant decisions, property registers or enforcement cases, so we can neither confirm nor rule out the claim. The honest answer is: not covered by the chat, and not yet verified. To settle it, you would need the grant decision and any claim from the county, not the chat.

**Nayiem's note:** The author's own statements in the evidence don't cover the building, the grant or the repair claim. The only related point, in the author's words: after the 2025 Reddit statement, people visited the author's properties, and the author moved house because the address had become public.

**Where this was asked:**

- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ikmh65/_/mbnuu4r/): "There are speculations he got money from the state to fix the building ... but then just peaced out with the money"
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ip0qha/_/nljwhu1/): "I know the county wants hold of him because of buildings in the city needing repair he won't do."

## Refunds

### Where is the proof that refunds were paid, such as bank records or txids for the roughly $900K Nayiem says he paid personally? Did it take two years or three, and why do people who sent the requested proof say they were never paid?

**The critic is right**

The critic is right: no proof of the roughly $900K has been published. The chat cannot settle this either way, because it effectively ends in October 2021 and Nayiem says most of his personal payments came after that, from late 2021 and 2022 onwards. What the chat does show: in April 2021, about 60 saved-asset coins were marked refunded, mostly sent by Mike [#4613-#4903], and some refunds went through project developers [#3258-#3260, #7570]. At that time Nayiem said he had "no money at all" [#2805] and "zero cash" [#5602]. He kept no payout ledger ("I just mark the addresses", [#3575]) and did not check individual claims of 50-200 USD [#3564], only each coin's total against its wallet [#3558]. The 2025 statement says in one place that refunds took "two years" and in another "three years". It gives no bank records or txids. The chat supports the complaints about unpaid claims. In August-September 2021, Chuck wrote that approved users were still waiting for saved assets and that "Weve made alot of promises we are not keeping" [#7180, #7421]. Separately, "thousands" of users missed the claim-form deadline [#5052]. Nayiem answered that he would "take care of that as well" [#5049, #5053], and nothing in the chat shows that happening. In the same conversation, after Nayiem said refunds would "take a few years" [#5012], Chuck offered "I can drag it out forever... Hang the carrot out front", and Nayiem replied "Go for it" [#5017-#5020]. A refund-token plan followed the next day [#5201-#5203], but Altfenix never launched. Nayiem says he has statements for some payments, but not a full ledger. He also says many txids can no longer be shown, because chains such as Qredit no longer exist. Until redacted statements are published, the $900K is only his claim.

**Nayiem's note:** In the author's own account, from late 2021 he paid refunds from his own income, mainly from his share of the 2022 sale of his mining businesses after the investors were paid (all of it except about $25,000 for personal debt), which he estimates at about $900K. He says he has statements for some of the payments but not a full ledger. Many of the 2020-21 chains used for refunds, including the old Qredit chain, no longer exist, so many txids cannot be shown now. The support tickets were lost when Freshdesk was later shut down, after the chat ends. He stopped refunds around 2022/2023, with only a few after that. He estimates the remaining unpaid claims at around $50,000–60,000, though they are now very hard to verify, and he says many late claims were fake. He makes no promise of further payment.

**Where this was asked:**

- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ip0qha/): "Where is the proof that you personally paid users back? Can you show bank transactions, blockchain transactions"
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ikt45d/_/mbrx2v3/): "You never refunded me for the Altilly scam despite me sending you and 'Charles' the proof you asked for"
- Reddit (post on a private user's profile; link and username left out): "I guess you missed mine total 5725 $."

### Why was the claim window cut from 60 days to 9 January 2021 (about 14 days), and the form removed on 28 January? Is that lawful?

**The critic is partly right**

The critic is right about what happened. The team first talked about a 60-day window ([#1643], [#1973]), and the Google form went live on 28 Dec 2020 [#2029]. On 3 Jan 2021 Nayiem said he would "change the window" for refunds [#2438] and that "7 days from today" payouts of saved coins would start [#2439]. He then posted an image of the new deadline notice [#2443]. The chat text itself does not state the date; the 9 January date comes from the public notice. The reason he gave was that "the amount of claims dropped a lot" [#2446]. Chuck objected that "changing date is a mistake" and that people would see it as "a desperation act" [#2444-#2445]. Nayiem promised a form people could "still fill in after the 14 days" [#2447]. On 27 Jan Chuck asked for the public form link to be removed and replaced by a notice that the claim period had expired. He also asked for a new link that "only us 3 can be aware of", "for special circumstances only" [#3355-#3358]. Nayiem replied that he would do it himself [#3362]. On 28 Jan he worked on the website [#3364] and removed the homepage line telling people to fill in the Google form [#3422-#3424]. The same day he mentioned a "new form link" for one user [#3573]. In May 2021 Chuck noted there were "thousands who were too late" [#5052]. The chat shows the late-claim route was meant to stay private, so the critic's point that it was cut quietly is supported. On legality, the chat contains no legal advice and this FAQ cannot give a ruling. As a general point, closing a voluntary claim form does not by itself cancel any legal claims people may have.

**Nayiem's note:** The author's account: the window was cut because of fake claims. People copied real transaction IDs from block explorers that pointed to known Altilly wallets and faked deposit-confirmation emails. The chat shows the team expected fake claims from the start ([#1645], [#1650], [#1960]). However, the specific fraud of copying transaction IDs is not described in the chat at that point. The reason recorded on 3 Jan was that claims had dropped off [#2446]. The author also says refunds mostly stopped around 2022/2023. Remaining claims are now very hard to verify, and no further payouts are promised.

**Where this was asked:**

- [Twitter/X](https://twitter.com/altillycom/status/1347083240708956161): "They've now quietly changed that to: 14 days from today...Final date is: 9th of January"
- [Reddit, r/banano](https://old.reddit.com/r/banano/comments/kr9tm9/_/gin5jqj/): "Only 14 days to claim your founds.? That is illegal, in Europe you have up to several years to claim"
- freebitcoins.com blog post (link left out because its address names a private person)

### Why did the claims rules include a user's country (with users in countries on a high-risk list denied refunds), a USD 10 minimum balance, and a required Google sign-up?

**The critic is partly right**

The chat explains all three rules, and the critics are partly right about them. Minimum: a team member proposed collecting user details, with claims limited to balances "worth more than $1 or $10" [#1972]. Nayiem had already argued for a USD 25 or 50 minimum, saying "I don't want airdrop users to claim their holdings", and Chuck agreed [#1964-#1970]. Nayiem then offered to tell users not to file below USD 10 [#1983]. So the cut-off was set on purpose, not by accident. Google sign-in: when Chuck asked about users without a Google account, Nayiem answered "They can create one" and said it was meant to cut spam [#2065-#2069]. Country: the proposed form included country of residence [#1972], and it was used for sanctions screening. At first that was a list of seven countries (Iran, Iraq, Libya, Myanmar, North Korea, Somalia, Syria) that Nayiem said the company was legally barred from sending funds to [#2514-#2516]. In practice, only Iran had actually been blocked at Cloudflare [#2515]. Later, Chuck worked from a 139-country list that he called "EU sanctions" but that was in fact the banking partner's high-risk country list, not a sanctions list [#4016, #4027-#4028]. PYRK alone had 15 claims declined on this basis [#4005]. Chuck remarked that the list seemed to cover "all sanctions of any type", and Nayiem replied "Yes" [#4023-#4026]. Nayiem named sending small amounts to Nigeria as the kind of risk he wanted to avoid [#4028]. Even so, Nigeria was deliberately left unmarked "per our conversation" [#4020-#4021, #4034-#4035]. Nayiem also told Chuck that for "a really pushy person" he should "do the refund, but not by email and remove all traces", and mentioned one such "special case" [#4029-#4033]. The author says those users were paid. This was screening, not a payment order. But it was applied broadly and inconsistently.

**Where this was asked:**

- [Reddit, r/Bitcoin](https://old.reddit.com/r/Bitcoin/comments/kn28kn/): "At the form to request your funds they ask about your country(payment priority by country!?)."
- [Reddit, r/Bitcoin](https://old.reddit.com/r/Bitcoin/comments/kn28kn/): "*Only users that had a balance with a value of more than 10 USD will be paid back."
- [Bitcointalk](https://bitcointalk.org/index.php?topic=5166945.60): "but first you need to sign up to google"

### Why did Altilly demand deposit-confirmation emails from years earlier, and reject blockchain evidence and signed messages proving address ownership? How were balances earned by trading supposed to be proven?

**The critic is partly right**

The chat explains the rule but does not justify all of it. The user database and its decryption config were lost ("we will have no idea what belongs to who", [#1308], [#1353]), so there was no internal ledger to check claims against. The first plan was to ask for a txid together with the deposit email, "so we can at least verify the transaction ocurred", and to track which txids had already been used ([#1956-#1958], [#1963]). The team expected fake claims ([#1650], [#1960]). Chuck said a txid on its own proved nothing ("Anybody can grab a tx ID and say its is thiers", [#5866-#5867]). He also worried that users would send in old deposit confirmations for coins they had already withdrawn [#3895-#3897]. So the deposit-confirmation email became the main test, and a claimant without one was "marked as invalid" [#3965]. The team knew this would shut out honest users. Nayiem wrote "not everyone received those emails" [#1962], and Chuck called it "the downside to only accepting deposit emails" [#4665]. Signed messages that prove address ownership are never discussed in the chat, even though they answer the txid-copying worry.

On trading balances, the team was warned early. At [#2112] Nayiem posts what reads as a user's complaint that "all btc funds were obtained through trading other coins" and could not be verified. When Chuck later asked "Deposits only still or balances from trades also", Nayiem replied: "Both can be done. But we don't have a method yet and are not going to think about refunding those people yet. First those that we can fully verify" [#4311-#4313]. The chat does not show such a method being built. Team members who had bought assets on Altilly were excused from sending deposit emails ("we can trust the team", [#3951-#3956]). On this point the critic is mostly right.

**Nayiem's note:** The author's account: fake claims were a real problem. Some people copied genuine txids from block explorers that sent coins to known Altilly wallets, and some faked deposit-confirmation emails. The author says this showed up in the Freshdesk support tickets, not in the management chat, and access to Freshdesk was later lost. The chat only shows that fakes were expected [#1645, #1650, #1960] and that Chuck said users would send in old deposit confirmations for coins they had already withdrawn [#3895-#3897]. The author also says many of the chains from 2020-21 no longer exist, so on-chain proof often can't be checked today.

**Where this was asked:**

- [Bitcointalk](https://bitcointalk.org/index.php?topic=5385112.0): "I even offered them to sign a message with privkeys...Nope, they rejected."
- Chat [#4331] (Bitcointalk screenshot): "If anything, blockchain is the best receipt of my deposit. Can't be faked, right?"
- Chat [#4332] (Bitcointalk screenshot): "How can you prove trading activity and buying made on the market? ... it seems like a perfect exit scam"

### Why were refunds only partial (for example, 507,000 of 999,990 PAC), and why were some users offered their original BTC instead of the coins they held?

**Partly answered**

The critics are right that many refunds were partial. The chat explains some of the reasons, but it has nothing on the specific PAC case.

The rules the team used: a refund was capped at the amount on the claim form, even when deposit emails showed more ("send 4600" [#4869-#4870], [#4828]). A claim needed a deposit-confirmation email, or it was marked invalid [#3965]. Some saved wallets held less than was owed, so the rule was "refund what we can" [#4651]. For example, the Betller coin wallet did not hold enough for its only claim [#4643]. The team asked that user whether he had withdrawn or sold some [#4662], then sent 90,700.5, "thats all we had" [#4686]. Coins where only one wallet was saved were moved to the unpaid list [#4073], [#4671].

Why deposits and not coins: users who had bought a coin were often refunded in the asset they had deposited to buy it [#3966]. The BTC, ETH, DASH and DOGE wallets were lost [#4094-#4095], which made other payouts harder. In September 2021 the team built a "BTC refund request page" with "800+ users" and "over 1600 entries" [#7517-#7519]. So BTC refunds were offered, but the chat does not explain why BTC was chosen over the coins users held.

The 507,000-of-999,990 PAC case does not appear in the chat. PAC is on the saved-wallet list, with both deposit and withdrawal wallets [#1384], [#1457]. Mike reported "pacglobal done" on 2 April 2021 [#4804], but the chat gives no amounts, so it cannot say whether that user got a partial or a full payout. For Mooncoin, Mike reported the main send done [#4788], [#4859]. On 1 July Chuck asked him to "send some Moon to a user", and the chat shows no reply [#6880], [#6881].

The team admitted gaps: "thousands who were too late" [#5052], and "promises we are not keeping" [#7421].

**Nayiem's note:** The author's account: fake claims were common. People copied real txids that had sent coins to Altilly wallets and forged deposit-confirmation emails. This is part of why claims were capped at proven amounts. The author stopped refunds around 2022-23 and puts remaining unpaid claims at around $50,000–60,000, though they can no longer be checked. Many refund chains no longer exist, so txids often cannot be produced.

**Where this was asked:**

- [Bitcointalk](https://bitcointalk.org/index.php?topic=5166945.80): "they can return 507,000 PAC, but my deposit was 999,990 PAC"
- [Reddit, r/MoonCoin](https://old.reddit.com/r/MoonCoin/comments/mtxr3d/): "They refunded me only a small part and they don't want to refund any more."
- [Reddit, r/dogecoin](https://old.reddit.com/r/dogecoin/comments/krtg1u/_/gx4t2d4/): "they said they can give me back my initial Bitcoin investment"

### Were refunds paid only to people who shouted loudest? Was a partial 'carrot' used to kill momentum, and was the same playbook reused at XeggeX?

**The critic is partly right**

The "carrot" criticism is right. On 15 May 2021 Chuck wrote "I can drag it out forever… give them something now and then.. Hang the carrot out front and they will follow", and Nayiem replied "Go for it." [#5017-#5020]. A refund-token plan followed the next day [#5201-#5203], but Altfenix never launched. Chuck also described a plan to spread refunds over a year "to drag it out buying us time" [#5960-#5962] and said he had "purposely strung it out to buy you extra time" [#6811]. When valuing claims, Nayiem said to take the price "most beneficial for us. So the lowest one" [#6842, #6846]; he says altcoin prices were spiking around the hack, and he did not want a one-day spike to set the value.

The "loudest got paid" claim is also largely supported. The stated order was: people with deposit emails first, then people without, then teams [#4306]. Two users who were recruiting for a class action could not produce deposit emails [#4304, #4324-#4325]. Nayiem first said "No we dont refund them yet. Let me review them" [#4328]. Both were then paid. The first was paid on a team member's personal vouch and described as needing payment "or he's gonna pitch a shit" [#4339, #4778-#4781, #4800]. The second, whom that team member said he did not know and Chuck had labelled a "squeeky wheel", was paid the next day [#4779, #4851-#4853, #4859]. Separately, Nayiem said a "really pushy" person in a country on the banking partner's 139-country high-risk list (not a sanctions list) could be refunded "not by email" and to "remove all traces", citing one "really offensive" user as "a special case" [#4020-#4033]. The author says those users were paid; the chat does not show the payments. Team members were excused from showing deposit emails [#3951-#3956]. Partly saved wallets were paid first come, first served until they ran out [#6023]. Refunds ended up partial. Some approved users were still unpaid in Aug-Sep 2021, when Chuck wrote "Weve made alot of promises we are not keeping" [#7180, #7421]. Among those leftovers were coins whose keys Mike held, such as TUSC and HIVE [#4878, #3917], and Chuck's September request to Mike got no reply in the chat. Nayiem says Mike never completed them.

XeggeX is outside this chat, which ends in Oct 2021. Public reports describe halted withdrawals, and later the XeggeX domain was reopened with its "refund" posts deleted. Those reports come from a single source that has its own stake. This evidence cannot show that the same playbook was reused.

**Nayiem's note:** The author's account: many claims were fake. People copied real txids that had gone to Altilly wallets and forged the deposit emails, which is why proof was required. Many 2020-21 refund chains, including the old Qredit chain, no longer exist, so txids often can't be shown. The author stopped refunds around 2022/23 and estimates unpaid claims at around $50,000–60,000. Those claims cannot be verified now, and nothing is promised.

**Where this was asked:**

- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1iyjjil/_/mev38g7/): "they are just giving back the accounts to those that care/insist enough ... That's what happened with Altilly"
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ik58q6/): "Altilly refunded part of the funds when the community became loud."
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1iusy5a/_/me0srv4/): "Then he threw a carrot, just like in altilly, and every momentum was gone"

### What happens to users whose coins were not 'saved'? Will non-saved assets (partly recovered HONK, 'wiped' MRX) ever be refunded or replaced, and with which coin?

**The critic is right**

The critic is right that the chat does not show non-saved assets being refunded or replaced. When a user asked which coin would replace lost coins, the only reply was "Info will be available later on the website" [#2344, #2346]. The stated plan was to pay saved assets first and non-saved later [#3431, #4582-#4583]. Assets with only part of their wallets saved were moved to the non-saved list [#4073, #4081].

After that, several ideas came up:
- selling leftover funds to cover some non-saved claims [#4738]
- a pegged "Altilly refund token" [#5201-#5203], later described as QSLP tokens to be minted for saved and unsaved users [#6806-#6807, #6836]
- 25% of the new exchange's fees, after Chuck suggested it [#5878-#5882]

By September 2021 there were two-step claim checks [#7209-#7214], conversion sheets valuing assets at late-December-2020 prices [#7426] and a BTC refund request page [#7517]. The chat record effectively ends around then [#7532], and it shows no non-saved payout. That is absence of evidence, not proof that nothing was paid.

MRX: in January 2021 Nayiem was handling the MRX refunds himself. He said MRX was "being paid directly to users" [#3193], and when Chuck asked "When can yopu finish the metrix?" he answered "almost done" [#3488], [#3492]. During the April saved-asset payout run the MRX wallets were reported at 0 [#4849, #5013]. The chat does not say they were "wiped", and it does not explain the zero balance. Unlike TUSC or HIVE, MRX was not left waiting on Mike.

HONK: only 5.25B was recovered [#6750]. The keys went to the HONK developer [#6739, #6928-#6929], who was himself a claimant. He chose to pay the other claimants and absorb the shortfall himself, keeping about 1.5B left over, which was to be deducted from what Altilly owed him [#6760-#6761]. Nayiem said to put the lost HONK on the unsaved list and "deal with it once we have the funds" [#6752, #6754]. The chat does not show that debt being paid.

A QSLP / refund token was named as the planned instrument, but no specific replacement coin or fixed value was ever set.

**Nayiem's note:** The author's account (2026-09-30), checked against the chat: not every approved user got their saved assets back. In September 2021 some approved users were still unpaid [#7180, #7421], and the chat does not show whether they were all paid later. The planned refund token for unsaved assets was meant to trade on Altfenix [#5202, #6657-#6660]. The name "ALT2020" appears only once, in a question from Chuck that got no answer [#7208]; the token was never launched. The share of fees planned for claims was 25%, not the "about 50%" the author first remembered; 50% was for operations [#5535, #5882, #5883]. The author stopped refunds around 2022/2023, with only a handful after that. He estimates remaining unpaid claims at around $50,000–60,000. He says these are now nearly impossible to verify because chains are dead (including the old Qredit chain) and the database was lost, and that many late claims were fraudulent. He makes no promise of future refunds. Nayiem also says the saved assets that stayed unpaid were held up because Mike kept access to those wallets and never completed the sends, and that Mike's delays held back refunds more widely. For saved assets the chat largely supports this (see the next question). For non-saved assets it does not. Those wallets were lost, and the reason given at the time was a lack of funds: "We will deal with it once we have the funds" [#6754], "People don't understand that there are no funds." [#7407].

**Where this was asked:**

- [Reddit, r/altillyhack](https://old.reddit.com/r/altillyhack/comments/my9l2v/): "does anyone have any information about what they will be doing for the 'Non Saved' assets?"
- Chat [#6750] (forwarded from the HONK developer): "We recovered 5.25 billion honk. The rest was lost."
- Chat [#2344] (forwarded): "What coin do you offer to us for replace lost coin ?"

### Why were approved or 'saved' refunds still unpaid months or years later (TUSC approved in April, MRX, FARM), when the team itself admitted it was breaking promises?

**The critic is right**

The critic is right. The chat confirms the delays, and it shows the team knew about them. On 3 Apr 2021 Chuck said TUSC was "only partially saved", so it was on the non-saved list [#4877]. Mike answered "i have the keys to both wallets" and "1.5b total from my notes" [#4878], [#4880], and Chuck moved it back: "I will move it back to saved list" [#4885]. 45 TUSC users were counted [#4900]. The chat does not record a formal TUSC approval. On 20 Apr, TUSC had "not yet" been distributed [#4905-#4906]. On 1 Jul, Chuck said some assets had still not been paid in the first round [#6876], "about 14 of these assets" [#6877]. On 25 Aug Nayiem posted an image and called it "heartbreaking", and Chuck replied that it was "approved and ready to send" [#7377-#7379]. In September Chuck wrote "Weve made alot of promises we are not keeping" [#7421].

The chat gives partial reasons. The user database was gone, so users could not all be emailed [#5011]. Some saved wallets did not hold enough to cover refunds [#4651, #4663]. The MRX wallets read 0 [#4849].

The main reason the chat shows is that the keys for the unpaid saved coins were with Mike, and the chat does not show those sends being finished. He held the TUSC keys from December 2020 ("I have those keys saved in my browser" [#1781]; "yes" to having access to both wallets [#1796], [#1799]; [#4878]) and told Nayiem on 20 Apr that TUSC had "not yet" gone out [#4905-#4906]. He held the HIVE keys "on my computer" and said he would post balances, which the chat never shows him doing [#3916-#3918]. By June Chuck still did not know which servers held "Hive, Honk Xenios and TUSC" [#6724]. Mike said the COLX wallet held "like 100m" [#5914-#5915], and the chat records no COLX payout. He said he had moved the PYRK user funds "to community fund wallet awhile back" [#7096], and the chat records no PYRK payout. He put the cryptonote coins off until he could "write a program" [#4621], [#4875], and the RDD stragglers off until he could "go thru all from time to time" [#5956]. A later Moon send got no reply [#6880-#6881]. After the April batch [#4613-#4903], his later send reports in the chat are about Wrkz only: "I've sent many small transactions already but there's a lot left" in June [#6780], and "the dev got the whole thing" in October [#7570-#7571]. Chuck's last request, on 6 Sep, asked Mike to "hit 'all' the saved assets and get out whatever is pending" [#7421]. Mike had said he was "dealing with finishing up house stuff" [#7411], and the chat shows no reply from him about the saved assets.

Nayiem shares part of the blame. He held the Hetzner hosting account [#5656-#5658], and in June he was the one closing down the bare-metal servers that held the saved wallets [#6672-#6676]. In January he handled some refunds himself, including Goldcoin [#3215] and MRX [#3193], [#3492]. When Chuck pushed to clear the saved assets, he put refunds behind QSLP and other work: "Until we have qslp running properly with an interface" [#7052-#7053], "3-4 days" [#7144], and "Will put my focus on it really soon. I'm rushing to get some funds in" [#7181]. None of that excuses the rest. Dated promises were removed from the website and replaced with "as quickly as possible" [#3418-#3421]. After Nayiem said it would probably "take a few years" [#5012], Chuck offered to "drag it out forever" and "hang the carrot", and Nayiem replied "Go for it" [#5017-#5020]. A refund-token plan followed the next day [#5201-#5203], but Altfenix never launched. In May, Nayiem asked to put refund support on a two-week "holiday mode" so the team could work on Qredit Motion [#6035]. Chuck advised against telling users about any pause [#6036-#6037]. FARM does not appear in the chat. The record ends in October 2021.

**Nayiem's note:** The author's account: Nayiem says Mike kept access to the TUSC, HIVE and other unpaid saved-asset wallets and never completed those refunds, and that Mike kept delaying them. The chat supports this for the coins listed above. It also shows Nayiem's own deferrals. He stopped doing refunds around 2022/2023, with only a handful after that. He estimates the remaining unpaid claims at around $50,000–60,000 in total. He says they are nearly impossible to verify now, because the old chains no longer exist and the database is lost, and that many late claims were fake. He makes no promise of further payment.

**Where this was asked:**

- Chat [#7421]: "Weve made alot of promises we are not keeping and natives are starting to get very restless. Losing trust"
- Chat [#7377] (Discord screenshot): "I got approved since early April.. i need my Tusc Coin back"
- Nayiem's Follow-Up PDF (Feb 2025) (MRX, FARM and another asset never returned)

### If all customer funds were hacked, why does an Altilly wallet still hold a large Banano balance, while Banano holders remain unpaid more than a year after confirmation?

**The critic is partly right**

The management chat never mentions Banano. It cannot confirm whether the wallet named on Reddit belonged to Altilly, what balance it held, or whether Banano was on the saved list. Banano is not on the 87-name saved list Chuck posted on 26 Dec 2020 [#1457], but Mike said that list was incomplete ("wasn't there like 225 in the original list" [#1461]), and coins such as TUSC, HIVE and Xenios were added to it later [#1781], [#1833].

The chat does not show who held the Banano keys. It shows how the saved wallets were held in general. Mike kept the "safe" wallets on a VPS of his own [#1299] and said "i had keys outside of the db on a server i was using to store 'safer' wallets" [#1621]. On 3 Jan 2021 Nayiem asked "do we have an export of all private keys from these saved coins? @MrMike_O" [#2440-#2441]. Mike said he could "probably write a program to do that" [#2478], and the chat shows no export after that. For the other saved coins left unpaid, such as TUSC and HIVE, the keys were with Mike (see the previous question). On the other side, Nayiem held the Hetzner hosting account where the saved-wallet servers ran [#5656-#5658], [#6672-#6676]. The chat does not say whether a Banano wallet was on those servers. The chat also shows that the team had no up-to-date list of the assets Altilly held. After the hack the list was rebuilt from CoinGecko [#2210], and some coins were placed on the lists from memory [#7532]. What the chat does contradict is the idea that "all customer funds got hacked". From the start the team split assets into "saved" and "not saved" [#2211, #2439, #3445], and saved coins were paid out in kind through 2021, with Mike doing most of the sending [#6026, #7421]. By May 2021 Chuck said "most saved assets" had been refunded to approved users [#4966]. On the core complaint, though, the critic is right: saved assets stayed unpaid to users whose claims had already been approved. Chuck later wrote "We still have saved assets that have not been refunded to approved users" [#7180], said some had not had their first round sent [#6876, #7344], and warned "Weve made alot of promises we are not keeping" [#7421]. He also noted "thousands who were too late" for the claim form [#5052]. The team discussed plans to refund non-saved assets: tokens [#6807], a two-step process [#7209], and conversion sheets based on Dec 24-26 values [#7426]. The chat shows no such payment being made. After October 2021 the chat has nothing on what happened to the remaining wallets. Separately, a Bitcointalk thread from February 2022 also disputes the refunds.

**Nayiem's note:** The author's account: he stopped doing refunds around 2022/2023, with only a handful after that. He estimates the remaining unpaid claims at around $50,000–60,000, but says they are now nearly impossible to verify because many 2020-21 chains are dead and the user database was lost. He also says many late claims were fake. On Banano, Nayiem says Mike kept access to the Banano wallet and never completed the refund, and that this is why the Banano holders were not paid. The same, he says, goes for the other saved assets that stayed unpaid. The chat cannot confirm this for Banano, because Banano does not appear in it. It does support it for TUSC, HIVE, COLX, PYRK and others, where Mike held the keys and the sends were never reported. It also shows Nayiem putting refunds behind other work [#7052-#7053], [#7181]. He makes no promise of further payment.

**Where this was asked:**

- [Reddit, r/banano](https://old.reddit.com/r/banano/comments/10j6wjo/): "They said all customer funds got hacked a couple years ago... obviously not the banano they had"
- [Reddit, r/banano](https://old.reddit.com/r/banano/comments/10j6wjo/_/j5ivzku/): "They didn't backup their Banano seed. ... They still have not refunded Banano despite refund confirmations over a year ago."

### Why did project teams have to chase their coins? Examples include 500M TUSC in a marketing-partner wallet, QPSN and Qredit swaps, and CRFI before its hard fork. Why did saved coins go to developers rather than directly to users?

**The critic is partly right**

The chat explains the policy but backs up much of the complaint. The team chose to go "project by project", depending on which developers they trusted to "distribute fairly" [#2106]. The stated plan was to send low-value saved coins back to developers who agreed to distribute them, with Altilly handling the rest itself [#2765, #2769]. Chuck warned that developers must not "just collect it to use for something else" [#2770]. The chat shows handoffs to developers for BYND [#2149], HONK [#6760-#6761] and WRKZ [#7037-#7038]. There was some follow-up: BYND payouts were checked on-chain [#3224], and a deleted BYND claim was queried [#3192]. For MRX, a user complained that the MRX team was blocking them and asked to be paid directly [#3187]. Nayiem replied that MRX was "being paid directly to users" [#3193], but the chat does not confirm that this payment happened.

The critic is right that the process was opaque and short of funds. Chuck himself did not know which coins were being refunded [#2775]. The HONK developer was sent only enough to pay himself. He paid the other users out of it, and Altilly still owed him the difference [#6760-#6761]. Around the same time, assets were being moved to "unsaved" until "we have the funds" [#6754]. TUSC was briefly listed as only partly saved [#4877], then moved back to the saved list [#4885]. Mike held the keys to both TUSC wallets ("i have the keys to both wallets" [#4878]; see also [#1781], [#1799]). There were 45 claimants [#4900], and Mike told Nayiem it had "not yet" been distributed in April 2021 [#4905-#4906]. The chat shows no TUSC send after that. Nayiem says Mike kept access to the TUSC wallets and never completed the refund. The QPSN holder was told to "fill in the form" [#2448-#2449]. The chat never says whether the 500M TUSC marketing-partner claim [#2289] was repaid. By mid-2021 about 14 first-round assets were still unpaid [#6876-#6877], and Chuck wrote "Weve made alot of promises we are not keeping" [#7421]. The chat does not mention CRFI.

**Nayiem's note:** The author's account: not every approved user got their saved assets back; he says Mike kept access to the wallets of the saved assets that stayed unpaid and never completed those sends. Many refund chains from 2020-21, including the old Qredit chain, no longer exist, so transaction IDs often cannot be shown now. The author stopped doing refunds around 2022/2023. They estimate the unpaid claims left over at around $50,000–60,000, but these can no longer be verified.

**Where this was asked:**

- Chat [#2289, #2290] (forwarded from a project team): "There was 500 million TUSC in there. We'd just like those back."
- Chat [#3187-#3189] (forwarded): "Please dont give my MRX to the developers . Pay it to me ."
- Chat [#2775]: "I get asked 100 times a day which ones are being refunded now"

### Why did the claims process break down in practice: no confirmation emails, bouncing repay@altilly.com, and no refunds even after tx IDs were sent?

**The critic is partly right**

The critic is right that the process failed users. The chat explains part of why, but it does not excuse it. The Google Form sent no receipt of its own. Nayiem said: "People don't get a reply or automatic email after filling in the form. They will be contacted later" [#2181-#2182]. Chuck reported that many claimants said they got no confirmation. He also warned that many missed the instruction to send documents separately by email [#2179, #2191-#2192]. The repay@ Fastmail box was set up in a hurry on 28 Dec 2020, and it had a login mix-up between "replay" and "repay" [#1993-#2028]. On 2 Jan 2021, Hotmail and Yahoo users reported that mail to repay@ bounced. The bounce said the message was "blocked because it contains content identified as spam". Nayiem said the inbox was still receiving mail and that the problem was probably not on their side. Users were told to keep their screenshots and wait to be contacted [#2324-#2337]. Paying for the Fastmail account comes up again later, with a declined card and an updated card [#3229, #3946]. Later still, Chuck noted that replies bounced whenever the Freshdesk help desk was down [#7339]. A txid alone was not enough to get a refund. From February 2021 the team asked claimants for deposit-confirmation emails. Claims without one were marked invalid [#3965, #5867]. Checks were also uneven. Nayiem said he did not check claims of 50-200 USD at all. He relied on the end balance matching instead [#3558, #3563-#3566]. For non-saved assets, the chat shows plans: partially saved wallets were to be paid first come, first served until the funds ran out [#6023], and there was later talk of QSLP tokens and a two-step process [#6807, #7209-#7214]. It does not show any confirmed payouts for fully non-saved assets.

**Nayiem's note:** The author's account: fake claims surfaced in Freshdesk support tickets, not in this chat. People copied real txids that had been sent to Altilly wallets and faked the deposit emails. The Freshdesk account ran on the author's card from March 2021 [#4417]. It lapsed for lack of payment in mid-2021 [#6770-#6772] and was restored, then lapsed again in August [#7202, #7215]; the author says access was lost for good later, after the chat ends. The author says many 2020-21 refund chains no longer exist, so payout txids often cannot be shown now. The author stopped doing refunds around 2022-23 and makes no promises about the remaining claims.

**Where this was asked:**

- Chat [#2095, #2179]: "after we fill in form och send it, shall we recieve conformation Email that you have recieved our form ?"
- Chat [#2324, #2325] (forwarded): "repay@altilly.com the email always returns back"
- Chat [#3231] (forwarded): "I have beam deposit tx id sent to repay@altilly com, but not recieve refund"

### When would refunds actually happen? Did the promised April 2021 start ever take place, and why were users still asking in 2023?

**The critic is partly right**

Partly. The April start did happen, but only for saved assets. In February 2021 Chuck drafted an update for users saying that "the first refunds for saved assets should begin being sent during the first or second week in APRIL" [#4282] (see also [#3983, #4142]). On 1-3 April 2021, about 60 coins were marked "done" in the team chat, all by the account believed to be Mike [#4613-#4903]. On 1 May Chuck wrote that "most saved assets [were] now refunded to those who were approved" [#4966]. Further saved-asset and partially-saved-asset payments followed into June [#6023, #6779, #6780, #6910].

It was still far from complete. Thousands of users missed the claim form [#5052]. In July, some first-round assets were still unpaid, and a second round promised for July had not gone out [#6872, #6876]. In August approved users were still waiting [#7180]. In September Chuck wrote that "weve made alot of promises we are not keeping" [#7421]. That request was addressed to Mike, who held the keys for the unpaid saved coins such as TUSC and HIVE [#4878], [#3917]. The chat shows no reply from him about the saved assets, and after the April batch his only send reports concern Wrkz [#6780], [#7570-#7571]. Nayiem says Mike kept access to those wallets and never completed the refunds. Nayiem also put refunds behind other work when Chuck pushed [#7052-#7053], [#7144], [#7181].

For non-saved assets (BTC, ETH, USDT and others), the chat shows no payments. It shows only spreadsheets and a claim page [#7426, #7517], plus plans for a refund or QSLP token [#5201-#5203, #6807]. The chat also contains an exchange about stalling. Nayiem said the process would "take a few years" [#5012]. Chuck then offered: "I can drag it out forever if you want... Hang the carrot out front" [#5017-#5019], and Nayiem replied "Go for it." [#5020]. The refund-token plan followed the next day [#5201-#5203], but Altfenix never launched. Together these help explain why people were still asking in 2023. On this point the critics are largely right.

**Nayiem's note:** The author's account: he stopped processing refunds around 2022/2023 and made only a handful after that. He estimates the unpaid claims at around $50,000–60,000 in total, but says they are now nearly impossible to verify because chains have shut down (including the old Qredit chain) and the user database was lost. He also says many of the late claims were fake. No further refunds are promised. The chat cannot confirm any of this, because it effectively ends in October 2021.

**Where this was asked:**

- [Reddit, r/altillyhack](https://old.reddit.com/r/altillyhack/comments/my974f/): "Altilly claimed to start reimbursing funds on April. I am wondering if this has happened yet"
- Chat [#2714] (group screenshot): "Will it take six months for the users to pay or will they pay earlier?"
- [Bitcointalk](https://bitcointalk.org/index.php?topic=5166945.100): "So what about refunds?"

### Was refund KYC a way to pay out less? Why did the refund plan (saved coins or XQR tokens) keep changing, and why was a claimant told they were not wanted in the community?

**The critic is partly right**

The critic is right that the plan kept changing. Over roughly four months in 2021 the team floated several ideas for assets that were not saved. These were an "Altilly refund token" pegged to some value [#5201-#5203], a 25% share of fees from a new exchange [#5879-#5882], and QAE claim tokens that holders could sell at a discount, for example 50% [#6657]. Later came QSLP tokens for unsaved assets [#6807] and a verify-then-Motion-app process [#7209-#7211]. Even payouts of saved assets fell behind. In September 2021 Chuck wrote internally that "we need to hit 'all' the saved assets and get out whatever is pending before pushing anything else. Weve made alot of promises we are not keeping and natives are starting to get very restless. Losing trust" [#7421]. That message was addressed to Mike, who held the keys for the unpaid saved coins, and the chat shows no reply.

On KYC: Chuck once asked whether a complaining claimant was upset "because he wont KYC?" [#7380-#7383]. That suggests identity checks were being asked of claimants. The chat does not show KYC was chosen to cut payouts. The stated reason for checks was to "verify the claims are legit" [#7210], and Nayiem wrote that "there are no funds" [#7407]. Nobody can check that last statement from the chat alone.

On "not wanted in the community": the remark appears only in a screenshot of the claimant's own message, which Nayiem forwarded to the group [#7405]. In it the claimant writes "you said you don't want me in the community" and asks whether he will be paid "in saved coins or xqr". The chat has no record of the original statement. The same screenshot shows the claimant apologising some days later. Chuck also reported that the claimant threatened a lawyer unless paid immediately for a coin he had never claimed [#7399-#7403]. Internally, Nayiem twice called the claimant "a noob" [#7398, #7406]. When Chuck offered to write him "a detailed explanation what our plan is", Nayiem replied "Don't waste your time" [#7408-#7409]. Whatever the dispute was about, that dismissive handling supports the complaint.

**Nayiem's note:** The author's account: the checks and deadlines were a response to fake claims, where people copied real txids that sent coins to Altilly wallets and forged deposit emails. The chat shows fakes were expected early on [#1645, #1650, #1960], but it does not describe this particular method. The author also says refunds mostly stopped around 2022/23. By their estimate, around $50,000–60,000 in claims remain unpaid, and these can no longer be verified because the chains and the database are gone.

**Where this was asked:**

- Chat [#7417] (Telegram screenshot): "you did kyc because you knew that you would have to pay out less"
- Chat [#7405, #7399]: "will you pay me in saved coins or xqr? because you said you don't want me in the community"
- [Bitcointalk](https://bitcointalk.org/index.php?topic=5385112.0): "your entire so-called team consists of 2 people...Invite someone who understands this."

### Why didn't Altilly declare bankruptcy and face the authorities? Customers threatened Swedish, UK, EU and Interpol action and accused the company of blaming them.

**The critic is partly right**

The chat never explains why no bankruptcy or insolvency was filed, and none took place. Public Companies House records (outside the chat) show that the author's QREDIT LTD (13077371) filed no accounts and was struck off in May 2022, not wound up. The chat shows the author himself dismissing these threats. On 30 Dec 2020 Chuck forwarded a customer ticket that exists only as images [#2155-#2156]. The author (Nayiem) replied "What an idiot." and "Let him do his thing." [#2158-#2159], then "He can go to the swedish embassy. We are not incorporated in Sweden" [#2164]. He did not say where Altilly was incorporated. Chuck answered "Im not mentioning that to anyone", and the author said "Yea better not" and "Ignore him" [#2166-#2168]. Chuck then told the customer he would be refunded if he followed the website instructions [#2169]. The author posted a second threatening email [#2339]. A team member (Deleted Account) replied "people who actually do anything would not be sending an email like that" [#2340]. In June 2021 the author wrote "I like it when Altilly users are saying that they are going to sue me. Like it will give them their money back instantly." [#6386-#6387]. Chuck said users couldn't sue "for several reasons", and the author agreed [#6388-#6390]. In Sept 2021, when another user threatened a lawyer over $10,000, the author wrote "People don't understand that there are no funds." [#7399, #7407]. Lawyers come up once ("Lawyers are all on holiday", [#2183]), with no follow-up. The author said he would sue Cherry Servers [#2875]. No lawsuit appears, but a "Notice regarding liability" from Cherry Servers was shared in March 2021 [#4349-#4351], which shows the liability question was raised with them. The chat mentions police only about people at the author's property [#2380-#2471], not about reporting the hack. The critic is right on these points. We can't check the ticket's exact wording, including the bankruptcy demand and the "blaming customers" accusation, because it exists only as images.

**Nayiem's note:** In the author's account, Altilly itself was never registered as a company. Mike had promised the author would formally take it over once Qredit Ltd was set up, and the incident began 12 days after that company was formed. The author says Qredit Ltd never traded, because its XQR holdings sat on Altilly and were lost [#1732-#1733]. The author also says they paid refunds until about 2022/23, estimates the unpaid claims at around $50,000–60,000, and says these can no longer be verified. None of this is a legal explanation for why no insolvency process was started.

**Where this was asked:**

- Chat [#2155, #2156] (support-ticket screenshots): "we are hurt while you point out that it is the customers' fault. you must have the dignity to declare bankruptcy"
- Chat [#2339] (LinkedIn InMail screenshot): "to prevent any others actions with the Interpol Police and authorities in Sweden, United Kingdom and European Union"

## Deleted messages and transparency

### Why did admins delete refund questions, remove the Discord refund channel and tickets, and delete or ban people discussing a class action?

**The critic is partly right**

On deleting and banning, the critic is largely right. On 15 Feb 2021 Chuck was deleting messages about "you know what" (a class action) as soon as they appeared. Nayiem warned him that this "might trigger some other suspicious things" and said "you can delete those messages but don't ban the user for saying that word" [#3929-#3931]. Chuck replied that anyone promoting a class action "needs to be removed immediately or they will contact everone in the members list". Nayiem answered "yea I understand" [#3932-#3934]. Earlier, on 6 Jan 2021, Chuck removed a critic who had named Mike, together with the critic's friend. Nayiem approved the removal with a thumbs-up. He objected only to deleting the messages ("Don't delete the messages"), but Chuck had already deleted them [#2679-#2683]. On 28 Feb 2021 Chuck said the two people "making all the noise about class action" were on the refund sheets and that neither could produce a deposit confirmation email. Nayiem replied "No we dont refund them yet. Let me review them" [#4324-#4328]. Chuck later described the same two as "trying to recruit for class action suit" [#4853]. In May 2021 Chuck opened a separate refunds group to keep refund-seekers out of the ideas group. Nayiem said it "wasn't needed" and that Chuck "can just ban them instantly from the ideas group", but he accepted the new group once Chuck said it showed refunds were still going on [#5003-#5007]. The reasons stated in the chat are legal risk and how things looked: Chuck wanted to avoid a lawsuit and stop members being contacted, and Nayiem worried that instant deletions looked suspicious. The Discord example is weaker. In [#3191-#3192], from a screenshot, Chuck wrote that it "sounds like beyondcoin deleted this users request for refund". Nayiem asked him to find out why. Altilly's Discord #refunds channel was still active on 28 Jan 2021 [#3572]. The chat does not show it being removed later.

**Nayiem's note:** The author gives his own account: he had no admin rights in the group before September 2026, when Chuck transferred ownership [#7576-#7578], and like any member could delete only his own messages. His deletions in the published archive are limited to customer and third-party data, and he says so in [#7598]. His messages from 2021 are shown unedited, including [#3931] and [#5005].

**Where this was asked:**

- [Bitcointalk](https://bitcointalk.org/index.php?topic=5166945.80): "Admins delete my questions in the telegram."
- Chat [#3929-#3934, #2680-#2683]: "instantly deleting messages about 'you know what' might trigger some other suspicious things"
- Chat [#3191] (Discord screenshot): "They deleted my ticket and didn't return the coins. Also removed the Altilly channel in discord"

### Was public messaging shaped to mislead? For example, Mike instructed staff to say 'we have full control of our systems' while the loss was already being estimated.

**The critic is right**

On 24 December 2020 the critic is right, and no one in the chat comes out clean. That morning Nayiem asked Mike for "more details about the hack that happened" [#1031]. A message sent in Chuck's name said the attack may have come in through an insecure rescue port and that three machines were affected [#1033-#1034]. That evening Nayiem asked whether the loss was "really under 10k" [#1056]. Mike told the team to say "we are still investigating the outage, and we have full control of our systems" [#1057], then answered "might be 15" and "wont know for sure until i get everything moved" [#1059-#1060]. Nayiem and Chuck went along with the "outage" framing. Nayiem drafted wording, Chuck and Mike adjusted it ("frequent is not a good word", "just suspicious is fine"), and Nayiem agreed [#1072-#1075]. Chuck pointed out that the status page showed the missing assets, and Mike replied "ill fix that soon" [#1078-#1079]. Chuck then drafted a public post that called it an outage, said services were moving "to a more reliable source", and pointed users to the updated status page. Nayiem approved it [#1083-#1085]. So "fix" may have meant updating the page, not hiding it. The next day Nayiem pushed for disclosure: "it will backfire if we don't tell the truth" [#1163]. The notice he drafted and published said the servers had been "hacked above OS level" and that it was not yet known whether funds were lost [#1167, #1232]. While drafting it, Nayiem proposed saying "hackers were unable to access funds". Mike stopped this with "we don't know this" [#1180, #1183]. Later, at Chuck's request, Nayiem removed a dated section from a public text and rewrote it with no date ("as quickly as possible") [#3418-#3421]. On 28 December Chuck also asked for something to be taken down so that it would not be "put out there" [#1911-#1918]. The removed content is not visible in the export. The chat does not show who deleted the servers or what anyone intended.

**Nayiem's note:** The author's account: when the "full control" line was written on the evening of 24 December, he believed it. Mike had just put the loss at about 10k, "might be 15" [#1056]-[#1060], and the servers had not yet been deleted; that only became known the next afternoon [#1103]. Once it was clear that much more was gone, the public notice said it was not yet known whether funds were lost [#1232]. At the time he trusted Mike and saw him as family. His view that the "hack" was an inside job came later and is his belief, not a finding. He also says he has owned the channel only since 28 Sep 2026 and, before then, could delete only his own messages [#7576-#7578]. The unflattering 24 Dec messages have been left in the published export.

**Where this was asked:**

- Chat [#1056-#1060]: "Just tell them that we are still investigating the outage, and we have full control of our systems"

### Is the published chat export complete and unaltered, given that messages were deleted and commentary was added in 2026? Will Nayiem screen-record the original chats with timestamps instead of a Google Doc?

**The critic is partly right**

The critic is right that the export is not complete. There are two questions here, and we answer both.

The group chat. Nayiem got ownership of the group only on 28 Sep 2026 [#7576-#7578]. He then deleted messages, and said he did so to protect customer data, unrelated third parties and early management staff [#7598]. 663 message numbers are missing between the first and last message: about 130 before the incident, about 530 after it, and 1 in September 2026. The export cannot show which of these were removed in 2026 and which were removed earlier, by anyone. Some are probably service entries. Telegram also lets any member delete their own messages at any time, so the export cannot rule out earlier deletions by Nayiem or anyone else. The chat also contains later additions by Nayiem, sent as replies: a few in February 2025 [#7572-#7575] and a set of commentary in September 2026 [#7579-#7597]. Their dates make them easy to tell apart from the 2019-2021 messages, but they are interpretation, not evidence. Some of it is one-sided. For example, it calls Mike "Mike/Paul" [#7595], and that identification is Nayiem's belief, not something the chat proves. The export format has no edit markers at all, so it can neither prove nor rule out that surviving messages were edited. Our own assessment calls the record "single source, curated by an interested party". The original group stays private. This website is the redacted public copy, and the complete unredacted chat is available to law enforcement on request. The strongest independent check would be a full, hash-verified export from another member, such as Chuck, to compare against.

The screen recording. The Reddit question (14 Feb 2025) asked for a screen recording of Nayiem's private chats with Mike. Nayiem says Mike deleted that whole private chat for both sides, so it cannot be recorded or recovered. We cannot verify this. The only fragments left are screenshots Nayiem posted in the group in May 2021, for example [#5025] and [#5028]. Nothing in the chat commits to a screen recording.

**Nayiem's note:** Author's account: he says he had no admin rights before 28 Sep 2026 (like any member, he could delete only his own messages), and that he removed customer data before publishing. His 29 Sep 2026 announcement said customer and personal data would be redacted. He also says Mike deleted their entire private Telegram chat for both sides, so that chat cannot be recorded or recovered. Only screenshots posted in the group survive, for example [#5025] and [#5028]. In [#7588] he notes he kept a message that might look suspicious rather than remove it.

**Where this was asked:**

- Chat [#7576-#7590]
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ip0qha/): "Will you screen record and scroll through the actual messages between you and Mike which shows dates and timestamps rather than providing a google -hosted version"

### Whose device did the Discord screenshots in Nayiem's document come from? They show 'Nayiem' instead of 'You'. And why did he claim he needed ChatGPT when his chats show fluent English?

**Not in the chat**

The management chat cannot answer either point. Its regular conversation ends in October 2021 [#7571]. After that it has only a few messages from February 2025 [#7572-#7575] and notes Nayiem added in September 2026 before publishing the chat on this site. In one of those notes he says some messages were deleted to protect customer and third-party data [#7598]. The Discord screenshots are from November and December 2022, so they are not covered. The chat assessment lists "Screenshots not from Nayiem's device" as not addressed. One general point: in Discord, your own messages normally appear under your display name, not as "You", so seeing "Nayiem" does not by itself show the images came from someone else's device. It does not prove they came from his either. Only the original files or a screen recording of the live account would settle it, and neither has been published.

On ChatGPT, the critic has a fair point. Over several years, the chat shows Nayiem writing longer English messages clearly and at length (e.g. [#4032], [#5605], [#5634]). These messages also contain occasional non-native mistakes (e.g. "on our eind" in [#2331], "explain you more in details" in [#6807]), which fits his statement that English is not his first language. The ChatGPT claim itself does not appear in the chat. Writing casual chat messages is not the same as writing a formal public statement, but the chat gives no support for saying he needed ChatGPT to write English.

**Nayiem's note:** The author's account: the Discord screenshots from Nov-Dec 2022 are among the few surviving records of his private dealings with Mike. He says Mike deleted their private Telegram history with "delete for both". The author says he has these screenshots. His rewritten story says "English is not my first language" and that the 2025 write-up was written quickly and from memory. The evidence provided does not say whose device took the screenshots, and it does not include his explanation of the ChatGPT remark.

**Where this was asked:**

- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1iq9g6t/): "It would have said 'you' not Nayiem. So who's device and screen shots are these?"
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1iq9h5y/_/mcyf51p/): "It seems like Nayiem could write English perfectly fine without ChatGPT."

### Why does Nayiem's PDF contain errors: a December 2020 notice saying 'Xeggex was hacked', a mis-dated 'December 2022' heading, and conflicting timelines (12 Dec versus 23-24 Dec)?

**The critic is right**

The critic is right: the 2025 PDF has these errors, and the chat corrects them. The chat puts the start of the incident at about 23 December 2020, not 12 December. On 24 Dec, Chuck drafted a post to users that referred to "the past 24 hours since the outage occurred" [#1084]. That same morning Nayiem asked Mike for details about "the hack that happened" [#1031]. Two messages that Chuck forwarded in reply said the attack may have come in through an insecure rescue port at the host level, and that 3 machines were affected [#1033-#1034]. The exchange about losses ("Is it really under 10k Mike?" and the reply "might be 15" from the account addressed as Mike) happened on 24 Dec [#1056, #1059]. On 25 Dec the same account reported its belief that someone had hacked into the host's systems and deleted all the servers at Cherry Servers [#1103, #1106]. Nayiem drafted a public notice ([#1167], stamped 26.12.20 00:09). The final version was addressed to Altilly users and dated 26 Dec 2020, 01:25 CET [#1232]. It named Altilly, not Xeggex, and it did not promise refunds. It said "We are not sure yet if funds are lost." Nayiem had wanted to add that the hackers could not access funds [#1180]. His partners objected that this was not known [#1183, #1190], so the notice left the question open. The PDF's wording is a paraphrase that uses the wrong exchange name. The "December 2022" heading sits above text about Xeggex users losing funds, which refers to the February 2025 collapse. On timing: according to Companies House (a public record outside the chat), Qredit Ltd was incorporated on 11 Dec 2020. The PDF's phrase "twelve days after forming the company" is therefore roughly consistent with an incident around 23 Dec. The chat has no messages from 2 to 18 Dec 2020, and the author says the "12 December" date was probably a mix-up with the incorporation date. The author says he wrote the PDF from memory in February 2025. This site's timeline follows the dated chat messages rather than the PDF.

**Nayiem's note:** The author's account: the PDF was written from memory in February 2025, and a note at the top says ChatGPT was used for readability because the author is not a native English speaker. The author says "12 December" was probably a mix-up with the company's incorporation date (11 Dec 2020), and that the "twelve days after" timing was correct.

**Where this was asked:**

- Nayiem's Follow-Up PDF (Feb 2025)

### Why did Nayiem's February 2025 livestream disappear, is there a recording, and did it show that the speaker is not Mike or Karl?

**Not in the chat**

The Telegram chat can't answer this. Most of it is the management group from July 2019 to 2021. It also has a few messages from February 2025 [#7572-#7575] and notes the author added on 27–29 Sep 2026 [#7576-#7598]. It never mentions this livestream. We found no recording, archive or transcript of the stream in any of the material we reviewed. So we can't say why it came down, whether a copy exists, or what it showed about who was speaking. The Reddit claim that the stream "confirms that Mike/Karl is not the person speaking" is still unverified either way.

In the chat, "Mike" (@MrMike_O) and Nayiem post from separate accounts. For example, Nayiem addresses @MrMike_O directly [#190], and other members tag both of them side by side [#214]. Separate accounts don't prove separate people, though, and nothing in the chat identifies a voice from a video.

Readers should know that the author's own 2026 notes in the chat say that "Mike" is Paul Vernon ([#7585], [#7587]). That is Nayiem's assertion, not independent evidence. Based on the sources we reviewed (Rekt News, 5 Mar 2025; the Quadriga wiki), the wider claim Karl = Mike = Paul Vernon has not been publicly backed up or proven in court, as far as we could find.

The critics have a fair point here: a public stream that disappears without explanation is a real gap in transparency. Only the people who ran it can close that gap.

**Where this was asked:**

- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ivmmns/): "what happened to the nayiem and [host] livestream I can't find it."
- [Reddit, r/XeggeX_Victims](https://old.reddit.com/r/XeggeX_Victims/comments/1lx6xie/_/n2n0t3o/): "Do you or anyone else have a recording of the livestream, or is there an archived version available?"
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ikt45d/_/mbu241g/): "the stream confirms that Mike/Karl is not the person speaking in the stream... is this the case?"

### Who controls altilly.com? Why is its WHOIS private, why did it redirect to Google and later to Nayiem's Reddit post, and who was the previous owner?

**Partly answered**

The chat covers only 2020-2021. It does not explain the current WHOIS privacy, who controls the domain today, or who set up the redirect to Reddit.

On 25 Dec 2020 Mike offered to point altilly.com at Nayiem's temporary server [#1173, #1181]. He then repointed the domain's Cloudflare DNS to Nayiem's IP [#1206, #1215]. That evening Nayiem posted a public notice, which the team had drafted together. It said the team had "lost access to... the domain" along with servers, wallets and code [#1232]. The chat does not bear out the domain part of that claim, because the team clearly still controlled altilly.com's DNS. The notice may have meant the compromised accounts at the old hosting provider [#1504-#1513], but as worded it does not match the chat. On 26 Dec Mike said he had set up the hosting account "3 years ago" [#1504], which is consistent with the domain's 2017 creation date. No message names the domain's registrant.

In June 2021 Mike suggested redirecting the altilly domain. Chuck objected that the information about the hack would then disappear, and Nayiem agreed not to do it [#6661-#6666].

On 23 Jul 2021 Chuck passed on a user's question about why altilly.com was redirecting to Google, and asked the same himself [#7114-#7115]. Nayiem said only he and Mike had DNS access, and at first said he believed Mike had changed it on purpose [#7119]. After checking the Cloudflare audit log he withdrew that. He said he had himself deleted qae.altilly.com, which he believed the site was running on [#7120-#7123]. About an hour later he reported it "fixed" and then "sort of" [#7124-#7125]. By then users in the refund group were already remarking on it [#7126]. This explanation is Nayiem's own account in the chat and has not been independently verified.

Public WHOIS shows altilly.com was created in 2017 and is registered at Namecheap. The registrant is not shown, then or now. The author says the domain was handed over through Namecheap in Dec 2022, but that rests only on his own screenshot and is unverified. On this point the critic is right. The site does not document who owned the domain before, who controls it today, or who set up the Reddit redirect, and it should say so plainly.

**Nayiem's note:** The author says (in the Feb 2025 PDF) that Mike handed the Altilly.com domain over through Namecheap in Dec 2022, and a Discord screenshot is offered as support. Our checks could not independently confirm this. Namecheap as the registrar does match the public WHOIS.

**Where this was asked:**

- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ip0qha/): "Why don't you show us who the previous domain owner actually was."
- Reddit (post on a private user's profile; link and username left out): "Altilly.com redirects to this post."
- Chat [#7114] (forwarded): "why is altilly name redirecting to google?"

### Is Nayiem's whole account a lie? Critics note that CEOs don't fix databases, CoinEx developers were helping XeggeX, and his Reddit account had no history.

**Partly answered**

The chat record is inconsistent with the claim that Nayiem's whole account is a lie, but it does not settle the question. A separate account, apparently Mike's, acts as the developer throughout. Chuck greets @MrMike_O [#17], and from then on a user now shown as "Deleted Account" talks about releasing code [#22-#23] and fixing withdrawals [#792]. Nayiem addresses this account as "Mike" and it answers [#1056, #1059]. Chuck also asks @MrMike_O whether the data is lost [#1160]. Matching @MrMike_O to "Deleted Account" is an inference from context, because Telegram hides deleted usernames.

On 26 Dec 2020 Nayiem said he "never had access to those servers" because "Mike didn't allow me" [#1492-#1493]. The database point cuts both ways. Nayiem did not run the database before the loss [#6557]. In June 2021 he was root on the server but could not reach the database [#6519], and he later moved the v1 database credentials into v2 [#6597], so he did some hands-on work.

There is also counter-evidence on honesty. On 24 Dec 2020 Mike suggested telling users "we are still investigating the outage, and we have full control of our systems" [#1057], and Nayiem helped draft that message [#1072]. Nothing in the evidence mentions CoinEx developers helping XeggeX, and the chat cannot show why his Reddit account had no history.

On transparency, the critic has a fair point: the record comes from one interested party. Nayiem took ownership of the channel in Sep 2026 [#7576-#7578] and has deleted messages [#7598], and there are gaps at sensitive points [#1055-#1070, #1323-#1333]. At the time, Chuck removed a critic from the group [#2679-#2680]. Nayiem approved the removal [#2681] but asked Chuck not to delete the messages [#2682]. Chuck deleted them anyway [#2683].

**Nayiem's note:** Author's account: messages were deleted to remove customer data and details of third parties [#7598], and he had no admin rights before 28 Sep 2026 [#7576-#7578], so he could delete only his own messages. He says Mike deleted their whole private Telegram history with "delete for both". He also says that after his 2025 Reddit statement people came to his properties and he moved house, which he gives as context for posting from a new, low-profile account.

**Where this was asked:**

- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ikt45d/_/mbqe8tg/): "Now let me tell you why everything you wrote here is a lie. ... Your reddit account has no activity whatsoever."

## Xeggex and Dokdo

### Was XeggeX a restart of Altilly by the same people, possibly funded with Altilly users' stolen altcoins and sharing Altilly's back end?

**Partly answered**

The chat runs from July 2019 to October 2021, before XeggeX existed, and never mentions it, so it cannot settle this question. It does show that Mike (shown as "Deleted Account") built and ran Altilly's technical side: the servers, the backups, the "safe" wallets and the encryption config [#1271, #1299, #1353, #1504]. Companies House lists a director registered as Michael O'Sullivan for Xeggex Software Services Ltd ([Companies House](https://find-and-update.company-information.service.gov.uk/company/14910559/officers)). Critics say this is the same Mike, and the name matches the one he is reported to have used. The chat never gives Mike's surname, though, so this link comes from public records and the author's own account, not from the chat.

The chat also shows that a restart was discussed, and the author was part of it. In May 2021 the group drafted an announcement asking users "what would you guys feel, if we would start another exchange?" [#5023]. Nayiem and Mike then planned a new exchange called "Altfenix", with Mike working on the back end [#5235, #5257, #5531]. Chuck asked whether its profits should go toward repaying the assets that were not saved [#5878]. He also warned that it could be seen "as just a way to get assets back" [#6667]. The chat does not show that Altfenix ever launched, or that it is connected to XeggeX.

On the back end: the public notice of 26 December 2020 said Altilly's "whole codebase" was lost [#1232]. In the chat, however, Mike says the code was in a private GitHub repo [#1521], and in May 2021 he says "All the code is saved. But the data populating those isn't" [#5316]. So Altilly's source code survived and could have been reused. The claim that XeggeX actually shares Altilly's back end comes from community investigators (a cpuchain.org page, now returning 403) and could not be verified. Nothing in the chat or in public records shows that XeggeX was funded with lost Altilly coins, so that is unproven either way. Rekt News (5 Mar 2025) points out that both exchanges gave a similar story when they failed (a compromised host, then a recovery that dragged on), but that is a pattern, not proof. Wayback snapshots from 2022 show XeggeX labelled "a service of Dokdo Global", so the author was also publicly linked to it for a time.

**Nayiem's note:** In the author's own account, Mike proposed in 2022 that they work on XeggeX together and approach its supposed owner "Karl". The author announced publicly that Dokdo would acquire XeggeX. Around November 2022 the author came to believe that Mike ran XeggeX himself and that "Karl" never existed, and the acquisition was cancelled. The author admits they did not warn XeggeX users until February 2025. Their reasons were that they expected not to be believed and wanted no further association. Their view that Mike took the Altilly funds is a belief, not something the chat shows.

**Where this was asked:**

- [Reddit, r/PRCYCoin](https://old.reddit.com/r/PRCYCoin/comments/snr1wk/): "We know the people behind Xeggex. long story short, its a sort of restart of Altilly."
- [Reddit, r/kaspa](https://old.reddit.com/r/kaspa/comments/11mjzyk/_/jbo7ng1/): "Xeggex is built by the same person that created Altilly."
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ik58q6/_/mbjpllt/): "Pretty sure Altilly stole my 5k in alts and created Xeggex"

### Is Nayiem actually 'Karl', XeggeX's CEO or real owner, repeating the Altilly rug? Should any investigation start with him?

**The critic is partly right**

The chat can't settle this. It covers July 2019 to October 2021, plus later notes Nayiem added in 2025 and 2026, and it never mentions Xeggex, Karl or Dokdo. Public records answer part of the question. No source we found shows that Nayiem was Karl, Xeggex's CEO or its owner. UK Companies House lists a different person as sole director and majority owner of Xeggex Software Services Ltd (2023-24). The official Xeggex GitHub organisation has a 2024 commit from the account of Altilly's developer "MikeO", not from Nayiem. xeggex.com was registered in August 2021.

That date needs context, and it does not clear Nayiem. In mid-2021 the chat shows Nayiem, then acting as CEO, still working with Mike on a successor exchange. In May 2021 they planned an exchange called "Altfenix" [#5235, #5605]. In August 2021 Nayiem asked Mike about running two exchanges with shared liquidity [#7275], and Mike replied that "the system is being setup so you can have multiple frontend exchanges already" [#7293]. In September 2021 there was talk of "new projects" and a "new dashboard" [#7386, #7389]. None of these messages names Xeggex. They do show that the two men were still building exchange software together when the domain was registered.

The critic also has a point about what came later. In 2022 Nayiem publicly announced that Dokdo would acquire Xeggex, and archived copies of the site from that year say "a service of Dokdo Global". By his own account, from late 2022 he believed Mike ran Xeggex and did not warn its users until February 2025. That makes him a fair person to question and a necessary witness. Nothing we found shows that he was the operator. We are not aware of any court or authority that has named anyone as Xeggex's operator.

**Nayiem's note:** The author's account: in 2022 Mike proposed that they work on Xeggex together and approach "Karl", and Nayiem announced the Dokdo acquisition. Around November 2022 he says he found out that "Karl" never existed and that Mike was running Xeggex himself, so he cancelled the deal. He stayed silent until February 2025 because he did not want his project at the time linked to that person, and because he expected not to be believed. He says the Reddit reactions to his 2025 disclosure bore that out. No screenshots of the GitHub "Karl" episode exist.

**Where this was asked:**

- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1iisdmd/): "The CEO with the name of 'Karl' has been found to be an individual by the name Nayiem Willems. He has previously rugged a different exchange"
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ikmh65/_/mbny38b/): "How do we know for a fact Nayiem is the CEO of Xeggex?"
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1iufb0c/_/mdynizd/): "Nayiem Willems. This is who we start with because we know he is involved."

### Dokdo's website listed XeggeX as its product, and XeggeX announced its acquisition by Dokdo. How is that 'no connection'? And if Altilly traumatised him, why did Nayiem take on another exchange?

**The critic is partly right**

On the Dokdo link, the critic is right. There was a public connection, and the author does not deny it. Wayback snapshots from 6 Jun 2022 and Sep–Dec 2022 show XeggeX described as "a service of Dokdo Global". So in 2022 it was presented publicly as a Dokdo service, not only as a planned acquisition, and the author himself announced the Dokdo acquisition. The author says the plan was later cancelled. If that is so, "no connection" can apply at most to the period after the cancellation. It does not apply to 2022. (These snapshots are external records, not part of the chat.)

The Telegram chat cannot settle the XeggeX question. It runs from Jul 2019 to Oct 2021, with annotations the author added in 2025–2026, and it never mentions XeggeX, Dokdo or "Karl". External public records show xeggex.com was registered on 31 Aug 2021 and the xeggex GitHub org was created on 20 Sep 2021, both before the 2022 acquisition talks. They also show the mrmikeo GitHub account had commit access to the Xeggex org in 2024. This fits the author's claim that Mike, not a separate "Karl", was behind XeggeX, but it does not prove it.

On "why take on another exchange after Altilly", the chat is relevant, and it does not simply support the trauma framing. In May 2021, about five months after Altilly went down, the group discussed starting "another exchange" [#5023]. Nayiem actively drove the idea: "think about the product and new exchange" [#5200], "I got the new domain for the exchange" [#5228], and plans for an invite-only exchange called Altfenix [#5599] [#5605]. In Aug–Sep 2021, Nayiem was still working on an exchange system with Mike. He asked @MrMike_O about running several exchanges [#7275]. A reply from a now-deleted account said "the system is being setup so you can have multiple frontend exchanges" [#7293]. Nayiem also wrote "people have their own private key on the exchange" [#7476] and "I need a week or so to discuss this with Mike" [#7480]. The chat shows the author still trusted Mike closely and was building a new exchange with him in 2021. It does not show whether this project was XeggeX.

**Nayiem's note:** The author's account: Mike suggested they work on XeggeX together and approach its operator, "Karl". That is why the author announced the Dokdo acquisition. The author says that around Nov 2022, when the Solar SXP theft happened, he concluded that Mike ran XeggeX himself and that "Karl" did not exist, and he then cancelled the acquisition. On why he took on another exchange after Altilly: he says he still saw Mike as "family" and was "too naive" to suspect him. He admits that from late 2022 he believed Mike ran XeggeX and did not warn its users for more than two years. His reason was that he expected nobody would believe him. He says that after the business relationship ended in late 2022, his only contact with Mike was about getting money back.

**Where this was asked:**

- [Reddit, r/XeggeX_Victims](https://old.reddit.com/r/XeggeX_Victims/comments/1lx6xie/): "Dokdo's website ... explicitly listed the XeggeX exchange and the XeggeX wallet as their products. Likewise, the website of XEGGEX.com announced the acquisition by Dokdo"
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ip0qha/): "If you were so 'traumatized' by Altilly, why were you so easily convinced to take over another exchange?"
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1immi9m/_/mc4a39b/): "Nayiem said he had no involvement with Xeggex since 2022 but that's a lie"

### Did Nayiem write XeggeX's statement clearing him himself? Why would XeggeX clear him but never say who Karl is, and why do earlier XeggeX posts read like his writing?

**Not in the chat**

The chat can't settle this. Its regular messages end in October 2021 [#7571]. After that there are only a few short replies from Nayiem in February 2025 [#7572] [#7574] [#7575] and his own notes added in September 2026 [#7576-#7598]. None of these mention XeggeX or "Karl", so the chat can't show who wrote any XeggeX post. One point to be open about: on 8–9 February 2025, the same month as the first XeggeX statement we found, Nayiem replied to several old messages from Mike ("Thank you Mike", "Thanks again") [#7572] [#7575]. Those replies say nothing about XeggeX or its statements. They neither support nor rule out the claim that he wrote one. Our materials don't include the statement that cleared Nayiem, and nobody has run a writing-style comparison. That means we can neither confirm nor rule out the claim that he wrote it. The critics have a fair reason to ask: Wayback snapshots from 2022 show XeggeX as "a service of Dokdo Global", Nayiem publicly announced a planned Dokdo takeover, and he did not warn XeggeX users for more than two years. On "who is Karl": the XeggeX statements we found (February and June 2025) never address who ran it. Public records instead link the developer "MikeO" to XeggeX: a GitHub commit to the xeggex organisation (1 Apr 2024) and a UK company director listing. Those records are verifiable, but they don't show who wrote any post. Nayiem's 2026 notes in the chat call Mike "Mike/Paul". That is his own claim, not independent evidence. Rekt, Warthog and Plisio all describe "Karl = Paul Vernon" as an unproven community allegation.

**Nayiem's note:** In Nayiem's account, Mike brought him "Karl from XeggeX" in early 2022. Dokdo's takeover was dropped around November 2022, when Nayiem came to believe that Mike ran XeggeX and that "Karl" never existed. On 3 December 2022 he agreed that the Dokdo references could be removed. He says he had no role at XeggeX after that. He has not directly addressed the claim that he wrote the clearing statement.

**Where this was asked:**

- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1inxb8g/_/mcgmuk9/): "Nayiem most likely wrote this himself. ... Why wouldn't they just say who Karl was?"
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1inxb8g/_/mcgul9r/): "some previous posts from Xeggex displayed the same writing patterns as Nayiem."
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1itk65d/_/mdsd1kv/): "Hehe because HE wrote that message."

### Was XeggeX's 'CEO Telegram/laptop hacked, database corrupted, funds are safe' story true, given orderly hot-wallet outflows on 2-3 February 2025 and Karl moving funds to MEXC 'for safekeeping'?

**The critic is partly right**

The Telegram chat cannot answer this. Most of it runs from July 2019 to October 2021. The only later messages are a few short replies from 8-9 February 2025 and the author's notes from September 2026, and none of them mention XeggeX. Public sources support the critic's doubts. XeggeX halted on 3 February 2025, blaming a hacked CEO laptop or Telegram account and a corrupted database. Rekt News (5 March 2025) cites Bitrace and Arkham, and screenshots shared by Salvium and Nerva, showing orderly outflows of USDC, USDT, ETH and BNB from the hot wallets on 2-3 February. Rekt and other critics read that pattern as a planned drain, not a sudden hack. We have not checked the raw transfers ourselves. The "funds are safe" line also did not hold. User balances were later replaced with IOU tokens (BTCXX, ETHXX, USDTXX), and on 27 June 2025 XeggeX announced closure and bankruptcy. No court filing has been made public. We found no primary source for Karl's reported "moved to MEXC for safekeeping" remark, so it is unverified. No authority has found the hack story false. The evidence makes it hard to believe, but it does not prove it untrue.

**Nayiem's note:** The author's account: around November 2022 the author came to believe that Mike ran XeggeX himself and that "Karl" never existed, so the planned Dokdo acquisition of XeggeX was cancelled. The author did not warn XeggeX users until February 2025. The reason the author gives is that people were expected not to believe it (and later did not). The author says that after the business relationship ended in late 2022, the only contact with Mike was about getting money back. The author has no first-hand knowledge of what happened at XeggeX in February 2025.

**Where this was asked:**

- [plisio.net](https://plisio.net/profiles/xeggex-exchange)
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ikb3ia/): "XeggeX blocked logins and withdrawals, citing a database issue. They claim 'funds are safe,' but offer no real proof."
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1iic1wh/_/mb5g86m/): "he admitted to MOVING FUNDS TO MEXC in the name of 'Safe keeping'"

### Where did XeggeX's assets go? Questions cover the Arkham-tracked wallets, PEP moved to other exchanges, balances replaced with IOU tokens (BTCXX/ETHXX/USDTXX), and whether volume was manipulated.

**Not in the chat**

The Telegram chat can't answer this. The main discussion runs from July 2019 to October 2021 and never mentions XeggeX. The author added a few short replies to old messages in February 2025 [#7572-#7575] and comments in September 2026, and none of these mention XeggeX either. XeggeX collapsed in February 2025. What is public: Rekt News ("Plant a Red Flag", 5 Mar 2025) reported orderly outflows of USDC, USDT, ETH and BNB from XeggeX hot wallets on 2-3 Feb 2025, before the "hack" announcement, citing Bitrace and Arkham. It listed an ETH address, a TRON address and a Pepe wallet that stayed active. We could not check the raw transfers ourselves and did no on-chain tracing of our own. Reports say user BTC/ETH/USDT balances were swapped for IOU tokens (BTCXX/ETHXX/USDTXX). We found no source for the claim that these later lost more than 80%. The ~$80M and ~12,000-user figures were never audited. We found no source showing where the PEP ended up or that trading volume was faked. The critics are right that these assets have never been accounted for, and we found no public record of any court or authority tracing them. Nothing we reviewed links the author to these wallets, though we did not trace the wallets independently. By the author's account, backed by 2022 Wayback snapshots, Dokdo's planned purchase of XeggeX was announced publicly in 2022 and then cancelled.

**Nayiem's note:** The author's account: Mike suggested that he and the author approach XeggeX's supposed owner, "Karl". The author then announced publicly that Dokdo would buy XeggeX; Wayback snapshots from 2022 show "a service of Dokdo Global". Around November 2022, the author concluded that Mike ran XeggeX himself and that "Karl" did not exist. He cancelled the deal, and the business relationship ended in late 2022. After that he stayed in contact with Mike only to get money back: the Solar funds, repaid in full by 19 March 2024, and later a promise Mike made to fund the remaining Altilly refunds for non-saved assets and to pay Chuck, which Mike never followed up on. He did not warn XeggeX users until February 2025. He admits this and says he expected people not to believe him. He says he had no role in XeggeX's wallets or its collapse.

**Where this was asked:**

- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1imsux4/_/mc5hyjx/): "End point for the recent XeggeX assets. This is just 1 wallet. (There are many)"
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ip0qha/_/mcp5enk/): "I think nayiem or whoever is running xeggex is transferring pep to other exchanges to sell."
- [rekt.news](https://rekt.news/plant-a-red-flag)

### Why is Michael O'Sullivan the director of XeggeX Software Services? Why was it incorporated in 2023 when XeggeX launched in 2021, and dissolved on 31 December 2024, just before the collapse?

**Partly answered**

The Reddit commenters have the dates right. UK Companies House shows XEGGEX SOFTWARE SERVICES LTD (14910559) was incorporated on 2 Jun 2023 and dissolved by compulsory strike-off on 31 Dec 2024. Companies House usually strikes a company off like this for administrative reasons, such as not filing, and the register does not show that the dissolution was timed to the collapse. From incorporation until 1 Mar 2024 the register lists a director named "JOHN, Michael Osullivan", recorded as Polish and living in England. From 1 Mar 2024 it lists "OSULLIVAN, Michael John", recorded as a citizen of Vanuatu living in China, who was also registered as a person with significant control. A second company, XGX SOFTWARE LTD (15572800), was incorporated on 18 Mar 2024 and dissolved on 26 Aug 2025. It lists "OSULLIVAN, Michael John", recorded there as Ecuadorean, as director and secretary. When these companies were filed, Companies House did not verify identities. The register shows only what the filer declared, and the differing name orders, nationalities and birth months are unexplained.

On timing: the xeggex.com domain was registered on 31 Aug 2021, so the UK company came about two years after the exchange launched. In 2022 the Xeggex website described the exchange as "a service of Dokdo Global, Dokdo, UAB". Dokdo was the author's company, during the planned acquisition described below. We found no public record of which legal entity, if any, operated Xeggex after that acquisition was dropped and before the UK company was formed.

The chat cannot explain why the company was formed or dissolved, because it ends in 2021. It does show that the Altilly team member "Mike" used the name Michael Osullivan. A support ticket he posted opens "Hi Michael" [#3288], and he shared a whitepaper cover signed "Michael Osullivan @MrMikeO" [#5529]. Separately, on 1 Apr 2024 the GitHub account mrmikeo, which was used for Altilly development, made a commit to Xeggex's official xeggex/hummingbot repository. It was a routine sync merge, but it required write access. This makes it likely, but does not prove, that the director listed on the register is the same person as Mike. Nothing in the public record we found shows that this person is Paul Vernon.

**Nayiem's note:** The author's account: Mike proposed that they approach "Karl" together so that Dokdo could acquire Xeggex. Around Nov 2022, the author concluded that Mike was running Xeggex himself, that "Karl" never existed, and that Mike was Paul Vernon. The author then cancelled the Dokdo acquisition. The author admits they did not warn Xeggex users until Feb 2025. They say this was because they expected people not to believe them. They say that after the business relationship ended in late 2022, their only contact with him was about getting money back. All of this is the author's belief and has not been independently established.

**Where this was asked:**

- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ik58q6/_/mbkz0z0/): "Xeggex dissolved on companies house December 31st 2024. ... This is the KO punch"
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ik58q6/_/mbl5n2t/): "The odd part is the incorporated date of 23 when Xeggex launched in 21."

### Does Nayiem own NonKYC, which shares XeggeX's codebase and design while denying any relationship? Did he personally delist PEP there after being insulted?

**Not in the chat**

The chat can't settle this. The Telegram group covers 2019 to 2021. It has only a few later messages, from 2025 [#7572-#7575] and 2026 [#7576-#7598], and none of them mention NonKYC, Pepecoin (PEP), a Discord insult or a delisting. Nothing in the chat or our analysis files shows who owns NonKYC, and nothing links Nayiem to it. We found no evidence either way, so we won't claim a denial or a confirmation.

The only NonKYC item we found is a GitHub account called "NonKYCDev". On 22 Dec 2024 it synced one branch of Xeggex's public hummingbot fork (github.com/xeggex/hummingbot). Hummingbot is an open-source trading-bot framework, not the exchange's own code, and anyone can sync a public fork. So this doesn't show a shared exchange codebase. It also doesn't show who runs either exchange, and it doesn't point to Nayiem.

We have no record of a PEP delisting or of who made that decision. The "called him fat, then he delisted" comment is an anonymous claim with nothing to back it up. We can't rule out the shared-codebase claim, but we have no evidence of our own for it. On ownership and the delisting, this question is still open.

**Where this was asked:**

- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ip0qha/_/mcp6quh/): "Xeggex and noKyc are not related in any way... BUT they share the same codebase..."
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1indj80/_/mcaz02j/): "making accusations that they are in on what happened to xeggex and that nayiem owns non kyc."
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1indj80/_/mcalf8c/): "I called Nayiem fat in the Discord then he delisted Pepe."

### Is the XeggeX account-recovery effort run by Nayiem's team, with a Discord helper talking to 'Karl' and fake accounts claiming recoveries? Why was PEP refunded first, and was there a deal with the PEP side?

**Not in the chat**

The team chat runs from July 2019 to October 2021. Nayiem added a few notes to it later, in February 2025 and September 2026. We searched all of it, including those later notes, and found no messages about XeggeX, Dokdo, a 2025 recovery helper, "Karl" or a PEP refund. The only "pepe" hit is from November 2020, when Chuck says community members are unhappy about a third party [#975]. It has nothing to do with PEP or XeggeX. The chat does not tell us who runs the recovery effort, whether the accounts claiming recoveries are fake, or whether there was a deal with the PEP side. We therefore make no claim either way.

Outside the chat, the public record has one related detail. Rekt News ("Plant a Red Flag", 5 Mar 2025) reports that a XeggeX Pepe wallet stayed active after the halt. That alone does not show a deal.

The critic is partly right on one point. XeggeX was publicly linked to Nayiem in 2022. Wayback snapshots from June to December 2022 show the site describing itself as "a service of Dokdo Global". Readers can reasonably take that to mean Dokdo operated XeggeX, or at least presented itself as the operator, during that period. Nayiem says the link came from a planned Dokdo acquisition that he later cancelled; see the author note. No independent source confirms or rules out that account. Whether "Karl" existed is still disputed, and no public source has settled it.

**Nayiem's note:** This is Nayiem's account, and the chat does not cover it. He says Mike suggested they work on XeggeX together and approach "Karl", and Nayiem then announced that Dokdo would acquire XeggeX. Around November 2022, he says, he found out that Mike was running XeggeX himself and that "Karl" did not exist, and he cancelled the acquisition. He says he had no role in XeggeX after that, including the 2025 recovery effort. He admits he did not warn XeggeX users until February 2025, and gives his reasons in the story.

**Where this was asked:**

- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1iudck5/_/me3s9im/): "Because [recovery helper] is Nayiem and team.  There is no Karl."
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ip0qha/_/mdbpev1/): "pepe is the only coin that gets refunded asap ... they made a deal with xeggex"
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1iudck5/_/mdy1786/): "No one has recovered their accounts. Anyone claiming so in on the scam."

### Is Nayiem involved with Pepecoin (PEP)? Critics point to his closeness with the PEP developer and to solar.org and pepecoin.org sharing a layout and font.

**Not in the chat**

The evidence can't answer this either way. The chat is the Altilly management chat, mostly from 2019 to 2021, and it never mentions Pepecoin or its developer. The author added some annotations in 2025-2026, and those don't mention Pepecoin either. The only "pepe" in the chat, [#975], is a 2020 remark in a discussion about faucets, three years before Pepecoin launched. Pepecoin appears in the research files only as context. The research notes say Rekt News, citing Bitrace and Arkham, listed a Pepe wallet that stayed active among the addresses tied to the Xeggex collapse. Nothing we reviewed links Nayiem to PEP's development, funds or governance, and nothing we reviewed rules it out.

The site-similarity argument is weak. Solar's site does use Nunito, but Nunito is a free Google Fonts typeface that many unrelated sites use, so a shared font says very little about who runs a project. We did not compare the two page layouts in detail, and a similar layout would be just as weak a signal. Contact or friendship with a developer is also not evidence of involvement. On the other hand, Nayiem has not given a full public account of how he relates to the PEP developer, so critics are right that a clear statement would help. The author's own account of how the contact started is below.

**Nayiem's note:** The author's account: in February 2025, after the Xeggex halt, a member of the Pepecoin community invited him onto a livestream. He spoke for about two hours about what he knew from working with Mike at Altilly, and about why he suspected a link to the Cryptsy history. No authority has confirmed that suspicion. After that, community members and Xeggex victims contacted him. He describes his role as CEO of Solar Network. In the material reviewed, he does not claim any role in Pepecoin, and he does not address the font or layout point.

**Where this was asked:**

- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1im7z2r/): "[PEP dev] and Nayiem (obviously one of the masterminds behind the XeggeX scam) have now become best friends."
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ilk5ol/): "www.solar.org looks similar to the pepecoin.org site. ... it's the same font (Nunito)."
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1inpr51/_/mchxdnw/): "Could Nayiem be involved w PEP as well?"

### Did XeggeX really go bankrupt, with no court or administrator named? How many users and how much money were affected (about 12k users, about $80M)? Will there be restitution, and should Nayiem pay it from his assets in Sweden?

**The critic is partly right**

The critic is right on the first point. On 27 Jun 2025 the Xeggex website said it was shutting down and "filing for bankruptcy" (Gate News, UAE Crypto Times). No court, case number or administrator has been made public, and no law-enforcement action against Xeggex has been reported. The figures of about 12,000 users and about $80M come from Xeggex or the press (Plisio). They were never audited, so treat them as claims.

No restitution has been announced. The Change.org petition asks for one, and it names Telegram "MrMike_O" as business director, not Nayiem. No court, administrator or claims process has named Nayiem, so there is currently no basis for requiring him to pay from his own assets. This FAQ cannot decide whether he owes anything. That would be for a court or administrator to decide. The team chat's messages from the time run from 2019 to 2021, with a few later messages from 2025 and 2026, the 2026 ones being Nayiem's own notes. None of them mention Xeggex or Dokdo, so the chat can't settle this question. We found nothing public showing that Nayiem owned or controlled Xeggex or held its funds. There is counter-evidence the critic is right to raise: the Wayback Machine shows Xeggex was described as "a service of Dokdo Global" in 2022, and Nayiem had publicly announced a planned Dokdo acquisition. That association was public.

**Nayiem's note:** This is the author's own account, not independently verified. Mike proposed working on Xeggex and approaching "Karl", and the author announced a planned Dokdo acquisition. Around Nov 2022 the author came to believe that Mike ran Xeggex himself, and the acquisition was cancelled. The author says he never ran Xeggex. He admits he did not warn Xeggex users for over two years. His reason: he expected people not to believe him. He says that after the business relationship ended in late 2022, his only contact with Mike was about getting money back.

**Where this was asked:**

- [gate.com](https://www.gate.com/news/detail/11806562)
- [change.org](https://www.change.org/p/demand-for-immediate-investigation-and-restitution-for-victims-of-xeggex-crypto-exchange-18ba0d68-051a-44fe-ac1a-8cbbf631f582)
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1immi9m/_/mc3tkkn/): "nayiem has plenty of assets in sweden to refund everyone"

### Why did Dokdo UAB go into liquidation in July 2025? What happened to its EUR 125,000 capital, and why did it owe unpaid social-security (SODRA) contributions?

**Not in the chat**

The evidence we reviewed does not answer this question. The Altilly management chat covers 2019-2021. It never mentions Dokdo UAB, its liquidation, its EUR 125,000 capital or any SODRA debt. Our own chat assessment lists "Dokdo/Xeggex links" as "Not addressed (2022+)". None of our analysis files contains company-register records, financial statements or liquidation filings for Dokdo UAB. So we cannot say why the company was liquidated in July 2025, whether any of the capital was left, or why social-security contributions went unpaid. The Reddit poster asks whether any of the EUR 125,000 remained after the Xeggex "hack". Nothing we reviewed shows, or rules out, any movement of Dokdo capital into or out of Xeggex. The poster is right that this is unclear. It stays open until the author publishes Lithuanian register extracts, Dokdo's financial statements, the liquidation decision and the SODRA records.

The public record does show a real link between Dokdo and Xeggex in 2022. An archived Xeggex notice posted by "Karl" says Xeggex would be acquired by Dokdo UAB. Wayback snapshots of the Xeggex site from 6 June 2022 and from September to December 2022 call it "a service of Dokdo Global". The author publicly announced the planned acquisition. A Reddit poster also says Dokdo's own website listed the Xeggex exchange and wallet as Dokdo products. We have not verified that independently. The author's earlier public line that he had "no connection" to Xeggex was therefore inaccurate. It is an interest he has to disclose.

**Nayiem's note:** The author's account: Mike proposed working on Xeggex and introduced "Karl". The author announced that Dokdo would acquire Xeggex, on the condition that it was fully KYC/AML compliant. The author says they were refused access to the backend and wallets for an audit. They say they cancelled the acquisition around November 2022, and that on 3 December 2022 they agreed to remove the Dokdo references from Xeggex. The author has not explained the 2025 liquidation, the use of the EUR 125,000 capital or the SODRA arrears in the material we reviewed. These points should go to the author for a direct answer, with documents.

**Where this was asked:**

- [Reddit, r/XeggeX_Victims](https://old.reddit.com/r/XeggeX_Victims/comments/1lx6xie/): "It is unclear if any portion of the €125,000 commitment remained after the XeggeX 'hack'."

### Who revived the XeggeX domain in January 2026 and deleted the refund posts on 15 February 2026, and is AnonEx a re-rug built on XeggeX's code?

**Not in the chat**

The management chat cannot answer this. It covers the Altilly years, and nothing in it mentions AnonEx, Dokdo or the later history of the XeggeX domain. We do not know who revived xeggex.com in January 2026 or who deleted the refund posts on 15 February 2026. Several outside write-ups describe the January 2026 return: the Nerva project (an interested party), Plisio (https://plisio.net/profiles/xeggex-exchange) and, according to Plisio, the Quadriga Initiative. Plisio describes it as the same operator coming back with the same IOU tokens, but none of these sources names that operator. The 15 February deletion is reported by Nerva, and we could not confirm it independently. On AnonEx: community posts allege that it is a clone running on XeggeX's code, and AnonEx is said to have replied that it only bought the software. We could not verify either claim from a primary source. The domain anonex.io was created on 21 November 2025, and whois lists the registrant as Njalla, a privacy service, so the owner is hidden. The shared-code claim remains an unverified allegation. We are not saying AnonEx is a re-rug. On Dokdo, the critic is right about part of it. In 2022 the author publicly announced that Dokdo would acquire XeggeX, and Wayback snapshots show XeggeX as "a service of Dokdo Global". The author says the deal was cancelled around November 2022, when he came to believe that "Karl" did not exist. He admits that he then did not warn XeggeX users for more than two years. A Discord message of 30 November 2022 from the author to Mike, about the Solar SXP swaps described in [Solar's statement of that day](/evidence/solar-statement-2022-11-30.png), reads "We are not going to say anything if you can return the funds in 24hrs." The author has made no claim about the 2026 domain revival or about AnonEx.

**Nayiem's note:** Author's account: Mike proposed that they work on XeggeX together and approach its operator, "Karl". The author then publicly announced that Dokdo would acquire XeggeX in 2022. Around November 2022 the author came to believe that Mike ran XeggeX himself and that "Karl" did not exist, and the acquisition was cancelled. The author admits that he did not warn XeggeX users for more than two years. He says he expected people not to believe him, and that after the business relationship ended in late 2022 his only contact with Mike was about getting money back. He has made no claim about the 2026 domain revival or about AnonEx.

**Where this was asked:**

- [plisio.net](https://plisio.net/profiles/xeggex-exchange)

### Or is Nayiem a scapegoat with no XeggeX ties, who helped victims regain access? (Defence claim)

**Partly answered**

The management chat can't settle this. Its working messages stop in October 2021 [#7571]. The words "Xeggex", "Dokdo" and "Karl" never appear in it. Nothing in the chat or the other evidence we reviewed shows Nayiem helping Xeggex victims get back into their accounts, so that part of the defence has no support here.

The claim that he had "no Xeggex ties" is not accurate. Nayiem publicly announced that his company Dokdo would acquire Xeggex. Wayback Machine snapshots from June to December 2022 (an external source, not part of the chat) describe Xeggex as "a service of Dokdo Global". That is a real link and should be disclosed as an interest. By his own account, Nayiem also did not warn Xeggex users until February 2025, after he says he learned in late 2022 who was behind it.

The "scapegoat" point is not established. For Altilly, the chat shows that Nayiem expected to take the blame [#1570] and that his business address was already public [#1579]. It also records his own statement that he never had access to certain servers because Mike did not allow it [#1492-#1493]. That statement is his account, not independent proof, and elsewhere in the same discussion he says the team used some hosting daily [#1483]. Nayiem points to external public records (Companies House filings for Xeggex Software Services Ltd and a 2024 GitHub commit by the account mrmikeo to xeggex/hummingbot) as linking Xeggex to Mike. We have not verified those records against the chat. Even taken at face value, they would not show that Nayiem had no involvement at all.

**Nayiem's note:** The author's account: Mike suggested working on Xeggex together and approaching "Karl", and the author announced the Dokdo acquisition. Around November 2022 the author says he learned that Mike was running Xeggex himself and that "Karl" did not exist, and the acquisition was cancelled. He admits he did not warn Xeggex users until February 2025. His reasons were that he expected not to be believed and that he feared for his family. He says that after the business relationship ended in late 2022, his only contact with Mike was about getting money back. He says he has had threats for years because people wrongly linked him to the Xeggex hack.

**Where this was asked:**

- [Reddit, r/XeggeX_Victims](https://old.reddit.com/r/XeggeX_Victims/)

## Solar

### Were layer-1 coins such as Solar (SXP), PYRK and SPX created as bait or honeypots for the operators' exchanges and then rug-pulled or abandoned?

**Partly answered**

The chat answers this only in part. It covers Altilly from 2019 to 2021. It says nothing about Solar (SXP), and SPX never appears in it. In the chat, the PYRK messages below come from an account shown as "Deleted Account". From context we believe this is Mike: Nayiem calls him "Mike" [#1751], and Chuck tags @MrMike_O and gets replies from that account [#3947, #7095, #7096].

For PYRK, the chat shows a closer insider tie than an ordinary listing. Mike wrote that "around 2.8 million of the altilly pyrk is mine" [#1748] and that a separate wallet "with 1.2m pyrk of mine … is gone" [#1745]. He also said "I don't remember anybody other than me having that much on the exchange" [#4807]. He and another contact seem to have run PYRK wallets and servers directly. Mike "moved some to a new address on pyrk" and heard from users about it [#2479]. Later he said "i need to go thru the pyrk ones, [the contact] had setup new stuff awhile back … just need to make sure i don't have any pyrk sitting on them" [#6056, #6057].

He planned "to offload pyrk" with that contact [#2482]. He then said he would "pull out my 2.8m pyrk from the wallet and leave the remaining user funds," out of 3.9m in total [#3175, #3176]. When Chuck later asked how much was in the PYRK wallet [#7095], Mike replied: "if you have a claim, let me know, i had moved those to community fund wallet awhile back" [#7096]. PYRK users did go through the refund process [#3947, #4005], but the chat records no PYRK payout, and the user funds sat in a wallet Mike controlled and had moved himself [#2479, #7096]. Nayiem says Mike never completed the PYRK refund.

So the Reddit and Kaspa commenters have a point that PYRK was closely tied to the exchange's operators. However, nothing in the chat shows who created PYRK, and nothing shows it was designed as bait or deliberately rugged.

The chat says nothing about Solar at all. Disclosure: Solar (SXP) was the author's own project. Solar's [statement of 30 November 2022](/evidence/solar-statement-2022-11-30.png) says that 1,878,477 SXP was fraudulently swapped between 12 August and 29 November 2022 through unauthorised BEP20->SXP swaps, and that "The identity of the perpetrator is known". It does not name anyone; the author's claim that it was Mike rests on his Discord screenshots. The author says the incident ended their business relationship in late 2022, and that Mike later paid all of it back (by 19 March 2024). The chat does not cover any of this, and the identity and repayment have not been checked independently.

**Nayiem's note:** The author's account: Solar (SXP) was the author's own project and was ranked in the top 200 on CoinMarketCap. Solar's [statement of 30 November 2022](/evidence/solar-statement-2022-11-30.png) says 1,878,477 SXP was fraudulently swapped between 12 August and 29 November 2022 and that the perpetrator's identity was known; it does not name him. That it was Mike comes from the author's Discord screenshots. The author says the incident ended their business relationship in late 2022, and that Mike eventually paid all of it back (by 19 March 2024). The group chat does not cover any of this, and it has not been checked independently.

**Where this was asked:**

- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ik58q6/_/mbkrq1m/): "layer 1 POW coin and honeypotfor their scam exchange"
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ika2yt/_/mbkt089/): "spx, pyrk - those were layer 1 pow coins which were meant to be traded there, and they rug pulled."
- [Reddit, r/kaspa](https://old.reddit.com/r/kaspa/comments/11mjzyk/_/jbo7ng1/): "they created PYRK as part of that exchange ... but now they abandoned it."

### Are 'Solar Enterprises' and the 'Solar Blockchain Foundation' registered anywhere, or are they brands used to obscure the Dokdo-XeggeX link? Is the SXP ticker (shared with Swipe) misleading, and why did SXP fall 86% after its XeggeX listing?

**Not in the chat**

The Altilly management chat can't answer this. The Solar and SXP events are from 2022 onward, and the chat never covers them. The word "solar" appears once, in an unrelated 2021 remark about batteries [#6392]. The chat never mentions XeggeX, Dokdo, SXP or Swipe. On registration: the critic says "Solar Enterprises" was an unregistered trading brand of Dokdo UAB, a Lithuanian company (registration code 306099775) that has since been liquidated. The critic also says it is not a registered Wyoming entity and that there is no record of a "Solar Blockchain Foundation". We found no registration under either name, but we did not search every registry, so the critic's point stands unrebutted. The UK Companies House record we reviewed lists the author as a director of a different company, Solar Network Finance Ltd (15377536), incorporated 31 Dec 2023. On the Dokdo-XeggeX link, the public record goes beyond a plan to acquire. In archived 2022 snapshots, the XeggeX footer read "A product of Dokdo Global". The XeggeX about page said it was "a service of Dokdo Global, Dokdo, UAB". The Dokdo site listed XeggeX Exchange and Wallet among "Our Products". SXP was listed on XeggeX on 10 April 2022, while the Dokdo acquisition was being arranged; the earliest archived Dokdo branding we cite is from 6 June 2022. Readers should treat that as a real conflict of interest. That record also sits badly with later statements that the author "was never involved" with XeggeX and had "no connection" with its operator. Our evidence doesn't cover the SXP ticker being shared with Swipe or the 86% price drop. We can't confirm or explain either. Readers should check the listing and price data themselves on public market trackers.

**Nayiem's note:** The author gives this account: Solar (SXP) was a legitimate project ranked in CoinMarketCap's top 200. Solar's [statement of 30 November 2022](/evidence/solar-statement-2022-11-30.png) says 1,878,477 SXP was fraudulently swapped between 12 August and 29 November 2022 and that the perpetrator's identity was known, without naming anyone. By the author's account, based on his Discord screenshots, the perpetrator was "Mike", who eventually paid all of it back. The author says that at around the same time they learned Mike was running XeggeX himself. After that they cancelled the Dokdo acquisition of XeggeX and ended the business relationship. This is the author's own claim. The chat doesn't corroborate it, and it doesn't address how the brands were registered, the ticker, or the price fall.

**Where this was asked:**

- [Reddit, r/XeggeX_Victims](https://old.reddit.com/r/XeggeX_Victims/comments/1lx6xie/): "Dokdo UAB operated under the unregistered brand SOLAR ENTERPRISES, allegedly as a means to obscure its connection to XeggeX."
- [Reddit, r/XeggeX_Victims](https://old.reddit.com/r/XeggeX_Victims/comments/1lx6xie/): "No registration was found for the 'Solar Blockchain Foundation'"
- [Reddit, r/XeggeX_Victims](https://old.reddit.com/r/XeggeX_Victims/comments/1lx6xie/): "Having the same ticker as Swipe (SXP) could be consired misleading ... (-86%)"

### What happened in the November 2022 Solar incident (1,878,477 SXP in unauthorised swaps)? Why was the known perpetrator not named, why did Nayiem offer silence in exchange for repayment, and was the roughly $400K returned the full amount?

**The critic is partly right**

The management chat does not cover this. Work discussion in the chat stops in September–October 2021 [#7560-#7571]. After that the chat has nothing until February 2025, apart from a few short messages [#7572-#7575], and then comments the author added in September 2026 [#7576-#7598]. No message in any period mentions Solar, SXP or the 2022 swaps, so none of what follows can be confirmed from the chat.

What the documents show: Solar's [statement of 30 November 2022](/evidence/solar-statement-2022-11-30.png), titled "UNAUTHORISED BEP20->SXP SWAP TRANSACTIONS", says that on 29 November 2022 "a series of unauthorised swap transactions were detected which took place between 12th August 2022 and 29th November 2022, exchanging non-existent BEP20 SXP tokens for mainnet SXP coins", and that "In total, 1,878,477 SXP was fraudulently swapped during this time resulting from a vulnerability detected in the BSC nodes used to provide API data to the swap service." It says this "was not due to a hack or breach of security of the Solar mainnet or Solar Core", that "user funds were never at risk", that no new SXP coins were created, and that "no funds were lost". On naming, it says only: "The identity of the perpetrator is known, and the necessary recovery processes are now in motion which cannot be discussed further for legal reasons." It does not name Mike or anyone else.

Mike's identity as the perpetrator comes from the author's Discord screenshots, not from the statement. The author's 2025 PDF (pp.13-16) includes them:
- 29 Nov 2022, 22:45, the author: "Why did you do it Mike?"
- 30 Nov 2022, 00:17, the author: "We are not going to say anything if you can return the funds in 24hrs."
- 30 Nov 2022, 05:43, MikeO: "sorry man. ya i fucked up… original plan was to earn some money from trading… liquidated out of my positions on the ftx crash… only thing that is possible is to return it as i can get it."
- 3 Dec 2022, MikeO: "I had nothing to do with the altilly hack."

The PDF's own text puts the deal plainly: "If you don't pay back what you took or stick to the deal, I will expose everything."

The critic is right on several points:
- The author did offer silence in exchange for repayment, and that put recovering the money ahead of warning the public, including Xeggex users.
- The repayment did not happen in 24 hours. The 2025 PDF had a heading dated March 2024 saying Mike paid back "(Part of)" the funds, and put the amount at about $400K. The author's account now is that Mike repaid the full 1,878,477 SXP in 12 payments between 1 December 2022 and 19 March 2024, back to the Solar swap wallet involved in the theft: the last of it about 16 months after the incident.
- The PDF did not itself say the $400K related to Solar. That link, and the [Solar repayment ledger](/story#after-altilly), come from the author's own records.
- Transaction IDs have been published only for the final five payments (18-19 March 2024, 1,300,000 SXP), which can be checked on the Solar blockchain. The first seven payments (578,477 SXP) have no published IDs, and a transaction alone does not show who sent it.
- A screenshot in the same PDF dated 3 December 2022, as we read it, shows Mike asking "should I start removing references to Dokdo on Xeggex?" and the author replying "Yes, please". So the two were still in contact about Xeggex days after the incident.

**Nayiem's note:** The author's account: the goal was to get Solar's money back. By the author's account, Mike repaid the full 1,878,477 SXP in 12 payments between 1 December 2022 and 19 March 2024, back to the Solar swap wallet involved in the theft. The final payments can be checked on the Solar blockchain (see the [Solar repayment ledger](/story#after-altilly)). The money was for the Solar incident, not for Altilly. By the author's reading, the transactions pointed to Mike. The business relationship ended in late 2022, and the author no longer trusted him. After that, the author stayed in contact with Mike only to get money back: first the Solar funds, and later a promise Mike made to fund the remaining Altilly refunds for non-saved assets and to pay Chuck, which Mike never followed up on. The author did not name him publicly because they had no proof that he ran Xeggex, were afraid of him, and did not want Solar, a legitimate top-200 project, linked to him. The author admits this meant Xeggex users were not warned.

**Where this was asked:**

- [Solar Network statement, 30 Nov 2022](/evidence/solar-statement-2022-11-30.png): "the identity of the perpetrator is known"
- Nayiem's Follow-Up PDF (Feb 2025), pp.15-16

### Why did Nayiem resign from Solar in November 2025, citing 'reputational issues and past decisions that weren't ours'?

**Not in the chat**

The published chat and our analysis files can't answer this. The Telegram chat covers the Altilly management group, mostly 2019–2021. It also has a few short replies from February 2025 and a set of annotations Nayiem added in late September 2026 before publishing the chat on this site. None of it discusses Solar. The only message containing the word "solar" is an unrelated 2021 remark about batteries [#6392]. The quoted wording comes from Nayiem's own resignation statement, published on Solar's blog on 28 November 2025. It says he ran into "barriers shaped by reputational issues and past decisions that weren't ours" while working on the card product, and it mentions "rigid, non-negotiable conditions" in the environment around the project. It doesn't say what those reputational issues or past decisions were, and it names neither Altilly nor any individual. Because these are Nayiem's own words, only he can say what they refer to, and nothing in our sources explains them. We won't guess. The one other Solar event our records document that could be relevant is the November 2022 incident. Solar's notice of 30 November 2022 said 1,878,477 SXP had been fraudulently swapped through unauthorised BEP20->SXP swaps between 12 August and 29 November 2022 and that "the identity of the perpetrator is known", without naming anyone. No evidence here shows whether that incident, the Altilly history or the later threats played any part in the 2025 resignation. Readers should treat any link between them as unconfirmed.

**Nayiem's note:** The author's account: the resignation statement is about Solar's own history, not Altilly. SXP began as the token of Swipe, a crypto wallet and Visa debit-card company that Binance acquired in 2020; Solar later inherited that legacy, including a token-swap agreement with Binance and the card product. The "reputational issues and past decisions that weren't ours" refer to that Swipe/Binance-era baggage, which he says limited what Solar's card product could do. The full record is published by the Solar Foundation: its [history](https://nayiemw.github.io/solar-foundation-website/history/), the [Binance token-swap agreement](https://nayiemw.github.io/solar-foundation-website/agreement/) and an [archived copy of the resignation statement](https://nayiemw.github.io/solar-foundation-website/archive/resignation-statement-nayiem-w/). Separately, he says that after the November 2022 SXP incident Mike paid back the full 1,878,477 SXP by 19 March 2024; the final payments are listed with transaction IDs on [My story](/story#after-altilly).

**Where this was asked:**

- [blog.solar.org](https://blog.solar.org/resignation-statement-nayiem-w/): "I ran into barriers shaped by reputational issues and past decisions that weren't ours."

## Other

### Is Altilly still operating, and is altilly.net (which appeared in 2023 promising repayment and then shut down) connected to the original team?

**Not in the chat**

The chat can answer the first part but not the second. It does not show Altilly trading again after the December 2020 incident. In May and June 2021 the team worked on a successor brand, Altfenix. altfenix.com had a demo page, and Altfenix pages were posted on qredit.io [#5771, #5909, #6864]. In June 2021 they talked about "reopen altilly / but make it Altfenix", with unpaid claims issued as tokens and the old domain possibly redirected [#6608-#6611, #6657-#6661]. In September 2021 the stated plan was still that Altfenix would go live within a few weeks [#7428]. The chat never shows Altfenix, or any of those claim tokens, running as a live exchange. In September 2026 Nayiem announced a plan to make the group public and read-only [#7579]. In the end the group itself stays private; the redacted chat is published on this site instead, and the unredacted chat is available to law enforcement on request. Nothing in the chat shows Altilly still operating as an exchange.

altilly.net is never mentioned in the chat. What we have comes only from Reddit. In July 2023 a subreddit, r/Altilly_Exchange, carried posts promoting "Altilly.net", with titles such as "Payment received" and "Thanks you altilly for reactivating my account". Most of them came from a single account. In February 2025 one Reddit user suggested the site "might be a replica", since the original was altilly.com. In July 2025 a user posted near-identical comments in several subreddits saying altilly.net had shut down. None of this shows who ran altilly.net. We found no evidence that connects it to the original Altilly team or to anyone from it. We also have no evidence that rules such a connection out. Treat it as unverified.

On the altilly.com domain: a first-hand account says it was handed over through Namecheap in December 2022. Our check could not confirm this, so the claim stays unverified.

**Nayiem's note:** In the author's own account, refunds mostly stopped around 2022/2023, with only a handful after that. The author says unpaid claims can no longer be reliably verified, because many chains are dead and the database is lost, and makes no promise of repayment. The author does not mention altilly.net in any of the statements we hold.

**Where this was asked:**

- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ikb3ia/_/mbl1cvs/): "isn't Altilly Exchange still around? Did they scam and still continue?"
- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ik58q6/_/n5e85ja/): "Altilly.net, you didn't just shut down your site, you shut down the hope of thousands."

### Why was the team paying off debts instead of restarting the exchange? Will Altilly ever resume?

**Partly answered**

The quote came from someone in the main group, and Chuck relayed it without naming the writer [#2999-#3005]. The team itself was not sure what the writer meant [#3001-#3004]. The "debt" most likely means what Altilly owed its users. About USD 1M was lost, and Nayiem expected the real figure to be higher [#1677]. The BTC, ETH, DASH and DOGE hot wallets were gone, though the ERC-20 tokens were still there [#4094-#4096]. The developer said the database and the config files needed to decrypt it were missing [#1352-#1353]. By May 2021 only the source code survived, with "No database" [#5309-#5310]. So there were no reliable balances left to restart from.

Restarting was discussed. On 5 Jan 2021 Nayiem wrote that people "really want the exchange back. Even though I don't want it." He floated a different model instead: a swap feature inside Qredit Motion where users keep their own keys and the team never holds funds [#2608-#2611]. The developer (shown in the export as a deleted account, taken to be Mike) replied that any new version "would have to be a completely walletless system" [#2612]. By June 2021 the plan was to "reopen altilly, but make it Altfenix" [#6608-#6610]. Unpaid claims would be issued as tokens that holders could trade or redeem [#6657-#6660]. A plan posted on 10 Sep 2021 gave about 2 weeks of Qredit Motion work first, then "3 to 4 weeks to go live with Altfenix" [#7428]. The chat never shows it launching.

There is no sign that Altilly will resume. The team's own records show the strain. In September 2021 Chuck, who handled refunds, told Mike that pending refunds had to go out "before pushing anything else", because "Weve made alot of promises we are not keeping" and users were "Losing trust" [#7421]. In the same month a user threatened a lawyer over lost DOGE [#7399].

**Nayiem's note:** In the author's own account, refunds stopped around 2022/2023, with only a handful after that. He puts the remaining unverifiable claims at around $50,000–60,000, and makes no promise about them. Altilly was never registered as a company. The author says he lost the energy to continue once he came to believe who "Mike" really was. That is his belief, not an established fact.

**Where this was asked:**

- Chat [#2999-#3005] (forwarded from main group): "Altilly should find a way to recover. But no, they're trying to pay off the debt"
- Chat [#6653, #6655] (forwarded): "Hello is there any possible exchange will resume again..?"

### Why would an operator rob a profitable exchange?

**Partly answered**

The chat does not show that Altilly was profitable, but it does not prove the opposite either. In July 2019, 17 months before the loss, Mike said "we are too small to worry about audits yet" and "too small to even start moving to safe storage" [#215-#216]. He expected audits to become relevant "probably 2020" [#219-#220]. When Nayiem asked how much of the 31 lost BTC was the team's own [#1662], Mike answered "i think around 0.8 was mine. Can't remember exactly what i had. exchange fees, not much" [#1663]. That is Mike's own rough estimate, not an accounting record. Days after the loss he said that only the week before he had expected the exchange to start bringing in income "soon finally" [#1901-#1902]. We found no mention in the chat of anyone drawing a salary or profit payout from Altilly. That is an absence in this record, not proof that none existed. Against that, the exchange did charge listing fees, which Nayiem helped set [#178, #771], and it had trading volume [#786]. So it had some revenue. Nayiem estimated the loss at "1mln" [#1677], and nothing in the chat suggests fee income anywhere near that size.

The critic has a fair general point. Whether the exchange was profitable or not does not rule out insider theft. Small fee income next to a large hot wallet makes the question sharper, not weaker. The chat still does not show who took the funds or why. Mike reported an outside attack at the time: the messages at [#1033-#1034] appear under Chuck's name but are forwarded from Mike, sent on 23 Dec. An inside job is not established.

**Nayiem's note:** The author's account: Nayiem says he never earned from Altilly and never drew a salary, that all listing and trading fees went to Mike, and that pay was meant to start after he formally acquired the exchange. The chat does not discuss that arrangement. The author believes the loss was an inside job by a developer. The chat does not establish this.

**Where this was asked:**

- [Reddit, r/pepecoin](https://old.reddit.com/r/pepecoin/comments/1ikt45d/_/mbp3f6w/): "Altilly was also profitable. But the answer is 'greed'."
