Written by Nayiem Willems, September 2026. This page sits next to the published Altilly management chat. Numbers like #1056 link to messages in that chat. Times in the chat export are UTC-8. In Sweden, where I lived, it was about 9 hours later.
In February 2025 I wrote a write-up called "Follow-Up on the Xeggex Story", which I shared with investigators and initially posted on Reddit. Everything that was in it is now on this site, except the details about a private person that I should not have published (see below); where its assumptions and statements were wrong, they have been corrected against the Telegram chat export. I wrote it fast, while Xeggex was collapsing and people were accusing me. I wrote it from memory, years after the events. English is not my first language. Several things in it were wrong, and people have used those mistakes against me. So I am writing it again more carefully, with the chat next to it so you can check what I say.
What I got wrong in 2025
- Dates. I wrote "12 December 2020" for the incident, then "13 December" for the $10k/$15k conversation. Both were wrong. The incident was 23-25 December 2020, and the $10k/$15k exchange happened on 24 December #1056–#1060. I also wrote that the collapse came "twelve days after forming the company", and that part was right. UK Companies House shows that Qredit Ltd (no. 13077371) was incorporated on 11 December 2020, with me as sole director and the only person with significant control. The incident began on 23 December, 12 days later. Mike does not appear anywhere in the company's register entry. "12 December" was my mistake: I mixed up the two dates, the day I formed the company and the date of the incident.
- The company. I wrote that I registered "Altilly" in the UK and planned a UK licence. The UK company was Qredit Ltd (no. 13077371), incorporated on 11 December 2020, with me as sole director. The chat never mentions it. It never traded, never filed accounts and was struck off on 17 May 2022 (see December 2020 below for why). The licence we were preparing was Estonian #5023, #5745.
- Revenue. I gave exact volume and profit figures. The volume can be checked in archived tracker pages: Altilly's reported 24-hour volume was mostly $10k–$130k in 2019 and $250k–$550k in autumn 2020, and peaked at about $880k on 15 December 2020 (CoinMarketCap, archived). Nomics counted about $68M for 2020 up to late November, and weekly totals in late 2020 were $2M–$5M. Trackers rated Altilly's volume quality low, and much of it came from a few small tokens. I have no records of profit. As I remember it, the fees went to Mike; he said about 0.8 of the 31 lost bitcoin was his, "exchange fees" #1662, #1663.
- The "postcard". I meant the Revolut card. In 2025 I placed it after the house videos and made it sound like something I sent out of sympathy. In fact Mike ordered a company Revolut card in February 2021. Revolut showed that its service was not offered in his country #3646, so the card came to my address and I forwarded it #3639, #3647, #3960. That was months before the house videos.
- The "PAUL Vernon" envelope. My 2025 write-up made the name Paul Vernon sound like something I found only later. In that write-up, written from memory, I described finding the name through a "paulv" code signature during the Xeggex period (2022) and then by searching the name on Mike's postal address, and I dated the moment "it became painfully clear" to December 2022. That was wrong. The card arrived in an envelope addressed to "PAUL Vernon", and I posted a photo of it in this chat on 4 February 2021 #3833, almost two years earlier. Mike himself had also named the old hosting email "[email protected]" on 26 December 2020 #1326, #1328. At the time I searched the name, found only a British blues musician, and let it go #7585. I did not connect the name to Cryptsy until 2022.
- Hetzner. I wrote "Hetzner servers (which I controlled)". The account was in my name, but Mike was the one moving wallets onto it #1119, #1121.
- The email. I wrote that Mike "dismissed" my question about which email was compromised. The chat shows that he wrote the address in the group himself #1326. What I remember him dismissing was a different question: whether "Paul" was his real name. The messages around that moment are missing from the export #1323, #1325, #1327, so I cannot show it, and I mixed the two up in 2025.
- The public notice. The notice text I quoted in 2025 named the wrong exchange and was not the real text. The real text is #1232.
- "Users were reassured their funds were safe." Every notice said "We are not sure yet if funds are lost" #1167, #1232. The only "safe" line came from me: I wanted to add that hackers could not access funds #1180. Mike replied "we don't know this", Chuck agreed, and it was dropped #1183, #1190–#1193. It was an assumption. The day before, Mike had put the loss at 10k, "might be 15" #1056–#1060, and he said the servers had been deleted, not robbed #1103, #1132. I also hoped the Backblaze backups still held the wallet keys. Mike said the backups were gone too, first "not sure if the hacker did that or maybe a billing issue at backblaze" #1108, then that they had been deleted #1342 and could not be recovered "once deleted by user" #1498. I remembered this as Mike saying Backblaze itself was compromised; the chat shows he said the backups were deleted, not that Backblaze was hacked.
- Refund checks. I wrote about "10,000+ transactions, 500+ assets", all checked one by one on blockchain explorers. About 137 assets were saved #1757, and our checks were not that thorough (see below).
- "Paul Vernon was never charged." I meant that he never faced justice, but the words were false. He was indicted in the US in 2019.
- Figures. In 2025 I wrote that Mike left us with "$900K in refunds to process and $2.4 million in 'saved' assets to return", and my personal website speaks of a "$2.4 million loss". Both descriptions of the $2.4 million are wrong. It was not the saved assets alone, and it was not the loss. It was the total of all claims, saved and non-saved assets together, from our final claims sheet. That sheet is not in the chat. The chat shows the valuation being set up #2534, #2553 and Chuck building the non-saved-asset and conversion sheets #7426. The chat's own estimate of what was lost is about $1 million #1677. Roughly 31 BTC #1600, at the roughly $27K per bitcoin implied in the chat at the time #1672, #1673, comes to about $0.8 million. The claims total can be higher than the loss for two reasons. The claims include the saved assets, which still existed. And the claims were valued at a later date. Until I publish the sheet, $2.4 million is my figure and cannot be checked here. The $900K is a separate claim: it is what I say I later paid in refunds from my own income. The chat does not show that either.
- The house. I wrote that Mike "used stolen funds to live in a luxury villa" and called his house a mansion. I cannot prove that. The chat shows him moving into a new house in 2021 while selling another one #5094, #6163–#6166, #7544. It does not show how either was paid for. What it does show is the contrast in that same year: Chuck going to the food bank #3430 and me with "no money at all" and "zero cash" #2805, #5602, scraping money together while we worked on refunds, while the developer who controlled the wallets #1299, #1621 was renovating his new house with an indoor pool #5106, #7430–#7431. Read the chat and its context, and draw your own conclusions.
- Private people. In 2025 I published the name of a private person linked to the postal address Mike gave, and a property listing. I wrote that "if there was a 100% guarantee that people would visit his location, I would share his personal details", and I shared what I had with an online group trying to find him. That was wrong. That person may have nothing to do with any of this, and a group of strangers is not the police. This site does not repeat those details. The evidence about Mike himself (the envelope, the hosting email, the code and registry links) is on the Who was Mike? page and in the chat; read it and draw your own conclusions about him.
- The authorities. I wrote that "a two-way dialogue was officially opened with the U.S. Marshals". A two-way dialogue was opened, so that I could send them information, but they never responded in it, other than giving me a tip reference number (see below). My 2025 wording made it sound like more than that.
- Things I stated as facts that I cannot prove. These were: that Altilly funds were traced to the EXMO and Livecoin hackers, that Mike "orchestrated everything", that I refunded $900K, and that a phone call was "final confirmation". Below I give each one as a belief or as an unproven figure.
How I got involved
I started Qredit (XQR) in January 2018. In August 2018 a person named Mike offered Qredit a free listing on the Altilly exchange, and I accepted. I later helped Altilly with front-end design and marketing #699, #752.
As I remember it, in late 2018 Mike suggested that I become the CEO and public face of Altilly, with Qredit as the exchange's own currency. He would stay in the background and run development. That was a private conversation before this chat starts, so these are not his exact words. Other public descriptions of my role do not match this one. In 2019 Altilly's Bitcointalk announcement said it was "now owned and operated by Hodler Enterprises". Altilly's notice after the hack said the exchange "was acquired in 2019", and also that it had no "official ownership by either of the 2 parties". My personal website says "I acquired Altilly in 2018 and invested $175,000 personally." I have not published documents that settle who owned Altilly or what I paid, so please read this section as my memory. The later chat shows the working setup. Fees were charged in XQR #183, #583, I spoke for Altilly in public, and Mike ran development and the servers #1492, #1493. The chat also mentions a company called Hodler Enterprises in connection with Altilly #702.
As I remember it, the arrangement was this. I had the title of CEO, and I would get ownership of the whole project once I had set up a proper company for it. There is no message in the chat that transfers ownership, so this is my memory, not a documented fact. Two messages fit with it. In September 2019, when Chuck pointed out that our site text looked tied to Hong Kong, I wrote that Altilly "operates out of Sweden", "But it's still incorporated in Hongkong, until I have the things sorted here" #757–#759. In December 2020, when Chuck asked about a Hong Kong address, Mike said it was for a company registration service he had meant to use to form a company in Hong Kong, and "never did do that tho" #1776–#1778. So the Hong Kong company I mentioned in 2019 was never formed. I repeated something I had not checked. As far as I know, Altilly was never registered as a company anywhere.
On 11 December 2020 I registered Qredit Ltd in the UK, as a step towards running Altilly as a regulated business. As I remember it, Mike had privately promised that once I had set up that company, I would formally acquire Altilly. We were already moving servers and wallets to my hosting provider, Hetzner, with Mike doing the moving (see below). The incident began twelve days later, before any acquisition, so I never formally owned the exchange I was the public face of. This is my memory; no message in the chat records the promise. Our private promises were made in a one-to-one Telegram chat between Mike and me, and I cannot show it: Mike deleted the entire history of that chat for both of us, so it cannot be recovered. Only fragments survive. In May 2021 I posted screenshots of part of that private chat in this group #5025, #5028; they are about the Estonian licence and a new exchange, not about ownership of Altilly. I also have Discord screenshots from November and December 2022. I also asked Mike to go through KYC as an owner of the business. He did not want to, and told me I could have full ownership instead. I do not know his reasons. I did not see it as a warning sign then. The chat never mentions Qredit Ltd; the company details come from Companies House.
I never drew a salary from Altilly and never earned any money from it. The plan was that pay would start once I had formally acquired it, and that never happened. That is my own account; the group chat does not discuss it. What the chat does show is where I stood at the time. Right after the hack I wrote that even with the database back "I will be in massive debt" #1533, and that I was "1mln usd in debt" #1882. A few days later I wrote "I have no money at all" #2805. I paid for services such as the support desk myself until I had "zero cash" #5602 and was "done paying for all those 3rd parties" #6772. In August 2021 I wrote that "we already have the funding for the crypto license" #7230. That money came from Mike: in May 2021 he had offered to put up about 10k for the licence, "i think i can probably get that 10k by the end of the week… should get that started as soon as you can", and to "send a little extra if i can" #5728, #5729, #5737, while I was applying for the Estonian licence #5735, #5745. The chat shows the offer; that he then sent it is my account. No message in the chat shows me receiving a payout, a salary or fee revenue from Altilly. Some messages were removed before publication #7598, though, so that absence is not proof on its own. Mike said at the time that he had only just been saying at home that "we might start having an incoming from this exchange soon finally" #1901. The only mention of a salary is a joke, in which I called myself his "favorite employer" #4198, #4201. My impression was that Mike was not chasing quick cash, and after the hack he offered to put in his own money #2806, #5728. That is only my impression, and some messages point the other way. He said some of the exchange-fee and PYRK balances were his #1663, #1748, he wondered "what we could have sold altilly for before the hack" #1889, and he said he was "happy with a few mil to live on" #5493.
December 2020
Around 23 December users started telling me that withdrawals were failing and that some balances showed zero. As I remember it, I called Mike and he said he had just woken up and did not know what was happening. That call is not in the chat. My own first message about it in the group, on 24 December, already called it "the hack" #1031.
What the chat shows is how Mike's account changed:
- 24 December (morning in Sweden). Mike's first report was that an attack came in through "an insecure recue port" and that 3 machines were affected #1033, #1034. These appear under Chuck's name because he forwarded them later that day. The export marks the first one as forwarded from Mike's (now deleted) account and dates the original late on 23 December in chat time, early on 24 December in Sweden.
- 24 December. I asked, "Is it really under 10k Mike?" #1056. The message just before my question is missing from the export. He answered "might be 15" and "wont know for sure until i get everything moved" #1059, #1060. In the same minute he suggested telling people "we are still investigating the outage, and we have full control of our systems" #1057. He also drafted a line saying data had been removed "due to the suspicious outage" #1065. I worked on that wording with him and agreed to it #1072, #1075. I went along with calling it an outage. As I remember it, he also said a failsafe had shut the platform down over a balance mismatch. That is not in the chat.
- 25 December. He wrote that "somebody hacked into their systems. deleted all the servers" #1103 and that the backups were gone #1108. When Cherry Servers first blamed non-payment, in an email from their support staff that Mike forwarded to the group #1110, he said "there were no overdue invoices, so thats a lie" #1111. Later he suggested that a change he had made kept the attackers out, "so i guess they got pissed off and just deleted everything" #1132.
- 26 December. Early that day he said the attacker came in through an old email still attached to the account #1289. Then [email protected] appears, with "history on that domain probably has my name", meaning Mike's own name #1326, #1328. The messages in between are missing #1323, #1325, #1327, so I cannot show whether someone asked him for it. Later he said that old email had no 2FA, unlike his current one #1504, and that Cherry told him the deletion request came from it over a Tor IP #1508. He said he would ask Cherry for the full login history #1509. Later he said the history "only went back 5 days" #1749. No Cherry login records were ever posted.
According to the research I rely on, the Cherry client relationship was in Qredit's name. Cherry's liability notice came to me #4349. Only Mike had logins to those servers, and I never had access #1492, #1493. In March 2021 I noted that Cherry's notice did not match an earlier email in which they "clearly stated it was their fault" #4350. Neither Mike nor I ever obtained full login records. As the account holder, I should have pushed for them.
There are also two accounts of why wallets were moving to Hetzner. Mike alone was moving Altilly's servers and wallets to my Hetzner account #1119, #1121, #1483, #2602. I had no access to the Cherry servers they were coming from #1492, #1493. On 24 December Mike drafted a line saying the move "wasn't planned" and was a reaction to the "suspicious outage" #1065, and my public notice said the same: we decided to move after noticing the suspicious activity #1232. But in the following days Mike wrote that the saved wallets had "been at the new host for awhile" #1371, that one coin was one he "was moving awhile back" #1447, and that he had been writing a guide on setting up the new servers "for moving over" #2586. Those later messages do not fit with "It wasn't planned". What made it across were mostly bitcoin clones added in the previous 30 days #1297, much of it low in value; I called part of it "worthless shitcoins" worth about $490 in total #2518, #2519. BTC, ETH, DASH, DOGE, XQR and the "safe" wallets stayed on Mike's Cherry servers and were lost #1299, #1600, #1733, #4094, #4095. According to Mike, those servers were deleted through an old login on his hosting account, from a Tor IP #1504, #1508.
I believe the "hack" came just as the high-value assets were due to move. That is my own reading. No message in the chat gives a date for moving them, and Mike only called the move "a big task" #1298. Some messages point the other way. Not only the big coins were left behind: Mike said another server holding "1.2m" was still at the old host #1392, and that a wallet with 1.2m PYRK of his own was gone #1745. And on 8 January 2021 I could still see 24 ETH in the Altilly wallet that had not been stolen #2861.
My own Qredit (XQR) was lost too. XQR was Altilly's fee coin, and I had moved all my own XQR onto Altilly because I trusted its setup. On 27 December Chuck asked "is XQR safe?" and I answered "Nope" and "All lost" #1731–#1733. It was, as I wrote, "right before a swap" #1734. That XQR was what I had to start Qredit Ltd with, so the company never traded. It filed no accounts and was struck off in 2022. I believe Mike took the XQR along with the rest, but that is a belief. The chat shows only that it was lost.
Mike put the bitcoin loss at "around 31 bitcoins, the rest i have no idea" #1600. I estimated the total at about $1 million, knowing it could be more #1677. I wrote and posted the public notice. It said the system "was hacked above OS level" and that we were "not sure yet if funds are lost" #1232. I based it on Mike's reports and trusted them. The notice also said we had lost the domain, while Mike was repointing that same domain's DNS #1206, #1227. That was inaccurate.
EXMO and Livecoin were hacked in the same days, and we discussed both #1053, #1088. Mike called it "state sponsored for sure" #1054. As I remember it, I was later told that some Altilly funds went to wallets linked to those attackers. I have no addresses and no tracing report, so please treat this as hearsay. At the time it made me believe we were part of a wider attack, and I told Mike "It's not your fault" #1256.
My home address was already public through my company registrations #1579. Threats reached Chuck and me #2155–#2160, #2385. On 3 January 2021 I found that someone had been in one of our guest igloos #2372. That night two people were running through the garden with flashlights, and I called the police #2471.
The refund years
The user database was lost #1352, #1353, so we rebuilt balances by hand. Users filled in claim forms and later forwarded their original deposit-confirmation emails. Those emails were our main check #2146, #4665. We looked up transaction IDs only sometimes, and less often than my 2025 text suggested (see #3564 below). Mike sent a balances spreadsheet #1719 and a list of 137 saved assets #1757.
Many saved-asset refunds were sent in kind by Mike from the recovered wallets, about 60 coins in early April 2021 alone #4613–#4903. Some went through the projects' own developers #2145, #2149, #2518. In 2021 I had almost no cash #2805, #5602. Some assets fell short. The MRX wallets showed zero while users were still asking about MRX #4580, #4849. I do not know why, and I cannot explain it.
Not every approved user got their saved assets back, and I won't pretend otherwise. In January 2021 I did some refunds myself #3215, #3514, but most of the saved-asset keys stayed with Mike, who kept them on his own machines #1621, #3917. He did the bulk sends in one push from 1 to 3 April 2021 #4613–#4903, and by May Chuck said most approved users had been paid #4966. The rest stalled. Mike promised a program for the leftovers "tomorrow" #4875, TUSC had "not yet" gone out #4906, and Chuck kept asking him about RDD, HONK and unpaid first rounds #5951, #6432–#6433, #6876. In the end I got HONK moving and handed its keys to the dev myself #6731, #6739. Part of the blame is mine: when Chuck pushed, I put refunds behind QSLP and other work #7052, #7144, #7181. Chuck's last request to Mike to clear everything pending got no answer in the export #7421.
Our Freshdesk help desk, where claims came in as support tickets, was set up and run by Mike, who called the admin login "my login" #83, #4421. At first he paid for it and our Fastmail himself #3229, #3288. In March 2021 a card payment failed, so I gave him my own card and he used it for both services #4417, #4419, #4420. I remembered this only vaguely, but the chat confirms it. After that, keeping the service running depended on me putting money on that card. When I had none, Freshdesk was disabled #5602, #5971, #6029, and it came back once I paid #6901. Even then, my card had been charged, but the account once still showed as "inactive", with all invoices paid #6903. Chuck could use it anyway #6904, and I never found out why it showed that. It was suspended again in August 2021, and Freshworks told us it had emailed "Michael", meaning Mike, and got no reply #7345. I paid again #7319, #7357. I do not know exactly when we lost the ticket history for good; the chat stops before that happened.
When the refund work in the chat stops in September 2021, it was not finished. First-round saved assets were still pending #6876, #7421. For non-saved assets, Chuck was still building the sheets and a BTC claim page #7426, #7517. From late 2021 I paid refunds from my own income. In 2022 I sold my mining businesses; I used the proceeds first to pay back the investors, and then used my own share of the sale to pay Altilly refund users. All of it went to refunds except about $25,000 that covered my personal debt; by my records this comes to about $900,000. I know a reader cannot verify that from this site, and that even published amounts and transaction IDs could be called random payments to random wallets. People who were not paid tend to say so publicly; most people who were paid do not. The people who can really check it are the projects that were listed on Altilly and their communities, by asking their own members whether they received refunds, including for non-saved assets (Check the refunds yourself). Not everyone was paid, and the people still complaining had real grievances.
I stopped paying refunds around 2022/2023. I made only a handful after that. Part of the reason is that by then I had come to believe who Mike really was, and I watched Xeggex carry on, and I lost the energy to keep going. That is a reason, not an excuse. My own estimate is that the claims still unpaid come to around $50,000–60,000 in total, but I cannot prove that figure. Most of those claims are close to impossible to check now: the user database was lost #1352, #1353, and many of the coins' blockchains, including the old Qredit chain, no longer exist, so neither the deposits nor my payments can be looked up. Many of the claims that came in near the end were fake. I am not promising further payments here. See the Refunds page for where this stands.
What I got wrong
Governance. As CEO I let one person hold all technical control: servers, keys, backups and the database config. In 2019 Mike wrote "we are too small to worry about audits yet" and "too small to even start moving to safe storage" #215, #216. I accepted that. We had no audit and no real cold storage, and I never insisted on server access. Our public About page still told users the opposite, that our safe storage was off network in a secured facility #721. Users trusted that, and it was not true.
Trusting Mike. I knew "Mike" was not his real name #7595. He told me he did not want to use his real name because he also ran adult websites, and that it would hurt his and Altilly's reputation if people knew an adult-website owner was behind an exchange. That is what he told me; I cannot verify it. Pseudonyms were not unusual in crypto at the time, and I accepted it. I never verified who he was. I trusted him completely: in May 2021 I told him "I trust you with the hosting panel. It's not like something bad ever happened before" #5658. I was the admin of our Revolut Business account. I invited him, set up his accounts and helped him order his card #3638, #3644, #3693. Revolut asks for identity checks, but in March 2021 Mike put his off ("my passport is at the china visa office" #4415), and I do not know whether he completed it. On 4 February 2021 his card arrived in an envelope addressed to "PAUL Vernon" #3833, and I forwarded it #3960. As I remember it, I searched the name, found only a British blues musician, and let it go (my 2026 note #7585). I kept working with him until at least September 2021 in this chat #5658, #7427–#7430, and in other channels until the Solar incident in late 2022. In May 2021 he offered me "that 10k" towards licence costs for our next venture, and I accepted #5728–#5740. That was wilful blindness, and I own it.
How refunds were handled. Some of my messages look bad because they were bad. They stay in the published chat:
- #5017–#5020, May 2021. After I complained that people were only now finding their balances #5011, Chuck wrote "I can drag it out forever if you want. Im pretty good with word play", "they will feel good about it" and "Hang the carrot out front and they will follow". I replied "Go for it." #5017–#5020, knowing that I intended to repay them through the new exchange, Altfenix. There was a plan behind the waiting: since January I had talked about repaying non-saved assets with a token #2442, #2853, and the next day I set it out as an "Altilly refund token", pegged to a value, listed on the new exchange (later Altfenix) and bought back "at 1usd for example", including from users willing to take less #5201–#5203. 25% of the new exchange's fees was set aside partly for hack claims #5535, #5882. There were no funds to pay otherwise #5184, #5602. In June the plan became tokens per coin with bid markets on Altfenix #6657–#6665. Chuck also described stretching out the saved-asset rounds to buy time #5962, #6027, #6811, and I called that "a good thing, because the next solution will be better and easier for all of us" #6813. Altfenix never launched. For the people told to wait, it was still stalling.
- #6842, June 2021. To value claims, we used CoinGecko's price history for the days of the hack #6838–#6841. I told Chuck to take the lower of the day's open and close prices — "the most beneficial for us. So the lowest one" — and, "if there is a massive difference with the day before, then again, the lowest value" #6842. Chuck suggested 25 or 26 December, "whichever is better for us", and I agreed #6844–#6847. The hack fell in a period when altcoin prices were spiking, and we did not want a one-day spike to set the value. Valuing at the date of the loss is normal, but choosing the lowest of the available prices "for us" favoured the exchange over the people owed money, and I should have picked one neutral rule instead. That was my idea, and it was wrong.
- #3564, January 2021. We had thousands of claims, many sent as screenshots, so I did not check every transaction: "We will be here for another 10 years if we start checking all txid's" #3566. Instead I checked each coin as a whole: after collecting all claims for a coin, the total had to match what was left in that coin's wallet — "I make sure that the end balance matches with what Im going to refund" #3558 — and if it did not, "then its fucked up", which had not happened yet #3570. Claims without an amount were held back until we found the deposit email #3555. Within that check, I did not look at individual small claims: "anything between 50-200 usd I don't check at all" #3563, #3564. I kept no separate payout ledger beyond marking addresses with users #3574, #3575, and team members who had bought on Altilly did not have to send deposit emails #3951–#3953. Checking the totals stopped anyone from claiming more than a wallet held, but it could not stop one person's inflated claim from being paid out of other people's share, and the missing payout ledger is why I cannot show today who was paid what.
- #4029–#4032, February 2021. Our banking partner gave us a list of 139 high-risk countries, including Nigeria #4020–#4028. Most of our users were from Nigeria, and we decided not to refuse them refunds #4021, #4034–#4036. My worry was that small payments into listed countries could get our accounts closed #4028 while we were setting up a regulated business with a new banking partner #4083. For "a really pushy person", I told Chuck to "do the refund, but not by email and remove all traces" #4029; Chuck replied "Wait" / "what?" #4030, #4031. I had already done this once for a long-time user who had become very offensive: I put him on a separate list to be paid at the end and deleted the messages #4032, #4033; he was paid later. The people were owed that money and they got it. But paying the loudest people quietly and erasing the record was unfair to those who waited, and hiding payments is not how a business that wants a licence should operate.
- #2158, #2159, December 2020. When Chuck showed me a threat, I wrote "What an idiot. Let him do his thing." People had lost money. That remark, and others like it #5059, #6386, show a dismissive attitude I am not proud of.
There are other messages you should see too:
- Critics were removed. I once said not to delete their messages #2682, but I also accepted deleting messages that mentioned a class action #3929–#3934.
- I removed a dated repayment promise from our site #3418–#3421 and took other text down #1918, #7179.
- While we were trying to buy back a copy of the database from someone who offered it, I wrote "we can't say that we just bought it from someone", and I agreed to say we "recovered an sql dump" #2967–#2973. The seller then disappeared with the deposit #3037.
- I wrote "don't worry about the users… I will come up with a clever solution" #5051 at the same moment Chuck said thousands had missed the deadline #5052.
- I planned a refund token partly to "create some trading activity on it" #5201–#5203, #6807.
On 25 December I also wanted to tell users that hackers could not reach the funds #1180. Mike replied "we don't know this" #1183, and he was right. The day before, when Chuck pointed out that the public status page showed missing assets, Mike said "ill fix that soon", and nobody objected #1077–#1079. On 27 December, when Cherry confirmed that all the server data had been wiped, I wrote "Don't share this with anyone yet until I have my stuff ready" #1564, #1566.
Some private remarks read badly and stay in the chat. In May 2021, while planning a new exchange with Mike, I wrote "We managed so far with the damage control of Altilly. I can't pull this twice. Next time will be one way ticket to Russia or China" #5354. I meant that I could not survive another collapse; a minute later I wrote "I don't know what i will do to myself if it ever happens again" #5361. Readers can judge that for themselves. I also said an internal refund list was something "no one needs to know a fuck about" #3147, and I agreed that we should not tell people Altilly was not incorporated in Sweden #2164–#2167.
After Altilly
In May 2021 Mike and I planned Altfenix. I pushed for cold wallets and manual withdrawals #5666, and he agreed #5668. A demo page went up #5771, but the exchange had not launched by September 2021 #7428. In December 2021 I took a job with another project and left Altfenix to Mike.
In early 2022 Mike told me an exchange wanted to list Qredit for free and that he had checked it. It was Xeggex. About a month later he said "Karl from Xeggex" wanted him to join and might sell the exchange, which would help pay refunds faster. Mike proposed that we work on Xeggex together and approach "Karl", and he introduced me to him. I proposed that my company, Dokdo, acquire Xeggex on the condition of full KYC/AML compliance, and I announced the plan publicly in 2022. For a while the Xeggex website itself described Xeggex as "a service of Dokdo Global"; archived copies from 6 June 2022 and from September to December 2022 show this. When I asked for the backend and wallet code for an audit, Mike shared only the frontend. As I remember it, he said it was "not ready yet for an audit". I disclose all of this because it is why some people later accused me of being behind Xeggex. None of it is in the chat, which ends in 2021.
As I remember it, code for another project first appeared on a GitHub account I understood to be Karl's, was deleted, and then appeared on Mike's account. He said he had "fat fingers". Once, when he code-signed the Qredit wallet for me on a Mac, the user name shown was, as I remember, "paulv". He said the Mac was secondhand. I let that go too. I have no screenshots of the GitHub episode, so this paragraph rests on my memory alone.
In late November 2022 we found that funds had been taken from Solar (SXP), a project I led. On 30 November 2022 Solar posted a statement in the Solar validator group on Discord, titled "UNAUTHORISED BEP20->SXP SWAP TRANSACTIONS". It was not posted on Solar's public Telegram channel, blog or Twitter, which is why earlier searches could not find a public copy:

It says that on 29 November 2022 "a series of unauthorised swap transactions were detected which took place between 12th August 2022 and 29th November 2022, exchanging non-existent BEP20 SXP tokens for mainnet SXP coins", and that "In total, 1,878,477 SXP was fraudulently swapped during this time resulting from a vulnerability detected in the BSC nodes used to provide API data to the swap service." It says this "was not due to a hack or breach of security of the Solar mainnet or Solar Core", that "user funds were never at risk", and that it did "not" result "in the creation of new SXP coins". It also says: "The identity of the perpetrator is known, and the necessary recovery processes are now in motion which cannot be discussed further for legal reasons." The statement does not name anyone. That the perpetrator was Mike comes from my own evidence, the Discord screenshots below, not from the statement.
The screenshots are in my February 2025 write-up; they are my own evidence, not an official record. On 29 November 2022 at 22:45 I wrote to him on Discord: "Why did you do it Mike?" At 00:17 on 30 November I wrote: "We are not going to say anything if you can return the funds in 24hrs." At 05:43 that morning MikeO answered: "sorry man. ya i fucked up… original plan was to earn some money from trading… liquidated out of my positions on the ftx crash… only thing that is possible is to return it as i can get it." On 3 December 2022 he wrote: "I had nothing to do with the altilly hack." My goal was to get that money back. It did not come back in 24 hours. By my account, Mike repaid the full 1,878,477 SXP in 12 payments between 1 December 2022 and 19 March 2024, back to the Solar swap wallet involved in the theft. The final payments can be checked on the Solar blockchain. That money was for the Solar incident, not Altilly.
Solar repayment ledger (author's records)
| Date | SXP | Transaction ID |
|---|---|---|
| 1 Dec 2022 | 79,326 | — |
| 15 Aug 2023 | 20,000 | — |
| 6 Nov 2023 | 30,000 | — |
| 19 Nov 2023 | 50,000 | — |
| 24 Dec 2023 | 99,151 | — |
| 22 Jan 2024 | 100,000 | — |
| 24 Feb 2024 | 200,000 | — |
| 18 Mar 2024 | 300,000 | f3669e37529613b3404e05aa392957f85f3399d69a07681545fc81afbc2f5125 |
| 19 Mar 2024 | 250,000 | db2d920119b1cfdb0cfc18ead64d2c2e53b45268da68b3409f8c354750adf6f5 |
| 19 Mar 2024 | 250,000 | 7db5a21493e3eb942de5d506d9932b197ecaf8b0063fb5e3ada8a9c076bf9153 |
| 19 Mar 2024 | 250,000 | a22584020653038e3871bb6a0c8b45dc96ecfc86d0ed3b57baddf5dea455a0b0 |
| 19 Mar 2024 | 250,000 | 8fa26f4671daf7fa0b3f7e04f8e119544c23b5b6f81dd71d79988410d0cc07c7 |
| Total | 1,878,477 |
Receiving address (the Solar swap wallet involved in the theft): SdiefkN6SmFiRLUNDjuGMKUu89Tvtx4NwX
At about the same time, around November 2022, I came to believe that Mike was running Xeggex himself, that "Karl" did not exist, and that Mike was Paul Vernon. These are my beliefs. No authority has confirmed any of them. I cancelled the Dokdo acquisition. On 3 December 2022 Mike asked me on Discord, "should I start removing references to Dokdo on Xeggex?", and I answered "Yes, please". A screenshot of that exchange is in my February 2025 write-up; it is not part of this chat. The business relationship ended in late 2022, and I no longer trusted him. After that, I stayed in contact with him for one reason: getting money back. First the Solar funds, which he repaid in full by 19 March 2024, and later a promise he made to fund the remaining Altilly refunds for non-saved assets and to pay Chuck. He never followed up on it. In 2025 I wrote that after he repaid "we never spoke again"; this paragraph is the more complete account.
While we worked together, Mike had his own project inside my Hetzner account, with its own API key. He could create and manage servers in that project #5937, #5941, #6040–#6042, but he had no access to the rest of my account. That is how Altilly's new servers were set up in 2020 #1119, #1121, #2586. After we split up in late 2022, I found out that he was also using that project for Xeggex, including a Solar node for Xeggex. I told him to move everything out of it. He finished in January 2023, and I deleted the servers.
I did not go public in 2022. Solar was a legitimate project in the top 200 on CoinMarketCap, and I did not want it linked to someone I believed was Paul Vernon. I also had no proof that Mike ran Xeggex, and I was afraid of him. I had a young child and a family to protect, and Solar to run. I believed Mike was Paul Vernon, whom a US court had placed in fugitive status, and I feared that he might have access to large funds. In March 2022 bitcoin from the 2014 Cryptsy theft started moving, as the blockchain analysis firm Elliptic reported (Elliptic). Nobody has shown who moved those coins; my fear that Mike might have access to them was only a fear. I also remember Mike once saying, in a private conversation, that he could make someone disappear. It is not in the chat, I cannot prove he said it, and I do not know what he meant. I mention it only because my memory of that remark frightened me, and it still does. I did not want to confront someone I believed was a wanted fugitive. Above all, I expected that nobody would believe me. The business relationship had ended, and the only contact I kept with him was about getting money back. My expectation turned out to be right. When I did go public in February 2025 and said that I believed Mike, "Karl" and Paul Vernon were the same person, many people did not believe me. On Reddit they wrote that I was "the perpetrator" and "Karl" myself (r/pepecoin, r/pepecoin), and that I did not "pass the sniff test" (r/pepecoin). More of these reactions are on the home page. That disbelief is exactly what I expected in 2022. I also expected that going public would hurt me more than it would help anyone, and in 2025 that happened too: after my statement, people came to my properties, and I moved house because my address was public. These are my reasons, not an excuse. I have to be honest about the cost. From late 2022 I believed Mike ran Xeggex, and Xeggex kept taking deposits for more than two years while I said nothing. I did not warn its users. I put getting the Solar money back, and keeping Solar away from this, ahead of speaking out. I also doubt that a warning from me would have stopped many people. When I went public in February 2025, Xeggex had already frozen withdrawals. Even so, when its website came back in March, people kept using it. Users asked on Reddit about buying there again (r/pepecoin), and in May 2025 a coin project still listed Xeggex as one of the places to trade its coin (r/BonkcoinPoW). In 2026 the Xeggex domain came back with a "refund" offer, and an old user wrote that he paid it a deposit, despite warnings all over Reddit (r/Crypto_Scam_Exchange). I cannot prove that an earlier warning would have changed nothing. People who lost money on Xeggex may still blame my silence, and I understand that.
In February 2025 Xeggex halted withdrawals, blaming a hacked CEO Telegram account and then a corrupted database. People started messaging me to ask who was behind Xeggex, and that is when I went public, with the write-up I correct at the top of this page. On 27 June 2025 Xeggex announced it was shutting down.
What I know and what I believe
What is documented:
- The incident was 23-25 December 2020. We estimated the loss at the time at about $1 million #1033, #1103, #1677.
- Mike ran the Cherry servers, and I had no access #1492, #1493, #1504, #1508.
- His explanations changed over those days #1056–#1060, #1103–#1132, #1289, #1504.
- Mike wrote [email protected] and said the domain history "probably has my name" #1326, #1328. That domain is one letter off satotechltd.com, whose WHOIS record lists Paul Vernon / Project Investors Inc #7577. I believe it was a typo, but that is my reading.
- Mike's Revolut card came to my address in an envelope addressed to "PAUL Vernon" #3647, #3833, #3960.
- The GitHub account "mrmikeo" (MikeO) is the account used for Altilly development, with the email [email protected]. On 1 April 2024 it made a commit to Xeggex's official GitHub organisation (xeggex/hummingbot, commit d1479b80fe).
- The Xeggex domain (August 2021) and its GitHub organisation (September 2021) existed before Mike told me about "Karl".
- UK Companies House lists a director registered as Michael O'Sullivan for XEGGEX SOFTWARE SERVICES LTD (dissolved 31 December 2024) and XGX SOFTWARE LTD (dissolved 26 August 2025) (Companies House). The register does not verify identities. I am convinced "Michael O'Sullivan" is an alias Mike used, possibly with a false passport. I cannot prove that myself; it needs to be investigated by law enforcement. Until it is, and only as a precaution, I am not accusing any real person who happens to share that name.
- Paul Vernon founded Cryptsy. In 2017 a US court entered an $8.2 million default judgment against him in the Cryptsy customer class action, after he did not defend it. A 17-count federal indictment was filed in Florida in 2019 and made public in January 2022. The court placed him in fugitive status in 2019. He has not been convicted, the charges are allegations, and no filing in that case mentions Altilly or Xeggex.
What I believe but cannot prove:
- That Mike is Paul Vernon.
- That "Karl" was Mike, and that Mike was behind Xeggex.
- That the Altilly hack may not have been an outside attack. I have no evidence of what happened on Cherry's side, and Mike denied any part in it on 3 December 2022. At the time, Altilly's own public statement, which went out while I was its public face, said that "suggestions of the attack being an inside job are totally untrue and unfounded". I held that view then, and I changed it later.
These beliefs formed from late 2022 onward, about two years after the Altilly incident. In the notes I added to the chat #7572–#7575, #7577, #7579–#7598, some of them are written as facts: "Paul Vernon 👌" #7585, "orchestrate" #7587, "10k out of nowhere" #7592 and "Mike/Paul" #7595. Please read those notes as my beliefs. My notes about the house "months after the hack" #7589–#7592 also leave out what the chat shows: Mike was selling another house at the time #5471, #6163–#6166, and the furniture for the new one had been in a warehouse "for a year" by September 2021 #7431. The chat does not show how the new house was paid for. No court or authority has confirmed that Mike is Paul Vernon, that "Karl" is Mike, or that Mike took the Altilly or Xeggex funds.
A community member once told me about a phone call that I took as confirmation. Silence on a phone line proves nothing, and I no longer rely on it. I will not publish anyone's address, phone number or photos, and I ask nobody to contact, confront or visit anyone. In 2025 I did not keep to this, as I said above, and I am sorry for it.
About the missing messages
663 message numbers are missing from the published export. Here is what I can and cannot tell you:
- Messages I removed. I removed some myself because they contained customer data, data about unrelated third parties, or data about early team members #7598. At least one gap, #7582, comes after I became owner, so that deletion was mine.
- Messages others may have removed. Mike could delete his own messages at any time before his account was deleted. Chuck created the group and was its owner until 28 September 2026 #7578, so he could delete messages too, as could any admin.
- What I cannot see. I only became owner of this group on 28 September 2026 #7576–#7578. Before that I had no admin rights in this group; like every member, I could delete only my own messages. I cannot see what was deleted, by whom, or when.
Some gaps fall at sensitive points, around 24 December #1055, #1058, #1061–#1064 and around the [email protected] email #1323, #1325, #1327. Customer data does not obviously explain those gaps, and I understand why they raise questions.
I did not remove messages because they make me look bad. Those messages are still there #2968, #4029, #5020, #6847. I would welcome a comparison with a full export from any other former member. The unredacted chat, including customer data, is available to authorities.
What I have given to authorities
In early 2025 I reported what I knew to the FBI and to the U.S. Marshals Service. The Marshals opened a two-way dialogue and gave me a tip reference number, 777-W77728. They never responded in it beyond that number. That number is a reference for my report. It does not confirm any investigation or any of my beliefs. The FBI has not given me a case number. As far as I know, no authority has made a public statement about Altilly, Xeggex or Mike.
I can give any authority that asks (contact me on Telegram at @nayiem):
- the unredacted management chat;
- the "PAUL Vernon" envelope photo;
- the Discord screenshots from November and December 2022, and Solar's 30 November 2022 statement;
- the other material I have mentioned on this page.
That is where this belongs. I made real mistakes as CEO and in how refunds were handled, and I have tried to own them here. I did not take the users' money.