Evo Admin Backend set-up on local server from March 17th Image http://infotombjhy7tcrg.onion/66fhf.jpg http://infotombjhy7tcrg.onion/p6dt9.jpg
Chat log from the past few hours http://pastebin.com/a9FBaR82
Email is being sent now, will post proof
Calm your tits Mis-calculated the time from my own timezone, oops. Sorry I'm late, get ready, documents are being forwarded in 5 minutes, and I will provide proof. Evidence of all* claims will also be added ASAP, waiting for a response also from Verto as he knows I am proceeding.
*all claims that aren't going to doxx anyone.
I'm not full of shit, looks like some coins could be making a move soon Either that or they are infact trying to buy time to pull something off against me, I have been sent 2 dox upto now which is apparently me, both incorrect. They have until 2PM (EST) to sort it out, in the mean time I'll release proof, I want to get this over with now after giving them the 24 hour timeline, but if there's still a chance of the coins being returned or some of them atleast, then I'm willing to wait a little longer and I will confirm the password salt-hash soon since everyone are completely paranoid off their tits right now.
If any top level Vendors want to come forward, I can give you great proof of everything.
PRE 24 HOUR UPDATE Received a new offer, this may actually go the right way. Contacting people to put this in place and will post proof ASAP. Not sure if they are trying to buy time, but information will be forwarded to Law Enforcement if there's any sign of bullshit in the next 30 minutes. Once this is done I will proceed to release EVERYTHING. Please bare in mind database will be redacted with truncated tables to prevent sensitive information (plain text PMs) etc. from being released and endangering other users.
Edit I have a server purchased in the case that this works out with the Evo site up and running on it, as it was on 17th March at around 9AM (EST). Onion will be set-up as soon as I know this is going ahead, will update further and have contacted /u/gwern for verification.
Update Received 2 death threats and new pay-off amounts to be silenced, all chat logs will be placed into paste bin soon along with screenshot links.
Proof, more to come http://pastebin.com/4Hrjs34i
1000 Sample Selection of Vendor User/Password Hashes released, salts will not be released to protect them. More stuff to come in the next few hours, however I haven't slept so may be tomorrow morning, if I hear nothing more from Verto after 24 hours, everything goes public. If the database dump is against any rules, please let me know and I (or you) can remove the link immediately, I couldn't find anything implicitly against it whilst skimming.
** Following further leads and compiling evidence **
First of all, I wish to comply with all rules of this sub and will NOT be posting any sensitive information relating to any doxx here.
Kimble, Verto and NSWGreat are amongst many previously involved with Evolution who will know exactly who this is. Considering a lot of my money was stolen in the inevitable exit scam from them, which I assumed I would have had time to warn people about before it happened, but to tell you the truth I haven't been online for the past month or so.
I posted a thread calling them out as all means of contact with either Verto or Kimble now seem to be dead. My thread was quickly removed and then the /r/EvolutionMarket subreddit was made private.
I have gathered as much information as I can to add to the large paper trail I am in possession of already. The separate staff mirror server was still active until around 2 hours ago.
Deposits for small withdrawals were being allowed through temporarily over the past few days depending on certain parameters, vendor level etc.
A function was added 3-4 days ago to prevent ALL withdrawals of over 5BTC indefinitely.
The amount which "NSWGreat" estimated as their total takings is quite a bit out from what I could see in the Admin back-end. They have also been stealing escrow funds that were in dispute for the past few months, maybe longer by telling both the Vendor and Buyer that they had favored the dispute to the other, meaning that the funds were left unclaimed for them to take.
Plain text (Unencrypted) conversations were available on the server between Verto and NSWGreat and I believe he genuinely wasn't in on the whole theft, as he asked for answers on the withdrawals and it seems he wasn't paid anything from it unless it was done manually. He HAS lied however in regards to his own story on the situation and his dox was posted in the Evo sub shortly before it went private too, this is the CORRECT dox and I assume he will not be posting here again any time soon. He doesn't have to worry about me because he was good to me personally in the past and I have nothing against him now, other than him being a piece of shit trying to attempt a pathetic exit scam on Agora post this fiasco.
Now, Verto. I don't have much information regarding him, other than the potential NEW IDENTITY he used to flee his country of residence. Other than that I don't have much which isn't encrypted.
Kimble however, now Kimble is quite the moron. Lots of unencrypted conversations which lead me to personal social media accounts, that were deleted 2 days ago. The problem with that is I have looked into Kimble before this and known her identity for a while. Because of this I also have linked relatives accounts and just yesterday there were best wishes directed to Kimble on their "trip" they were taking. It looks as if Kimble is passing it off as a 2 year vacation to them and flew out yesterday from an Airport that I may soon disclose if both of them do not comply.
If you both do not come forward now and speak (you know where to reach me outside of Reddit), then I will proceed to first, unwillingly, provide all information to relevant Law Enforcement and your dox, Evolution Source Code, Redacted SQL Dump from 17th March and also unencrypted chat logs will either be released publicly (not here as I have mentioned, due to sub rules) or I will sell them off for no more than my losses from your disgusting theft.
Come forward now, reach out to me, put this right. I have a close enough figure to your overall takings from this and what I am encouraging you to do, is to place ALL coins BACK into the Evolution hot wallet and I will host the site on a fresh server for the next few days so that I can release all Escrow funds and withdrawals. I am being GENEROUS with the option to do this, as I will allow you to keep anything then left over by anyone that hasn't returned to claim their funds. This is a MORE THAN FAIR offer.
Heads up to any other Market Admins that see this, when you hire a programmer to fix your own security holes, don't fucking cross them and give them a notice before fucking them off with no final payment. All's I am going to say is, backdoors galore and I left the final vulnerability I found for you WIDE open in the final revision of the auth module, well done Verto, you piece of shit.
Don't even think of offering me any money now, although all I want is my own money back, it is necessary that you do the same for the whole community if you want any compliance from me. You have 24 hours to get in contact with me by any means necessary before I begin to take further action, as the time ticks by your ass hole will begin to gape as you get closer to being locked behind bars.
Also, anyone such as Deepthroat, if you aren't full of shit, feel free to pass on any extra information you have. I have a potential current location, and I believe (cannot prove) they have both traveled to the same destination.
Fresh Key:
-----BEGIN PGP PUBLIC KEY BLOCK-----
mQINBFUKySwBEADTAErUVeGAee0eAadHuo4/LSS0XMWSRvYVUgzrF3FHxx+C4jVd
zPVZSC3EWYYAh1cQaByZirsfJt16Lx84Ae6RhxlsriAuIdzdvZRmWsGPCI17wENg
IUBKVfuDyVxsjKZMISg7i/wukvblKyVyQKZ/E2YELHYY6Z4HHiO9M3acjFeYi8Gw
6u+0Wl1JDPxdtrMR1luSU8EMPQck7tcBxEXeWxMKsiftcD9dr9P+nKmsmab1gAOT
PsudvJoo7IA8jeW4Ia04jWsu/TZUsDWjx9DqHP1KJqxLz0pnUsnM0I7zZEkLyDEl
7nvZNpDPWVgPxsbrs0Huu/4vq+xbbVygm8nDv2F0dG7nGwdPj/tuJYclWhqkkSrY
TFF/uVM2TxXFXWOYAruaPSF/Yqj9x/U2FCjOfRutQ0yDqBSK7W95WNNUJBp9vAnM
J7eTbOs92qsQIysANwI/sb9DCczIjqNDnE54uzxEDOaYWr2EvTRYqHWSG9wsJ6Ne
wUcRDEBZYd8O7D2FbDowToXl5lyZ2lVYHiNGpZvjZii2jLQCTh84116RNlVoKfIu
Rzyhh9fyr/hfuWyKawyc9DBUHwbBkd3d579ykkqcR0BStVvX1wxii4XdEDl+BL10
1f+rzmK2Btdjibfz0i8J2J+DcBHnEqEPu7FYUIouyTMcNBZHyEFlE9KpcwARAQAB
tBhaIC0gTCA8ei1sQGhpZGRlbi5vbmlvbj6JAjkEEwECACMFAlUKySwCGw8HCwkI
BwMCAQYVCAIJCgsEFgIDAQIeAQIXgAAKCRAg5CE6IOCwfR5mD/9QfyF4qrM12rgp
6BMuboZglH6aHC4Ek5RlHQQKuUI93aArBVHY9IZDs8HyC+gJOTbKe+k9H5CkJjJ/
OayZopcj4QXrc5+CvKIk4aPP4E+83A5vOrRRy69V0VNGWAF6M+33r1yd+pQo+vB+
N8+LR1uVNAoMIuDeNRLv/rR5BOlGhCXsrui9H5h7Xd3TS2DfTL10uRzDR9QAS+CK
fA7CLJydeeNLZiJZqf0mTkSYp2l7xjPSHA991B9JvgGTUL1Vpls4ugunYsv5yAmk
Xym5dgYlYYhau5ZDlSztMe7WEVJ6dKpkKxa9v0taUi1pScnEcRIKI0QP9A8UXmON
eOPAwKs6bkYHEdyp3tm+jf2SwOfuuPn9zysjU/V1daBZlX6607WHaa+/ctQDbfH3
KsYLiuInGkLWf1btNQNT14+wm2a9k8vAZlOGcMtLBUAo8o8IEYnMmJUX9NHDzTGu
gRXePZNaiRTjBgGPqln/9gYlzzJLO71W8Z8rDQzzGU7dPfSGfLhavryGDgZNDwU+
rgK49ivCtl1Q6yxXN+jn3+0HROk9wWeF9lGjNUpb0rS/dEoUIOn8huaLme3e+NzT
soPauWt2FSd51aFBuH8z7Ms7vcfAf6GVSPHqOlxoXmZUT6c6GA6WSa8a8Iz6sQxR
TaCmXBNfRMisiuukU771t+8ypq0feA==
=0+hp
-----END PGP PUBLIC KEY BLOCK-----
Quick Update: I know a lot of you are skeptical, but this is the real deal and I am following all leads as best I can and I didn't wish to release as much info as I did to be honest even though there isn't much there.
In the past 2 hours, I have been in contact with someone who I believe to be a third party in this speaking on their behalf as everything seems to add up, I will continue correspondence and try to confirm everything. I have also had a pay-off offer from him, which I happily declined, it was more than what I lost also. Received a lot of offers to buy the source code, all of these offers will be respectively declined too, it will be made public after their time window runs out.
Any journalists looking to contact me and can't understand PGP, I will not speak to you any further, you can make a big story about this once it's all in the open, I will be updating here every few hours as things develop. Another correspondent has made some strong claims which I will follow up to confirm.
Please wait and I will provide hard evidence very soon along with verification of who I am. An old Evo PR Moderator has PM'd me and I will speak to them soon too and see what information they have available, any old chat logs etc.
One more thing No, of course I couldn't guarantee they would see this, but it is in the public eye and I have tried to reach out to them through other channels and also had no response there in the last 24 hours, I thought making it public would be more of a shock to them and I thought about it from my own point of view, I think I would definitely take a look in the sub, forums etc to see how everyone was freaking out after what I had done, I have to grab at anything to accomplish this here, it may be a lost cause, of course I could be full of shit or have incorrect info that has been left as a breadcrumb trail for someone like me or LE to follow into a hole.
In the case of censoring z-l@sigaint.org
Update 7:30AM (EST) I have been in further contact with some-what reliable sources, but cannot prove anything from them, a lot seem to be LE trying to get information.
Interestingly I have had a lot of messages from vendors who lost out offering me percentages of their losses if I manage to pull this off, I find this very kind and I am greatful, however I don't think it would be best for me to accept anything under the circumstances, however tempting it is. I really appreciate everything though!
I can confirm I have been in contact with Verto, he has verified his identity from specific questions regarding my work for him. He seems to be very confident that he is pretty much untouchable, however Kimble is definitely in the same location as him right now, who's identity I have. I'm looking for sources within the country I believe them to be and I am looking into various options if they don't budge as they seem to be trying to "call my bluff" as such, believing that I won't take action after all this.
Will be confirming hashes later with /u/gwern if he is willing to do so and as this deadline closes I will release screenshots, chat logs and eventually the source code + Kimble's doxx elsewhere from here. Timeline may be overstepped slightly if I feel more can be done, handing evidence to Law Enforcement is what I'd like to think of as a last resort, because then the coins are definitely lost forever.
Edit New discussions of big sums coming in now, if all else fails may have to pay as many people back as I can prove from withdrawals up to the morning of the 17th. Will keep everyone posted.
A faint hope for justice blossoms... +1