18-Year-Old Hacker's Boastful Discord Display Leads to Uncovering of $19 Million Theft Case

Odaily星球日报Publicado a 2026-05-13Actualizado a 2026-05-13

Resumen

An 18-year-old hacker from the U.S., Dritan Kapllani Jr., has been exposed by on-chain investigator ZachXBT for his alleged involvement in multiple cryptocurrency social engineering attacks, with total funds stolen estimated at $19 million. The case gained attention after Dritan inadvertently revealed his involvement during a Discord voice call in April 2026, where he screen-shared his Exodus wallet containing approximately $3.68 million to show off his wealth during a "Band 4 Band" argument. Tracing this wallet address led investigators to uncover its connection to a major theft from March 14, 2026, where 185 Bitcoin (worth around $13 million at the time) was stolen. Approximately $5.3 million from that heist was funneled into Dritan’s wallet. Further analysis linked the same wallet to over $5.85 million from other social engineering attacks dating back to 2025. While Dritan has not yet been formally charged, he is identified as "Co-Conspirator 1" in recently unsealed court documents related to the 185 Bitcoin theft case. Another individual, Meme coin KOL yelotree, is also implicated for allegedly assisting with money laundering through a car rental business. Dritan, who had been living a lavish lifestyle and was previously seen as untouchable within hacking circles, turned 18 recently, making him legally accountable. His previous "immunity" has ended as law enforcement closes in.

Original | Odaily Planet Daily(@OdailyChina)

Author | Asher(@Asher_ 0210)

Last night, on-chain investigator ZachXBT exposed an 18-year-old hacker from the United States named Dritan Kapllani Jr. According to the disclosed information, this young man named Dritan Kapllani Jr. is suspected of involvement in multiple social engineering attacks targeting cryptocurrency users, with an estimated total amount involved of approximately $19 million. Although he has not been formally charged yet, he has already been included as a 'co-conspirator' in U.S. judicial documents.

This case quickly attracted attention, not only because of the massive amount involved but also because its starting point was highly dramatic—a voice call meant for showing off wealth became the breakthrough for the entire investigation.

Just Showing Off Wealth Once on Discord

On April 23, 2026, a dispute that occurred in a Discord voice channel kicked off the incident.

It was a voice call known as 'Band 4 Band,' where participants compared their 'strength' in the most direct way—by showcasing their respective assets. The atmosphere soon shifted from teasing to rivalry. Driven by this sentiment, Dritan, to prove he was richer, directly started screen sharing and displayed his Exodus wallet interface, showing a balance of about $3.68 million.

A few weeks later, this scene was revisited. On-chain investigator ZachXBT used this address as a starting point, linking together what were originally scattered transactions one by one, gradually revealing a longer funding trail.

A Cache of 185 Bitcoin Theft Funds Surfaces

Going back to March 14, 2026, a social engineering theft involving 185 Bitcoins occurred, valued at around $13 million at the time. The funds were quickly transferred out of the original address and swiftly entered an on-chain distribution system.

As early as the next day, about $5.3 million of it was transferred into the wallet Dritan displayed during the Discord voice call (address: 0x4487db847db2fc99372a985743a26f46e0b2bba6). Over the next few weeks, this approximately $5.3 million was continuously split, transferred through multiple addresses, and sent to various destinations. By the time of that April 23 voice conversation, about $1.6 million had already been further moved.

Not the First Time Involved in Crypto Theft

Tracing back from the wallet address Dritan displayed, it quickly became apparent that the funds in it didn't only come from that 185 Bitcoin theft.

According to on-chain analysis, the funding sources for this wallet can be traced back to multiple social engineering thefts in 2025, totaling over $5.85 million. Different victims, different times, but after the funds were transferred away, they would be rapidly split and then moved on through a string of addresses, following a very similar pattern. By matching these funds one by one, it was found that many transfers eventually landed in this wallet address Dritan displayed.

It's worth noting that Dritan once had a 'Band 4 Band' dispute with hacker John Daghita (Lick). Lick was later arrested for allegedly stealing about $46 million in U.S. government funds, and in a later-deleted Telegram post, he had publicly shared Dritan's old address (address: 0x97da0685dbba50b4cbabb0ca9e8336f4fbe41122). Currently, this move appears more like an act of retaliation.

Judging from on-chain behavior, this old address showed a highly consistent pattern with the funds flow of the wallet Dritan displayed in terms of fund splitting methods, transfer paths, and subsequent destinations, and is therefore believed to be used by the same controlling party.

Judicial Documents 'Name' Him for the First Time

It wasn't until May 11, 2026, that this on-chain funding trail was officially confirmed for the first time in judicial documents. That day, the criminal indictment against Trenton Johnson was unsealed. He was charged for his involvement in that 185 Bitcoin theft case and faces up to 40 years in prison.

In the indictment, a key co-conspirator is labeled as 'Co-Conspirator 1 (CC-1),' and the on-chain analysis community has already pointed this identity towards Dritan Kapllani Jr. Although Dritan has not been formally charged yet, he has transitioned from a 'linked address' in on-chain inference to a 'co-conspirator structure' in the judicial narrative.

Additionally, the same document mentions another individual involved—Meme coin KOL yelotree, who is accused of assisting in money laundering through his car rental business in Miami and faces up to 30 years in prison.

Turning 18, The Dissolute Life Comes to an End

Previously, Dritan had been living a life of extravagance for a long time, frequently posting related content on Instagram and interacting with other hackers via Telegram. In hacker circles, he was once considered to have a kind of 'protagonist aura'—several groups associated with him (like ACG, 41 / RM Boyz, etc.) were successively dealt with by law enforcement, yet he himself remained untouched.

But as he turned 18, this 'aura' ended, and his past actions began to be pursued legally.

Preguntas relacionadas

QWho exposed the 18-year-old hacker Dritan Kapllani Jr., and what was the initial trigger for the investigation?

AThe hacker was exposed by blockchain investigator ZachXBT. The investigation was triggered by Dritan showing off his Exodus wallet (with a balance of about $3.68 million) during a 'Band 4 Band' Discord voice call on April 23, 2026.

QWhat is the total estimated value linked to the social engineering attacks involving Dritan Kapllani Jr.?

AThe cumulative amount linked to the social engineering attacks involving Dritan Kapllani Jr. is approximately $19 million.

QHow did a specific 185 Bitcoin theft connect to Dritan's wallet, and what happened to the funds?

AIn the 185 Bitcoin theft on March 14, 2026 (worth about $13 million at the time), approximately $5.3 million was transferred into the Exodus wallet Dritan later showed off. This money was then split and moved through multiple addresses, with about $1.6 million transferred out before the Discord call.

QWhat is Dritan Kapllani Jr.'s status in the US legal case (Trenton Johnson) related to the 185 Bitcoin theft?

AIn the unsealed criminal complaint against Trenton Johnson, Dritan Kapllani Jr. is referenced as 'Co-Conspirator 1 (CC-1).' While he has not been formally charged yet, his role has moved from a blockchain-inferred association to being officially identified as a co-conspirator in the judicial narrative.

QAccording to the article, why did Dritan's perceived 'main character halo' in the hacker community end?

ADritan's perceived 'main character halo' in the hacker community ended because he turned 18 years old. Upon reaching legal adulthood, his past actions became subject to legal consequences and prosecution.

Lecturas Relacionadas

AI Relay Stations Spark Heated Debate on Zhihu: Behind Cheap Tokens, What Are Users Really Worried About?

A discussion on Zhihu about "AI relay stations" shifted the niche developer topic of "cheap tokens" into broader user awareness. Users moved beyond simply questioning the legitimacy of these services to focus on practical concerns: Where do cheap tokens truly come from? Is the model being accessed the real one? Can relay stations see prompts, code, and API keys? For occasional users, are the risks worth it? The core debate centered less on price and more on trust. A primary worry is model authenticity—the risk of "model swapping," where users paying for a premium model might be routed to a cheaper one, creating an information asymmetry. Others argued that cost comparisons matter; while cheaper than official pay-as-you-go APIs, relay stations may not be the lowest-cost option versus subscriptions, domestic models, or free tiers, making user needs assessment crucial. Speculation about token sources ranged from legitimate bulk discounts to gray-area methods like account sharing or exploiting regional pricing. This opacity makes risk assessment difficult for users. Data security emerged as a critical concern, especially for enterprise use. When processing sensitive information like code, contracts, or client data, the inability to verify a relay station's data handling, retention, or access policies poses significant compliance and confidentiality risks. The evolving consensus suggests relay stations can be used cautiously for low-sensitivity, disposable tasks (e.g., summarizing public info, simple translation). However, they should not be the default for sensitive, professional, or production workflows involving proprietary data, Agents, or automated systems. Recommendations include avoiding large prepayments, not relying on a single service, using test prompts to monitor quality, anonymizing data where possible, and keeping official channels as backups. Ultimately, the discussion framed tokens not just as a billing unit but as a measure of real cost encompassing price, model integrity, data security, and service stability. The popularity of relay stations highlights user demand for affordable access, but the debate underscores a key trade-off: the savings from cheap tokens may come at the price of trust, transparency, and control over one's data and AI experience.

marsbitHace 13 min(s)

AI Relay Stations Spark Heated Debate on Zhihu: Behind Cheap Tokens, What Are Users Really Worried About?

marsbitHace 13 min(s)

In-Depth Research Report on TradFi: The Convergence Wave of Crypto and Traditional Finance

In 2026, the crypto industry is undergoing a profound infrastructure-level transformation—TradFi assets are migrating on-chain at an unprecedented pace. According to CoinGecko's Q1 2026 report, the total value locked (TVL) of tokenized real-world assets (RWA) has surpassed $31 billion, a nearly 4x increase from $7.8 billion at the beginning of 2025, with the sector’s aggregate market capitalization reaching $19.3 billion. Among these, the market cap of tokenized stocks surged from $2 million to $486 million, with Q1 spot trading volume reaching $15.1 billion—a single quarter already surpassing the entire second half of 2025. RWA perpetual contract Q1 trading volume reached a staggering $524.8 billion, far exceeding the $313 billion for all of 2025. Meanwhile, BlackRock's BUIDL fund has reached $2.3 billion in scale and has filed for two new tokenized funds, signaling that the world's largest asset manager's tokenization strategy is evolving from pilot to product suite expansion. HTX, as a core participant in the crypto exchange sector, officially launched TradFi perpetual futures products including NVDA, AAPL, MSFT, META, and SPY in 2026, enabling crypto users to gain 24/7 trading access to core U.S. equities. Boston Consulting Group predicts that global tokenized asset scale could reach $16 trillion by 2030, while McKinsey offers a conservative estimate of approximately $2 trillion. The on-chain migration of TradFi assets is no longer a "future narrative" but a structural transformation unfolding in real time, as crypto exchanges evolve from single crypto asset trading platforms toward "multi-asset-class trading infrastructure."

HTX LearnHace 16 min(s)

In-Depth Research Report on TradFi: The Convergence Wave of Crypto and Traditional Finance

HTX LearnHace 16 min(s)

Blocked Its Own Treasure, WeChat AI Steps Up

Tencent's stock surged over 10% on June 2nd amid reports that WeChat, with 1.43 billion monthly users, is finalizing tests for a native AI Agent. The reported feature, accessible by swiping right from the main interface, allows users to issue commands in natural language. The AI then decomposes tasks and automatically calls upon relevant Mini Programs within WeChat to complete actions like ordering food, booking tickets, or making payments, creating a closed-loop service execution system. This strategic shift follows the internal conflict and subsequent "blocking" of Tencent's standalone AI app, Yuanbao, by WeChat for violating sharing rules during a 2026 Spring Festival promotion. The incident highlighted a lack of internal consensus and exposed the weakness of competing in the standalone AI assistant arena against rivals like ByteDance's Doubao (345M MAU) and Alibaba's Qianwen. The new WeChat AI Agent aims to leverage WeChat's unique assets—its massive user base, standardized Mini Program APIs, WeChat Pay, and identity system—to move from simple content generation to actual task execution. Analysts note this changes the competitive landscape from model benchmarks to which AI can connect to more real-world services. However, success depends on key variables: the capability of Tencent's underlying Hunyuan model, managing massive inference costs, and redesigning incentives for Mini Program developers whose traffic might be bypassed. The move is seen as an attempt to keep user service intent within WeChat's ecosystem as AI begins to redefine how users access services.

marsbitHace 1 hora(s)

Blocked Its Own Treasure, WeChat AI Steps Up

marsbitHace 1 hora(s)

ByteDance Adopts Arm CPUs, Jensen Huang: So Sad I Didn't Buy Arm

**Summary:** At Computex 2026, Arm CEO Rene Haas announced that ByteDance and Oracle have adopted Arm's self-designed Arm AGI data center CPU. The company expects significant revenue growth from this product, projecting $20 billion in demand for the 2027/2028 fiscal years. Haas noted that restricting AI-capable CPUs from the US to China is nearly impossible due to their widespread applications. Arm's stock has surged dramatically this year, notably rising 16% after NVIDIA's Arm-based Vera CPU and RTX Spark announcements. A highlight was the informal, humorous on-stage conversation between Haas and NVIDIA CEO Jensen Huang. Huang joked about NVIDIA's failed attempt to acquire Arm and playfully lamented selling his Arm shares. Both executives showed a clear sense of camaraderie and shared regret over the missed merger. Key technical topics were discussed: 1. **AI PC Design:** Huang explained NVIDIA's RTX Spark superchip (with a 20-core Arm CPU) is designed for future AI agents that will autonomously run and use tools on PCs, blending local and cloud processing. 2. **Agent vs. OS:** Huang emphasized the operating system remains crucial, as AI agents rely on its APIs and tools to function. 3. **Growth Constraints:** He identified the shift to "useful AI" that generates profitable tokens as a primary driver for immense, almost limitless, computational demand. Haas outlined Arm's strategy across PC and data centers. For PCs, Arm collaborates with partners like NVIDIA and MediaTek, offering its compute subsystem (CSS) for custom SoCs. In data centers, its Arm AGI CPU (built on TSMC's 3nm process) has gained major partners including OpenAI, Meta, and now ByteDance and Oracle. Arm presented a multi-year roadmap for its in-house CPU line. The article concludes that while GPUs dominated the AI training race, the explosion of AI agents is shifting significant focus to CPUs for inference, state management, and tool orchestration. The industry is trending towards vertical integration, with companies like cloud providers designing chips and chip/IP firms offering full solutions, all competing to deliver more efficient computing per watt.

marsbitHace 1 hora(s)

ByteDance Adopts Arm CPUs, Jensen Huang: So Sad I Didn't Buy Arm

marsbitHace 1 hora(s)

Trading

Spot
Futuros
活动图片