18-Year-Old Hacker's Boastful Discord Display Leads to Uncovering of $19 Million Theft Case

Odaily星球日报Опубліковано о 2026-05-13Востаннє оновлено о 2026-05-13

Анотація

An 18-year-old hacker from the U.S., Dritan Kapllani Jr., has been exposed by on-chain investigator ZachXBT for his alleged involvement in multiple cryptocurrency social engineering attacks, with total funds stolen estimated at $19 million. The case gained attention after Dritan inadvertently revealed his involvement during a Discord voice call in April 2026, where he screen-shared his Exodus wallet containing approximately $3.68 million to show off his wealth during a "Band 4 Band" argument. Tracing this wallet address led investigators to uncover its connection to a major theft from March 14, 2026, where 185 Bitcoin (worth around $13 million at the time) was stolen. Approximately $5.3 million from that heist was funneled into Dritan’s wallet. Further analysis linked the same wallet to over $5.85 million from other social engineering attacks dating back to 2025. While Dritan has not yet been formally charged, he is identified as "Co-Conspirator 1" in recently unsealed court documents related to the 185 Bitcoin theft case. Another individual, Meme coin KOL yelotree, is also implicated for allegedly assisting with money laundering through a car rental business. Dritan, who had been living a lavish lifestyle and was previously seen as untouchable within hacking circles, turned 18 recently, making him legally accountable. His previous "immunity" has ended as law enforcement closes in.

Original | Odaily Planet Daily(@OdailyChina)

Author | Asher(@Asher_ 0210)

Last night, on-chain investigator ZachXBT exposed an 18-year-old hacker from the United States named Dritan Kapllani Jr. According to the disclosed information, this young man named Dritan Kapllani Jr. is suspected of involvement in multiple social engineering attacks targeting cryptocurrency users, with an estimated total amount involved of approximately $19 million. Although he has not been formally charged yet, he has already been included as a 'co-conspirator' in U.S. judicial documents.

This case quickly attracted attention, not only because of the massive amount involved but also because its starting point was highly dramatic—a voice call meant for showing off wealth became the breakthrough for the entire investigation.

Just Showing Off Wealth Once on Discord

On April 23, 2026, a dispute that occurred in a Discord voice channel kicked off the incident.

It was a voice call known as 'Band 4 Band,' where participants compared their 'strength' in the most direct way—by showcasing their respective assets. The atmosphere soon shifted from teasing to rivalry. Driven by this sentiment, Dritan, to prove he was richer, directly started screen sharing and displayed his Exodus wallet interface, showing a balance of about $3.68 million.

A few weeks later, this scene was revisited. On-chain investigator ZachXBT used this address as a starting point, linking together what were originally scattered transactions one by one, gradually revealing a longer funding trail.

A Cache of 185 Bitcoin Theft Funds Surfaces

Going back to March 14, 2026, a social engineering theft involving 185 Bitcoins occurred, valued at around $13 million at the time. The funds were quickly transferred out of the original address and swiftly entered an on-chain distribution system.

As early as the next day, about $5.3 million of it was transferred into the wallet Dritan displayed during the Discord voice call (address: 0x4487db847db2fc99372a985743a26f46e0b2bba6). Over the next few weeks, this approximately $5.3 million was continuously split, transferred through multiple addresses, and sent to various destinations. By the time of that April 23 voice conversation, about $1.6 million had already been further moved.

Not the First Time Involved in Crypto Theft

Tracing back from the wallet address Dritan displayed, it quickly became apparent that the funds in it didn't only come from that 185 Bitcoin theft.

According to on-chain analysis, the funding sources for this wallet can be traced back to multiple social engineering thefts in 2025, totaling over $5.85 million. Different victims, different times, but after the funds were transferred away, they would be rapidly split and then moved on through a string of addresses, following a very similar pattern. By matching these funds one by one, it was found that many transfers eventually landed in this wallet address Dritan displayed.

It's worth noting that Dritan once had a 'Band 4 Band' dispute with hacker John Daghita (Lick). Lick was later arrested for allegedly stealing about $46 million in U.S. government funds, and in a later-deleted Telegram post, he had publicly shared Dritan's old address (address: 0x97da0685dbba50b4cbabb0ca9e8336f4fbe41122). Currently, this move appears more like an act of retaliation.

Judging from on-chain behavior, this old address showed a highly consistent pattern with the funds flow of the wallet Dritan displayed in terms of fund splitting methods, transfer paths, and subsequent destinations, and is therefore believed to be used by the same controlling party.

Judicial Documents 'Name' Him for the First Time

It wasn't until May 11, 2026, that this on-chain funding trail was officially confirmed for the first time in judicial documents. That day, the criminal indictment against Trenton Johnson was unsealed. He was charged for his involvement in that 185 Bitcoin theft case and faces up to 40 years in prison.

In the indictment, a key co-conspirator is labeled as 'Co-Conspirator 1 (CC-1),' and the on-chain analysis community has already pointed this identity towards Dritan Kapllani Jr. Although Dritan has not been formally charged yet, he has transitioned from a 'linked address' in on-chain inference to a 'co-conspirator structure' in the judicial narrative.

Additionally, the same document mentions another individual involved—Meme coin KOL yelotree, who is accused of assisting in money laundering through his car rental business in Miami and faces up to 30 years in prison.

Turning 18, The Dissolute Life Comes to an End

Previously, Dritan had been living a life of extravagance for a long time, frequently posting related content on Instagram and interacting with other hackers via Telegram. In hacker circles, he was once considered to have a kind of 'protagonist aura'—several groups associated with him (like ACG, 41 / RM Boyz, etc.) were successively dealt with by law enforcement, yet he himself remained untouched.

But as he turned 18, this 'aura' ended, and his past actions began to be pursued legally.

Пов'язані питання

QWho exposed the 18-year-old hacker Dritan Kapllani Jr., and what was the initial trigger for the investigation?

AThe hacker was exposed by blockchain investigator ZachXBT. The investigation was triggered by Dritan showing off his Exodus wallet (with a balance of about $3.68 million) during a 'Band 4 Band' Discord voice call on April 23, 2026.

QWhat is the total estimated value linked to the social engineering attacks involving Dritan Kapllani Jr.?

AThe cumulative amount linked to the social engineering attacks involving Dritan Kapllani Jr. is approximately $19 million.

QHow did a specific 185 Bitcoin theft connect to Dritan's wallet, and what happened to the funds?

AIn the 185 Bitcoin theft on March 14, 2026 (worth about $13 million at the time), approximately $5.3 million was transferred into the Exodus wallet Dritan later showed off. This money was then split and moved through multiple addresses, with about $1.6 million transferred out before the Discord call.

QWhat is Dritan Kapllani Jr.'s status in the US legal case (Trenton Johnson) related to the 185 Bitcoin theft?

AIn the unsealed criminal complaint against Trenton Johnson, Dritan Kapllani Jr. is referenced as 'Co-Conspirator 1 (CC-1).' While he has not been formally charged yet, his role has moved from a blockchain-inferred association to being officially identified as a co-conspirator in the judicial narrative.

QAccording to the article, why did Dritan's perceived 'main character halo' in the hacker community end?

ADritan's perceived 'main character halo' in the hacker community ended because he turned 18 years old. Upon reaching legal adulthood, his past actions became subject to legal consequences and prosecution.

Пов'язані матеріали

GitHub, Transfixed by AI

On the night of February 9th, GitHub suffered a major outage caused by a simple configuration change—reducing a cache refresh interval from 12 to 2 hours—that triggered a cascade of failures. This was not an isolated event, but part of a broader pattern. In early 2026, GitHub experienced at least 8 major incidents, failing to meet its promised 99.9% availability. These outages stemmed from structural issues: explosive growth in load, tight service coupling, and insufficient protection against abnormal traffic. This unprecedented load is driven by AI Agents. In 2025, GitHub handled ~1 billion commits. By 2026, weekly commits reached 275 million, projecting to ~14 billion for the year—a 14x increase. AI tools like Claude Code now contribute 4.5% of all public repository commits, with weekly submissions surging 25x in just three months. AI-generated pull requests jumped from 4 million to 17 million per month in half a year. Unlike human developers, AI Agents work continuously, generating commits at a scale that overwhelms infrastructure designed for human rhythms. The surge also shattered GitHub's business model. Copilot's flat-rate pricing, based on assisting human developers, became unsustainable as Agentic AI sessions consumed resources worth hundreds of dollars for a few dollars in fees. In response, GitHub imposed usage limits and, by June 1st, shifted to a pay-per-use "AI Credits" system. Facing this new reality, GitHub realized a 10x scaling plan was insufficient. It announced a need to *redesign* its architecture for 30x current scale—decoupling services, adding fault isolation, and improving change management to prevent cascading failures. Other platforms like Stripe and AWS are facing similar challenges with AI Agents. Fundamentally, GitHub is transitioning from a human collaboration platform to an "exhaust pipe" for automated AI workflows. Its detailed post-mortem reports aim to maintain trust during this turbulent rebuild. The February outage was not just a technical glitch, but a signal of the software industry's entry into a new, AI-driven era.

marsbit12 хв тому

GitHub, Transfixed by AI

marsbit12 хв тому

Both Suffer Massive Losses Exceeding $90 Billion, Which Is in Greater Peril: Strategy or Bitmine?

Facing massive paper losses exceeding $90 billion each amidst a sharp market downturn, "Digital Asset Treasury" (DAT) giants Strategy and Bitmine find themselves in a precarious position, but with different underlying risks. Strategy, heavily invested in Bitcoin (BTC), faces significant financial strain. Its strategy relies heavily on debt, including convertible notes and preferred stock (STRC) requiring substantial dividend payments. With its cash reserves dwindling and BTC offering no staking yield for cash flow, Strategy's high leverage makes it vulnerable. A continued price decline could force asset sales to meet obligations, potentially creating a negative feedback loop. Its market value has already fallen sharply. In contrast, Bitmine, an Ethereum (ETH) holder, appears on firmer financial ground. It primarily funds its purchases through equity offerings (like ATM programs), avoiding debt pressure. It also generates income by staking a large portion of its ETH holdings. While not immune to market drops and shareholder dilution concerns, Bitmine maintains more flexibility, recently announcing a new preferred share offering to raise further capital. The core divergence lies in their financing: Bitmine uses equity (investor money), while Strategy uses debt (borrowed money). Consequently, Bitmine currently faces less immediate liquidity pressure than Strategy, which must navigate the dual challenge of servicing debt/dividends and a declining core asset (BTC) price.

marsbit19 хв тому

Both Suffer Massive Losses Exceeding $90 Billion, Which Is in Greater Peril: Strategy or Bitmine?

marsbit19 хв тому

Where the AI Bubble Really Is: Which Layer of Players Are Naked

AI Bubble: Where It Really Is and Who's Swimming Naked This analysis dissects the AI industry not as a single entity but as a five-layer pyramid, arguing that bubbles are concentrated in specific tiers, not uniformly distributed. **Key Distinction from the 2000 Dot-com Bubble:** Unlike 2000, where companies had stock prices before revenue, today's leading AI players have massive, contract-backed revenue driving their valuations. Core infrastructure demand is real, with every GPU running at full capacity for paying customers. **The Five-Layer Pyramid & Bubble Assessment:** * **L0 (Fab/Manufacturing) & Top L4 (Leading AI Apps): NO BUBBLE.** Companies like TSMC, NVIDIA, major cloud providers (Microsoft, Google, Meta, Amazon), and top AI labs have real revenues and orders. Supply is tightly constrained by TSMC's disciplined capacity control and physical limits like power/land for data centers, preventing a supply glut. * **L1 (Memory): BATTLEGROUND.** Sky-high HBM margins could signal a new structural cycle or a classic "boom before bust." The oligopoly of three major players may enforce supply discipline, making this a high-stakes bet. * **L2 (Interconnect/Optical Modules): BUBBLE TERRITORY.** Companies like Lumentum and AAOI have seen stock surges (4-10x) far outpacing revenue growth. This hardware segment has lower physical barriers to expansion than fabs, allowing speculation. It mirrors the 2000 bubble's epicenter—optics. * **L3 (Infrastructure/"GPU Landlords"): VULNERABLE.** GPU leasing companies profit from the current compute shortage but own no long-term moat. Their business model relies on a temporary bottleneck that will ease as big tech expands and new tech (e.g., potential space-based data centers) emerges. * **L4 Long Tail (VC-backed Startups): STRONG BUBBLE SIGNALS.** VC funding concentration in AI is twice that of the 1999 peak. Many startups with little revenue use the valuation logic of successful giants to justify their own, creating high risk of a "valuation crunch" when funding dries up. **Critical Risks to Monitor:** 1. **GPU Depreciation & Accounting:** Companies extending the assumed useful life of GPUs artificially boost profits. The true economic life depends on future generational leaps from NVIDIA. 2. **"GPU Credit" & Off-Balance-Sheet Leverage:** Emerging structures where shell companies borrow to buy GPUs and lease them out (with chipmakers sometimes investing) move debt off major balance sheets. This echoes the "vendor financing" of 2000 and the securitization risks of 2008, though currently small-scale. 3. **TSMC Abandoning Caution:** If the primary supply bottleneck (TSMC's conservative capacity planning) breaks, runaway supply could trigger a bust. 4. **Algorithmic Efficiency Breakthrough:** A major leap in software efficiency could drastically reduce the need for raw compute hardware, undermining the investment thesis. **Conclusion:** The AI boom is expensive and has frothy areas, but its core is underpinned by real demand and physical supply constraints. The bubble risk is layered: most present in optical components, GPU leasing, and the long-tail startup ecosystem, while the foundational chip manufacturing and leading application layers remain relatively solid—for now.

marsbit32 хв тому

Where the AI Bubble Really Is: Which Layer of Players Are Naked

marsbit32 хв тому

Торгівля

Спот
Ф'ючерси
活动图片