OSINT Signals Possible Raid and Arrest of Crypto Threat Actor Following Seizure-Style Wallet Transfers
Three Key Takeaways
- Suspected arrest: A threat actor ‘Danny’, linked to crypto and SIM-swap operations is believed to have been arrested.
- Seizure-style transfers: His wallet movements match patterns seen in earlier law-enforcement crypto seizures.
- Previous cybercrimes: Danny is tied to Genesis and Kroll breaches totaling over $500 million.
Multiple OSINT and threat-intel accounts, including ZachXBT, claim that a British cybercriminal using the alias Danny / Meech, has likely been arrested. Believed to be Danish Zulfiqar Khan, his cryptocurrency wallets show patterns similar to law enforcement seizure activity.
Wallet Activities Leading to Speculations
Danny’s tracked crypto wallets moved funds in the same address, mirroring patterns seen in past seizures. He was reportedly based in Dubai, where a villa was raided and additional individuals were arrested.
Based on OSINT observations and community reporting, he has been unresponsive for several days, which is fueling speculation about the arrest. It has about $18.58 million consolidated in the address: 0xb37d617716e46511E56FE07b885fBdD70119f768
This wallet consolidation happened in several addresses linked to him that ZachXBT had been tracking.
A Dark Wen Informer update added that Danny was allegedly involved in the $243M Genesis Creditor theft in August 2024 alongside actors known as Malone, Veer, Chen, and Jeandiel.
He is also suspected to be involved in the Kroll SIM swap attack in August 2023 that enabled over $300 million theft through social-engineering.





