OSINT Signals Possible Raid and Arrest of Crypto Threat Actor Following Seizure-Style Wallet Transfers 

Published
Written by:
Vishwa Pandagle
Vishwa Pandagle
Cybersecurity Staff Editor

Three Key Takeaways

Multiple OSINT and threat-intel accounts, including ZachXBT, claim that a British cybercriminal using the alias Danny / Meech, has likely been arrested. Believed to be Danish Zulfiqar Khan, his cryptocurrency wallets show patterns similar to law enforcement seizure activity. 

Wallet Activities Leading to Speculations

Danny’s tracked crypto wallets moved funds in the same address, mirroring patterns seen in past seizures. He was reportedly based in Dubai, where a villa was raided and additional individuals were arrested.

Based on OSINT observations and community reporting, he has been unresponsive for several days, which is fueling speculation about the arrest. It has about $18.58 million consolidated in the address: 0xb37d617716e46511E56FE07b885fBdD70119f768

Danish’s Passport
Danish’s Passport | Source: Dark Web Informer on X

This wallet consolidation happened in several addresses linked to him that ZachXBT had been tracking.

A Dark Wen Informer update added that Danny was allegedly involved in the $243M Genesis Creditor theft in August 2024 alongside actors known as Malone, Veer, Chen, and Jeandiel.

He is also suspected to be involved in the Kroll SIM swap attack in August 2023 that enabled over $300 million theft through social-engineering.


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: