VERSE PRESS

Crypto News, Global First.

Four Arrested in Poland Over Crypto SIM-Swap Scheme; ZachXBT Alleges Known Threat Actor Among Suspects

Polish authorities have detained four people accused of running SIM-swap attacks against cryptocurrency holders and laundering tens of millions of Polish zloty, with anonymous blockchain investigator ZachXBT publicly alleging that one of the suspects is a threat actor known online as "Merry."

|

The arrests, reported on June 25, 2026, were conducted with investigative support from the U.S. Federal Bureau of Investigation. Polish prosecutors are pursuing money laundering charges, though the specific criminal statutes have not yet been publicly confirmed. The identities of all four suspects remain unverified by Polish authorities, and ZachXBT's identification of "Merry" is an allegation, not a formal charge.


How the Attack Works

SIM-swap fraud is a form of identity theft in which an attacker convinces a mobile carrier to reassign a victim's phone number to a SIM card the attacker controls. Once that transfer is complete, any SMS-based two-factor authentication codes sent to the victim's number are intercepted by the attacker instead. For cryptocurrency accounts, that access is often enough to authorize withdrawals and drain wallets entirely. The suspects in Poland allegedly combined this technique with social engineering, manipulating telecom staff or potentially exploiting insider access, though that element has not been confirmed by Polish authorities in this specific case.


ZachXBT's Role

ZachXBT is an anonymous on-chain forensic investigator who publishes findings through Telegram and X. He began his investigative work after being personally victimized by crypto scams, a background that informs both his methods and his focus. He uses wallet address clustering across multiple blockchains, open-source intelligence including domain registration records and court filings, and monitoring of private Discord and Telegram communities where cybercriminals sometimes inadvertently reveal wallet addresses. He operates independently of law enforcement but has contributed to several real-world arrests.

In August 2024, his tracing of 4,064 BTC helped secure two arrests in a $243 million social engineering attack against a single Genesis creditor; his work also assisted in freezing $9 million in connected funds. In March 2026, his work preceded the arrest of John "Lick" Daghita in Saint Martin, linked to more than $90 million in suspected thefts from U.S. government wallets. In May 2026, his investigation contributed to the identification of Dritan Kapllani Jr., an 18-year-old U.S.-based suspect linked to approximately $19 million in social-engineering thefts conducted through Discord. The Poland case fits an established pattern in which his public disclosures precede or coincide with formal police action.

The suspects in this case appear connected to a loosely organized online network known as "The Com," according to reporting by The Block and Crypto Potato. This decentralized group of predominantly young, English-speaking social engineers and SIM-swappers is responsible for some of the largest individual crypto thefts in recent years. Members of this network frequently discuss stolen proceeds openly in private group chats, a behavior ZachXBT has repeatedly used to identify and trace them.


Poland's Regulatory History

Poland's involvement is not coincidental. Before 2024, the country's virtual asset service provider registry required only a 616 PLN registration fee (roughly $150) with no minimum capital, no professional liability insurance, no physical infrastructure checks, and no meaningful criminal background screening, according to analysis by Kancelaria Skarbiec, a Polish legal firm. Registration was granted automatically within 14 days. That framework made Poland attractive for shell crypto operations. The Huione Group, sanctioned by the U.S. Treasury in October 2025 for processing more than $4 billion in illicit funds including proceeds from North Korean hacking, had its crypto exchange component registered in Poland. The four arrests may reflect a broader tightening of enforcement as regulators and prosecutors adapt to the vulnerabilities that framework created.


A Global Problem With Regional Weight

The attack method used in Poland is not a European edge case. It is most dangerous in mobile-first economies where SMS-based authentication remains the default security layer for both fintech apps and crypto exchange accounts.

Africa is most exposed. The continent processes 74 percent of global mobile money transactions, and SIM swaps account for 43 percent of mobile money fraud across the region. In South Africa alone, SIM-swap attacks are responsible for an estimated $192 million in annual telecom fraud losses, roughly 60 percent of the country's total. Digital banking fraud in the country surged 86 percent in 2024, rising from approximately 52,000 to 98,000 reported cases. Kenya recorded a 327 percent increase in SIM swap incidents between 2024 and 2025, according to Safaricom data. Nigeria reported approximately $32 million in crypto and mobile fraud losses in 2024. Exchanges operating across Africa rely heavily on SMS-based two-factor authentication, exposing their users to exactly the vulnerability alleged in the Poland case. Tanzania offers one concrete example of a mitigation approach: a 2023 agent training program reduced agent-assisted fraud by 51 percent, a model that researchers have described as replicable across the region.

South Asia carries similar risk. Pakistan now ranks third globally for crypto adoption, behind India and the United States. Across India, crypto exchanges broadly use SMS-based one-time passwords as a primary authentication method, including through telecom-specific verification services tied to major national carriers. India reported roughly $2.7 billion in total cyber fraud losses in 2025, a figure broad enough that SIM-swap attacks against crypto accounts are likely underreported within it. Bangladesh and Pakistan present compounding exposure: both countries maintain limited formal regulatory frameworks for virtual asset service providers, and both rely heavily on SMS-based verification across banking and crypto platforms alike, leaving a large and growing user base with little structural protection against the attack method at the center of the Poland case.


What Comes Next

The Poland arrests follow Europol's October 2025 SIMCARTEL operation, which dismantled SIM-box networks across 14 European countries, seized more than 1,200 SIM-box devices capable of running 40,000 SIM cards simultaneously, confiscated $333,000 in cryptocurrency, and resulted in seven arrests. They also follow an earlier Europol operation in which ten hackers were arrested across Spain, Austria, and Romania for SIM-swapping attacks against high-profile targets including celebrities, resulting in the theft of more than $100 million in cryptocurrency.

Together, these operations signal a sustained enforcement posture rather than isolated police actions.

For exchange operators, the practical message is direct. SMS-based two-factor authentication is no longer a defensible default. Hardware security keys using FIDO2 or WebAuthn standards, authenticator apps, and biometric verification are available alternatives. Telecom APIs now allow platforms to check for recent SIM swap activity before processing withdrawals. Chainalysis recorded $17 billion in total crypto stolen via scams and fraud in 2025, a record figure covering the full range of fraud typologies; SIM-swap attacks represent a subset of that total, not its entire scope.

The infrastructure to reduce that number exists. The question is whether platforms deploy it before the next wave of attacks.