Operation Bayonet: The Month Police Secretly Ran Hansa Market
When the largest darknet market in Europe was taken over by Dutch police in June 2017, nobody noticed. Not the buyers. Not the vendors. Not even the site's own moderators.
Operation Bayonet broke every convention of darknet enforcement. Instead of pulling the plug, police kept Hansa Market online for twenty-seven days, impersonating its administrators while quietly rewiring the platform into an evidence-gathering machine. A sloppy dev server started everything
The case began, as many do, with someone else's mistake. In late 2016, researchers at security firm Bitdefender discovered a Hansa development server exposed on the open internet — a staging copy of the site that had never been hidden behind Tor. They passed the lead through Europol, whose European Cybercrime Centre routed it to Dutch investigators. The server sat in a Dutch data center. Police installed monitoring equipment, imaged the drives, and reconstructed the entire market on their own network. According to Wired's detailed account, old IRC chat logs preserved on a linked German server contained the two administrators' real names — and, for one of them, a home address. Tor had held. The humans around it had not. A blockchain breadcrumb led to Lithuania
The suspects appear to have sensed something wrong: the servers went silent and the market moved. Rather than raid and kill the operation, the National High Tech Crime Unit spent months waiting for a second break. It came in April 2017, when one administrator paid for new hosting from a bitcoin address already documented in those chat logs. Blockchain analysis firm Chainalysis traced the payment through a Dutch payment provider to a hosting company in Lithuania. Working under a mutual legal assistance treaty, Dutch agents positioned themselves at the data center while German police raided both suspects' homes on June 20, 2017. The men, aged 30 and 31 from Siegen, reportedly handed over their credentials under questioning. Three days later, Hansa ran entirely from servers under police control in the Netherlands. Total downtime during the migration: about three minutes. The site was rebuilt as a surveillance tool
Once inside, investigators modified the platform itself. As reported by Wired and confirmed in the Dutch prosecution service's announcement, the takeover let officers capture data no server seizure could have produced: - Passwords logged in plaintext instead of hashes, exposing users who reused credentials elsewhere
- The PGP encryption feature altered to save a readable copy of messages — often delivery addresses — before encrypting them
- Photo uploads stripped of metadata as usual, but only after a geotagged copy was stored
- Multisignature escrow silently disabled, allowing roughly 1,200 bitcoin to be seized at shutdown
One trick was bolder still. Vendors were offered a backup key file for recovering escrowed funds; police replaced it with a booby-trapped document that phoned home when opened, unmasking dozens of sellers' IP addresses. AlphaBay fell, and the refugees walked in
The timing was engineered. On July 5, 2017, Thai authorities arrested Alexandre Cazes, founder of AlphaBay, then the world's largest darknet market. The FBI allowed the resulting outage to read as ordinary downtime rather than announcing a seizure, per the FBI's account of the operation. Panicked users migrated — and Hansa, with its reputation for security, was the obvious refuge. "They flocked to Hansa in their droves," Interpol director Rob Wainwright said at the time. "We recorded an eight-times increase in the number of new users." Registration had to be suspended briefly because the police-run infrastructure could not cope with demand. For nearly a month, law enforcement operated Europe's busiest drug marketplace — and welcomed its newest customers personally. Cazes undid himself with a welcome email
AlphaBay's collapse owed nothing to cracks in Tor either. Court filings show investigators learned in December 2016 that AlphaBay's original welcome emails included a header leaking the admin's personal address: pimp_alex_91@hotmail.com. That single string led to his PayPal accounts, his front company EBX Technologies, and eventually his identity as "Alpha02," as Ars Technica reported from the forfeiture complaint. When Thai police searched his Bangkok home on July 5, his laptop was unencrypted, unlocked, and logged in as AlphaBay admin. Cazes was found dead in his cell days later, before extradition. What the harvest actually caught
On July 20, 2017, simultaneous press conferences in The Hague and Washington ended the operation. Europol put the final numbers starkly: Data on some 420,000 user accounts. Roughly 27,000 transactions surveilled during the covert period. About 10,000 foreign buyer addresses forwarded to Europol for follow-up investigations across Europe. A dozen of Hansa's top vendors arrested within weeks, with Dutch police conducting knock-and-talk visits on suspected buyers whose addresses were already in hand. The doctrine shift Bayonet left behind
The operation drew genuine ethical criticism: under judicial authorisation, police facilitated thousands of drug sales — including orders placed by users who joined after the takeover. Prosecutors defended it as proportionate; defense lawyers have challenged such evidence ever since. Both things can be true. Strategically, the lesson reshaped darknet commerce. Takedowns displace trade rather than destroy it — Dream Market absorbed much of the traffic within months, and at least twelve Dream vendors were caught reusing Hansa credentials there. But running a market captures its users, not just its servers. For anyone using onion services today — our Tor browser guide covers the fundamentals — the uncomfortable takeaway stands. A market that loads fast, resolves disputes fairly, and behaves normally proves nothing about who operates it. Uptime is not legitimacy. Treat everything listed in our market watch coverage accordingly.