you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 14 min ago 255 onions tracked
home / news / market watch
14 July 2026 market watch 4 min read

How small opsec mistakes unmasked the Wall Street Market admins

In late April 2019, Wall Street Market was the second-largest darknet market on Tor, serving roughly 5,400 vendors and 1.15 million customer accounts. Withdrawals stopped, about 11 million dollars in escrow cryptocurrency began moving toward admin wallets, and within a week three young men in Germany were under arrest.

The FBI, the BKA and the Dutch police had been working the case since July 2017. Yet the identities named in the criminal complaint came from mundane operational security failures, not from any break in Tor itself.

A failing VPN exposed coder420

The administrator known as coder420 reached the WSM servers through two paid VPN providers. When his connection through the first provider dropped, the session continued unprotected and handed investigators his true IP address, according to the FBI affidavit supporting the charges. That address belonged to a UMTS stick, a mobile internet dongle registered under a suspected fictitious name. Registration alone does not create anonymity. Between February 5 and 7, 2019, BKA surveillance electronically located the stick at Tibo Lousee's home in Kleve and at the IT company where he worked as a programmer. On the day of his arrest, investigators observed the stick connecting to WSM infrastructure shortly before the raid. Lousee's computer was unlocked, and the matching UMTS stick sat in his possession.

Correlated login times gave away Kronos

The second administrator used a different VPN provider, and his tunnel reportedly held. It did not matter. An IP address assigned to a family home, with the account registered to the suspect's mother, contacted the same VPN provider within the exact windows when administrator-only components of WSM were accessed. After his arrest, Jonathan Kalla confessed that he was Kronos. He described his technical role, identified the forum location and admitted that the trio had run an earlier marketplace together.

One PGP key used twice

The third administrator, known as TheOne, left the most elegant trail behind. The PGP public key stored for TheOne in the WSM database was identical to the key of dudebuy, an account on Hansa Market that Dutch police seized in 2017 during Operation Bayonet. Records from a bitcoin payment processor showed that dudebuy's refund wallet funded a 2016 purchase made under the buyer name Martin Frost, complete with a personal email address. Analysts at the US Postal Inspection Service then followed commission wallets through a commercial mixing service and, as TechCrunch recounted, de-mixed them back to Frost. The same wallet cluster tied all three men to German Plaza Market, an earlier marketplace they allegedly drained via exit scam in May 2016 and used to fund WSM's launch. Check any key against its history with our PGP verify tool before trusting an identity online.

Greed set the clock

On March 25, 2019, a rival market announced its shutdown and deposits flooded into WSM. Three weeks later withdrawals froze. Between April 22 and 26, independent blockchain watchers tracked 10 to 30 million dollars leaving wallets tied to the site; prosecutors put the figure closer to 11 million. The running exit scam forced the two-year investigation to act on April 23 and 24 rather than wait for a cleaner case. Servers were seized in Germany, the Netherlands and Romania, and Europol reported recovering over EUR 550,000 in cash plus six-figure sums in Bitcoin and Monero, per its takedown announcement.

Extortion from the inside

Then came something uglier than a disappearance. A moderator called Med3l1n, apparently cut out of the exit scam, contacted users whose support tickets contained addresses and order details in unencrypted plain text. He demanded 0.05 bitcoin, about 280 dollars, and threatened to pass the compiled material to the FBI unless they paid. Days later he published the backend login credentials and the administration panel's IP address on Dread, as ZDNet reported at the time. The revenge bought him nothing. Years-old forum posts and photographs identified him as Marcos Paulo De Oliveira-Annibale of Sao Paulo, and Brazilian police executed a search warrant as the US charges were unsealed.

Breadcrumbs beat encryption

Tor conceals the network path, not personal habits. Every mistake in this case predated the arrests by months or years, waiting in logs, databases and blockchains for someone patient enough to correlate them.
"We are on the hunt for even the tiniest of breadcrumbs to identify criminals on the dark web," US Attorney McGregor Scott said.
The lessons are simple enough to list:
    reused keys survive every layer of protection, correlated login times betray shared infrastructure, blockchain flows are permanent and mixers can be unwound, and plain-text support tickets outlast any anonymity setup.
No onion link for this market exists anymore. Anyone trading under the Wall Street Market name today runs a phishing clone built to harvest your credentials or your coins. More background lives in our security notes.

more notes

all news ›