Second and third rounds on the dossier pipeline, reviewed locally before commit. Retrieval - wayback_pass.py: retries every BLOCKED/DEAD/THIN/ERROR linked source through the Wayback Machine; blocks carry the snapshot date, archive URL and the live verdict. 143 slots retried: 93 fetched, 37 no snapshot, 12 script shells, 1 PDF. - fetch_sources.py: fetch_wayback() helper. - add_extra_sources.py: files staged extra_* finds (web search, not on the DB record) into the store with a provenance note. - Cases re-sourced by web search: 248 (Oslo: Document.no, Avisa Oslo, NRK; the linked Le Parisien piece is case 242 and is marked OFF-CASE), 258 Kharkiv, 260 Singapore, 358 Bangkok, 365 Las Vegas, 388 Verneuil-sur-Seine, 390 Zoersel, 430 Homestead. 341 of 364 cases now hold a fetched article; 11, 66 and 399 have no public text source (podcast, police video, direct victim report). Trimming - auto_trim.py: case-anchored furniture cut for UNTRIMMED blocks. Finds the body run that mentions the case, merges across subheadings and short furniture gaps, drops teasers, share bars, date/URL/caption lines and subscription pitches; refuses pages with no record term or almost no body. 302 blocks trimmed; 16 left on auto-trim-review.md (7 OFF-CASE suspects). Every cut is labelled AUTO-TRIMMED, UNREVIEWED in the dossier; the full extract stays in staging/. Decisions with anchors in trim-decisions-auto.json. - build_cases.py / verify_all.py: banners for auto-trimmed and archived blocks, staged-file check extended to Wayback blocks, flag legend under the record. Detention rule - README "Definitions": the DB field `kidnappings` is the DETENTION violence type (victim, guard, staff or relative held to force submission or execute the theft), distinct from the Kidnapping scenario (taken away and held). - detention-flag-review.md / detention-flag-corrections.json: 40 records reviewed with evidence; 30 set-to-1 proposals accepted by the owner on 2026-09-06 (listed in corrections-approved.md), 10 still open. - apply_detention_wording.py: "Violence Used" in the 70 reviewed summaries now names detention explicitly (62 of 70 labelled), supported by the summary's own text; idempotent; supersedes the batch scripts' wording. Worklist and docs - sofia-worklist.md: 248 decisions, detention rule item replacing the old "no abduction" item, fresh-search section for the textless cases. - README-START-HERE.md: progress notes, run commands, next steps. - Bug fixed in passing: Wayback blocks stored in-memory text with carriage returns; now stored as read back from disk. verify_all.py PASSES (2321 checks). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GZZENdTLzNGsbNy4DyF1yt
175 lines
18 KiB
Plaintext
175 lines
18 KiB
Plaintext
================================================================================================
|
||
CASE 092 | Unidentified man | July 1, 2021 | USA
|
||
================================================================================================
|
||
|
||
DATABASE RECORD
|
||
id 92
|
||
date July 1, 2021
|
||
original_date July 1, 2021
|
||
year 2021
|
||
month 7
|
||
quarter 2021-Q3
|
||
victim Unidentified man
|
||
location Unknown
|
||
country USA
|
||
scenario Malicious Invitation - SocialEng
|
||
description Bitcoin holder drugged and robbed by Tinder date
|
||
kidnappings 0
|
||
violence_torture 0
|
||
drugs_alcohol 1
|
||
weapons 0
|
||
theft 1
|
||
life_taken 0
|
||
money_wanted "Small amount"
|
||
coin_type Bitcoin
|
||
reports Crypto News Australia
|
||
notes Woman posed as crypto trader on Tinder, went home with man, scoped his drink. He woke up a day later and found that phone and possessions were stolen along with small amount of crypto from exchange account - cold storage was attempted to be but stolen since it was well-protected with Casa
|
||
has_processed_date 1
|
||
created_at 2025-11-13 05:44:45
|
||
(flag legend: 'kidnappings' is the DETENTION flag — 1 when the victim was held against
|
||
their will at any point, tied, locked in, held at gunpoint or taken away; it is NOT the
|
||
same as the 'Kidnapping' scenario, which means taken away and held. See README, Definitions.)
|
||
|
||
AI SUMMARY [generated at bulk import, NOT verified against sources]
|
||
**Victim:** Unidentified man
|
||
|
||
**Attackers:** Known associate(s) who betrayed victim
|
||
|
||
**Attack Method:** Malicious Invitation - SocialEng
|
||
|
||
**Violence Used:** Drugging
|
||
|
||
**Crypto Stolen:** "Small amount" in Bitcoin
|
||
|
||
**Status:** Investigation ongoing
|
||
|
||
LINKED SOURCES
|
||
[url] https://cryptonews.com.au/news/tinder-date-goes-bad-in-attempted-crypto-grab-91283/
|
||
|
||
NOTES ON THIS FILE
|
||
* matched to sheet row 93: exact date + country, unique candidate
|
||
|
||
------------------------------------------------------------------------------------------------
|
||
ARTICLE 1
|
||
Source Crypto News Australia
|
||
URL https://cryptonews.com.au/news/tinder-date-goes-bad-in-attempted-crypto-grab-91283/
|
||
Origin reported_K&R sheet, row 93, column "Articles"
|
||
Length 2,176 chars
|
||
------------------------------------------------------------------------------------------------
|
||
Tinder Date Goes Bad in Attempted Crypto Grab
|
||
|
||
A US man was drugged by a woman he met on Tinder who then attempted to steal his crypto.
|
||
|
||
The man, who was a client of Casa, a company that offers heightened Bitcoin security, reported the attempted robbery to the Casa team, who performed a postmortem on the incident.
|
||
|
||
Over the weekend, a CasaHODL client survived a ‘wrench attack’ – he was drugged and persuaded to give up access to phone, accounts, and passwords. With the client’s permission, we are sharing the story to help others learn to protect themselves.
|
||
|
||
Tweet from Nick Neuman, CEO & co-founder of CasaHODL
|
||
Beware the Tinder Trap
|
||
A blog post written by Casa’s Jameson Lopp details the strange and concerning attack. According to the victim, the woman claimed to be a crypto trader on her bio, which intrigued him and helped him establish common ground with her. After chatting online, they met up at a coffee shop. He thought she looked different from her photos, but not enough to raise any red flags.
|
||
|
||
Later, they went back to his place for a drink and while he was in the bathroom it is suspected the woman laced his drink with scopolamine, also known as ‘Devil’s Breath’, or a benzodiazepine. Both drugs cause loss of inhibition and memory. He woke up the next day, noticing that his phone was missing and that attempts had been made to withdraw crypto from several of his accounts.
|
||
|
||
Thankfully, the man was not harmed in any way and the perpetrator only managed to steal a small amount of his crypto, largely thanks to Casa’s multisig technology. The scammer managed to get a small amount of bitcoin out of one of his exchange accounts. He was able to block some of the other requested purchases and withdrawals by contacting those custodians to inform them of the compromise.
|
||
|
||
"The attacker managed to get a small amount of bitcoin out of one of our client’s exchange accounts. He was able to block some of the other requested purchases and withdrawals by contacting those custodians to inform them of the compromise. Since the attacker only had one of the client’s five keys to his Casa multisig, those funds could not be spent."
|
||
Jameson Lopp, Casa co-founder
|
||
|
||
------------------------------------------------------------------------------------------------
|
||
ARTICLE 2
|
||
Source Crypto News Australia
|
||
URL (no URL recorded for this column)
|
||
Origin reported_K&R sheet, row 93, column "Article 2"
|
||
Length 8,402 chars
|
||
------------------------------------------------------------------------------------------------
|
||
Casa Client Case Study: The Tinder Trap
|
||
by Jameson Lopp 5 days ago 7 min read
|
||
This week we received an emergency lockdown request from a client who had been attacked and was dealing with multiple account compromises as a result. Spoiler alert: their funds secured via Casa multisig remain safe.
|
||
While this story had a fairly good ending, it is worth analyzing what went wrong because it is a novel attack. We want the rest of the ecosystem to be aware of the malicious actors who are lurking on dating apps and appear to be becoming more crypto-savvy. The following is published with permission from the client.
|
||
The Hook
|
||
This client is a bachelor who, like tens of millions of others, uses dating apps to meet women. Last week he came across the profile of a woman whose Tinder bio stated that she worked as a crypto trader. Our client found this intriguing and messaged her since it is rare to come across someone who is interested in talking about crypto. In one of his first messages with this woman he mentioned that he too, was a crypto trader, in the aims of establishing some common ground.
|
||
After chatting online they decided to meet up at a coffee shop. The person who showed up looked similar to the photos on the Tinder profile, but not exactly the same. He didn't think much of it because people often don't look like their profile photos. At the coffee shop she said her parents bought her some bitcoin, but otherwise she didn’t talk about crypto for the rest of their time together.
|
||
Afterwards they went for a walk and eventually settled on going to the client’s residence for a drink. They stopped to buy alcohol, but upon getting to the client’s residence he noticed she was more interested in listening to music than in drinking.
|
||
After some period of time the client went to the restroom. While he was there we suspect the woman laced our client’s drink with scopolamine, also known as ‘Devil's Breath,’ or a benzodiazepine. These drugs are well known to cause loss of inhibition and memory loss. A US Department of State report in 2012 noted the following:
|
||
Scopolamine can render a victim unconscious for 24 hours or more. It is most often administered in liquid or powder form in foods and beverages. The majority of these incidents occur in night clubs and bars, and usually men, perceived to be wealthy, are targeted by young, attractive women.
|
||
His memories are fuzzy after this point, but the client recalls drinking a bit more after returning from the restroom. Some time later, he believes the woman picked up his phone and asked him to show her how to unlock it and find his passwords. He knew that something didn’t seem right, but his inhibitions and safeguards had been stripped away. The last thing he remembers is kissing her...
|
||
The Attack
|
||
Our client woke up the next day in his bed and noticed his phone was missing, though his wallet along with cash, debit cards, and ID were still there. No other valuables (such as his electronics and passports) were stolen from the residence.
|
||
He began checking various accounts from his laptop and saw that purchases from his bank account had been attempted at several exchanges and bitcoin withdrawals had been attempted from other custodial services. The attacker was systematically trying to clean out his crypto accounts. What happened?
|
||
This is basically of a mash-up of two different attacks:
|
||
A sim swap
|
||
A more traditional drugging and robbing of an incapacitated victim
|
||
The reason this is like a sim swap attack is because criminals are realizing that your phone is often the master key to your entire digital life. It can be used to access your email and financial accounts - for most people, their email account is the master key to many other accounts - it can be used to reset passwords to any account tied to that email address. In terms of effectiveness, this attack is far worse than a simple sim swap. The attacker does not merely have access to your phone calls and text messages which can be used to man-in-the-middle account reset requests, they have your phone and all of the sensitive information it contains.
|
||
Many of our clients will also have password managers and 2FA on their phone. In the case of this client, though he was not using SMS 2FA, he was using TOTP 2FA via a google authenticator app on the phone. Since the attacker had coerced his phone unlock pin from him, they had access to 2FA for all of his accounts.
|
||
We do not believe that this attack was solely perpetrated by the woman he met. She most likely handed the phone over to someone else, possibly a criminal organization, to get to work draining his various accounts as quickly as possible. The woman was most likely acting as a social engineer.
|
||
The attacker managed to get a small amount of bitcoin out of one of our client's exchange accounts. He was able to block some of the other requested purchases and withdrawals by contacting those custodians to inform them of the compromise. Since the attacker only had 1 of the client's 5 keys to his Casa multisig, those funds could not be spent.
|
||
A Wrenchless Wrench Attack
|
||
This particular scenario is essentially the same as the well-known "wrench attack;" the only difference is the method of coercion employed. While a regular wrench attacker employs physical pain or the threat thereof, with this attack your compliance is compelled via drugs. As such, it’s worth reviewing our previous guidance on wrench attacks because it applies 100%.
|
||
The major takeaway for protecting your funds from this type of attack is ensuring that you do not have immediate access to a signing threshold of key material that can be used to spend the funds. In an attack where you are no longer in control of your own mind or body, you must consider yourself to be your own worst enemy.
|
||
Pro Tips
|
||
Always meet strangers in public places, preferably one with surveillance cameras so that footage can be collected by law enforcement if something goes wrong.
|
||
Compare the person's profile photo when you meet them in real life. If it is questionable that the photos are actually of themselves, that is a red flag.
|
||
Never leave food or drinks unattended.
|
||
Never accept food or beverages offered by strangers or new acquaintances.
|
||
Limit consumption of intoxicants if it is just you and a stranger in a private setting.
|
||
Always have a friend who will check in if they have not heard from you after a predetermined time. This friend should know as much as possible about your location, plans, and the person you are meeting.
|
||
Never publicize or discuss your crypto holdings (or interest) with strangers.
|
||
If a stranger mentions being into crypto but then does not actually seem to know much about it, consider that they may simply be fishing for a specific type of victim.
|
||
Consider activating a "remote wipe" feature on your phone. This should not be relied upon as protection, however, as a remote wipe feature can not be used if you are unconscious.
|
||
Protect your holdings with multisig and keep your keys at different locations - even if you are totally compromised, it will be impossible for the attacker to move funds without moving to multiple locations, which is not practical.
|
||
In our client's own words:
|
||
"I want to highlight how much Casa saved me in this instance, and how valuable such a service is to someone like me. I did have all my funds on Coinbase or on a single cold wallet in the past. I could have easily just given her all my net worth under the influence, but having a multisig setup made that impossible."
|
||
Knowledge Sharing is Caring
|
||
I’ve been tracking physical attacks against bitcoin holders for several years; at time of writing only 70 incidents have been cataloged. There are a few problems inherent to this effort:
|
||
Physical attacks are still quite rare in comparison to digital attacks. The risk to the attacker is much higher; criminals are still figuring out if the reward is worth the risk.
|
||
I suspect that the majority of physical attack victims do not publicize what happened to them out of fear that it may make them a bigger target.
|
||
We must learn from individual failures so that others do not repeat the mistakes of the past. If you have been a victim of a physical attack, especially one with novel attributes, I encourage you to contact us at incidents@team.casa. I am happy to publish privacy preserving case studies so that we can continue strengthening security best practices for Bitcoiners.
|
||
|
||
------------------------------------------------------------------------------------------------
|
||
FETCHED ARTICLE 1 [AUTO-TRIMMED — UNREVIEWED]
|
||
!! Furniture was cut by a script keyed on this case's record, not by a person.
|
||
!! It may still carry passages about OTHER cases from a round-up article.
|
||
!! The full page extract is kept in staging/ if a cut needs revisiting.
|
||
Source cryptonews.com.au
|
||
URL https://cryptonews.com.au/news/tinder-date-goes-bad-in-attempted-crypto-grab-91283/
|
||
Field url
|
||
Retrieved 2026-09-05T12:53:31+00:00 via raw HTTP retrieval, deterministic extraction (HTTP 200)
|
||
Language unknown
|
||
Kept paragraphs headline [0] + 4-14 of 18
|
||
Length 3,348 chars
|
||
Integrity sha256 778784751e42e7b07acdb0965a74e3eab5271d3739ac0820e9b1d94bdf31c3db
|
||
Trimmed AUTO-TRIMMED, unreviewed: kept paragraphs 4-14 plus headline [0]; dropped 3 leading and 3 trailing paragraphs. Case-term hits on page: 8.
|
||
Caveat retrieved from a live page on the date above. Unlike text copied
|
||
from the spreadsheet, there is no second copy to hash it against.
|
||
------------------------------------------------------------------------------------------------
|
||
|
||
ORIGINAL (unknown, verbatim as retrieved)
|
||
|
||
Tinder Date Goes Bad in Attempted Crypto Grab - Crypto News Australia
|
||
|
||
A US man was drugged by a woman he met on Tinder who then attempted to steal his crypto.
|
||
|
||
The man, who was a client of Casa, a company that offers heightened Bitcoin security, reported the attempted robbery to the Casa team, who performed a postmortem on the incident.
|
||
|
||
Over the weekend, a CasaHODL client survived a ‘wrench attack’ – he was drugged and persuaded to give up access to phone, accounts, and passwords. With the client’s permission, we are sharing the story to help others learn to protect themselves.
|
||
|
||
Tweet from Nick Neuman, CEO & co-founder of CasaHODL
|
||
|
||
A blog post written by Casa’s Jameson Lopp details the strange and concerning attack. According to the victim, the woman claimed to be a crypto trader on her bio, which intrigued him and helped him establish common ground with her. After chatting online, they met up at a coffee shop. He thought she looked different from her photos, but not enough to raise any red flags.
|
||
|
||
Later, they went back to his place for a drink and while he was in the bathroom it is suspected the woman laced his drink with scopolamine, also known as ‘Devil’s Breath’, or a benzodiazepine. Both drugs cause loss of inhibition and memory. He woke up the next day, noticing that his phone was missing and that attempts had been made to withdraw crypto from several of his accounts.
|
||
|
||
Thankfully, the man was not harmed in any way and the perpetrator only managed to steal a small amount of his crypto, largely thanks to Casa’s multisig technology. The scammer managed to get a small amount of bitcoin out of one of his exchange accounts. He was able to block some of the other requested purchases and withdrawals by contacting those custodians to inform them of the compromise.
|
||
|
||
The attacker managed to get a small amount of bitcoin out of one of our client’s exchange accounts. He was able to block some of the other requested purchases and withdrawals by contacting those custodians to inform them of the compromise. Since the attacker only had one of the client’s five keys to his Casa multisig, those funds could not be spent.
|
||
|
||
Although this incident is bizarre, it is sadly not unprecedented. As the price of Bitcoin continues to rise, so too do the scams, particularly romance scams. According to Australian government website Scam Watch, there were 277 reports of romance scams in June alone, resulting in losses of A$5,857,472. Many of these incidents do not make the news though there have been some high-profile cases; Australian schoolteacher Melanie Kilgour was involved in a romance scam in 2020 that cost her an estimated $50,000 worth of bitcoin.
|
||
|
||
Crypto News Australia has put together an excellent guide on how to avoid Bitcoin scams, including a section on romance scams, which we strongly recommend you check out. Additionally, at the end of his postmortem, Lopp provides a list of useful strategies to help protect yourself and minimise the risk of becoming a victim of a romance scam.
|
||
|
||
Ben Carey is a Brisbane-based writer, with a wide range of experience, from copywriting to game design and film and tv scriptwriting. He's been following, investing, and trading crypto since 2017. He has three lambos (in Gran Turismo), and can often be seen around town wearing a Bitcoin or Ethereum themed Christmas sweater.
|
||
|
||
================================================================================================
|
||
generated from attacks-export-Gart-website.json + reported_K&R | case 092
|
||
================================================================================================
|