{"id":18863,"date":"2021-02-28T17:57:26","date_gmt":"2021-02-28T17:57:26","guid":{"rendered":"https:\/\/davidgerard.co.uk\/blockchain\/?p=18863"},"modified":"2021-02-28T19:22:34","modified_gmt":"2021-02-28T19:22:34","slug":"tether-leaks-and-deltec-leaks-an-unverified-but-interesting-document-dump","status":"publish","type":"post","link":"https:\/\/davidgerard.co.uk\/blockchain\/2021\/02\/28\/tether-leaks-and-deltec-leaks-an-unverified-but-interesting-document-dump\/","title":{"rendered":"Tether Leaks and Deltec Leaks: an unverified but interesting document dump"},"content":{"rendered":"<p>There&#8217;s supposedly a hacked document dump \u2014 which I don&#8217;t have a copy of \u2014 from Deltec Bank, including account details and emails relating to Tether and Bitfinex. Someone has been posting bits of it to Twitter.<\/p>\n<p>Tether is a company that issues a dollar-substitute crypto token called &#8220;tether,&#8221; which Tether had long falsely claimed was 100% backed by US dollars. Tether recently <a href=\"https:\/\/davidgerard.co.uk\/blockchain\/2021\/02\/23\/new-york-settles-with-tether-a-wrist-slap-with-a-strong-leash\/\">settled with the New York Attorney General<\/a> over these false claims. Bitfinex is Tether&#8217;s closely associated crypto exchange \u2014 who denied sharing ownership with Tether, until the link was revealed in the Panama Papers leaks. Deltec has been Tether&#8217;s banker since 2018, and seems to have rather stronger links to Tether than you might expect from being a company&#8217;s banker \u2014 Deltec has done a <a href=\"https:\/\/davidgerard.co.uk\/blockchain\/2021\/01\/14\/news-twitter-on-the-blockchain-the-us-coup-on-the-blockchain-gensler-in-at-the-sec-ripple-ex-cto-loses-bitcoin-keys\/\">podcast on behalf of Tether,<\/a> and there&#8217;s talk that Tether\/Bitffinex are part-owners of Deltec.<\/p>\n<p>I don&#8217;t know if this new document dump is for real \u2014 it&#8217;s unclear if this is a real dump, a fake dump, or a mix of real and fake data. It has some issues.<\/p>\n<p>Tether has stated that the dump is &#8220;forged&#8221; and &#8220;bogus.&#8221; [<a href=\"https:\/\/twitter.com\/Tether_to\/status\/1366075544287207430\"><i>Twitter<\/i><\/a><i>, <\/i><a href=\"https:\/\/web.archive.org\/web\/20210228172934\/https:\/\/twitter.com\/Tether_to\/status\/1366075544287207430\"><i>archive<\/i><\/a>]<\/p>\n<p>I&#8217;m treating the alleged dump as unverified but interesting gossip for now, and not trusting a word of it without verification.<\/p>\n<p>But even just as unverified gossip, the dump&#8217;s being talked about \u2014 so I think it&#8217;s worth documenting what we have so far.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/davidgerard.co.uk\/blockchain\/2021\/02\/28\/tether-leaks-and-deltec-leaks-an-unverified-but-interesting-document-dump\/deltec-logo\/\" rel=\"attachment wp-att-18865\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-18865\" src=\"https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2021\/02\/deltec-logo.png\" alt=\"\" width=\"340\" height=\"210\" srcset=\"https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2021\/02\/deltec-logo.png 680w, https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2021\/02\/deltec-logo-300x185.png 300w, https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2021\/02\/deltec-logo-348x215.png 348w\" sizes=\"auto, (max-width: 340px) 100vw, 340px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<h3>Email from &#8220;deltecexposed&#8221;<\/h3>\n<p>I got the following email a couple of weeks ago. (The full headers indicate it did indeed come from ProtonMail.)<\/p>\n<blockquote><p>Date: Sun, 14 Feb 2021 05:05:28 +0000<br \/>\nTo: &#8220;dgerard@gmail.com&#8221; &lt;dgerard@gmail.com&gt;<br \/>\nFrom: deltecexposed &lt;deltecexposed@protonmail.com&gt;<br \/>\nSubject: iFinex\/Tether Exposed &#8211; Deltec Bank<br \/>\nMessage-ID: &lt;tT8N-fDEYBxvOjB1PN84GjKuDRt4akviYfglJXgw_vMOmU3X8kTh9ubq65u2XXcb7KNFp6mtWeqIXAbZTTI-5CFLitIZ2FAcU5w3_jLG0Sg=@protonmail.com&gt;<\/p>\n<p>hello friend<br \/>\nthe zip file contains some information about the Tether and iFinex&#8217; banking relationship with Deltec Bank<\/p>\n<p>http:\/\/\u2014\u2014\u2014.onion\/bovine-chihuahua<br \/>\n&#8212; u need tor browser to download the file &#8212;<br \/>\n&#8212; scan file on virustotal to check for malware &#8212;<br \/>\n&#8212; extract archive in VM &#8212;<\/p>\n<p>enjoy the content<\/p>\n<p>p.s. all database files will be publicly leaked during the next few days\/weeks<\/p><\/blockquote>\n<p>I was very busy at the time and not checking my email properly, so I didn&#8217;t notice this for a few days. By the time I got to the Tor link, it wasn&#8217;t working. I emailed asking for a working copy, but haven&#8217;t heard back.<\/p>\n<p>I don&#8217;t know if others received a similar email.<\/p>\n<h3>Tweets from @deltecleaks<\/h3>\n<p>On Tuesday 23 February at 15:02 UTC \u2014 a few hours after the NYAG settlement went up \u2014 someone put up a Medium post: [<a href=\"https:\/\/deltecexposed.medium.com\/deltec-bank-trust-and-their-relationship-to-tether-and-ifinex-be41be43b1e3\"><i>Medium<\/i><\/a><i>, <\/i><a href=\"https:\/\/web.archive.org\/web\/20210223072719\/https:\/\/deltecexposed.medium.com\/deltec-bank-trust-and-their-relationship-to-tether-and-ifinex-be41be43b1e3\"><i>archive<\/i><\/a>]<\/p>\n<blockquote><p><b>Deltec Bank &amp; Trust and their relationship to Tether and iFinex<\/b><\/p>\n<p>Deltec Bank \u2014 the shadow offshore bank which is backed by iFinex Inc. (Tether and Bitfinex) has suffered a critical security breach.<\/p>\n<p>There is a private database dump of their business infrastructure and customers on the darknet which may lead to a crash of the whole Bitcoin ecosystem.<\/p>\n<p>We\u2019re currently looking for journalists which are willing to successively release articles related to the findings in those database leaks.<\/p>\n<p>Contact: deltecleaks@protonmail.com<\/p><\/blockquote>\n<p>An account called @deltecleaks started posting to Twitter, at 22:30 UTC on Monday 22 February. The account was rapidly suspended for doxxing, but some tweets made it to the archive sites. [<i>Twitter, <\/i><a href=\"https:\/\/archive.vn\/elHJU\"><i>archive<\/i><\/a><i>; Twitter, <\/i><a href=\"http:\/\/web.archive.org\/web\/*\/http:\/\/twitter.com\/deltecleaks\/*\"><i>archive<\/i><\/a>]<\/p>\n<p>The tweets were mostly account names. Some had\u00a0 balances attached. Several of the names were known Tether or Bitfinex principals or their relatives.<\/p>\n<p>There&#8217;s also a list of Deltec&#8217;s MSSQL database tables and users.<\/p>\n<h3>Tweets from @LeaksTether<\/h3>\n<p>When @deltecleaks was suspended, an account called @LeaksTether (Tether Leaks) started posting: [<i>Twitter, <\/i><a href=\"http:\/\/web.archive.org\/web\/20210224204503\/https:\/\/twitter.com\/LeaksTether\/status\/1364650317208551431\"><i>archive<\/i><\/a>]<\/p>\n<blockquote><p>Ever wonder what attracted #Tether to #Deltecbank ? Over the next few weeks, I will provide daily leaks from inside the #Tether brrr machine #Bitcoin<\/p><\/blockquote>\n<p>A lot of the tweets are allusions to future leaks about particular individuals.<\/p>\n<p>@LeaksTether predicts the whole Tether scheme will all fall over, no sooner than 15 March, though without any detail as to why: [<i>Twitter, <\/i><a href=\"https:\/\/archive.is\/FTHSq\"><i>archive<\/i><\/a>]<\/p>\n<blockquote><p>16 days max, could be less. Let&#8217;s just say any criminal conspiracy is only as strong as its weakest link, and fear is a great motivator.<\/p><\/blockquote>\n<h3>Alleged Tether-Deltec emails<\/h3>\n<p>The meat of @LeaksTether is screenshots of three emails between Tether and Deltec \u2014 <i>presumably<\/i> from the same dump as DeltecLeaks.<\/p>\n<p>The purported messages are from Julian Arriagada, a compliance manager at Tether at the time.<\/p>\n<p>The first two messages are to Lacy Garcia, then using her married name Lacy Roosevelt \u2014 though, according to her LinkedIn page, Garcia stopped working at Deltec in November 2017, nearly three years earlier. [<a href=\"https:\/\/www.linkedin.com\/in\/lacy-garcia\/\"><i>LinkedIn<\/i><\/a><i>, <\/i><a href=\"https:\/\/i.imgur.com\/q0SIf1x.png\"><i>archive<\/i><\/a>]<\/p>\n<p>The tweets of emails are usually removed in short order. The @LeaksTether account hasn&#8217;t been suspended as I write this \u2014 though the poster switches it off a lot.<\/p>\n<p>The first tweet was on 24 February: [<i>Twitter, <\/i><a href=\"https:\/\/web.archive.org\/web\/20210224185617\/https:\/\/twitter.com\/LeaksTether\/status\/1364650317208551431\"><i>archive<\/i><\/a>]<\/p>\n<blockquote><p>To: lroosevelt@deltecbank.com<br \/>\nSubject: Acceptance of terms<br \/>\nFrom: Julian Arriagada &lt;julian@tether.to&gt;<br \/>\nCC: abutler@deltecbank.com<br \/>\nDate: Mon, 25 May 2020 13:32:09<\/p>\n<p>Hi, Lacy<\/p>\n<p>This mostly works for us, but it would be a better solution if the notice term was reduced for providing the proof of funds.<\/p>\n<p>There are also some concerns around the proposed fees. As you are only providing a notional balance declaration, and not a loan facility, we think the fee structure should better reflect this fact.<\/p>\n<p>I will send you a slightly revised proposal, either later today, or tomorrow.<\/p>\n<p>Best Regards<\/p>\n<p>Julian<\/p><\/blockquote>\n<p>The next message is dated an hour later. If this is real, this is what Tether think they&#8217;re doing: [<i>Twitter, <\/i><a href=\"https:\/\/archive.is\/rYtrb\"><i>archive<\/i><\/a>]<\/p>\n<blockquote><p>To: lroosevelt@deltecbank.com<br \/>\nSubject: Acceptance of terms<br \/>\nFrom: Julian Arriagada &lt;julian@tether.to&gt;<br \/>\nDate: Mon, 25 May 2020 14:33:54<\/p>\n<p>Lacy,<\/p>\n<p>To answer your question. We are building an asset base outside of US dollars, with cryptos and equity stakes in crypto companies being the main areas of interest.<\/p>\n<p>Whilst we believe in the value of these assets, the regulators, and the legacy financial system they represent, do not.<\/p>\n<p>Until we win the war of ideas, we needed to find a way to present a figure which speaks to the value of our assets, but in a language acceptable to legacy financial operators.<\/p>\n<p>If it works for you, we can schedule a chat. My number is \u2014\u2014\u2014.<\/p>\n<p>Best Regards<\/p>\n<p>Julian<\/p><\/blockquote>\n<p>What&#8217;s Tether&#8217;s plan? To <i>replace Bitcoin:<\/i> [<i>Twitter, <\/i><a href=\"https:\/\/archive.is\/XVF8z\"><i>archive<\/i><\/a>]<\/p>\n<blockquote><p>To: \u2014\u2014\u2014<br \/>\nSubject: Market overview \/including DSCX\/<br \/>\nFrom: Julian Arriagada &lt;julian@tether.to&gt;<br \/>\nDate: Tue, 11 Aug 2020 16:30:52<\/p>\n<p>we&#8217;re not there yet, but when we are the plan is to lock the existing issue, and allow exchanges to ignore the peg and move the price upwards. The rest is quite technical, but 0=1, and everything else is speculative interest for the market to go after.<\/p>\n<p>Best Regards<\/p>\n<p>Julian<\/p><\/blockquote>\n<h3>Is this for real?<\/h3>\n<p>The employment dates anomaly on the Lacy Garcia LinkedIn page is a serious problem with @LeaksTether&#8217;s claimed messages.<\/p>\n<p>@LeaksTether claims, however, that Garcia was &#8220;still an associate&#8221; of Deltec in 2020, and may still be today \u2014 and that the staff photos on Deltec&#8217;s &#8220;about us&#8221; page were stock photos and locals. [<a href=\"https:\/\/twitter.com\/LeaksTether\/status\/1366073449815375876\"><i>Twitter<\/i><\/a><i>, <\/i><a href=\"https:\/\/web.archive.org\/web\/20210228173327\/https:\/\/twitter.com\/LeaksTether\/status\/1366073449815375876\"><i>archive<\/i><\/a><i>; <\/i><a href=\"https:\/\/twitter.com\/LeaksTether\/status\/1366074294355316736\"><i>Twitter<\/i><\/a><i>, <\/i><a href=\"https:\/\/web.archive.org\/web\/20210228173441\/https:\/\/twitter.com\/LeaksTether\/status\/1366074294355316736\"><i>archive<\/i><\/a>]<\/p>\n<p>There&#8217;s some names of less-known Tether\/Bitfinex-related persons in the DeltecLeaks account names dump, such as various Van Der Velde relatives.<\/p>\n<p>For the moment, I&#8217;m treating all of this as interesting but unverified gossip. You should too.<\/p>\n<p>&nbsp;<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">It\u2019s cool. We don\u2019t really believe the \u2018leaks\u2019. And we look forward to you ending all the FUD as soon as possible, by publishing the audit that will show us all the $35bn you have backing all the tethers you\u2019ve minted&#8230; \ud83e\udd74<\/p>\n<p>&mdash; Jay Filmer \ud83c\udf37\ud83d\udea8\ud83e\udd40 (@UncleJaysus) <a href=\"https:\/\/twitter.com\/UncleJaysus\/status\/1366077836776386570?ref_src=twsrc%5Etfw\">February 28, 2021<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<br><br><div align=\"center\"><p><a href=\"https:\/\/www.patreon.com\/bePatron?u=8420236\"><img src=\"https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2021\/10\/become_a_patron_button.svg\" alt=\"Become a Patron!\" title=\"Become a Patron!\" width=217 height=51><\/a><br><p style=\"align:center;\" class=\"patreon-badge\"><i>Your subscriptions keep this site going. <a href=\"https:\/\/www.patreon.com\/bePatron?u=8420236\">Sign up today!<\/a><\/i><\/p><\/div>","protected":false},"excerpt":{"rendered":"<p>I&#8217;m treating it as unverified gossip for now, and you should too.<\/p>\n","protected":false},"author":1,"featured_media":18865,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[38,977,2161,39],"class_list":["post-18863","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorised","tag-bitfinex","tag-deltec","tag-lacy-garcia","tag-tether"],"jetpack_featured_media_url":"https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2021\/02\/deltec-logo.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/posts\/18863","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/comments?post=18863"}],"version-history":[{"count":19,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/posts\/18863\/revisions"}],"predecessor-version":[{"id":18883,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/posts\/18863\/revisions\/18883"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/media\/18865"}],"wp:attachment":[{"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/media?parent=18863"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/categories?post=18863"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/tags?post=18863"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}