Login
Sign Up
Blockchain investigator ZachXBT publicly identified Dritan Kapllani Jr., an 18-year-old US national, as a central figure in a series of social engineering attacks totaling approximately $19M. While not yet formally charged, judicial documents classify him as a conspirator in a scheme that gained traction due to a dramatic self-incrimination event. The investigation originated from a casual wealth display that inadvertently provided the forensic link required to trace illicit fund movements across the network.
The catalyst for the exposure occurred on April 23, 2026, during a Discord voice chat session known as "Band 4 Band," where participants competed by showcasing their digital assets. Under competitive pressure to prove his financial standing, Dritan enabled screen sharing to display his Exodus wallet interface, revealing a balance of roughly $3.68M. This footage, initially intended as a status signal, was later recovered and analyzed by ZachXBT, who used the visible wallet address to reconstruct a complex trail of fund transfers spanning months of criminal activity.
Forensic analysis traced the funds back to a major social engineering incident on March 14, 2026, involving the theft of 185 BTC, valued at approximately $13M at the time. Within 24 hours of the initial breach, roughly $5.3M of these assets were moved to the specific wallet address Dritan had displayed during the Discord session (0x4487db847db2fc99372a985743a26f46e0b2bba6). Subsequent transactions fragmented this sum across multiple addresses, with approximately $1.6M further transferred by the time of the April 23 chat, demonstrating a sophisticated layering strategy designed to obscure the money trail.
Data compiled by Woofun AI indicates that the capital in Dritan's wallet did not originate solely from the 185 BTC theft. Blockchain analysis revealed connections to multiple social engineering campaigns dating back to 2025, aggregating to over $5.85M. Despite varying victim profiles and execution dates, the funds followed a consistent pattern of fragmentation and transit through intermediary addresses before converging on the wallet Dritan publicly displayed, confirming a unified operational methodology.
The investigation also uncovered a prior conflict between Dritan and another hacker, John Daghita, known as Lick, who was arrested for allegedly stealing $46M in US government funds. In a deleted Telegram post, Lick publicly disclosed an older wallet address associated with Dritan (0x97da0685dbba50b4cbabb0ca9e8336f4fbe41122) in an apparent act of retaliation. Blockchain analysis confirms a high degree of consistency between the fund movement patterns of this older address and the primary wallet, suggesting both were controlled by the same individual.
On May 11, 2026, these findings were formalized in a criminal indictment against Trenton Johnson, who faces a maximum sentence of 40 years for his role in the 185 BTC theft. The legal document identifies a key figure as "Co-Conspirator 1 (CC-1)," whom the blockchain analysis community has identified as Dritan Kapllani Jr. Although Dritan remains uncharged, he is embedded within the conspiracy framework through associated addresses. The indictment also names Meme coin influencer yelotree, accused of laundering funds via a Miami car rental business, facing a potential 30-year prison term.
Woofun AI notes that Dritan previously cultivated a reputation of impunity within the hacking community, often sharing a lavish lifestyle on Instagram while groups like ACG and 41/RM Boyz faced law enforcement action. This perceived "heroic aura" evaporated upon his 18th birthday, as legal jurisdiction solidified and his digital footprint became actionable evidence. The case underscores the increasing efficacy of combining on-chain forensics with behavioral analysis to dismantle decentralized criminal networks.