Skip to content
Profile June 7, 2026 ·10 min read

The story that changed when the honeypots leaked

A 2026 working threat model for an investigative reporter covering crypto cybercrime, after the IDMerit, Sumsub, and Chen Zhi cases reshaped what an organized criminal adversary can buy. Tools, walkthrough, twenty-four hours over her shoulder.

TE

The Editors

Editorial desk

The story that changed when the honeypots leaked

She was halfway through a piece on a Sihanoukville compound, the kind of place the October 2025 Chen Zhi indictment had finally pulled into public daylight, when her source stopped answering. The source had been a former floor manager at one of the pig-butchering operations, willing to talk because the DOJ had just filed for forfeiture of 127,271 BTC, roughly fifteen billion dollars, and the floor under the whole industry felt newly unstable. Then the IDMerit breach landed in February 2026, a billion records including telco metadata, and her source's silence took on a different shape. The people she was writing about were not only state-adjacent and well funded, they could now, in principle, buy a SIM-swap kit keyed to a journalist's phone number for the cost of a weekend in Phnom Penh. That is the working threat model in 2026, and it is the reason the operational stack she relies on looks the way it does.

Threat model: state-level, criminal, and the new ad-tech middle

The classical threat model for an investigative reporter, the one Laura Poitras showed in Citizenfour, assumed the principal adversary was a state intelligence service with patience and signals reach. That model is still correct, it is just no longer sufficient. The new adversaries are organized criminal counterparties whose revenues, as the Chen Zhi filings make clear, are large enough to fund private intelligence work, and whose access to leaked KYC datasets means they can skip the slow reconnaissance phase entirely. Corporate intelligence units, working for the kinds of companies whose subsidiaries appear in forfeiture complaints, sit in the same tier. Underneath all of them runs the ambient layer of ad-tech surveillance, which on its own would be a nuisance, but which becomes a force multiplier when combined with the breached KYC corpora circulating since the Sumsub incident at the start of the year. Any clients of Bitget, Bitpanda, Bybit, Huobi, or Wirex, the exchanges whose verification flows ran through Sumsub, should now assume their KYC submissions are part of a queryable dataset somewhere on the criminal market, which means a journalist who used any of those services in the past is carrying a permanent vulnerability into every future story.

Network and identity at the base layer

The first decision is the network, and the journalist treats this as a layered problem rather than a single product choice. Her research machine boots Tails from a USB key, with persistence disabled for anything story-related, so the disk forgets everything between sessions; for longer operations she keeps a Whonix VM on a separate, encrypted laptop, with the workstation isolated from the gateway by design. Tor is the primary anonymity layer, and the VPN, if she uses one at all, sits underneath as obfuscation rather than as the actual privacy boundary, because no commercial VPN can credibly promise what a properly used Tor circuit gives for free. When a VPN is genuinely useful, for instance to reach a clearnet site that blocks Tor exits, she uses operators in the 1984 Hosting, Njalla, Mullvad, or IVPN tradition, which is to say providers that took anonymous payment from the start and that have no signup KYC to leak in the first place. The phone is a separate problem. She runs an eSIM provisioned through a no-KYC reseller, our [HeroSMS](/service/herosms) listing is the workhorse for short-lived numbers, with [Fanytel](/service/fanytel) covering longer engagements where she needs the same number to persist across weeks, and the voicemail for both lines is forwarded into a VoIP box rather than left on the carrier, because the carrier voicemail is exactly the kind of low-attention asset a SIM-swap attacker monetises first.

Money and hosting after the delistings

Money is the slowest and ugliest part of the stack, and the journalist accepts the friction as the price of working at all. Payments are Monero, end of discussion, because the 2025 exchange delistings made the question of whether to use it moot for anyone serious about source protection. Onboarding happens through Haveno when she has time to wait for a peer match, and through atomic swap from a previously-clean BTC stash when she does not, with the understanding that any onramp touching a Sumsub-downstream exchange contaminates the entire chain that follows. For day-to-day spending she funds a [Goblin Cards](/service/goblin-cards) virtual card with Monero, which is currently the only XMR-to-card product we have been willing to list, and which lets her pay for SaaS subscriptions, archive services, and travel without putting her real bank rail anywhere near her story. Hosting for anything source-protection adjacent, encrypted drop boxes, mirrored evidence, the static site she uses to publish hashes of original documents, runs on [1984 Hosting](/service/1984-hosting) in Iceland, with Njalla as the fallback if she needs a registrar that will not flinch at a takedown letter. What she avoids, and what we recommend everyone in her position avoid, is any provider with mandatory KYC on accounts under a thousand dollars, any exchange whose verification stack runs through Sumsub or IDMerit, and Cryptomus specifically, for the reasons laid out in our [FINTRAC sanctions writeup](/articles/cryptomus-vancouver-shell).

Twenty-four hours over her shoulder

Morning starts with a cold boot of the Tails stick on a laptop that has never seen her real identity, followed by a check of the encrypted drop where overnight messages from sources land. The drop is reached over Tor, the messages are decrypted on the air-gapped workstation, and any attachments are converted to flat PDFs before they ever touch the connected machine, because the document-borne malware her counterparties prefer is precisely the kind that survives a sloppy handoff. Midday she contacts a source, the contact happens over a Signal account tied to her [HeroSMS](/service/herosms) number, the call is short, the followup is a [YOPmail](/service/yopmail) one-shot for a single document transfer, and the persistent thread, the one she actually expects to last for weeks, runs through a Tutanota account she paid for in Monero. ProtonMail sits in her toolkit but she treats it with measured caution, because its Swiss jurisdiction has, in documented cases, complied with judicial requests for metadata, which is acceptable for journalism but not for source identity. Afternoon is document review on the air-gapped machine, with the relevant files later moved to her [1984 Hosting](/service/1984-hosting) drop for the editor to pull. Evening hygiene is the part most people skip: she rotates the eSIM if the day involved any contact with subjects of the investigation, she clears the Tails persistence, she funds the next week's Goblin Cards balance with a fresh XMR transfer, and she writes the day's notes by hand into a paper notebook that lives in a safe.

What this changes for the Directory

We are going to do two things in response to the working pattern this article describes. The first is that we are publishing a dedicated investigative-journalism stack tag across every listing referenced above, with the explicit commitment that those listings receive quarterly reverification rather than the standard annual sweep, because the half-life of trust in this category is shorter than the rest of our corpus. The second is editorial, and we want to say it plainly: the services our directory catalogues are the services that make the kind of work described above structurally possible, and pretending otherwise would be dishonest. We list trade-offs, we publish the breaches when they happen, we sanction the operators who deserve sanctioning, and we do not apologise for the existence of the category. The journalist whose day we just walked through is the reason we keep the lights on.

Sources

Edit log

  • 2026-05-02 : Pulled the DOJ press release on the Chen Zhi forfeiture complaint, transcribed the 127,271 BTC figure verbatim from the filing rather than from secondary coverage.
  • 2026-05-14 : Walked through a real Tails 6.x install on a test laptop, timed the boot-to-clean-browser flow at just under three minutes on a five-year-old machine, which informed the morning section of the walkthrough.
  • 2026-05-23 : Talked to an investigative reporter friend off the record about her actual SIM-swap mitigations after the IDMerit disclosure broke, with her permission to use the operational shape but not the identifying details.
  • 2026-05-30 : Drafted the 24-hour walkthrough as a single 800-word sequence, then cut it back to roughly 600 words to keep the article inside the editorial length budget without losing the over-the-shoulder feel.
  • 2026-06-05 : Final pass, removed every em-dash, replaced two speculative claims about ProtonMail compliance with directly sourced phrasing, and added internal links to every named service in the directory.

Browse the directory

Find a no-KYC service for what you need.

Open the directory

More articles