Who was Mike?

The evidence on whether Altilly’s lead developer, known in the chat as “Mike”, was Paul Vernon of Cryptsy.

Read this first. No court or authority has confirmed that Mike is Paul Vernon, or that Mike took the Altilly funds. This page sets out the documents that bear on those questions, including the ones that point the other way. Where something is only Nayiem's belief, it is labelled as a belief.

The developer who built and ran Altilly's exchange software appears in the chat as "Deleted Account". The team called him Mike and tagged him as @MrMike_O. He ran the servers, the wallets and the database #1492 #1493 #1299 #2491. He lived in north-east China #3639 #2674.

After the chat ended, Nayiem came to believe that Mike was Paul Vernon, the founder of the Cryptsy exchange, who is under US indictment. This page asks how far the evidence supports that belief.

How the cards are graded. Each card is graded by how much weight it can bear on the question "who was Mike?":

  • Strong: a document from the time that is hard to explain another way.
  • Moderate: a real document that needs one reasonable assumption.
  • Weak: a detail that fits but proves little.
  • Points the other way: facts that weaken the case or complicate it.
  • Context: public records the other cards rely on.

In short

  • Well documented: Mike was a real person, separate from Nayiem. He used the name Michael Osullivan and the GitHub account mrmikeo.
  • Well documented: In February 2021 Mike ordered a company Revolut card. It arrived in an envelope addressed to "PAUL Vernon". When Revolut asked him to verify his ID in March 2021, he put it off #4415.
  • Well documented: Mike is on no company register we found. The UK company formed in December 2020, Qredit Ltd, lists only Nayiem.
  • Likely, but not confirmed: Mike used the name Paul Vernon.
  • Possible, but unproven: Mike is the Paul Vernon of Cryptsy. Several details fit, but each one has an innocent explanation, and no authority has said so.
  • Not shown by anything on this page: that Mike took the Altilly funds.

The evidence

Strong evidence

Mike was a real person, separate from Nayiem

Some people online have said that Mike never existed and that Nayiem was Mike. One example is a Reddit post of February 2025 (https://old.reddit.com/r/pepecoin/comments/1il8ei9/). The chat does not support that claim.

  • He answered to "Mike". When Nayiem or Chuck tagged @MrMike_O, "Deleted Account" answered #790 #792 #794.
  • He used the name Michael Osullivan. A support email to him opens "Hi Michael" #3288. In May 2021 he shared a whitepaper cover with the author line "Michael Osullivan, @MrMikeO" #5529.
  • He linked his own GitHub account, github.com/mrmikeo #4380.
  • He lived in China. He asked whether Revolut sends cards to China #3639, and described the weather in the north-east #2674.
  • Nayiem lived in Sweden. At the same time, Nayiem was writing from Sweden and planning a trip to Stockholm #5734 #5735.
  • Mike was named publicly before any of this. A 2018 Bitcointalk announcement names "Michael Osullivan" as the Altilly coin developer (https://bitcointalk.org/index.php?topic=5086735).

This shows that Mike was a real person with a working identity of his own. It does not show which of his names, if any, was his legal name.

Strong evidence

The Revolut card addressed to "PAUL Vernon"

In February 2021 Nayiem set up a Revolut Business account for the team and invited Mike and Chuck.

  • Nayiem told Mike he could now order a card #3638.
  • Mike asked, "they send physical cards to china?" #3639. He then got the message "Sorry, our service is not offered in your country" #3646.
  • Nayiem replied, "Send it to my address, I will send it to you then" #3647.
  • Mike wrote "ok, done" #3653, and Nayiem confirmed, "Mike is registered and ordered his card" #3693.
  • Two days later Nayiem posted a photo of a Revolut DHL envelope, dated 3 February 2021, delivered to his address. It was addressed to "PAUL Vernon" #3833. Chuck asked, "card already?" #3834.
  • Chuck ordered his own card and received it separately #3846.
  • Mike later wrote that parcels "can take a few days to clear customs" in China #3837, and on 19 February, "oh, i got my revolut card today" #3960.

The name on the card is whatever the account holder registered. Here the account holder was the person the team knew as Mike, writing in 2021, years before anyone had a reason to invent the link. This is the most direct document on this page.

What it does not show: that a bank had checked the name. In March 2021 Revolut asked Mike to verify his ID. He put it off: "my passport is at the china visa office" #4414 #4415 #4416. We do not know whether he completed that check later. Revolut's own records would show what name, if any, the account was verified under (see "What would settle this").

Moderate evidence

Mike's own words: "[email protected]"

On 26 December 2020, while the team tried to work out how the servers had been wiped, Mike said the attacker got in "thru an old email still attached to the account" #1289. About 25 minutes later he wrote the address and added a comment:

[email protected] #1326 history on that domain probably has my name #1328

Later that day he said it was an email he had used "when initially setting up the service 3 years ago", with no 2FA #1504. He said Cherry Servers told him the deletion request came from that email over Tor #1508.

This was written before anyone in the group suspected Mike of anything. It shows that Mike had used the address [email protected], and that he expected the domain's history to show his name.

Caveats.

  • Three messages around these are missing from the export: numbers 1323, 1325 and 1327. The message just before the address reads only "the old email address that was used does" #1324. We cannot see what the missing messages said or who removed them.
  • The address points to "satotechlt.com", not "satotechltd.com". The next card explains why that matters.
Moderate evidence

The satotechltd.com WHOIS record

A historical WHOIS record shows who registered satotechltd.com, one letter different from the address Mike wrote. Nayiem posted a screenshot of it in the chat in 2026 #7577. The record shows:

  • the domain was created 18 July 2015, with expiry 18 July 2016;
  • the registrant is "PAUL VERNON", company "PROJECT INVESTORS INC", Delray Beach, Florida.

Project Investors Inc. is the company that ran Cryptsy. A Bitcointalk post from January 2016 lists a Hong Kong "Satotech Limited" linked to Vernon, with the same phone number as the WHOIS record (https://bitcointalk.org/index.php?topic=1173703.msg13568578#msg13568578). Nayiem posted that link too #7583.

Why this is only moderate.

  • The link depends on reading "satotechlt.com" as a typo for "satotechltd.com". That is Nayiem's reading, made in 2026, when he posted the satotechltd.com record in reply to Mike's message #7577. It is reasonable, but it is not proven.
  • Neither domain is registered today, so the records cannot be checked live.
  • The one historical record we have covers only 2015 to 2016. Mike dated his use of the email to about 2017 #1504. The record does not show whether the domain was renewed.
Weak evidence

The Dalian mailing name matches a person in the Cryptsy court record

While ordering the card, Mike gave a postal address in Dalian, China, and a name to mail things to #3662 #3663. He also gave a phone number #3669.

The addressee's name is the same as a name that appears in court filings in the Cryptsy receivership, where it is connected to Vernon.

We do not publish the name, the address or the phone number, and we do not describe the court filings in more detail, so that the person cannot be identified. They belong to a private person who may have nothing to do with any of this and is accused of nothing here. Please do not try to find out who it is. The details are redacted from the chat on this site, and the full details are available to authorities. Nayiem did include this name, with a property listing, in his February 2025 write-up, which he shared with investigators and initially posted on Reddit. He now says that was wrong (see What I got wrong in 2025).

Caveats.

  • The name is common in China, and we have not confirmed that the two are the same person.
  • A receiver's filing contains allegations, not findings.
  • Nayiem's 2026 note on this message is a belief written with hindsight, not a record from the time #7581.
  • Because the name is withheld, readers cannot check this match themselves. That is why it is graded weak here, and why the Assessment does not rely on it.

It fits with the envelope and the email above, but on its own it could easily be a coincidence.

Weak evidence

Mike and the stolen Cryptsy bitcoin

On 1 April 2021 Mike brought up Cryptsy without being asked: "was looking at the old cryptsy hack stuff. The bitcoin that was stolen was never redeemed after it moved" #4525. He linked the exact transaction #4526 and said it was "now worth 664 million dollars" #4527. Then he added:

yea, we had noticed they hadn't moved years ago, thought it was strange back then that they didn't move after a year. my guess is they messed up something and lost access to the keys. #4529

Nayiem joked, "I would like to have those keys" #4530. Mike replied "me too" and "im sure people still watching those addresses tho" #4531 #4532. Chuck said he watched them too #4534.

In 2026 Nayiem highlighted the word "we" #7596. That word could mean Cryptsy's own staff, but it could just as well mean people in the crypto community, who followed these coins closely. Chuck, for one, said he watched them too. On its own this proves nothing. It is here because it shows Mike knew the Cryptsy theft in detail.

For context: about a year later, in March 2022, the Cryptsy theft coins moved for the first time in nearly eight years (Elliptic, https://www.elliptic.co/blog/bitfinex-2.0-elliptic-traces-bitcoin-worth-512-million-from-2014-cryptsy-exchange-theft). Elliptic does not say who moved them.

Moderate evidence

The mrmikeo GitHub account and the Xeggex commit

These are public records, which we checked on 29 September 2026. Git author names and emails are chosen by the user, so they show which account was used, not who was behind it.

  • The Altilly repositories. The official Altilly Node client (github.com/altilly/nodealtillyapi) lists its author as "Michael Osullivan". Its commits were made by the account mrmikeo, and a 2019 commit to another Altilly repository used [email protected].
  • The mrmikeo profile. The account was created in 2017. It shows the name "MikeO" and the location "Northern China" (https://github.com/mrmikeo). Mike linked to it himself in the chat #4380.
  • The Xeggex commit. The official Xeggex GitHub organisation has a fork of the hummingbot trading software. The latest commit on its main branch, d1479b80fe, dated 1 April 2024, was made by mrmikeo through GitHub's web interface (https://github.com/xeggex/hummingbot/commit/d1479b80fe4003100502eea94d7142d3de54c7eb). It is a routine "sync with upstream" merge, not new code. But only an account with write access to that Xeggex repository could make it.
  • Coding style. The Altilly client, a personal client on the mrmikeo account, and Xeggex's official Node client share an unusual way of writing the same setup code. This is our own comparison. A shared habit is suggestive, not conclusive.
  • Dates. The xeggex.com domain was registered on 31 August 2021, and the Xeggex GitHub organisation was created on 20 September 2021.

This is good evidence that the Altilly developer's account had a working role at Xeggex in 2024. On the question of Paul Vernon it says nothing either way.

Context

Companies House

Xeggex's UK companies. The UK register lists officers under the name Michael Osullivan for two Xeggex-related companies:

  • XEGGEX SOFTWARE SERVICES LTD (no. 14910559), incorporated 2 June 2023 and dissolved 31 December 2024.
  • XGX SOFTWARE LTD (no. 15572800), incorporated 18 March 2024 and dissolved 26 August 2025.

The register records what the filer declares. When these companies were filed, Companies House did not verify identities. The different name orders, nationalities and birth months are themselves worth noting. Nayiem is convinced "Michael O'Sullivan" is an alias Mike used, possibly backed by a false passport; the different name orders, nationalities and birth months would fit that. The register cannot prove it; establishing who filed these entries is a job for law enforcement. The name may also belong to a real person who has nothing to do with this. We do not accuse anyone of that name of anything.

Altilly's company. Mike does not appear on any company register we have found in connection with Altilly. The next card covers the company Nayiem formed.

Context

Qredit Ltd: the company Nayiem formed, with no Mike on the register

We checked the UK register (Companies House) on 30 September 2026 (https://find-and-update.company-information.service.gov.uk/company/13077371).

  • QREDIT LTD (no. 13077371) was incorporated on 11 December 2020, at a London formation-agent address.
  • Nayiem Willems is the only director and the only person with significant control, holding 75% or more of the shares and votes.
  • Mike does not appear, under any name: not as Michael Osullivan, not as Paul Vernon, and not in any other role.
  • The company never filed accounts or a confirmation statement. It was struck off and dissolved on 17 May 2022.
  • The chat never mentions this UK company. There are also no messages between 2 and 18 December 2020, so the incorporation date falls in a gap in the export.
  • Willems Ventures Ltd was incorporated the same day. In the chat Nayiem tied it to his tourist resort #1579 #1583. He says it had nothing to do with Altilly.

Altilly itself was never on a register we could find. In 2019 Nayiem wrote that Altilly was "still incorporated in Hongkong" #759. But on 28 December 2020, when Chuck asked about a Hong Kong address #1776 #1777, Mike said it was "maybe for a company registration service i was going to use originally to form a company in hk. never did do that tho" #1778. The two statements conflict, and the later one is Mike's own.

The bank account was Nayiem's too. The Revolut Business account was in Nayiem's business name, and he was its admin. Mike was a team member with a card. When Revolut asked Mike to verify his ID in March 2021, he put it off: "can't do it right now, my passport is at the china visa office" #4414 #4415 #4416. Nayiem then gave his own card instead #4417. No later message shows Mike completing the check.

Nayiem's account (not shown in the chat).

  • Nayiem says Mike privately promised that, once Nayiem had set up Qredit Ltd, he would formally take over Altilly. The chat has no message that transfers ownership.
  • He says Qredit Ltd never traded because his own XQR (Qredit) coins were held on Altilly and lost in the hack. The chat confirms the XQR was lost: Chuck asked "is XQR safe?" and Nayiem answered "Nope" and "All lost" #1731 #1732 #1733 #1734.
  • He believes Mike took the XQR along with the rest. That is his belief. The chat shows only that the XQR was lost.

Why it matters, both ways. On paper, every legal and financial responsibility sat with Nayiem: the company, the bank account and the public role. Mike left no trace on any register connected to Altilly. That fits Nayiem's account that Mike kept his name off everything. It also means Nayiem, not Mike, is the one people could hold to account, and the company he formed never filed accounts and was struck off. The incident began on 23 December 2020, twelve days after Qredit Ltd was incorporated.

Context

Paul Vernon's public record

The following is documented in court and government records. None of it mentions Altilly, Xeggex or "Mike".

  • Cryptsy. Paul E. Vernon founded Cryptsy and ran it as CEO through Project Investors Inc. of Delray Beach, Florida. In January 2016 he disclosed that the exchange had lost about 13,000 BTC in July 2014, which he blamed on a hack. Cryptsy collapsed that month.
  • Default judgment. In the customer class action (S.D. Fla., no. 9:16-cv-80060), Vernon did not respond. On 27 July 2017 the court entered a default judgment of $8.2 million against him. The court also declared the roughly 11,325 BTC stolen on 29 July 2014 to be property of the customer class (Silver Miller, https://silvermillerlaw.com/?p=734). A default judgment means he did not defend the case. It is not a trial finding.
  • Indictment. A 17-count federal indictment was filed on 15 August 2019, unsealed in January 2022 and announced by the DOJ on 26 January 2022 (S.D. Fla., no. 1:19-cr-20509). The charges are wire fraud, money laundering, computer fraud, tax evasion and destroying records. The indictment alleges that Vernon:
  • Fugitive status. The plaintiffs' lawyers describe him as a fugitive believed to be in China (Silver Miller, 27 January 2022, https://silvermillerlaw.com/?p=1627). We found no report of an arrest or a trial.
  • His side. In 2016 Vernon denied theft. He said the losses came from a real cyber attack and that the money he took was salary.
  • He is presumed innocent of the criminal charges.
Weak evidence

Details that fit, but prove little

  • Location. Mike lived in north-east China #2674 #3639 and gave a Dalian mailing address #3663. Vernon is reported to have moved to China in late 2015. Dalian also appears in 2016 press reporting on Vernon's activities in China (CoinJournal, https://coinjournal.net/news/cryptsy-paul-vernon-exchange-china/).
  • Age. Mike said he joined the army in 1991 #5456. The Companies House officer was born in 1973. The DOJ gave Vernon's age as 48 in January 2022. These fit together, but many people were born around 1973. We have not verified Vernon's military record, and one published source gives a different enlistment year.
  • Knowledge. Mike had been looking at the Cryptsy theft and linked its exact transaction #4525 #4526.

Each of these would be unremarkable on its own.

Points the other way

Common names and a one-letter typo

  • "Paul", "Mike", "Michael" and "O'Sullivan" are very common names. So is the Dalian addressee's name.
  • The link from Mike's email to Vernon's company depends on reading "satotechlt" as "satotechltd". That is a reasonable reading, but it is still a reading.
  • The envelope shows only the name Paul Vernon. There are many people with that name. Nayiem says that when he searched it in 2021 he found a British blues musician #7585.

The case rests on several independent items pointing the same way, not on any single one. Each item alone could be a coincidence.

Points the other way

The house videos do not show where the money came from

On 16 May 2021 Mike said he had "moved half my stuff to new house today" #5094, and the team saw videos of the new house, still under renovation, including a very large bath, an indoor pool, the garden and his room #5099 #5106 #5114 #5115 #5123 #5125. Chuck joked, "Im moving in with mike either in this life or the next" #5111. The work was still being finished in September 2021 #7430 #7431.

In 2026 Nayiem added notes calling these "5 months after the hack" #7589 #7590 #7591, and in 2025 he wrote that Mike lived in a villa paid for with stolen funds. Those claims leave out what Mike said at the time:

  • He was selling another house. He had cut its price in February 2021 #4204, hoped to sell it over the summer and "live off that cash" #5471 #5472, and found a buyer in September 2021 #7535 #7544.
  • Of that house, he said it was bought "like 9 years ago" #6163–#6166.
  • The furniture for the new house had been "sitting in a warehouse for a year" by September 2021 #7431. Taken literally, the furniture was bought before the December 2020 loss.

In context, the "nine years" remark was about the house he was selling, not the new one. The chat does not show when or how the new house was bought, or how the renovation was paid for. The house does not show that Mike took Altilly money, and this page does not claim that it does.

Points the other way

No authority has confirmed any of this

  • No court, police force or government body has said that Mike is Paul Vernon, or that Mike was involved in the Altilly loss.
  • The charges against Vernon concern Cryptsy only.
  • Nayiem says he reported his information to the FBI and the US Marshals Service in early 2025. He says the Marshals opened a two-way dialogue and issued a tip reference, 777-W77728, but never responded in it beyond that, and that the FBI gave him no case number. A tip reference confirms only that a report was filed.
  • Community write-ups that link Vernon to Altilly or Xeggex, such as Rekt News (https://rekt.news/plant-a-red-flag), describe it as an allegation. Most of them trace back to Nayiem's own 2025 posts, so they are not independent confirmation.
  • Mike denied any part in the Altilly hack. According to Nayiem's screenshots, he did so on Discord on 3 December 2022. Mike's account is deleted, and he has not answered here.
Points the other way

Nayiem trusted Mike for years

A fair reader will ask why, if the signs were there, Nayiem did not act on them at the time. The chat shows that he did not suspect Mike during the period it covers:

  • On 25 December 2020 he told Mike, "don't be ashamed or whatever Mike. It's not your fault" #1256.
  • In May 2021 he told Mike, "I trust you with the hosting panel. It's not like something bad ever happened before." #5658, and accepted Mike's offer of "that 10k", and "a little extra", towards the crypto licence for a new venture #5728 #5735 #5737.
  • In September 2021 he was still planning work with Mike #7428.
  • He held the "PAUL Vernon" envelope in his hands in February 2021 #3833. He wrote in 2026 that he "always knew that Mike never used his real name" #7595.

Nayiem says he worked with Mike in other channels into 2022. He says the relationship ended after Solar (SXP), a project he led, found in November 2022 that funds had been taken. Solar's statement of 30 November 2022, posted in the Solar validator group on Discord and titled "UNAUTHORISED BEP20->SXP SWAP TRANSACTIONS", says that on 29 November 2022 unauthorised swaps were detected which took place between 12 August and 29 November 2022, exchanging non-existent BEP20 SXP tokens for mainnet SXP coins, and that "In total, 1,878,477 SXP was fraudulently swapped". It says "The identity of the perpetrator is known, and the necessary recovery processes are now in motion which cannot be discussed further for legal reasons." It does not name Mike or anyone else. That Mike was the perpetrator comes from Nayiem's Discord screenshots in his February 2025 write-up, not from the statement. In them, on 29 November 2022 at 22:45, Nayiem asks "Why did you do it Mike?"; at 00:17 on 30 November he writes "We are not going to say anything if you can return the funds in 24hrs."; and at 05:43 MikeO replies "sorry man. ya i fucked up… original plan was to earn some money from trading… liquidated out of my positions on the ftx crash… only thing that is possible is to return it as i can get it." On 3 December 2022 MikeO wrote "I had nothing to do with the altilly hack." By Nayiem's account, Mike repaid the full 1,878,477 SXP in 12 payments between 1 December 2022 and 19 March 2024, back to the Solar swap wallet involved in the theft; the final payments can be checked on the Solar blockchain (see the Solar repayment ledger). Nayiem says that after the business relationship ended in late 2022, he stayed in contact with Mike for one reason: getting money back. First the Solar funds, and later a promise Mike made to fund the remaining Altilly refunds for non-saved assets and to pay Chuck, which Mike never followed up on. Nayiem did not warn Xeggex users in that time. The screenshots are Nayiem's own evidence, and the ledger is his own record: the final transactions can be looked up, but a transaction does not show who sent it. Mike's role is unconfirmed on this site.

What follows from this. Nayiem's belief that Mike is Paul Vernon, and that the Altilly "hack" was an inside job, formed years after the events. His 2026 notes in the chat state some of this as fact: "Mike/Paul" #7595, and "orchestrate" #7587. Read those notes as his beliefs. Nayiem is also an interested party. He was Altilly's public CEO, many people blame him, and he curated this export.

What this page does not claim

  • It does not claim that Mike is Paul Vernon. It claims that the documents above make that a reasonable question, and it shows how far they go.
  • It does not claim that Mike, or anyone, took the Altilly funds. The chat shows that Mike alone controlled the systems that were wiped. It does not show what happened to the money.
  • It does not accuse anyone named Michael O'Sullivan, or anyone named in the Cryptsy court record other than Vernon himself.
  • It does not ask anyone to find, contact or visit anyone. Please don't. If you have information, give it to the authorities.

What would settle this

Any one of these would settle the identity question far better than this page can. Most of them are held by companies or authorities, not by Nayiem.

  1. Revolut's records. The team member who ordered the "PAUL Vernon" card #3693 #3833 went through Revolut's onboarding. If he later completed the ID check he put off in March 2021 #4414 #4415, Revolut holds the verified name and identity document. Authorities can request them.
  2. Cherry Servers' records. These would show who registered the [email protected] email on the hosting account, and the full login history Mike said only went back five days #1509 #1749.
  3. The original files. This means the envelope photo with its metadata, and a full, unedited export of this chat from another former member, such as Chuck, to compare against the gaps.
  4. Checks by the authorities. Law enforcement can compare the identity documents behind the Revolut account, the Companies House filings and the Dalian address with the identity of the indicted Paul Vernon.
  5. On-chain tracing. Tracing the Altilly hot and "safe" wallets lost in December 2020 #1299 #1600 might show where the funds went, and whether any of them reached addresses tied to Mike, to Nayiem or to anyone else.
  6. Mike's own answer. A statement from Mike, under any name, would help, especially if it came with a verifiable identity.

What would count against Nayiem's belief:

  • a verified Revolut identity under a different legal name;
  • proof that the Dalian addressee is a different person from the one in the Cryptsy filings;
  • a documented reason for the [email protected] email that has nothing to do with Vernon.

The private name, address and phone number withheld on this page, the unredacted chat, including deleted messages, and the original photos are available to any authority that asks, via Telegram at @nayiem.