The phone went dark at 2:14 a.m. The wallet went dark by sunrise.
Polish authorities arrested four people this week in a SIM-swap and money laundering operation that allegedly drained tens of millions of zloty in crypto. A pseudonymous investigator linked one of the suspects to the case through his own Instagram feed.
I. The phone that stopped being his
Marek was thirty-eight. He designed packaging for a Warsaw studio that mostly worked with cosmetics brands. He had been in crypto since 2019, not as a true believer, just as someone who watched friends buy apartments with money the friends did not seem to have earned. He kept most of his coins on a major exchange because the app was clean and the recovery flow felt grown-up. He had two-factor authentication turned on. SMS. The default. The one the exchange recommended when he signed up.
The phone was face-down on the nightstand. It was 2:14 a.m. on a Tuesday. His girlfriend was asleep. The dog was on the floor. The phone did not ring. It did not buzz. It simply lost signal.
He noticed because he woke up to use the bathroom and tapped the screen out of habit. No service. He assumed the tower. He went back to sleep.
By the time he made coffee, his exchange balance was zero. Not low. Zero. The login worked. The app opened. The portfolio screen rendered the way it always did. There was just nothing in it.
Picture it. The same screen. The same font. The same green and white. Empty.
That moment, multiplied across an unknown number of accounts in Poland and abroad, is the case that Polish authorities began closing on this week.
II. What the carrier did not know it did
On Wednesday, Poland's Central Bureau for Combating Cybercrime, the CBZC, announced the arrest of four people in connection with a crypto SIM-swap and money laundering operation. The Block reported it first in English, citing the pseudonymous on-chain investigator ZachXBT. The Polish-language announcement from CBZC came alongside it. All four suspects were remanded into pre-trial detention. Charges include participation in an organized criminal group, theft by hacking, and money laundering. Maximum penalty: 25 years.
The suspected laundering volume, according to Polish authorities, runs into tens of millions of zloty. Ten million zloty is roughly $2.5M USD. The full figure has not been broken out publicly, but the phrase "tens of millions" puts the operation, at minimum, in the multi-million dollar range.
Here is what a SIM swap is, in the plainest words it can be put in.
Your phone number is not really inside your phone. It lives in a database at your carrier. When the carrier moves your number to a new SIM card, your phone goes dark and the new SIM rings.
That is the entire trick. The attacker does not break into your phone. The attacker convinces the carrier, or someone with access to the carrier's systems, to move your number onto a SIM card the attacker is holding.
Once the number is on their SIM, every text message meant for you arrives at them. Including the six-digit code your exchange sends when someone tries to log in. Including the code that authorizes a withdrawal. Including the code that resets your password.
The 2FA the exchange told Marek to turn on was the door. The SIM swap was the key.
According to the CBZC, the group did not just sweet-talk call center workers. They allegedly breached the IT infrastructure of companies that work with Polish telecom operators. They used specialized software and social engineering to get into employee email accounts. From inside those inboxes, the SIM swaps got easier. They were no longer asking the carrier for a favor. They were the carrier, from the carrier's own system.
That is the part that should slow you down.
The fraud did not happen at the edge of the network. It happened at the desk of someone whose job was to keep the network safe.
III. The money path, which is never one pipe
Once the coins moved off the victim accounts, they did not move in a straight line. They never do.
The CBZC describes the laundering layer as a distributed financial network. Personal bank accounts in Poland and abroad. International payment platforms. Multi-currency digital wallets. The point of that structure is not speed. It is friction for anyone trying to follow.
Each hop is a small fee and a small delay. Each hop is also a jurisdiction, a different subpoena, a different language for the warrant. By the time the trail crosses three borders, the cost of recovery for any single victim's coins exceeds the value of the coins.
That math is the business model.
The FBI logged $68M USD in U.S. SIM-swap losses in 2021, $72M USD in 2022, and almost $50M USD across 1,075 reported attacks in 2023. Those are only the ones people reported. Most victims do not report. They are embarrassed. They believe, on some level, that they did this to themselves.
They did not.
IV. The man who flexed the evidence
This is where the case becomes a different kind of story.
ZachXBT is a pseudonymous American researcher who has spent the last four years embarrassing crypto criminals with public records and screenshots. He has helped law enforcement with arrests and recoveries on more than one continent. He posts on X. He does not give interviews. He is, by now, a fixture of any serious SIM-swap or rug-pull case in the English-speaking corner of crypto.
On the day of the Polish arrests, ZachXBT publicly alleged that one of the four people in custody was a Polish social engineering threat actor known online as "Merry," real name Wojtek Kulisz. Polish authorities have not confirmed names. They rarely do at this stage.
The way ZachXBT made the link is worth reading slowly.
He compared the designer clothes, the watches, the chains, the sneakers, on Kulisz's public Instagram account, "wojtekk," with the items reportedly seized during the raid.
The same watches. The same chain. The same sneakers.
The Instagram was the receipt.
There is a kind of person in crypto fraud who cannot resist showing the proceeds. The car. The hotel suite. The bottle in the club. They believe the audience is other operators. They forget that the audience also includes a guy with a spreadsheet and a thousand screenshots saved by date.
If the allegation holds, the part of this case that put a name on a suspect was not surveillance. It was vanity.
V. Marek's morning, again
Marek did not get his coins back.
He filed a report. He changed his number. He moved what he could rebuild to an authenticator app, the kind that generates codes on the device itself instead of by text message. He bought a hardware wallet, the small USB-looking device that keeps the keys offline. He learned, two years too late, the phrase the security people had been saying the whole time. SMS 2FA is not security. It is a habit the industry has not fixed because fixing it is annoying.
He still uses the same carrier. He did not really have a choice. There are only so many of them.
What he lost was not just the coins. It was the assumption that the phone in his hand belonged to him.
That is the assumption the machine eats.
VI. The shape of the machine
Strip the case down and you can see the parts.
A telecom back office with too many people in it. A 2FA standard that the entire crypto industry knows is broken and still uses by default. A laundering layer that is cheap to build and expensive to chase. A social media culture that rewards posting the watch. An OSINT investigator filling the gap that law enforcement budgets cannot.
None of those parts are new. The arrests in Warsaw this week are part of a wider European push that includes Europol's SIMCARTEL operation from October 2025. In March 2025, T-Mobile was ordered in arbitration to pay $33M USD over a single SIM swap that drained a customer's crypto wallet. On June 1, 2025, ZachXBT exposed Canadian SIM swapper Cameron Redman, alleged to have stolen $37M USD in 2020, with only $5.4M USD recovered.
The names change. The structure does not.
If you are reading this with an exchange app open in another tab, the ugly question is not whether your password is strong. The ugly question is whether your phone number is really yours.
Tonight, somewhere, a swap is being prepared. A SIM is in a tray. An inbox is open that should not be open. A watch is being photographed for an Instagram grid that will, eventually, be evidence.
The four in Warsaw are in custody. The machine is not.
- The Block | June 25, 2026 | "Four arrested in Poland over crypto SIM-swap attacks; ZachXBT links 'Merry' to case" | https://www.theblock.co/post/406159/four-arrested-poland-sim-swap-attacks-crypto-exchanges-zachxbt-social-engineering-threat-merry
- Central Bureau for Combating Cybercrime (CBZC), Poland | June 2026 | Public announcement of arrests and charges
- ZachXBT | June 25, 2026 | Public posts on X identifying Wojtek Kulisz ("Merry") via Instagram "wojtekk"
- FBI Internet Crime Report | 2021, 2022, 2023 | SIM-swap loss figures
- Europol | October 2025 | SIMCARTEL operation announcement
- Arbitration ruling, T-Mobile | March 2025 | $33M USD award in SIM-swap case
- ZachXBT | June 1, 2025 | Public report on Cameron Redman
Editorial Notice
MarkTell is a true crime publication about financial fraud. Some scenes, dialogue, and sequential details are reconstructed from court filings, enforcement actions, news reports, and public records. Where the public record does not provide exact details, editorial reconstruction is used to convey the documented pattern of events. Names of private individuals may be changed to protect identity. All factual claims are sourced to public documents cited in the Evidence Trail above. MarkTell does not provide investment, legal, or financial advice. Nothing published here constitutes a recommendation to buy, sell, or avoid any investment. Allegations described in active cases have not been adjudicated and defendants are presumed innocent until proven guilty. Readers should conduct their own due diligence before making financial decisions.