Bitcoin Forum
August 03, 2026, 02:05:49 PM *
News: COLDCARD users only: critical vulnerability risks funds stored on COLDCARD devices; immediate action required
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Incident Report Warning: BTC to XMR | Address Mismatch: El Capo/kyc.rip  (Read 39 times)
Trêvoid (OP)
Copper Member
Hero Member
*****
Offline

Activity: 574
Merit: 677


kycnone.com █ No KYC / AML


View Profile
August 01, 2026, 12:35:10 PM
Last edit: August 01, 2026, 01:34:32 PM by Trêvoid
 #1

ORDER
ID: 340FE******* · Created 31/07/2026, 10:28 · BTC → XMR (float)
Sent: 1 BTC to bc1q**** · Quoted: 180.12325097 XMR
Victim XMR address: 47ueAvGSdFAQDJSUHE4S2UGWBeVSW3F5DNXFcsE3LdQCDNzKyPyJdS3Yw9Vm12aYbD341CG9SWcB2Ve 6w2tYNTB7DH8Cgxs
Placed via kyc.rip, routed "VIA El Capo"

  • the kyc.rip order page showing the order status + destination address (the one that matched victim wallet).
  • the kyc.rip order page showing the later “FINISHED” destination address (the wrong address).
  • the elcapo.io track.html error (“Order ID and recipient address do not match”).

https://talkimg.com/images/2026/08/01/Uo65uJ.jpg
https://talkimg.com/images/2026/08/01/Uo6ogW.jpg
https://talkimg.com/images/2026/08/01/Uo6Bxv.jpg

Words from victim:

1. My address was in El Capo's own database
elcapo.io/pages/track.html requires BOTH order ID and recipient address to match. On 31/07 I entered the order ID + my address and it returned the order: CONFIRMING, 1 BTC → 180.12325097 XMR. Today, identical inputs: "Order ID and recipient address do not match." Their system validated my address, then stopped. This is on El Capo's side, independent of kyc.rip.

2. They never disputed the address for 24 hours
My first message on simpleX, 31/07 15:13, stated the order ID and my address explicitly. Their reply at 15:16: "Hello, allow me a moment. Checking." No objection then or at any point during the next day of discussion about this order.

3. They confirmed sending elsewhere
01/08, I asked which address they sent to. Their answer: 89YnymxutUFDcbhqBqZbkUdKhXCQ4E1EJ6Nk5QHc6RHzKe75h5PCXyK37sXf2Giec5hMDB6GvZ4bT5b RTWWMfF6uJrYKEeR — not my address. Same address that appeared on the kyc.rip page after it flipped to FINISHED.

4. The tx hash proves nothing
They provided e722083b064244d3c4f4a4331827f7af03d871968946fc4d3ae1d8fc2c431929. In Monero recipients and amounts are hidden — any transaction looks identical. tx_key or get_tx_proof is the only proof; every wallet stores it automatically, one command. Requested by me and by you. Not provided.

(update by Trêvoid, I got the keys later but it was sent to a different xmr wallet not victim wallet)

5. The stalling itself
A genuine AML hold is one sentence: "we're holding it, here's why, here's when." Instead, over 24 hours: "checking" → "funds are a bit difficult" → Because high AML → "team is working" → "there's no dead lines, once its done-its done" → a hash. Each answer bought hours and gave nothing checkable.


Note to the community from Trêvoid:
I had a user contact me today about this situation, and I’m stating it clearly one more time. Please do not swap large amounts on your own.
I strongly recommend using our designated intermediary system for any swaps.
This is a public warning. This user case may be real or fabricated, since there’s no letter of guarantee, we can only rely on the victim’s message and the screenshots. I am taking this case seriously and sharing it here to warn the community. If there is no LoG for the swaps, do not ever use that service!

I will personally contact “el capo” and “kyc.rip” and request them to issue (LoG) for the swaps in future. If they cannot provide it, I will label them as a scam. It’s enough that I was polite about these newly created services and the best UI design directories especially when it comes to advertising scam swap services and scamming users.


Don’t trust “good-looking, coded-nice UI” vibe aggregator that doesn’t actually care about the community.

Evidence: screenshots of elcapo.io/track before and after, kyc.rip CONFIRMING (xmr address) and FINISHED (theirs), full SimpleX log with El Capo and user. All available on me a and if need can send to mods.

Elcapo_io
Newbie
*
Offline

Activity: 1
Merit: 0


View Profile
Today at 01:06:21 PM
 #2

Saludos, community.

We’re clarifying the situation.

We’re confident this is part of an ongoing, coordinated campaign against our service that has been running for close to a month. This time, the accusation was simply swallowed whole and stretched to fit, without any real verification.

Background. Three weeks ago, this same so-called “victim” already attempted to defraud our service. The first attempt was an order for 100 ETH using a fake smart contract that displayed a “successful” transaction hash on an address with a zero balance. After that failed, he tried to contact our partner and accuse us of swapping the deposit address - also unsuccessfully. He then deleted the chat and disappeared for three weeks.

We highlight this timeline specifically because in the new order he reused the exact same Monero receiving address from his first attempt - apparently not smart enough to even bother changing it. This time the scheme was a bit better thought out, but no - not every attack like this gets past a service with real experience.

What actually happened. The user stayed in contact throughout, funds were sent, and our partners and outside observers saw an AML report on his address — meaning anyone can see exactly what kind of activity he’s involved in and how he makes his living. After the funds were sent, he claimed he never received the Monero.

On the screenshots. Any ten-year-old knows how to open a browser’s dev tools and type whatever they want into the page. A screenshot proves nothing on its own - without independent technical confirmation (tx_key/get_tx_proof, on-chain data, server-side logs), it’s just an image. If a service you’re working with doesn’t offer a Letter of Guarantee, at the very least record your screen during the transaction. That’s real evidence - a screenshot is not.

On the evidence. Every party involved in this case - the user himself, and the partner through whom the exchange was processed - has already received a full set of confirmations from us: tx_key, internal system screenshots, transaction hashes. They had every opportunity to verify this. Instead of engaging with the facts, the decision was made to turn it into a public show.

As a matter of policy, we don’t publish transaction data in public - that’s part of our confidentiality standard, and we’re not going to break it on demand, especially under pressure. Everyone who needed this data for legitimate purposes already has it. If the author or the alleged victim disagrees, they’re welcome to state on record that they never received it - instead of building an accusation on our silence.

Our position.

 • We state, with full confidence, that this case is 100% fabricated.
 • We will not continue any form of cooperation with this “opinion leader.” We will not tolerate being placed in the position of the accused, being handed ultimatums, or having conditions dictated to us - not by him, not by anyone.
 • On our own initiative - not because anyone demanded it - we have already implemented a Letter of Guarantee (LoG) for all swaps going forward, and we continue to operate normally.

Exchangers today have essentially no protection against bad-faith accusations and smear campaigns. Sure, there are fly-by-night operations out there just to grab a quick profit. But building a service that actually works isn’t funded by amounts of 20k-30k–60k — that’s not nearly enough to justify the cost of launching, running operations, and paying a team's salaries. Torching your own reputation for that kind of money simply doesn’t add up.

This is our response to everything happening right now. Thank you for your attention.

Con respeto — El Capo team.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!