Former Altilly operator Nayiem Willems has published more than two years of internal exchange records as part of an effort to support his allegation that a developer who controlled key parts of Altilly’s infrastructure under the name “Mike O’Sullivan” was actually Paul Vernon, the founder of collapsed cryptocurrency exchange Cryptsy.
The allegation remains unverified. No court, law-enforcement agency or government authority has publicly identified Altilly’s developer as Vernon, and the newly released archive itself repeatedly states that it does not prove the identification or establish that “Mike” was responsible for Altilly’s December 2020 collapse.
What has changed is the amount of primary material available for scrutiny.
Willems on October 1 released a searchable, read-only archive of Altilly management correspondence covering July 2019 through October 2021. The records include conversations before, during and after the exchange’s security incident, alongside a separate evidence section examining the identity of the developer the team called Mike.
Willems says he became Altilly’s CEO and public face in 2018, invested $175,000 of his own money and was left dealing with customer claims totaling approximately $2.4 million after the exchange collapsed. He says he has provided unredacted material to law enforcement.
Altilly’s Developer Controlled Servers, Wallets and the Database
The significance of the identity question comes from the access Mike allegedly possessed.
According to the contemporaneous management messages published by Willems, the developer operated Altilly’s exchange software and had responsibility for its servers, wallets and database. The archive identifies his Telegram account as @MrMike_O and says he operated publicly under the name Michael Osullivan or Michael O’Sullivan.
That level of control would have placed the developer close to the most sensitive components of a centralized exchange.
Altilly reported suspicious server activity in December 2020. Contemporary notices said several servers unexpectedly rebooted, an unfamiliar system user appeared and the team subsequently lost access to production servers, databases and cryptocurrency wallets. Off-site backups were also reported deleted.
Some high-value hot-wallet assets were stolen, while other funds became inaccessible after the underlying infrastructure and records disappeared. Willems now says the resulting customer claims ultimately amounted to around $2.4 million.
The episode illustrates the same broader operational problem seen in more recent centralized-exchange security failures: safeguarding private keys is only one part of exchange security. Privileged access to servers, authentication systems, wallet infrastructure and administrative tools can be just as important.
A Revolut Envelope Is the Strongest Piece of the New Identity Evidence
The most striking item in Willems’ archive dates from February 2021, less than two months after Altilly went offline.
The internal conversation shows Willems setting up a Revolut Business account and inviting Mike to obtain a company card. Mike asked whether Revolut could deliver physical cards to China. When the service apparently would not ship there directly, Willems offered to receive the card and forward it.
Two days later, according to the archive, Willems posted a photograph of a DHL envelope delivered to him for the card. The recipient printed on the envelope was “PAUL Vernon.” Mike later wrote that he had received his Revolut card in China.
That is potentially significant because the conversation predates Willems’ later public allegation by years.
But it is not conclusive identification. The archive notes that the name printed on the shipment reflected information entered for the account rather than proof that Revolut had verified the holder as Paul Vernon. When Revolut subsequently requested identity verification in March 2021, Mike reportedly said his passport was at a Chinese visa office. The published conversation does not show whether that verification was later completed.
Revolut’s original onboarding and verification records would therefore carry substantially more evidentiary weight than the envelope alone.
An Old Email Domain Creates Another Possible Cryptsy Link
A second thread comes from an email address discussed immediately after the Altilly incident.
During the December 26, 2020 investigation, Mike reportedly said an attacker had gained access through an old email account associated with the hosting environment and wrote an address using the domain “satotechlt.com.” He added that the history of the domain would probably contain his name.
Willems’ archive compares that address with a historical WHOIS record for the nearly identical domain “satotechltd.com.” That record listed “PAUL VERNON” as registrant and Project Investors Inc. as the company. Project Investors was the Florida corporation that operated Cryptsy.
The problem is the missing “d.” The email in the Altilly conversation refers to “satotechlt,” while the historical Cryptsy-linked registration is “satotechltd.” Treating one as a typo for the other is plausible, but it remains an assumption rather than independently established evidence.
The newly published site appropriately grades that connection as suggestive rather than definitive.
Public Records Confirm a Developer Trail but Not Vernon’s Identity
Other evidence can be checked independently.
The GitHub account “mrmikeo” has a public history connected to software used around Altilly and projects associated with Willems. The same account also appears on a 2024 commit to an official Xeggex GitHub repository, establishing at minimum that the developer account associated with Altilly later had write access to Xeggex code.
UK Companies House records independently show Xeggex-related companies with officers using variations of the name Michael John Osullivan. Filings across the companies contain different declared nationalities, countries of residence and even different birth months.
Those discrepancies are unusual, but Companies House records from that period largely reflected information submitted by filers rather than establishing that the person behind the filings was Paul Vernon.
Accordingly, the public GitHub and corporate records strengthen the case that the “Mike” identity had a life beyond Altilly. They do not establish who was physically behind that identity.
Cryptsy’s Collapse Gives the Allegation Much Higher Stakes
The reason the allegation matters is Paul Vernon’s documented history with Cryptsy.
Vernon founded and operated the Florida-based exchange through Project Investors Inc. Cryptsy collapsed in early 2016 after customers lost access to their cryptocurrency.
A U.S. federal court later entered a default judgment identifying more than 11,325 BTC taken from Cryptsy customers as property of the customer class. In 2022, prosecutors unsealed a 17-count criminal indictment accusing Vernon of wire fraud, money laundering, computer fraud, tax evasion and destruction of records.
According to the U.S. Department of Justice, prosecutors allege Vernon stole more than $1 million from customer wallets between 2013 and 2015, moved to China in late 2015 and later remotely accessed Cryptsy’s servers after a receiver took control of the business, destroying its customer database.
The charges remain allegations unless proven in court. Public records still describe Vernon as outside the United States, and no later prosecution resolving those charges was found during research for this article.
None of those official Cryptsy records mentions Altilly, “Mike O’Sullivan” or Xeggex.
The Released Archive Also Contains Evidence That Cuts Against Willems’ Theory
One reason the new material is more useful than the earlier social-media accusations is that it preserves facts that complicate Willems’ own argument.
Willems clearly trusted Mike after Altilly collapsed. Internal messages show him telling the developer in December 2020 that the incident was not his fault. Months later he was still discussing future business plans with him and allowing him access to infrastructure.
The archive also acknowledges that a common name on a shipment is not unique identification, that the historical domain connection depends on a one-letter discrepancy and that no law-enforcement body has confirmed the central allegation.
Most importantly, the material does not establish that Mike caused the Altilly breach or took customer assets. Mike reportedly denied involvement in the hack in later communications.
Those limitations matter. Crypto investigations can quickly turn matching usernames, locations or technical habits into claims of identity that appear stronger than the underlying evidence actually supports.
That problem is increasingly important as incidents involving privileged infrastructure and exposed technical systems demonstrate how difficult it can be to separate the identity of an operator from the credentials an attacker was able to use.
The Bigger Failure May Have Been Exchange Governance
Even if the Vernon identification ultimately proves wrong, the archive exposes a governance weakness with direct relevance to crypto investors.
A person operating under an identity that Willems now says was never properly established appears to have held substantial technical authority inside an exchange handling customer assets.
That should not be possible at a financial platform with meaningful custody responsibilities.
An exchange can publish wallet addresses, maintain sufficient assets and even operate honestly while still carrying enormous key-person risk if one developer controls servers, wallets, databases and backup infrastructure. Proof of reserves does not reveal who possesses administrative credentials. On-chain balances do not show whether employees have undergone identity verification or whether access is separated across multiple people.
The same distinction matters when users encounter problems accessing assets held by centralized exchanges. The important questions are not limited to whether the coins exist. Investors also need to know who can control the systems standing between those coins and the customer.
Good exchange architecture should make the identity of one engineer almost irrelevant. Wallet movements should require multiple approvals. Production access should be logged and independently reviewed. Backups should be isolated from production credentials. Administrative privileges should be compartmentalized, and staff controlling customer assets should be subject to serious identity and background checks.
Altilly appears to have lacked several of those safeguards.
What Would Actually Resolve the Paul Vernon Question?
The next stage requires evidence outside Willems’ archive.
Revolut could establish what identity documents were submitted for the 2021 business account. Historical hosting-provider records could show the names, emails, IP addresses and authentication activity associated with Altilly’s infrastructure. GitHub could preserve account-registration and access metadata unavailable from public commits. Law enforcement could compare those records against information already held in the Cryptsy investigation.
A forensic examination could separately address the more important financial question: whether the person controlling the Mike accounts had anything to do with the December 2020 intrusion or movement of Altilly assets.
Until evidence of that quality appears, two questions should remain separate.
The newly published material provides a substantial basis for investigating whether “Mike O’Sullivan” was an assumed identity and whether the operator had links to other exchanges. It does not yet establish that Mike was Cryptsy founder Paul Vernon.
And even proving that identity would not automatically prove responsibility for Altilly’s collapse.
For investors, however, the records already tell a useful story. A cryptocurrency exchange can fail long before a wallet is drained if too much operational power is concentrated in people whose identities, access and accountability have never been properly established.
Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.
His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.
Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape.

