Indianapolis teacher, composer avoids prison time after guilty plea in child sex crimes case

A former Indianapolis teacher and internationally known composer will spend no time in prison after pleading guilty to multiple felonies in a child sex crimes case.

Julian Wachner, 56, pleaded guilty on Wednesday to five counts of possession of child sex abuse material as a Level 5 felony. He also pleaded guilty to one count of felony cocaine possession.

An Indianapolis resident, Wachner was subsequently sentenced to six years of probation and no prison time. As part of his plea deal, Wachner must register as a sex offender and participate in several drug and child abuse prevention programs.

In a statement, the Marion County Prosecutor’s Office said the plea agreement filed for Wachner was for a sentence of up to 10 years in prison. Judge Jeffrey Marchal imposed the sentence, opting for no prison time.

“Prosecutors pushed for a sentence harsher than the one opposed [sic],” said MCPO officials.

Cryptocurrency, cocaine and CSAM

Wachner was arrested late last summer by the Indianapolis Metropolitan Police Department after various allegations came out against him. At the time, he had recently served as a fourth-grade math teacher for Invent Learning Hub and was world-renowned for his music compositions.

Court documents released soon after Wachner’s arrest detailed how he used over $800 in cryptocurrency to purchase child sex abuse material on the dark web. After being confronted by police, Wachner reportedly admitted to making “hundreds of purchases.”

A search of Wachner’s home later uncovered an Apple MacBook Pro, a hard drive and a “substantial quantity of cocaine” inside his bedroom closet. On the laptop, investigators reportedly found “dozens” of files containing child sex abuse material.

Keep reading

Hunter Biden Blames Liquidity, “Predatory Snipers” For LAPTOP Memecoin Collapse

As you may have seen, the LAPTOP memecoin saw a sharp swing in token price during its first hours of trading.

The headlines are all the same.

Token down 99%. Rug pull. Biden Crime Family. The list goes on.

This is far from the truth.

The reality is that available liquidity could not sustain the strong level of interest at launch. Technical issues coupled with predatory “snipers”, who seek to beat liquidity providers to market, caused a spike in price, which has since stabilized to healthy levels.

The team’s allocation is locked. Nobody on our side sold, and nobody could have. I, personally, have not made a single dollar.

I’m used to legacy news and social media trolls spinning realities to fit their own narrative.

The fully diluted valuation of the token is over $1 billion. And we’re actively working on the best solutions to optimize liquidity and continue engaging my community.

We gave free tokens to those who lost on Trump’s memecoin. 

Somehow the media is painting that as a “failure”.

This journey is far from over. We built this community for the long game, and that’s exactly how we’re playing it. I’m going to keep doing what I do best: ignoring the noise, and reclaiming the narrative.

Maybe he can finally get back to his lucrative art career?

Keep reading

Hackers Withdraw 320 Million In Bitcoin From Blockstream’s Liquid Network Federation Reserves

The Liquid Network said Sunday that purported white-hat hackers withdrew about 4,000 bitcoin, worth about $320 million, from the federation wallet that backs L-BTC.

Bridge nodes were disabled, and the sidechain was paused. Other issued assets, including USDT, DePix and RWAs, were unaffected, the official account said on X.

The Liquid Network is a federated sidechain of Bitcoin, founded by Adam Back’s Blockstream. The Liquid chain issues a variety of assets such as LBTC, which it backs with BTC on the Bitcoin main chain, held in a large multisig of 15 corporate and known members. 11 of the 15 members need to sign a valid multi-signature transaction to move coins from the treasury. Before the hack, the treasury held over 4200 BTC; after the hack, Blockstream’s proof of reserves page reports a little over 207 BTC left. 

The hackers withdrew 4,019.4 BTC from the reserve address in a peg-out transaction using the SideSwap Peg-out Authorization Key. SideWap is a bridge exchange and a member of the Liquid Federation. While details on the mechanism of the hack are not confirmed yet, it appears an inflation bug on the LBTC side chain was exploited by the hackers to create over 4,000 LBTC that did not exist before, and cash them out for on-chain bitcoin from the federation. Because the transaction appeared as valid, given the consensus bug, the federation members’ HSM security servers signed the BTC withdrawal transaction, worth roughly 320 million at the time. 

The hacker moved the funds to an address ending in 6gyqjlte, from which they quickly signed a new transaction with a message on the OP_RETURN arbitrary data field saying “we are whitehats. contact us on chain.” Those coins were still at that address at the time of writing.

A small mainnet transaction to the hacker address followed by an OP_RETURN saying “Please contact security@blockstream.com”, presumably from a Blockstream public address, though that remains unconfirmed. A later OP_RETURN spend from the hacker address carried “Please contact us on Signal @m671aw.70”, however, this may be spam and does not share a link to the address with the stolen funds.

In response to the breach, exchanges were told to pause L-BTC deposits and withdrawals. Bridge nodes on the Liquid Network have been paused, limiting access to the side chain, which continues to produce blocks. 

JAN3 CEO Samson Mow said Aqua’s Liquid features were affected and that on-chain bitcoin still worked. Other wallets in the industry that use the Liquid Network are expected to be affected. Users holding LBTC now effectively have their savings at risk, since the underlying BTC is currently not redeemable. Given the private nature of the Liquid chain, user onchain analytics are scarce and not much public information is known about how much LBTC is held by retail users versus corporations of Blockstream itself. Nevertheless, should the funds not be returned, it would be a heavy blow to the Liquid Network’s user base.

Users of LBTC don’t have many options but to wait for conversations with the hackers to resolve. Given the size of the hack, it would be difficult for the hackers to get away with stealing all that bitcoin, though perhaps not impossible.

What may happen is that the hackers ask for a finder’s fee and return the majority of the funds. 

Keep reading

Hunter Biden (and his laptop) enter the cryptosphere with new meme coin

The son of former President Joe Biden is launching a meme coin that takes aim at his family’s nemesis, Donald Trump. And he’s naming it for the most-infamous personal computer in American political history.

Yes, Hunter Biden’s laptop will live on. At least on the blockchain.

Biden’s token will trade under the ticker, $LAPTOP, and launch Sept. 9 on Base, a digital ledger built by Coinbase Global, the largest U.S. crypto exchange, people familiar with the matter said.

The token’s name is inspired by the sensation that followed the public’s discovery of Biden’s former computer in 2020. The contents of that device, from messages that documented his foreign business dealings to nude photos of the president’s son doing drugs, were eventually laid bare. And the leaks forged a cottage industry of investigations, conspiracies—and digital media content.

On Monday, Biden posted on X a short video clip of his laptop being referenced by different media outlets, teasing the launch of his meme coin.

Meme coins carry no intrinsic value, and most tumble in price within days or even hours after their launch. But some of the tokens have remained relevant thanks to their affiliations with a procession of celebrities, personalities and politicians who issued them to cash in on their fame. Coins tied to President Trump, first lady Melania Trump and former New York Mayor Eric Adams rocketed in value when they launched, only to crash within days.Expand article logo  Continue reading

In launching $LAPTOP, Hunter Biden will bring his weekslong media blitz to the cryptosphere. The 56-year-old has been seen and heard everywhere of late—podcasts, news shows and Substack essays—and at times alongside right-wing provocateurs such as Tucker Carlson and Nick Fuentes. He has opened up on his past troubles, present grievances, and at times promoted the virtues of crypto.

Keep reading

Under-The-Radar Oklahoma Bitcoin Mining Site Condemned After Leaking 3 Million Gallons Of Water

A massive water leak in El Reno, Oklahoma has brought new scrutiny to a Bitcoin mining operation that city officials say had been operating without required approvals and in violation of multiple building and safety codes, according to KFOR 4. Three million gallons of water were leaked, according to KOCO ABC.

The facility, operated by Athlon BT LLC, had largely escaped public attention until the leak was discovered. City officials say the company had also installed a fire hydrant without their knowledge, while questions remain about how water was being used at the site.

Athlon originally applied for building permits in 2022. By 2023, however, El Reno had issued a stop-work order after the permits expired and officials identified multiple fire and life-safety code violations. The company was given until December 2023 to address the problems, according to the city.

Instead, officials say Athlon continued construction and eventually began operating the facility despite lacking the inspections and final certificate of occupancy required by the city. Officials have cited problems involving electrical systems, drainage and other areas of the property.

“They really weren’t in compliance at all,” city spokesperson Lyndsay Bayne said.

The discovery came as a surprise not only to residents but also to local officials, who said the Bitcoin mining operation had attracted little attention before the leak, according to KFOR 4.

Athlon had previously described the structures on its website as “mobile data centers.” The operation, however, differs considerably from the large hyperscale data centers proposed in communities such as Yukon and Piedmont, which have generated debate over their potential demands on local infrastructure and water supplies.

The KFOR 4 report says that El Reno officials say Athlon told the city its equipment was air-cooled and therefore should not have required water for cooling. According to the city, the water line involved in the leak was supposed to serve only a fire hydrant.

That hydrant itself has raised additional questions. Officials say Athlon installed it behind the property without notifying the city, and it did not appear on municipal records. The hydrant was also reportedly concealed beneath a large pile of brush.

KFOR later observed above-ground piping that appeared to connect the mobile data center units and extend toward the hydrant. Athlon’s website, before becoming unavailable, also referenced what the company called “hydro-cooling technology.” Those details have prompted questions about whether the water line may have served a purpose beyond fire protection.

Keep reading

DOJ Seizes Over $560,000 in Cryptocurrency Donations for Hamas

The FBI has seized more than $560,000 in cryptocurrency donations intended for Hamas, the Justice Department said Tuesday in announcing a disruption of financing for the militant group.

In addition to seizing cryptocurrency meant to support Hamas’ military wing, the department said that it had taken control of website domains and communication platforms used for fundraising and recruitment, and had obtained information about thousands of people who had contacted Hamas with a goal of giving money to the group.

“My message to Hamas is clear: your networks are not secure, your crypto is vulnerable, and we will not stop until your ability to wage war is defeated,” Jeanine Pirro, the U.S. attorney for the District of Columbia, said in a video statement announcing the operation.

According to FBI affidavits filed in connection with the seizures, Hamas began testing virtual currency fundraising in or around early 2019 through its Qassam Brigades, or military wing, and solicited donations on its Telegram channel and also used direct online fundraising. Hamas officials bragged that the currency would be untraceable and their websites offered instructions for how to make anonymous donations, the affidavits say.

A major investigative break arrived last year when FBI officials identified a financing network soliciting donations to the Qassam Brigades via virtual currency and a confidential source located in the United States alerted law enforcement to a Telegram post asking for contributions to an email address associated with Hamas.

Brett Leatherman, an FBI assistant director in charge of its cyber division, said the bureau would “continue to use its authorities to intercept illicit funds and prevent terrorist organizations from exploiting digital networks to finance their operations.”

Hamas officials could not immediately be reached for comment.

Copyright 2026 The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed without permission.

Keep reading

CrowdStrike and Federal Authorities Dismantle Russian Malware That Secretly Stole Crypto for 8 Years

A campaign of malware operated by Russian cybercriminals for eight years was dismantled by federal authorities in conjunction with the cybersecurity firm CrowdStrike on Thursday. The malware, identified by the security firm as “EggJagger” or as Sality malware, preyed upon thousands of users of virtual currency by engaging in “clipboard hijacking.” The most common method that users of virtual currencies such as Bitcoin and Ethereum employ in order to send currency is to copy a virtual currency address from a web page to a computer’s clipboard and then later to paste the virtual currency address into the corresponding field of a wallet application. The malware sat idle on a user’s computer and then, before the user had a chance to discover the substitution, would change the virtual currency address that had been placed in the user’s clipboard to an address controlled by the cybercriminals, reported CoinDesk.

Once the compromised address was pasted into the user’s wallet software, and the resulting transaction had been confirmed, the cryptocurrency was transferred irretrievably to the attacker. While there was no particular attack functionality that triggered any alerts, the single defense against such an attack was for the user to manually verify the address that they had pasted into the sending field. Typically the first and last characters of a wallet address would be verified against what was expected, but in this case all would need to be checked. The reason for this type of attack to have persisted for some eight years is that it is an easy one to implement, and places the onus of security on the end user to perform correctly in these situations.

Analysis by CrowdStrike has uncovered the malfeit cryptocurrency operators amassed 12.1 million rubles ($150,000) in the years the malware was active and operating, however most of the stolen cryptocurrency had been deposited into online wallets, remained untouched by the cybercriminals. However with the recent and ongoing surge in value of many of the world’s most popular cryptocurrencies the hacker’s abandoned stash has appreciated significantly to an estimated $1.35m. The returns on such a relatively simple attack vector to extract cryptocurrency from individuals is significant and in this instance highlights that such malware, whilst still active after eight years, continues to reap significant returns on little more than foraging for victims, capitalizing on default settings and exploiting human nature of individuals utilizing online cryptocurrency services.

A major weakness of the botnet infrastructure behind EggJagger was the minimal security controls in place around the network of infected computers. As long as a compromised computer was responding to commands appropriately, it could be included in the botnet of other compromised systems. In a live demonstration of the vulnerability on Monday at CrowdStrike’s Day Zero summit in Las Vegas, the security team of researchers used the same hole to subvert EggJagger and replace the legitimate peer addresses embedded in the malware with the IP addresses of their own servers. Suddenly, more than 15,000 computers infected with EggJagger around the world lost connection to their command-and-control servers in an instant, bringing the whole operation crashing down.

The high-profile takedown of the long-running Russian malware operation highlighted the persistent cyber threats to financial infrastructure emanating from Russia, as well as the growing role of the private cybersecurity sector working in conjunction with law enforcement to counter threats to the financial system. Despite having developed sophisticated operational security measures over an eight-year period, Sality ultimately relied on a relatively simple vector to steal cryptocurrency from thousands of individuals and businesses – that of exploiting routine human practices. The botnet’s vulnerability to having its peer connections severed by not authenticating the connections was identified by law enforcement and subsequently exploited to dismantle the operation in a single action, bringing an end to a threat that had affected thousands of individuals and businesses across South Florida and the country.

Keep reading

Former FBI Agent Charged With Stealing Nearly $1 Million In Crypto, Asked ChatGPT How To Hide It

A supervising U.S. FBI agent who worked in intelligence at the national headquarters has been arrested and accused in a federal court filing of stealing more than $1 million in cryptocurrency.

The high-level special agent, identified as Patrick Steven Yarmoch, allegedly turned himself in to agency colleagues, reporting that he dug crypto keys from FBI systems to make as many as a dozen transfers to himself from accounts tied to foreign individuals he’d investigated, according to an August 1 account filed with the U.S. District Court for the Eastern District of Virginia.

“During the afternoon of July 28, 2026, Yaroch contacted DOJ Employee 1 via Signal and requested to meet to discuss personal matters,” prosecutors said in the complaint.

“Upon meeting DOJ Employee 1 at FBI headquarters, Yaroch immediately started to break down as he told his story.”

Yarmoch — who held a “top secret” security clearance — had worked in counterintelligence, specifically with an investigative unit that focused on an unnamed “adversary nation,” according to the court filing, which noted he was suspended for a couple of days before being fired and arrested on July 31.

The resident of Ashburn, Virginia, had worked as a supervisory special agent at FBI headquarters in Washington, specifically in its counterintelligence and espionage division. He’d previously worked for years out of Boston, where he’d been in a national-security unit investigating the adversary nation referenced in the court filing.

In handling the digital assets, Yarmoch was said to use accounts with Kraken and also Suilend, the decentralized finance (DeFi) ecosystem for the Sui blockchain, via a Slush wallet.

The FBI searches of his computer and phone records revealed some of his recent questions to AI apps, including, “If you had a bucket of money (around $1 million) and you wanted to leave the USA and become a resident or citizen of an EU country, what would you do?”

To which the app allegedly recommended Portugal as a favored destination.

Investigators also located travel plans for Yarmoch and his family to go to Portugal next month, and located the power of attorney forms for Portugal.

“Yaroch stated he was not planning to funnel money into Portugal,” the complaint said.

Yaroch told FBI WF Agents that his family had a trip planned to Portugal in September 2026 to meet friends. Yaroch realized he might not be able to attend the trip but stated he hoped his wife and child would still go on the trip.”

Later searches included whether Americans need a visa when connecting through Turkey and help drafting a follow-up email about a job opportunity and life in Greece.

He was also said to take recent trips to Germany, and Grenada that he hadn’t reported internally, in violation of FBI rules.

Yarmoch was placed in detention in Alexandria, Virginia.

Keep reading

Home invasions became most common crypto wrench attack in H1 2026: CertiK

Crypto home invasions rose to 20 in H1 2026 from one a year earlier, while France accounted for 33 of 52 verified wrench attacks, according to CertiK.

Home invasions became the most common form of crypto wrench attacks during the first half of 2026, rising to 20 publicly reported incidents from just one a year earlier, according to blockchain security firm CertiK. 

On Thursday, CertiK said it verified 52 wrench attacks worldwide in the first half of 2026, up 33.3% from 39 incidents during the same period in 2025. Kidnappings rose to 16 from 12, while robberies declined from five incidents to one. 

CertiK said the recorded financial exposure linked to the attacks reached about $124.1 million, up from $10.5 million a year earlier. The figure is not limited to confirmed thefts and may include ransom demands, victim transfers, frozen or recovered assets and failed ransom demands. 

The increase in home invasions suggests criminals are increasingly bypassing digital safeguards by physically coercing crypto holders and their families.

Keep reading

“Nothing Is 100%”: CZ Warns Bitcoin Holders After $89 Million Coldcard Wallet Exploit

A third wave of thefts against Bitcoin wallets built on flawed Coldcard firmware ran through Saturday morning, lifting observed losses to roughly 1,367 BTC – close to $89 million – drained from 4,585 addresses since Thursday.

As Cyberkendra.com reports, the size is not the interesting part. The third wave is the first one designed to be hard to follow, and that shift tells self-custody holders more about what happens next than any dollar figure does.

Galaxy Research published the wave-three findings early Sunday. Between 12:23 UTC on July 31 and 06:42 UTC on August 1, across blocks 960,396 to 960,471, another 207.73 BTC left 1,912 addresses. That is roughly a tenth of a coin per victim.

Wave one, which opened at 01:10 UTC on July 30 and closed 41 minutes later, took 1,082.65 BTC from 1,195 addresses — nearly a full coin each.

Wave two, on July 31, collected just 76.16 BTC from 1,478 addresses.

Median losses tell the same story more bluntly: 0.270 BTC in wave one, 0.010 in wave two, 0.013 in wave three. The operator is now emptying wallets worth a few thousand dollars apiece and still finding enough of them to spend ten hours sweeping.

Waves one and two were easy to map because the attacker made them easy.

Both funneled coins through a handful of shared collector addresses into P2WPKH holding wallets (pay-to-witness-public-key-hash — plain single-key SegWit outputs, fully visible on chain).

Wave three abandoned that.

Each victim’s coins went to their own destination, and the proceeds now sit in 293 separate P2WSH vaults (pay-to-witness-script-hash, a format that keeps its spending conditions hidden until the first time the coins move). The sweeper also batched an average of 6.37 victims per transaction, where wave one took exactly one at a time, and scanned only the default derivation path instead of testing several branches per seed. Even the fee constant changed — 30 sat/vB in wave one, 50 and 10 in wave two, roughly 200 then exactly 10 in wave three.

That is either the same crew rebuilding after being enumerated in public, or a second crew grinding the same broken key space on its own.

The falling average haul suggests the profitable end of the vulnerable key space is picked over. That is cold comfort. Wave three’s median take of 0.013 BTC is the clearest evidence yet that no balance is now small enough to be beneath the scanner’s notice — and the sweeping had not stopped three days in.

Keep reading