RSS Amplifier

DANNY DE HEK · Aug 1, 2026

Aurum’s Damage Control Zoom: Promises, Reassurance And The Questions That Remain

0
Sign in to vote or save

DANNY : DE HEK · DANNY DE HEK

“We’re going to refund the money to all the users who have lost funds.” — Bryan Benson

Suspected Misleading Website

By the time the meeting began, confidence had already been shaken. Investors had watched deposits and withdrawals stop, reports of compromised wallets spread across the community, and the company’s primary domain display a Cloudflare “Suspected Misleading Website” warning. At the same time, AURUM was rapidly directing users toward a Newly Launched Website under the Neyro brand while insisting the company remained fully operational and committed to compensating affected users.

I watched the presentation from beginning to end. I wasn’t looking for reassurance or carefully crafted promises—I was looking for evidence. Over the past several months I have investigated AURUM’s business model, examined regulatory warnings issued in multiple jurisdictions, reviewed blockchain evidence, analysed company documents, and followed the project’s evolution in real time. This emergency presentation became another important piece of that investigation—not because it conclusively proved what happened, but because it revealed how the company chose to explain the crisis, justify its recovery strategy, and reassure investors whose confidence had already been severely tested.

The presentation also raised new questions. While executives repeatedly promised transparency, compensation, and a stronger future through a new AI-powered Web3 ecosystem called Neyro, many of the most important details remained unanswered. As you read through this investigation, I’ll compare the claims made during that emergency presentation against the evidence currently available, the company’s previous statements, blockchain activity, regulatory concerns, and the rapidly changing infrastructure now replacing the original AURUM platform.

AURUM Foundation & NEYRO Exposed: The “AI Trading Bot” That Doesn’t Trade – Blockchain Investigation

This isn’t my first investigation into AURUM.

In my earlier report, I examined the company’s claimed banking services, AI-powered trading products, affiliate-driven business model, and regulatory warnings issued by authorities in multiple countries. I also documented unanswered questions about licensing, transparency, and the risks facing investors.

Since that investigation was published, the situation has changed dramatically.

AURUM now says it suffered a sophisticated cyberattack during its migration to a new Web3 infrastructure. The company claims attackers gained unauthorised access to parts of its legacy systems, compromising company assets, user funds held on the platform, internal databases, and the neyro.network domain.

AURUM Neobank Exposed: Crypto Bank Illusion, AI Trading Bots And MLM Ponzi Red Flags In Plain Sight!

In response, AURUM has unveiled an entirely new ecosystem centred around Neyro, describing it as the next generation of its business and the future home of its AI-powered trading products.

The purpose of this investigation is not to speculate about what may have happened. It is to examine the claims being made today, compare them with the evidence currently available, and determine whether the company’s explanations withstand scrutiny.

As always, I encourage readers to look beyond the marketing, separate verifiable facts from forward-looking promises, and make informed decisions based on evidence rather than hope.

A Sophisticated Cyberattack?

From the opening minutes of the Zoom meeting, Bryan Benson established the explanation AURUM wanted its community to accept. According to him, the company had been targeted by a sophisticated and coordinated cyberattack during the final stage of its Web3 transition. The presentation claimed attackers gained unauthorised access to parts of AURUM’s legacy infrastructure, affecting internal company funds, user funds held by the company, the neyro.network domain, and certain internal systems and databases.

That explanation became the foundation for everything that followed. The suspended services, missing balances, compromised wallets, domain problems, recovery roadmap, compensation promises, and rapid move towards the new Neyro ecosystem were all presented as consequences of an external attack. AURUM positioned itself as the victim of a carefully planned operation rather than a company whose own systems, controls, and representations required deeper scrutiny.

What was missing was the evidence needed to independently test that account.

The presentation did not identify the attackers, disclose the exact vulnerability, explain which private keys or systems were compromised, provide a wallet-by-wallet accounting of the losses, or name the cybersecurity specialists supposedly leading the investigation. No forensic report was presented. No detailed incident timeline was shown. No law-enforcement reference number was disclosed. The words “sophisticated,” “coordinated,” and “cyberattack” were repeated with confidence, but the technical proof remained out of sight.

That distinction matters. A company is entitled to report that it believes it has been attacked. Investors are equally entitled to ask for evidence before accepting that explanation as fact. At this stage, the cyberattack remains AURUM’s account of what happened, not an independently verified finding.

AURUM’s presentation did not describe the alleged cyberattack as an isolated event. Instead, it placed the incident inside a much larger story about a planned migration to new Web3 infrastructure. According to the company, attackers struck during the final stage of that transition and gained access to parts of the older system while AURUM was attempting to maintain normal operations.

The Al Trading Bot

This explanation matters because it does more than identify a supposed point of entry. It also provides the company with a reason for the sudden appearance of NeyroLabs, a new website, new branding, new infrastructure, and another AI trading bot. The old platform was described as “legacy infrastructure,” while the replacement was presented as the safer, stronger future investors should continue supporting.

However, public infrastructure records show that neyrolabs.io already had a TLS security certificate issued on 17 July 2026, roughly two weeks before the emergency presentation. That does not prove the alleged attack was fabricated. It does establish that the replacement website was being prepared before AURUM publicly introduced it during the crisis.

The timing creates an important question. Was NeyroLabs part of a genuine migration announced and documented before withdrawals began failing, or did the company already have a replacement platform ready while investors remained unaware of the transition taking place behind the scenes?

During the presentation, AURUM described the Web3 migration as one of the most complex stages in the evolution of a technology platform. Yet no detailed migration schedule, technical documentation, smart-contract upgrade path, independent audit, or earlier public notice was produced to show exactly when the transition began and what systems were being replaced.

The Web3 Transition

The new website also remains connected to the old infrastructure. Links from NeyroLabs still direct users back to the AURUM back office, hosted under the same aurum.foundation domain now displaying a Cloudflare warning for a suspected misleading website. That creates another contradiction: AURUM is presenting Neyro as a new and secure Web3 environment while continuing to rely on parts of the system it says were affected by the attack.

The Web3 transition may be genuine. But at present, it also functions as a convenient bridge between the collapse of the old platform and the launch of the next one. Investors deserve a complete timeline showing when NeyroLabs was created, when the migration was approved, what infrastructure had already been moved, and why those plans were not clearly disclosed before the crisis became public.

While AURUM’s emergency presentation focused almost entirely on the alleged cyberattack, one of the most significant pieces of evidence was never mentioned.

A detailed on-chain Forensic Investigation by CrYptO G, one of the technical investigators from the Avengers Anti-Fraud Alliance, had already examined AURUM’s published smart contracts, traced the movement of investor funds across multiple blockchains and compared the company’s public marketing with what could actually be verified on-chain.

This investigation did not rely on rumours, screenshots or promotional videos.

CrYptO G examined the published smart contracts, analysed the blockchain transaction history and documented his methodology in a comprehensive forensic report that I have made available alongside this investigation. Readers can review his findings and assess the evidence for themselves.

The report raises fundamental questions about AURUM’s central sales pitch.

For months, investors were told their money was being managed by sophisticated AI trading agents operating continuously in live markets. The company repeatedly promoted a non-custodial system where users supposedly remained in complete control of their funds while autonomous algorithms generated returns around the clock.

The newly launched Neyro website continues making exactly the same claims.

It promises 24/7 execution, AI-powered trading, Quantum Alpha, non-custodial infrastructure, and repeatedly tells investors they remain in control of their capital and can withdraw whenever they choose.

CrYptO G‘s forensic analysis paints a very different picture.

According to his examination of the published contracts, the observable code did not contain the sophisticated AI trading logic repeatedly described in AURUM’s marketing. Instead, the contracts primarily accepted deposits while reserving privileged control functions for the operator. His analysis also found that the examined BNB Smart Chain contract did not expose a withdrawal function available to ordinary users, despite repeated claims that investors always remained in control of their funds.

His investigation then followed the money.

On TRON, CrYptO G documented a function that swept stablecoin balances to an operator-controlled wallet before tracing the subsequent movement of funds across numerous additional addresses. On BNB Smart Chain, he followed substantial cash flows moving through operator-controlled wallets before being dispersed through hundreds of transactions. Every conclusion was supported by publicly verifiable blockchain records that readers can independently examine.

This brings us to what I believe is the single most important unanswered question in the entire AURUM investigation.

Where was the trading?

If investors’ money was genuinely being traded by sophisticated AI agents, there should be evidence showing those trades taking place. There should be verifiable records demonstrating how profits were generated, which exchanges executed the trades, how risk was managed and how the advertised returns were achieved.

CrYptO G‘s report says he could not identify that trading activity within the published contracts he examined.

That makes AURUM’s emergency presentation all the more remarkable.

The company spoke extensively about hackers, malware, infrastructure, recovery plans, compensation and the future of Neyro.

It did not directly address the technical findings in CrYptO G‘s forensic investigation.

If AURUM believes CrYptO G‘s analysis is incorrect, it now has an opportunity to demonstrate why. It can publish independently audited trading records, explain how its AI execution architecture actually functions, reconcile the published contract code with its marketing claims and provide technical evidence showing where the advertised trading took place.

Until then, CrYptO G‘s forensic investigation remains one of the most important pieces of evidence in this entire case—not because it proves every answer, but because it asks the question that AURUM still has not answered:

If the AI trading system was genuinely generating the returns investors were promised, where is the evidence that it was ever doing what the company claimed?

Investors were given confidence without accounting

One of the most important slides in the presentation was titled “Where We Stand Today.” It stated that a portion of company and user funds had been compromised, while the majority of assets remained secure and the incident did not threaten the stability or continuity of the business.

Those are reassuring statements, but they are not measurable ones.

AURUM did not disclose the total value of assets allegedly held before the incident, the amount supposedly compromised, the number of affected users, the value still under company control, or the percentage of funds considered secure. Without those figures, investors cannot independently assess whether the losses were minor, severe, or potentially fatal to the business.

The wording also placed several important claims beyond immediate scrutiny. “A portion” could mean almost anything. “The majority” could mean 51% or 99%. “Does not threaten the stability of the business” is a conclusion, not evidence. No balance sheet, proof-of-reserves statement, wallet inventory, insurance coverage, or independent financial audit was presented to support it.

This is especially important because AURUM simultaneously promised to recover affected assets, restore user balances, compensate those who had lost funds, rebuild the platform, launch new infrastructure, and continue developing the Neyro ecosystem. Each of those commitments requires money. Yet the presentation did not explain how much capital remained available or where compensation funds would come from.

Investors were given confidence without accounting.

Until AURUM publishes a complete wallet-by-wallet reconciliation, identifies the assets under its control, quantifies the losses, and provides independent verification of its reserves, the claim that the business remains stable should be treated as an unverified company assurance rather than an established fact.

The statement most likely to keep frightened investors holding on was Bryan Benson’s promise that AURUM would refund users who had lost funds and make affected members whole. That assurance was repeated alongside references to recovery, compensation, restored balances, and a future relaunch under stronger infrastructure.

The Promise To Make Everyone Whole

For anyone who has lost money, that promise is powerful. Hope can become the reason people stop asking difficult questions, delay reporting losses, or continue trusting the same people who controlled the system. I understand why victims want to believe repayment is coming. But after investigating hundreds of failed investment schemes, I have learned that a promise of compensation is not the same as a funded compensation plan.

The presentation did not disclose the total losses, identify the source of repayment funds, provide a timetable, publish eligibility criteria, explain whether compensation would be paid in cash or platform credits, or name an independent administrator. It also did not show insurance coverage, audited reserves, segregated client accounts, or any legally binding commitment guaranteeing repayment.

AURUM’s own roadmap placed compensation in a future phase after an audit and investigation had been completed. That means the company was promising reimbursement before it had publicly established the full scale of the losses, identified all affected users, or explained what assets remained available. Investors were asked to trust the outcome before being shown the numbers.

This is where hope must be separated from evidence. Until AURUM publishes a transparent, independently verified compensation framework backed by identifiable funds, the promise to make everyone whole remains a public assurance from the same organisation now asking investors to accept its explanation of the collapse.

The AURUM Recovery Roadmap

AURUM presented a four-phase recovery roadmap designed to reassure investors that the crisis was under control. The plan moved from audit and investigation, to recovery and compensation, then platform relaunch, and finally a return to full operations and future expansion.

On the surface, the roadmap appeared organised and reassuring. The problem was that almost every phase depended on promises rather than evidence.

The first phase promised a comprehensive technical and security audit, identification of affected assets and users, and a final recovery strategy. Yet AURUM did not identify the cybersecurity firms conducting the investigation, disclose the scope of their work, publish any preliminary findings, or explain when investors could expect an independent report.

The second phase promised asset recovery, restored balances, and a fair and transparent compensation framework. However, no formula was provided for calculating investor losses, no explanation was given as to where the repayment funds would come from, and no independent administrator or trustee was identified to oversee the process.

The third and fourth phases quickly shifted the focus towards relaunching the platform, expanding the Neyro ecosystem, and continuing the development of new AI-powered products. By this stage, the presentation had largely moved beyond explaining the crisis and was once again asking investors to look towards the future.

There was another glaring omission.

Nowhere in the roadmap did AURUM address the findings of Crypto G’s forensic blockchain investigation, which had already questioned whether the advertised AI trading system was operating as claimed before the alleged cyberattack. If the blockchain evidence raises fundamental questions about the business model itself, those questions need to be answered alongside any discussion about rebuilding the platform.

A roadmap can organise intentions.

It cannot prove that the money exists.

It cannot prove that the platform is solvent.

And it cannot prove that investors will actually be repaid.

Until AURUM publishes independently verifiable evidence supporting each phase of its recovery plan—including an independent cybersecurity report, audited financial information, a transparent compensation framework, and answers to the technical issues identified in Crypto G’s forensic report—the roadmap remains a statement of intent rather than proof of capability.

As I watched the emergency presentation unfold, I kept waiting for someone to address what had already become the most important piece of evidence in this investigation.

It never happened.

The Promise To Make Everyone Whole

The presentation spoke at length about hackers, infrastructure, malware, audits, compensation, the Web3 migration, and the future of Neyro. Yet there was no meaningful discussion of Crypto G’s forensic blockchain investigation, despite it directly challenging one of AURUM’s most fundamental claims: that investor funds were being managed by sophisticated AI trading agents operating on-chain.

That omission matters because the blockchain evidence raises questions that cannot simply be answered by claiming a cyberattack occurred.

Crypto G’s forensic investigation examined AURUM’s own published smart contracts on both BNB Smart Chain and TRON. According to the report, the contracts did not contain observable AI trading logic consistent with the company’s public marketing. Instead, they accepted deposits, transferred funds under operator control and, in the case of the TRON implementation, contained a function that swept the entire balance to an external operator-controlled wallet. The report also found no user withdrawal function within the examined BNB contract, directly contradicting repeated claims that investors remained in full control of their capital and could withdraw at any time.

The report goes even further.

Crypto G traced more than US$31.7 million flowing through a single cash-out wallet over a seventeen-day period before the funds were fragmented into hundreds of outbound transactions. The report also highlights that the same operational pattern appeared across multiple contracts and concludes that the blockchain activity it observed was inconsistent with the AI-powered trading system promoted to investors.

Those findings existed before the emergency Zoom meeting.

If AURUM believed Crypto G’s forensic analysis was incorrect, this presentation provided the ideal opportunity to explain why. The company could have demonstrated audited trading records, identified the exchanges where trades were executed, explained how its off-chain AI infrastructure interacted with the published smart contracts, or provided independent technical experts to rebut the report’s conclusions.

Instead, none of that happened.

The discussion moved away from the blockchain and towards recovery.

Away from the contracts and towards future products.

Away from evidence that could be independently examined and towards promises about what comes next.

That is why the blockchain remains the elephant in the room.

A cyberattack may explain why services stopped working.

It does not, on its own, explain why Crypto G’s forensic investigation found no observable evidence that the published smart contracts were performing the sophisticated AI trading repeatedly promoted to investors. Nor does it explain why users lacked direct withdrawal functionality or why the documented movement of funds differs so significantly from the impression created by AURUM’s marketing.

Until AURUM directly addresses Crypto G’s technical findings with independently verifiable evidence, the most important questions surrounding its AI trading platform remain unanswered.

neyrolabs.io already had a TLS security certificate issued on 17 July 2026

Almost as soon as AURUM announced the alleged cyberattack, a new website appeared.

neyrolabs.io was presented as the future of the business, introducing a new brand, a new AI trading platform and a new flagship product called Quantum Alpha. Rather than focusing on the events that had just unfolded, the website immediately returned to the same promises investors had been hearing for months: autonomous AI agents, continuous execution, non-custodial trading, full control of your capital and around-the-clock performance.

The language sounded familiar because it was.

The site claims Neyro is “the first non-custodial AI agent layer for trading”, that users “retain full control at all times”, that funds remain on-chain, and that investors can “withdraw anytime.” Those statements are central to the company’s marketing, yet they also mirror claims that were already questioned by the independent blockchain forensic investigation. According to that report, the examined smart contracts did not provide users with a withdrawal function and did not contain observable AI trading logic consistent with the platform’s public claims.

The website also promotes Quantum Alpha as a live trading agent delivering +30.98% performance over the last 30 days, with more than 1,700 users and continuous execution. However, no independently audited trading records accompany those figures. There is no explanation of how the performance was calculated, no third-party verification, no published trade history and no evidence connecting those results to genuine external market activity.

One of the more surprising discoveries was that, despite presenting Neyro as a fresh start, parts of the new website still direct users back to the original AURUM back office hosted under the aurum.foundation domain. At the very time investors were being encouraged to embrace a new platform, the login process continued to rely on infrastructure associated with the old one.

That creates an obvious question.

If Neyro is genuinely a completely new and secure Web3 ecosystem, why does it still depend on components of the infrastructure AURUM says were compromised?

The website also places significant emphasis on leadership, institutional experience and sophisticated technology. Visitors are introduced to Andrew Isaacs, described as a former Managing Director at Galaxy Digital and Morgan Stanley, alongside claims of more than US$23 billion in executed transactions and institutional expertise. Professional biographies can help establish credibility, but they do not independently verify that the AI trading system performs as advertised or that investor funds are being managed in the way the company describes.

The launch of Neyro may represent a genuine evolution of the platform.

It may also represent an attempt to move the conversation away from frozen withdrawals, missing funds and difficult questions surrounding AURUM’s previous promises.

For investors, the branding is not the issue.

The evidence is.

The Presentation Shifted From The Crisis To The Future

One of the most revealing aspects of AURUM’s emergency Zoom meeting wasn’t what the company said about the alleged cyberattack. It was how quickly the presentation moved beyond it.

After outlining the supposed attack and promising compensation, the focus shifted towards the future. Investors were introduced to a new Web3 infrastructure, a redesigned ecosystem, Quantum Alpha, NeyroLabs, new development priorities, and the next generation of AI-powered trading.

It was a noticeable change in direction.

Thousands of people joined the meeting because they wanted answers about their money. Instead, significant portions of the presentation concentrated on products that had not yet launched, technology still under development, and a vision for what AURUM hoped to become after the crisis.

Having investigated hundreds of investment schemes over the years, I’ve seen this pattern before.

When confidence begins to collapse, attention often shifts from explaining what went wrong to promoting what comes next. The conversation moves away from losses and towards innovation, away from today’s problems and towards tomorrow’s opportunities. That observation alone does not establish wrongdoing, but it is a recurring pattern investors should recognise.

Bryan Benson repeatedly spoke about emerging stronger, rebuilding the ecosystem, and creating an even better platform than before. Andrew Isaacs was introduced as leading the technical direction of Neyro, while the audience was encouraged to continue believing in the company’s long-term vision.

What remained largely absent was the same level of detail about the events that had already occurred.

The presentation did not spend comparable time explaining the missing funds, the blockchain evidence, the published smart contracts, the operator-controlled wallets, or why Crypto G’s independent forensic blockchain report found no evidence that the advertised AI trading activity had ever taken place.

Instead, the emphasis moved forward.

For investors, that distinction is important.

A new website does not explain the old one.

A new AI trading agent does not explain the previous AI trading agent.

A new roadmap does not explain what happened to existing funds.

And a new brand does not automatically resolve the unanswered questions surrounding the previous one.

Before anyone places confidence in the next chapter of AURUM’s story, the company first needs to fully explain the last one. Until that happens, the future being presented through Neyro remains built upon questions from the past that have yet to receive satisfactory answers.

One of the hardest parts of investigating collapsed investment schemes is watching people cling to hope long after the evidence has begun pointing in another direction.

I understand why.

If you’ve invested your savings, convinced your family to join, or built a business promoting the opportunity, accepting that something may be fundamentally wrong is incredibly difficult. The promise that “everyone will be made whole” becomes far more than a business statement. It becomes an emotional lifeline.

Over the years I’ve seen this happen repeatedly. Whether the explanation is a banking problem, a regulatory delay, a blockchain upgrade, a liquidity issue, or a sophisticated cyberattack, the message is often the same: be patient, don’t panic, trust the leadership, everything will be fixed. Sometimes those assurances prove correct. Sometimes they become the final chapter before a project disappears altogether.

That is why evidence matters more than optimism.

AURUM is asking investors to believe that compensation will be paid, assets will be recovered, the platform will return stronger than before, and a new generation of AI-powered products will restore confidence. Those are significant promises. They deserve equally significant evidence.

At the time of writing, investors are still waiting for an independently verified forensic report explaining the alleged cyberattack. They are still waiting for audited proof of reserves, a detailed accounting of the compromised assets, a transparent compensation framework, and an explanation reconciling the company’s public marketing with both the blockchain evidence documented by Crypto G’s independent forensic report and the findings presented throughout this investigation.

Hope should never replace due diligence.

Neither should loyalty replace accountability.

Every investor has the right to hope they recover every dollar they have lost. But they also have a responsibility to ask difficult questions, demand independently verifiable answers, and carefully examine the evidence before placing more trust in the same people asking them to remain patient.

The cryptocurrency industry was built on a simple principle:

Don’t trust. Verify.

After everything that has happened with AURUM and Neyro, those three words may be more important now than ever before.

After reviewing the emergency presentation, the new Neyro website, Crypto G’s independent blockchain forensic report, regulatory warnings from multiple jurisdictions, and AURUM’s own marketing over many months, I believe this investigation has reached the point where the company needs to answer specific questions with independently verifiable evidence, rather than further assurances.

If AURUM genuinely suffered a sophisticated cyberattack, the company should be able to identify the attack vector, explain exactly which systems were compromised, disclose the wallets affected, and quantify the losses. If an independent cybersecurity firm has been engaged, investors deserve to know who they are, what they have found, and when their report will be released.

The same applies to the business itself.

Where are the audited trading records supporting the AI trading claims?

Which exchanges were executing the trades?

How were the advertised returns actually generated?

If Quantum Alpha and the wider Neyro ecosystem genuinely perform as described, where is the independently verified performance data supporting those claims?

The blockchain evidence also deserves a direct technical response. Why do the published smart contracts examined in Crypto G’s forensic report appear to lack the observable AI trading logic promoted to investors? Why was no user withdrawal function identified in the examined BNB contract? How does AURUM reconcile its repeated claims that users remain in full control of their funds with the blockchain evidence documenting operator-controlled movement of assets?

The timing of recent events also requires clarification.

When did the Web3 migration actually begin?

When was NeyroLabs.io first developed?

Why was the replacement platform already being prepared before the emergency presentation?

Were investors informed that this migration was underway before withdrawals began failing?

And perhaps the most important question of all remains unanswered.

If AURUM intends to reimburse every affected investor, where are the funds that will make those repayments possible?

These are not hostile questions.

They are the questions every investor should be asking before deciding whether to continue believing the promises made during the emergency presentation.

In any legitimate financial operation, confidence is built through transparency, independent verification, and accountability.

After everything that has unfolded, AURUM now has an opportunity to provide exactly that.

Until those answers are supported by independently verifiable evidence, this investigation will continue to follow the evidence wherever it leads.

When I first began investigating AURUM Foundation, the story centred on extraordinary promises, regulatory warnings, and an AI trading platform that appeared too good to be true.

Since then, the evidence has continued to evolve.

Regulators in multiple jurisdictions have issued public warnings. Crypto G’s forensic blockchain investigation examined the smart contracts and followed the movement of investor funds. Marketing claims were compared against publicly verifiable blockchain data. Withdrawals reportedly became problematic. A new brand emerged. An emergency presentation blamed a sophisticated cyberattack. A replacement platform was unveiled before many investors had even received satisfactory answers about the original one.

Viewed individually, each of those events could be explained.

Viewed together, they tell a far more concerning story.

Throughout this investigation, I have tried to separate facts from allegations, marketing from evidence, and hope from reality. Where the blockchain provides answers, I have relied on the blockchain. Where regulators have issued warnings, I have referred to those warnings. Where AURUM has made public statements, I have quoted the company in its own words. Where Crypto G’s forensic investigation raises technical questions, I have presented those findings. And where questions remain unanswered, I have said so.

Ultimately, this investigation is not about proving people wrong.

It is about ensuring investors have access to information they were unlikely to receive during promotional webinars, recruitment presentations, or carefully managed Zoom calls.

The cryptocurrency industry often speaks about transparency.

Transparency is not measured by polished websites, ambitious roadmaps, or impressive presentations.

It is measured by whether independent investigators can verify what a company claims.

That is the standard AURUM now faces.

If the company’s AI trading technology genuinely performs as advertised, the evidence should eventually demonstrate that.

If every affected investor will be repaid, the funding and compensation process should be transparent and independently verifiable.

If the cyberattack occurred exactly as described, a detailed forensic investigation should ultimately support that account.

Until then, the strongest evidence available remains the blockchain itself, the published smart contracts, the documented movement of funds, Crypto G’s forensic report, the growing list of regulatory warnings, and the company’s own public statements.

Those records cannot be rewritten after the fact.

They will remain long after the presentations have ended, the websites have changed, and the marketing has moved on.

As with every investigation I publish, if AURUM, Neyro, their executives, developers, or promoters wish to provide verifiable evidence addressing the specific issues raised throughout this article, I remain willing to examine it with an open mind.

Evidence has always been welcome.

It still is.

Because in the end, the truth is not determined by who speaks the loudest. It is determined by what can be proven.

This investigation doesn’t end with this article.

If anything, it marks the beginning of an even more important phase.

When I published my original investigation into AURUM Foundation, the focus was on the company’s extraordinary claims, its compensation model, the growing list of regulatory warnings, and the people promoting the opportunity. Since then, Crypto G’s forensic blockchain investigation has examined the underlying smart contracts, traced the movement of investor funds, and raised serious technical questions about whether the platform was ever operating in the way investors had been led to believe. Now, following the company’s own announcement of a major security incident, the story has entered an entirely new chapter.

The evidence now falls into three distinct categories.

First, there are AURUM’s own statements, presentations, and promises.

Second, there are the independent findings of regulators across multiple jurisdictions that have publicly warned investors about different aspects of the company’s activities.

Third, there is the blockchain itself, together with Crypto G’s forensic investigation—a permanent public record that neither critics nor the company can rewrite after the fact.

My role is not to tell readers what they must believe.

My responsibility is to collect the evidence, compare competing claims, document contradictions where they exist, and continue asking questions until those questions are answered with independently verifiable proof.

If AURUM, Neyro, Bryan Benson, Andrew Isaacs, or anyone representing the company wishes to respond to the specific issues raised throughout this investigation, I remain willing to review any verifiable evidence they provide. That includes independent cybersecurity reports, audited trading records, proof of reserves, technical explanations addressing the smart-contract findings identified in Crypto G’s forensic report, or documentation supporting the claims made during the emergency presentation.

The same invitation extends to former employees, developers, promoters, and investors.

If you have documents, blockchain evidence, internal communications, or other information that may help establish what happened, I encourage you to get in touch. Every investigation benefits from additional evidence, particularly when that evidence can be independently verified.

For investors, the lesson is simple.

Never confuse confidence with proof.

Never confuse marketing with evidence.

And never allow hope to replace due diligence.

Because long after the presentations have ended, the websites have been redesigned, and the promises have faded, the blockchain will still be there—quietly recording what actually happened.

That is where this investigation began.

And until the outstanding questions are answered, that is where this investigation will continue.

After investigating hundreds of cryptocurrency investment schemes, I’ve learned that no two collapses look exactly the same.

Some platforms disappear overnight.

Others slowly stop processing withdrawals.

Some blame regulators.

Others blame banks.

Some point to liquidity problems, software upgrades, or technical failures.

Increasingly, cryptocurrency platforms point to cyberattacks.

That doesn’t mean every reported hack is fabricated. Legitimate companies are hacked every year, and sophisticated cybercriminals target financial platforms every day. If AURUM genuinely suffered the attack it describes, an independent forensic investigation should eventually establish exactly what happened, who was responsible, what assets were affected, and how investor funds will be recovered.

But as an investigator, I cannot ignore the broader pattern.

Before the alleged attack, regulators in multiple countries had already issued warnings. Crypto G’s forensic blockchain investigation questioned whether the advertised AI trading platform was ever operating as investors had been led to believe. The published smart contracts appeared inconsistent with repeated claims that users remained in full control of their funds. The forensic report also documented operator-controlled movement of assets and found no observable AI trading logic in the published contracts it examined. Then reports emerged of withdrawal problems. Shortly afterwards, AURUM announced a sophisticated cyberattack, introduced an entirely new Web3 platform under the Neyro brand, and asked investors to remain patient while promising compensation.

Those events deserve to be examined together—not in isolation.

The emergency presentation repeatedly encouraged investors to focus on the future rather than the past. New branding, new infrastructure, new AI agents, and a new roadmap were presented as evidence that AURUM would emerge stronger than ever.

Yet before investors can reasonably place confidence in the next chapter, they deserve a complete explanation of the previous one.

Where is the independently verified evidence that the advertised AI trading system operated as described?

Where are the audited trading records?

Where is the independently verified cybersecurity report into the alleged cyberattack?

Where is the transparent accounting showing what was lost, what remains, and how every affected investor will be repaid?

Those questions are not obstacles to recovery.

They are the foundation of it.

At this stage, I am not prepared to conclude that AURUM’s explanation of the cyberattack is either true or false.

What I am prepared to say is this:

The evidence currently available does not yet support many of the assurances investors have been asked to accept on trust.

Until independently verifiable evidence answers those outstanding questions, investors should approach every promise, every presentation, and every new product with the same principle that cryptocurrency was built upon:

Don’t trust. Verify.

This investigation relies entirely on OSINT — Open Source Intelligence — meaning every claim made here is based on publicly available records, archived web pages, corporate filings, domain data, social media activity, and open blockchain transactions. No private data, hacking, or unlawful access methods were used. OSINT is a powerful and ethical tool for exposing scams without violating privacy laws or overstepping legal boundaries.

I’m DANNY DE HEK, a New Zealand–based YouTuber, investigative journalist, and OSINT researcher. I name and shame individuals promoting or marketing fraudulent schemes through my YOUTUBE CHANNEL. Every video I produce exposes the people behind scams, Ponzi schemes, and MLM frauds — holding them accountable in public.

My PODCAST is an extension of that work. It’s distributed across 18 major platforms — including Apple Podcasts, Spotify, Amazon Music, YouTube, and iHeartRadio — so when scammers try to hide, my content follows them everywhere. If you prefer listening to my investigations instead of watching, you’ll find them on every major podcast service.

You can BOOK ME for private consultations or SPEAKING ENGAGEMENTS, where I share first-hand experience from years of exposing large-scale fraud and helping victims recover.

“Stop losing your future to financial parasites. Subscribe. Expose. Protect.”

My work exposing crypto fraud has been featured in:

No posts

Read the original on dehek.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.