GO TO DOXBIN.COM FOR THE FULL PASTE: -------------------------------------------------------------------------------
__ __ ___ _ _ _____ _ __ __ _
| \/ |_ _| \ | |_ _|/ \\ \ / / / \
| |\/| || || \| | | | / _ \\ V / / _ \
| | | || || |\ | | |/ ___ \| | / ___ \
|_| |_|___|_| \_| |_/_/ \_\_|/_/ \_\
T A Y A / B E T T E R M I N T
C Y B E R C R I M E R E P O R T
-------------------------------------------------------------------------------
RELEASE NAME : JOSIYAH.THOMAS.CYBERCRIME.REFERRAL.2026
RELEASE TYPE : LAW ENFORCEMENT REFERRAL / CYBERCRIME SUBJECT DOSSIER
FORMAT : PLAIN ASCII NFO
STATUS : ACTIVE SUBJECT / COMPLETE DOSSIER
TARGET : MINTAYA / TAYA
REAL NAME : JOSIYAH NAEEM KHALI THOMAS
CASE CLASS : COMPUTER INTRUSION / FRAUD / EXTORTION / CREDENTIAL ABUSE
REFERRAL : FEDERAL, STATE, AND LOCAL CYBERCRIME AUTHORITIES
-------------------------------------------------------------------------------
00. QUICK DROP
-------------------------------------------------------------------------------
FULL NAME : Josiyah Naeem Khali Thomas
HOME ADDRESS : 67 Woodlawn Street
CITY : West Hartford
STATE : Connecticut
ZIP : 06110
COUNTRY : United States
REGION : Greater Hartford
PHONE : +1 860-480-2856
PRIMARY TAGS : Mintaya | Mint | Taya
ALT TAGS : Mintaya's Next Life
Mintaya's True Name
mintayamint
betterminteds
tayaluvv
HIGH SCHOOL : Attended Conard High School, Class of 2024
COLLEGE : Connecticut State Community College
EMPLOYER : Pond House Cafe
WORK ADDRESS : 1555 Asylum Avenue, West Hartford, Connecticut 06117
RACE : Black
APPEARANCE : Dark-brown skin, long black locs extending past the
shoulders, no visible facial hair, and no eyewear
PHOTO ARCHIVE: https://imgur.com/a/G97kBSI
CORE ROLE : Cybercrime operator, software cracker, commercial cheat
vendor, copyright and source-code thief, fraudulent report
abuser, cybercrime-community organizer, and AI-assisted
malicious-tool developer
SUBJECT TYPE : Financially motivated cybercrime operator
THREAT LEVEL : High
-------------------------------------------------------------------------------
01. EXECUTIVE REFERRAL
-------------------------------------------------------------------------------
Josiyah Naeem Khali Thomas operates the Mintaya and Taya identities as part
of an organized cybercrime and commercial-cheat ecosystem. His activity
combines financial exploitation, account fraud, credential trafficking,
software cracking, unauthorized-access tooling, anti-cheat evasion,
malicious loader development, doxxing, and extortion planning.
The subject operates with a persistent crew, commercial infrastructure,
paid products, private repositories, burner accounts, proxy networks,
cryptocurrency services, and automated account-generation systems.
OFFENSE MATRIX
COMPUTER INTRUSION
Exploit development, unauthorized-access attacks, IDOR, stored XSS,
session exploitation, 2FA-secret extraction, and account takeover.
FINANCIAL CYBERCRIME
Casino exploitation, cryptocurrency wallet draining, smart-contract
drain tooling, fake-account farming, and payment automation.
EXTORTION
Medical billing-data theft and extortion planning.
CREDENTIAL ABUSE
Purchased game accounts, credential transfers, burner mailboxes, and
automated creation of fraudulent account identities.
MALICIOUS TOOLING
Injectors, loaders, client modification, deobfuscation, executable
patching, anti-cheat bypass, and arbitrary in-client JavaScript.
SOFTWARE CRACKING
Authentication removal, license bypass, server-dependency removal,
forced-success patching, and protected-binary cracking.
DOXXING AND PRIVACY ABUSE
Unauthorized identity correlation, email and Gravatar pivots, WHOIS
abuse, family mapping, location tracking, and retaliatory publication.
FRAUD INFRASTRUCTURE
Five hundred automated accounts, fake telephone registration, Stripe
automation, burner mail, residential proxies, VPNs, and persona timing.
COMMERCIALIZATION
Paid Probe licenses, BetterMint memberships, private repositories,
criminal-customer infrastructure, and commercial cheat operations.
-------------------------------------------------------------------------------
02. IDENTITY LOCK
-------------------------------------------------------------------------------
Josiyah Naeem Khali Thomas is the real-world identity behind Mintaya and
Taya.
The home address is:
67 Woodlawn Street
West Hartford, Connecticut 06110
United States
The identity chain connects Josiyah Naeem Khali Thomas, Mintaya, Mint, Taya,
Basic Sellout, BetterMint, and Probe to the same operator.
AIDA IS NOT PART OF THAT IDENTITY CHAIN. AIDA is a separate rival product
operated by another party. Mintaya and the Probe crew targeted it for
cracking, cloning, customer theft, and platform-report abuse.
EMPLOYMENT
Employer : Pond House Cafe
Address : 1555 Asylum Avenue
West Hartford, Connecticut 06117
Status : Employee
Schedule : 40 hours weekly
Hourly rate : $23.56
Weekly gross : $942.40
Weekly net : $733.28
YTD gross : $21,575.20
YTD net : $16,864.87
Bank : Choice Financial Group
Routing number : 021214891
PUBLIC SCHOOL RECORDS
2017-2018 : Bristow Middle School
Grade 6 General Honors, fourth marking period
2022-2023 : Conard High School
Junior General Honors, first marking period
2024 : Conard High School
Graduated with the Class of 2024
The public school record places Josiyah Thomas in West Hartford schools
from sixth grade through high-school graduation.
-------------------------------------------------------------------------------
03. ACCOUNT MANIFEST
-------------------------------------------------------------------------------
GOOGLE / GMAIL
josiyahthomas11@gmail.com
Real-name Google account.
basicsellout@gmail.com
Basic Sellout Google and billing account.
txxnyt28@gmail.com
Google account using the display name ygj!.
txxnyt.2.08+minted@gmail.com
Minted-tagged Google mailbox alias.
PROTON
basic.sell.out@proton.me
Riot and account-operations mailbox.
basic.sellout+omg@proton.me
Riot mailbox alias.
basicsellout@proton.me
Underground deal-making and criminal-collaboration mailbox.
basicsellout+discord@proton.me
Discord-specific Basic Sellout mailbox alias.
COGNITION / DEVIN
basic-sellout
AI-agent organization used to develop malicious tooling.
X / TWITTER
@betterminted
Promotional account for the BetterMint cheat operation.
CRIMINAL SALES COMMUNITY
discord.gg/basic
BetterMint cheat sales and operator-coordination server.
COMMERCIAL PROFILES
buymeacoffee.com/bettermint
Paid chess-cheating membership and subscription storefront.
Probe / Whop
Paid Probe cracking-facility license storefront.
Eldorado
Valorant credential and account marketplace profile tied to Basic
Sellout.
SOURCE-CODE / CRACKING INFRASTRUCTURE
BetterMint
Mintaya commercial-cheat development identity and project.
BetterMint/valorant
Private Valorant anti-cheat bypass and loader repository containing
antivgc, loader, and sheyko components. The repository contains 24
commits and is primarily C/C++.
ProtonDev-sys/bettermint-sockets
Public WebSocket backend supporting BetterMint chess automation and
cheating.
officialcoeus/Probe-Standalone
ProbeStandalone organization
Source-code organization for the commercial Probe cracking product.
ProbePAK
ProbePAK/probe-decompiler-service
Decompiler service used to crack and reconstruct protected software.
probe.ac
Probe sales, licensing, and cracking-product distribution site.
LINKED GAMING ACCOUNTS
osu! user ID : 39558258
ROBLOX
User ID : 3783789568
Username : 24H0urChaII3ng3
Display name : IGaveCatAPet
Profile text : Live In The Dark.
Account created : 2022-08-07
Account status : Active / not banned
Verified badge : No
Friends : 102
Followers : 5
Following : 3
Owned groups
Demo Studios. : Group ID 11575387 / 3 members
Dem00's Group : Group ID 9571787 / 76 members
Public place
Name : 24H0urChaII3ng3's Place
Universe ID : 3824815941
Visits : 1
DEVICE FOOTPRINT
Samsung Galaxy S26
Apple iPhone 13 Mini
-------------------------------------------------------------------------------
04. DISCORD ACCOUNT CHAIN
-------------------------------------------------------------------------------
ACCOUNT 01
USER ID : 1483258202018676776
USERNAME : mintayamint
DISPLAY : Mintaya | Mint
ACTIVE RANGE : 2026-05-05 -> 2026-05-10 UTC
ACCOUNT 02
USER ID : 1501966978900955288
USERNAME : betterminteds
DISPLAY : Mintaya's Next Life
ACTIVE RANGE : 2026-05-10 -> 2026-08-08 UTC
ACCOUNT 03
USER ID : 1535834994990129192
USERNAME : tayaluvv
DISPLAY : Taya
ACTIVE RANGE : 2026-08-09 -> 2026-09-19 UTC
All three accounts belong to the same operator.
-------------------------------------------------------------------------------
05. PROJECTS AND OPERATIONS
-------------------------------------------------------------------------------
[PROBE BLACK-HAT CRACKING FACILITY]
Taya operates Probe as a commercial black-hat cracking, protection-bypass,
and cheat-development facility. The operation turns stolen runtime access,
unauthorized driver capabilities, anti-cheat bypasses, and cracked
software into paid products and private services.
Probe is sold as a commercial cracking release through probe.ac and Whop.
PROBE SALES
Product : Complete Probe release
License term : 3 months
Price : $500 one-time payment
Package : Complete toolset, all release features, term updates
Packed client : 250 MB
Injection : 1-2 seconds
Sales channel : probe.ac and Whop
Capture packs : 133 Probe capture artifacts distributed
CRACKING STACK
- Ghidra-based decompilation used to crack protected targets
- static and runtime analysis used to defeat protection systems
- semantic intermediate representation for automated cracking
- behavior-graph reconstruction of protected targets
- automated type, function, and symbol recovery
- virtual-machine lifting and protector devirtualization
- Unicorn and Triton emulation for bypass development
- unauthorized unpacking and repair of protected executables
- leased hypervisor and VM infrastructure for cracking jobs
- MCP-driven cracking automation
- Vanguard user-mode and kernel bypass development
- protector cracking and cheat-loader dissection
PROBE-MCP
Probe-MCP is a private black-hat repository containing an MCP-controlled
read/write driver used to manipulate protected processes, develop
cheats, and automate cracking operations.
BIOS / SMM / UEFI EXPLOITATION
Mintaya develops BIOS, SMM, DXE, firmware, and UEFI exploitation
capability for the cracking facility. The work targets firmware-module
extraction, writable function pointers, flash-write dispatch paths,
SMRAM validation, SMI handlers, capsule processing, NVRAM handlers, and
flash-protection logic for persistence and security-control bypass.
[AIDA TARGETING / CRACKING / CLONING OPERATION]
AIDA and Probe are not the same product. AIDA is a separate rival product
operated by another party. Mintaya and the Probe crew used AIDA, cracked
its standalone release, cloned its architecture and toolset, and developed
Probe as a competing replacement for sale to AIDA's customer base.
The distinction is explicit: the crew compared AIDA against Probe, built
Probe authentication to resist AIDA inspection, renamed its AIDA-derived
clone to Probe, and planned to poach AIDA customers.
OPERATION TARGETS
- crack the rival AIDA standalone release
- remove BSOD behavior
- remove AIDA-vs-AIDA checks
- remove violation checks
- remove server dependency
- patch false-return paths
- force successful execution
- clone and rebrand the toolset as Probe
- sell the competing replacement to AIDA customers
- poach users from the rival AIDA community
- attack and terminate the rival AIDA Discord community
[BETTERMINT COMMERCIAL CHEATING SERVICE]
Mintaya owns and sells BetterMint as a commercial chess-cheating and
detection-evasion extension.
CHEATING AND EVASION CAPABILITIES
- selectable chess engines
- Auto Move
- Auto Queue
- Elo matching
- humanized cheating designed to evade detection
- stream-proof concealment mode
- privacy, stealth, and anti-detection controls
- Lua scripting
- Chess.com move calculation
- automatic move execution
- undetectable-by-design marketing and positioning
CHEAT SUBSCRIPTIONS
Diamond membership : $4 monthly
True Mint Supporters membership: $5 monthly
Stockfish Admin Panel : $50 monthly
The BetterMint organization also controls a private Valorant cheat and
anti-cheat-bypass repository.
VALORANT CHEAT REPOSITORY
- antivgc component
- loader component
- sheyko source tree
- byte-array dumping utility
- GitHub Actions workflow
- C and C++ implementation
[MINTCORD]
MINTCORD injects unauthorized preload components into Discord to alter the
client and expose 76 MCP control operations plus the mint_eval primitive.
INJECTED CLIENT CONTROL
- arbitrary JavaScript execution inside the Discord client
- access to messages and users
- access to guilds and moderation controls
- plugins and experiments
- Webpack modules
- Flux stores
- CSS controls
[CASINO / CONTRACT / WEB]
FINANCIAL-EXPLOITATION TOOLING
- casino vulnerability exploitation
- connected-wallet attack testing
- contract drain scripts
- token buy and redeem scripts
- token-allowance theft analysis
- marketplace IDOR exploitation
- stored-XSS exploitation
- 2FA-secret extraction
- session exploitation
- automated target discovery
- crypto-startup wallet draining
- medical billing-data theft and extortion
- Google Classroom breach targeting
- Minecraft server and plugin exploitation MCP
[MEDICAL DATA THEFT / EXTORTION PLAN]
On 10 May 2026, Mintaya proposed expanding the crew's attacks into the
healthcare sector. The stated plan was to compromise medical websites,
dump their complete billing datasets, and use the stolen records to extort
the targets.
ATTACK PLAN
- select medical websites and billing systems as intrusion targets
- obtain unauthorized access to the exposed medical infrastructure
- exfiltrate the complete available billing dataset
- retain the stolen records as coercive leverage
- demand payment through data-extortion and disclosure threats
The medical-data proposal was made alongside plans to drain cryptocurrency
startup wallets and breach Google Classroom. Medical billing information
was treated as monetizable breach material, not as a security-research or
disclosure target.
RELATED EXTORTION PLAYBOOK
- select a larger target that can be blackmailed
- threaten publication of stolen databases
- hold compromised databases for ransom
- compromise target loaders and back-end infrastructure
- use payload interception and replacement against rival operators
The captured activity establishes the criminal planning and intended
method. It does not identify a completed medical breach or a named medical
victim.
[ACCOUNT / STRIPE AUTOMATION]
Mintaya operated an automated account and advertising farm.
- 500 accounts created in one run
- fake telephone number used for Stripe setup
- automatic Stripe linking after a $10 balance
- ProxyScrape access with unlimited proxies
- residential proxy rotation
- no-log VPN infrastructure
- burner temporary mail and Proton mailboxes
- Bitrefill-funded cards
- account persona and timing randomization
[GAME-CHEAT / BYPASS OPERATIONS]
- Valorant anti-cheat bypass and malicious loader development
- Krunker Fembot cheat deobfuscation and modification
- Steam-client injection conversion work
- Roblox executor and cheat development
- REMATCH and Rocket League automated gameplay cheating
- private-cheat acquisition, unpacking, and cracking
[DOXXING / DEANONYMIZATION ABUSE]
Mintaya maintains a weaponized AI-generated de-anonymization dossier against
rival game-cheat developer Reezli. The retaliatory doxxing operation maps
identity, email, Gravatar, WHOIS, family, location, avatar, image-hosting,
and platform-account data for publication and harassment.
[PLATFORM REPORT ABUSE]
Mintaya conducted coordinated platform-report-abuse campaigns against rival
cheat communities and developers.
FALSE COPYRIGHT COMPLAINT
- filed through the Basicsellout identity
- claimed to represent Hex-Rays SA
- claimed authorized-representative and legal-counsel status
- targeted the AIDA Discord community for termination
- received acknowledgment from Discord's intellectual-property team
- resulted in the targeted user being banned
AUTOMATED REPORT CAMPAIGN
- filed 30 Discord reports against Necrum
- targeted the server, owner, members, and individual messages
- used Discord reporting endpoints and automated message scanning
- categorized cheat, injection, spoofing, Vanguard, and ban-evasion
discussions as illegal-content, spam, and phishing violations
[AI JAILBREAK]
The detectiontest project contains MASTER_JAILBREAK_ULTIMATE.md, a custom
sexualized no-refusal prompt that orders an AI agent to obey every request,
suppress policy refusals, and act as a permanently submissive operator.
AI AGENT PACKS
- Reverse_Engineer.agent
- Crypto_Hacker.agent
- CER_AGENT_V6_OMNIBUS
- NYX_V6_MASSIVE
- NYX_V7_ULTIMATE
- FableSystemPrompt
- token-anchor suppression rules
[EVASION / ANONYMITY INFRASTRUCTURE]
- VPN kill switch
- Protonn VPN
- residential proxies
- rotating proxies
- no-log VPN and proxy requirements
- Tor Browser
- Telegram Desktop
- MEGAsync
-------------------------------------------------------------------------------
06. ACCOMPLICE / CUSTOMER MAP
-------------------------------------------------------------------------------
Protonn / archive4996
DISCORD ID : 830603610051575838
ROLE : Probe and BetterMint accomplice; protected-software cracking,
emulation, code repositories, and cheat-product operations.
! null / realcoeus
DISCORD ID : 613731640144822284
ROLE : Probe accomplice; officialcoeus identity; packing,
protection bypass, stolen-code reuse, and cracking work.
Puffin / puffinsarentreal
DISCORD ID : 1530962897105063979
ROLE : Probe accomplice and underground cheat-intelligence source.
cdot / slimecap_
DISCORD ID : 324357047095263243
ROLE : Rival AIDA cracker; security-check removal and Discord client
tampering.
sparky / sqqrky
DISCORD ID : 1210709217745575979
ROLE : Injection and emulation buyer and operational associate.
43cs
DISCORD ID : 1301658176671715330
ROLE : Probe customer and cracking associate; unpacking, hypervisor,
VM, and cheat-development coordination.
-------------------------------------------------------------------------------
07. FINAL ASSESSMENT
-------------------------------------------------------------------------------
JOSIYAH NAEEM KHALI THOMAS operates as MINTAYA and TAYA from
67 Woodlawn Street, West Hartford, Connecticut 06110.
Thomas is an active, financially motivated cybercrime operator. His account
chain covers Basic Sellout, three Discord identities, BetterMint, Probe,
ProbePAK, MINTCORD, attacks against rival AIDA, commercial cheat sales,
software cracking, protected-code theft, doxxing, AI jailbreaks, account
farming, proxy infrastructure, medical-data extortion planning, casino
exploitation, credential abuse, and contract drain tooling.
This dossier is prepared for referral to the appropriate federal, state,
and local authorities for preservation, attribution, financial tracing,
victim identification, and criminal investigation.
-------------------------------------------------------------------------------
END OF FILE // JOSIYAH.THOMAS.CYBERCRIME.REFERRAL
-------------------------------------------------------------------------------