Roobet Hands Player KYC to Fraudster for Six Months
The fraudster didn't hack anything. He just asked nicely, and Roobet said yes. For six months.

A Roobet player is currently being extorted for $200,000 by a fraudster who did not need malware, did not need a keylogger, and did not need to compromise a single line of code. All he needed, according to the victim's account posted Friday evening, was a convincing enough story to get Roobet's own staff to hand over the keys to someone else's account, identity documents and all, and keep the con running for half a year before anyone noticed.
The player, posting as @cakir61tr on X, laid out a timeline so catastrophic that it reads less like a support ticket and more like the plot of a film where the casino is the villain and nobody in the building has read the script past act one.
@Roobet gave away my KYC with their HANDS. Today a fraudster contacted me saying he got my Roobet Leaderboard payouts sent to his Roobet account (a complete different account) for over 6 months & also convinced admins to change my mail adress that was used on first register to his mail adress, stole my Roobet account. After accessing my account (which by the way I had 2FA, but he also got admins to remove that) Accessed to KYC info about me, and is now threatening me to Publish my KYC if I dont give him $200.000.
Let that sequence breathe for a moment. The fraudster convinced Roobet staff he was the legitimate account holder. He got them to redirect six months of leaderboard payouts to his own wallet. He got them to change the registered email address. He got them to remove two-factor authentication, the one security feature that is supposed to make exactly this kind of nightmare mathematically improbable. And he accessed the victim's KYC documents, which are now being held as ransom for two hundred thousand dollars.
The punchline, if you can call it that, is in the follow-up:
So the fraudster convicted Admins & Roobet staff he is me. Roobet sent the leaderboard money that they owe me to his account for months, changed the email on my account with 1 word without any verification just with social engineering for months.
One word. That is what stood between a legitimate player's account security and total compromise. A single word from a stranger was sufficient to convince "Crypto's Fastest Growing Casino" to reroute payouts, change credentials, disable 2FA, and hand over sensitive identity documents. Not a password. Not a 2FA code. Not even a half-convincing forged document. Just a conversation where someone said the right thing to the wrong employee, and the entire KYC apparatus, which exists supposedly to protect accounts and verify identity, was reprogrammed to serve the person committing the fraud.
The KYC irony
KYC, in crypto casino parlance, stands for Know Your Customer. It is the process by which a platform verifies you are who you say you are, usually by demanding a government ID, a selfie, and sometimes a utility bill. It is also the thing crypto casinos advertise as a security feature. The logic is simple: if we have your documents on file, nobody else can impersonate you.
What @cakir61tr's case demonstrates is that KYC works brilliantly as a security measure right up until the casino's own staff decide that someone else is you, at which point those documents become a liability so potent that they are now being priced at $200,000 by the person holding them.
The fraudster did not hack Roobet. He did not exploit a database vulnerability or run a phishing campaign against the player. He talked to Roobet employees, convinced them he was @cakir61tr, and they did the rest. They changed the email. They killed the 2FA. They redirected the money. They handed over the identity documents. The casino performed every step of the account takeover on the fraudster's behalf, apparently without once stopping to verify whether the person making the requests was the same person whose passport was sitting in their system.
This is not the first time
Roobet's relationship with account security has been, let us say, interpretive. Just last week, this publication documented a separate case in which a player posting as T claimed someone bypassed his 2FA and withdrew $4,800 within minutes of a win. The funds traced through two blockchain hops to a wallet holding 50,000 BTC. At the time, the 2FA bypass was concerning enough on its own. Now, with @cakir61tr's allegation that Roobet staff will voluntarily remove 2FA at a stranger's request, that earlier incident looks less like a sophisticated attack and more like a pattern.
In both cases, the player had 2FA enabled. In both cases, it did not matter. The only difference is that T lost $4,800. @cakir61tr lost six months of leaderboard earnings, control of his account, his identity documents, and is currently being shaken down for an amount that would make a reasonable person consider leaving the country.
What happens next
Roobet has not publicly responded to the allegation as of publication. The official account, which at time of writing boasts over 239,000 followers and a verified business badge, last tweeted promotional content with the practiced normalcy of a platform that would very much like you to focus on the slots.
@cakir61tr's post includes four screenshots, presumably showing the fraudster's communications and the extortion demand. The account is new, with only two tweets, which will inevitably fuel speculation about the claim's legitimacy. But the specificity of the allegation, the screenshots, and the fact that it aligns with a documented pattern of Roobet security failures make it considerably harder to dismiss than the usual "this casino is rigged" drive-by.
Here is what we know: a fraudster claims to have socially engineered Roobet's staff over a period of months. He claims to have received another player's payouts. He claims to have obtained that player's KYC documents. And he is now demanding $200,000 to not publish them.
The only entity in this story that was supposed to be verifying identities was Roobet. The fraudster did not defeat the KYC system. He recruited it. And the casino, the self-described fastest growing in crypto, apparently never noticed that it was paying the wrong person for six straight months.
Some growth metrics, it turns out, are easier to track than others.
Comments
Loading comments…
