Thursday, June 24, 2010
Just Conjecturin', Vol. 19: The Real Problem with the UB Hand Histories
As I expected would happen back in April or May, the interference factor over at 2+2 has increased due to a couple of nasty trolls, one of whom seems to have intentionally sabotaged some of Chops' efforts in trying to speak to former and current UB employees. It's a shame that some people don't realize that the proper way to investigate a story is to listen to everyone, whether that person is presumed, innocent, guilty, insane or whatever, then compare the stories one receives and explore the differences therein. Unfortunately the tale behind the scandals is almost too big; too many people have things to hide, and thus efforts by good writers to explore the tale honestly are being messed with by people with hidden agendas.
But please don't feed the trolls, folks. I've done a little bit of that but am swearing off everything in that area except the exposing of lies, which unfortunately has to be done. Think about why the trolls might be doing what they're doing, and keep an open mind to all possibilities. Don't exclude the chance that certain factions involved in the behind-the-scenes struggles involving Cereus and its earlier component companies might even be willing to self-administer a flesh wound or two to throw others off the correct path. It's all quite Machiavellian, and it pays to keep that in mind as one attempts to learn from the unfolding saga, but all that is grist for a future post.
This time, it's back to those confounded, messy hand histories that UB sent out over the past several months in response to ongoing requests and complaints from players. The problem was that the hand histories were all but incomprehensible, often broken down into files that contained individual hands, rendered in Notepad file format. Barry Greenstein, one of the better souls in poker, posted the HH's that he received here, and many months ago I did some digging around in those files to see what I could find, first deciphering the formats and then trying to find instances of shady play.
The first part I accomplished pretty well, the second part not so much. It was only after I made the attempt to find "cheating" hands that the poker world learned that the UB hand-history batches that were sent out were pre-edited; the powers that be at Cereus had only included hands where the already-identified hands gave action against the players requesting the hand histories. And in Barry's case, he had not received a refund, meaning that the possible cheating hands were nothing more than... oddly played hands.
This was probably the same conundrum that a former WSOP world champion not affiliated with UB encountered when he agreed to examine thousands of possible cheating hands in conjunction with settlement talks between the current and former owners of UB. Except for the most obvious forms of cheating, such as when a cheater's K-K is folded to another player's A-A pre-flop or when a ridiculous bluff or call of a bluff is made (such as what happened at the end of the infamous PotRipper tourney), a lot of supposed cheating is indistinguishable from the variance in playing styles that is the hallmark of poker. It takes long-term patterns and unusual win rates to determine more subtle forms of cheating, and it's possible that outside of an internal expose, the methods undertaken by Michael Josem and others might have been the only viable way to uncover the cheating seen in the UB scandal.
But about those UB hand histories: Why exactly are they so messed up, so useless for any real analysis?
Given that Cereus has shown no interest in sending out complete hand histories for the affected players, one has to dig further. Company officials have floated claims that the older hand histories are on a different server, in another format, and are just generally difficult to access. It's been reported to me that UltimateBet's first few years of hand histories were saved in MySQL format, and that they ported over to Oracle in 2005 or 2006, but for programmer Uri Kozai to be able to access all supposed cheating hands in the 2003-07 time frame and derive a financial solution to the supposed cheating based on net wins and losses by the known cheating accounts, the company was clearly able to combine all hand histories into a coherent whole for examination.
And yet that ability seems to have disappeared when the players want their complete hand histories? Sorry, that one doesn't fly, despite the general incompetence demonstrated by Cereus's technical and support staff in recent months.
Let's assume a different starting line. Let's begin with the wholly plausible argument that Cereus could send out complete hand histories to players, but they just don't want to. Is there any evidence to support this hypothesis?
Yes. In this video interview, no less an UltimateBet persona than Annie Duke stated that publicly-named-as-cheater Russ Hamilton had 88 accounts at UB, as pointed out by 2+2 supermod Kevmath in this thread.
If one assumes that Duke's "88 accounts" story regarding Hamilton is true -- and it jives with what's been alleged to me by other sources -- then there's a ready-made explanation for why the hand histories as sent out are fractured and incomplete. Only 23 accounts and over 100 screen names, including multiple name changes, were identified. Most of those, but not all, have been traced to Russ, but even if every single one of those was a Russ account, it still leaves as many as 65 Russ Hamilton-controlled accounts that are unnamed and unaccounted for.
While it's possible that none of these other accounts were involved in the cheating, it's more likely that at least some of them were. Cereus probably did locate the largest among the cheating accounts, the ones that would be most likely to be uncovered by cheated players' analysis, but Hamilton by all reports did not provide the account names, the same way his share holdings had to be forcibly seized. In addition, Cereus and the KGC have provided no evidence that they investigated any accounts beyond those named within player complaints, nor did they submit to a truly independent audit, claims to the contrary notwithstanding.
Therefore, it's likely that hundreds of thousands or a few millions more in cheating went undiscovered when compared to the numbers officially released. Don't forget to add in the fact that the methodology used in determining refunds accounted only for action given between players and cheating accounts, and had no way to account for action wrongfully denied, as in the made-up K-K versus A-A example above. As massive as the total cheating amount was, it was almost surely underestimated.
And that returns us back to the bollixed hand histories. The real reason they're messed up is because Cereus likely does not want players looking at additional hands where some of these other still-hidden accounts may have played. A settlement between the new and old ownership groups was already reached, additional shares belonging to three others besides Hamilton were forfeited, and there's no way for the cash-strapped "new" Cereus to go back for a second helping of settlement funding. Given the other financial struggles and massive debt load Cereus faces, there's no way they can afford the risk of additional millions in refunds themselves.
The corporate answer, then, is just to obfuscate. Joe Sebok's good-faith efforts notwithstanding -- and despite my disagreement with his choices, he still did what he did in signing with Cereus in good faith -- I expect we'll see a fire engulf the MIT server farm before full UB hand histories ever see the light of day. Joe's efforts in that regard were fruitless and frivolous; he technically achieved his goal of getting out the hand histories... but not really. That's the sad and the short of it.
Wednesday, June 02, 2010
Holloway Killing Suspect at LAPT Peru?
[By FRANKLIN BRICENO, Associated Press Writer Franklin Briceno, Associated Press Writer]
LIMA, Peru – A young Dutchman previously arrested in the 2005 disappearance of Alabama teen Natalee Holloway is the prime suspect in a weekend murder of a Peruvian woman, police said Wednesday.
Joran van der Sloot is being sought in the Sunday killing of 21-year-old Stephany Flores in a Lima hotel, Criminal police chief Gen. Cesar Guardia told a news conference. He said the suspect fled the country the next day by land to Chile.
The Dutch government said Interpol has issued an international arrest warrant for Van der Sloot.
Guardia said the 22-year-old Dutchman, who was in the country for a poker tournament, appears with the young woman in a video taken at a Lima casino early Sunday....
I'm gonna guess the guy was a no-show for the tourney if this is true. Maybe Otis or Shamus can check it out?
Friday, May 28, 2010
Just Conjecturin', Volume 18: Fakes a-Plenty Among the KGC 31
In the early part of 2010, a partial list containing 15 accounts was leaked out from Cereus. This leak was also suspicious, though an investigation into the accounts listed therein, done by me, showed that the accounts themselves were very real and were indeed part of the cheating scandal. I obtained this list just a couple of weeks ago. This may be the list WCP is planning on releasing, or they may have since then obtained a more complete list via the same source, due directly to the pressure I've been exerting.
The 15 accounts include 14 separate names, with one name (a real person very close to Russ Hamilton) being listed on two different accounts, but with different addresses and the addition of a middle initial in one of the names. The list does include either three or four real people, but the huge problem here is that most of this list is fakes: fake accounts with made-up names or phony addresses allegedly created at Russ Hamilton's behest, later to be used by Hamilton in the cheating.
Today it's time to publish the fakes, noting that all these names are supposed to have been included on the Kahnawake Gaming Commission's official list of 31 people connected to the cheating. The fact that many of these fakes are obvious casts even more suspicion on both the source of the leak and the KGC itself, since either, with even a modicum of effort, could have deduced the fakes and eliminated them from the list. (Or, conversely, published them with a grand proclamation of how things were being done in regard to the scandal.)
So here are the ten fakes:
Bill Gordon
User Id – 40018
Address: 1221 windbrook San Diego, California
Tele - No Number
Undetermined – 1221 is an invalid street number, but 11221 would be legit, no zip.
This is a play-money account, perhaps even of a real person, that was converted into a cheating account internally at a later date. All such low-ID accounts on the KGC list are of similar origin.
James Brunson
User Id - 966687
Address: 1444 Wagner Las Vegas, NEVADA 89134
Tele - No Number
Fake address (would be in the middle of I-15), wrong zip for street
Confirmed fake. If you’re going to have a lot of fakes, you may as well toss a “Brunson” in there for verisimilitude, right?
Jason Plunto
User Id - 1676953
Address: 2480 W. 99th Chicago, ILLINOIS 60402
Tele – No Number
Confirmed fake. Google sat maps show a house at this general location, but “Plunto” does not appear as a name in all of Chicago white listings and the houses in this vicinity front on a side street.
Frank Dursley
User Id - 1676958
Address: 2549 Maple Humeston, IOWA 50123
Tele - No Number
Fake address , confirmed fake
Rufus Black
User Id – 2422566
Address: 73 W 53rd Biloxi, MISSISSIPPI 39530
Tele - No Number
Confirmed fake.
Carol Plizga
User Id - 2510148
Address: 7006 grouse road las vegas, NEVADA 89134
Tele – 7023969970
Probable fake – Grouse St. (not "Road") w/ same zip code exists, but numeric addresses not in same range
Jason DelMonte
User Id – 2561615
Address: 78 Grainger Rd Evanston, ILLINOIS 60427
Tele - No Number
Fake address – zip wrong for Evanston, no such road
Confirmed fake
Thomas King
User Id - 2561621
Address: 301 Appleton Miami, FLORIDA 10234
Tele - No Number
Fake zip, fake street
Confirmed fake
Eli Argo
User Id - 2561631
Address: 604 e 23rd st grand rapids, MICHIGAN 70469
Tele - No Number
Fake address, fake zip
Confirmed fake
Spencer Price
User Id - 2641649
Address: 4044 Billings Canton, COLORADO 11111
Tele - No Number
False zip code, Canton, Co barely exists, and roads are numeric county roads
Confirmed fake
* * * * *
These are presented in ID # order for a reason. Notice the tight grouping associated with some of these IDs:
Jason Plunto: 1676953
Frank Dursley: 1676958
Jason DelMonte: 2561615
Thomas King: 2561621
Eli Argo: 2561631
It's no coincidence. These accounts were almost certainly created during two sessions when multiple accounts were being created via Hamilton's directives, and accounts near to these in numeric order could easily be checked to see if more fakes are unearthed. One they'll find for sure is the "Dan Francis" account associated with "ShaqTack" and others, which numerically fits right in with the Plunto/Dursley run:

The Francis grab comes from a 2+2 poster who saved the original "brainwashdodo" screen grabs; I'd love to acknowledge him but I cannot find his message this morning. (Contact me, please.) How the Francis account was missed or not included within the above list of 14-15 names remains beyond me, but it has been alleged to me that many fake accounts used in the cheating have not even been uncovered, and I now believe this claim. Again, it calls into question both the motives of the person who leaked the list and the laughable way in which the KGC report was constructed and presented to the public. It is true that most of the dollar value in cheating attributed to the fakes is probably accounted for by the names in this list, but the fact that the list itself is both so blatantly stuffed with the fakes and so obviously flawed makes its origins and motives suspect.
I'd love to see WCP release the full 31-name list next week, if indeed they have it; they may not. They can release the four real names on this list if they wish, or I can do it at a later date. I'm still researching to see if (a) all four are indeed real, and (b) exactly what benefit(s) they may have received from the cheating.
I know of approximately ten more of the real people who are supposed to be on the full KGC list of 31, but it is likely that the list will be as much a tool of business and political convenience as it is an attempt to get to the truth, and the complete list may well contain parties guilty of the cheating, parties guilty of other things, and perhaps even an innocent party or two.
And of course, it has parties that don't even exist. You now know about these.
(I hereby give permission for the list of ten accounts above and the Dan Francis screen grab to be distributed freely. -- HLH)
* * * *
P.S.: Phil Hellmuth is innocent in the cheating. He remained clueless about the entire scandal until it blew up behind his back, and to the best of my knowledge he still doesn't know jack about what really transpired. Has he been a silly frontman still looking to make a buck off his name? Sure, but that's just Phil.
* * * *
P.P.S.: Okay, so I can't count late at night after working all day. This is Volume 18, not 17. Any bets that the over/under on this series tops 40?
Friday, May 21, 2010
Just Conjecturin', Volume 17: The Real Story of the UltimateBet Refunds
How the $22 million amount was determined and how it was distributed to cheated players is something that's been answered only in overly general, often inadequate terms. The more specific answer begins with a court deposition given by onetime UB programmer Uri Kozai, who was the man finally tasked with developing a refund method for players after other options fell through. Despite being a programmer (and therefore automatically being cast under the general net of suspicion surrounding the UltimateBet affair), Kozai appears to have had no connection to the cheating itself. [Kozai does remain connected to secondary firms still pursuing interests related to Cereus and the old Excapsa matters, and is of course among the many Excapsa shareholders outed through the efforts of a major Excapsa executive seeking leverage, back in the day.]
The cheating, more specifically the surreptitious code that allowed its users to spy on other players' hole cards in real time, was known internally as "God Mode", not the more official-sounding "AuditMonster1" and "AuditMonster2" tags listed in the final Kahnawake Gaming Commission report.
Not only did the hidden God Mode exist long before Kozai entered the scene, but Kozai himself was reported to be "livid" after being clued in as to the code's secret location. Kozai was tipped off, allegedly, by legal counsel to one of the other UB parties ensnared in the affair, this as pressure from the outside for a complete explanation continued to mount.
Ever more cheating accounts were uncovered and the amount needing to be refunded grew and grew, and this was the crux of the $81 million lawsuit filed by official purchaser Blast-Off Limited against Excapsa, the original UB owners, on the basis of Blast-Off having purchased "damaged goods". One round of refunds totaling about $7 million had already been issued, though that was clearly inadequate in the face of additional uncovered cheating accounts.
The scandal's scope grew ever wider, and as the larger second wave of accounts was acknowledged, the span of time that the cheating included was stretched back all the way to 2003. The $22 million was a very real number as estimated by Kozai, based on his examination of the suspect accounts, and is likely the exact figure Kozai himself listed in his deposition in the Blast-Off/Excapsa battle. The deposition is buried deep within the many documents connected to the liquidation of Excapsa. The figure within Kozai's deposition suggesting the total refunds needed was redacted from publicly available documents, meaning it might not match to the penny the $22 million that was refunded, but since Kozai's figures were those used both to compute the refunds and to resolve the "damaged goods" legal battle between Blast-Off and Excapsa, the two can be presumed to match.
In one light, one could say that the $22 million returned over both rounds of refunds was an honest, good-faith effort to compensate all the cheated players -- not forgetting, of course, that Blast-Off expected Excapsa's shareholders to pay for it. [As it turned out, an additional 24 million shares of Excapsa stock were annulled as part of the final legal deal. The owners of those shares and the annulment's relationship to the earlier, more publicized stock forfeiture connected to Russ Hamilton is a topic for a future post.]
In another light, however, one could also say that the whole $22 million in refunds was a giant, approximately-shaped band-aid slapped on the scandal in the hopes that it was enough to make the pressure go away. Not quite a sham, but not quite true, either. It's best described as a desperate measure employed to give all the shareholders -- on both sides -- at least the chance to move forward and continuing collecting revenue from players.
The real story is this: Despite the enormity of the amount refunded, the individual refunds could not possibly be correct, in whole in or in part, and there is likely no affected player who ever received the exact refund that he should have received. Many players received nothing or not enough, while there must be others who received too much.
Kozai's formula involved looking at the net long-term profit of each of the cheating accounts known at that time, adding those accounts' profits together -- which is where the $22 million figure came from. The matching funds, thus secured, were then distributed on a flat-line percentage basis to all player accounts that showed a net loss in action against those cheating accounts.
Kozai's method, as mentioned, was a last resort, and it involved no specific analysis of the hands themselves. It was utterly impossible for Cereus to determine what hands involved cheating by a God Mode-using account, and what hands didn't which isn't to say they didn't try. Cereus even enlisted the help of a World Series of Poker Main Event world champion -- one not named "Hamilton" or "Hellmuth" -- who looked at thousands of hands and finally gave it up as a lost cause. At that point there was nothing left to do but use Kozai's calculations.
So why was it impossible to go back into the records and determine more specifically who was cheated, when, and for how much? Because of this: The God Mode tool was written early on in UB's history, and it was written in such a way that it stood outside of UB's standard cache of auditing tools. Neither UltimateBet in the days before the merger with AP, nor Cereus today, have ever had any capability to track exactly when God Mode was being used. Worse, there were accounts that were used both for cheating and for innocent, straight-up play, and the real play and the cheating play within these accounts were intertwined over months, even years of action. The end result was a morass that defeated all detailed attempts at a hand-by-hand or session-by-session reckoning of the affair.
Players who still hope to receive a to-the-penny accounting of the cheating that took place at their tables will be perpetually disappointed, because no such accounting is possible. Cereus COO Paul Leggett stated, in a recent interview, "[E]verybody got every penny back...." While a huge amount of money was refunded, the fact that the God Mode play could not be tracked internally makes Leggett's statement a frivolous claim. Other factors weaken the claim even more, including the probable existence of additional cheating accounts never included in the calculations, along with entire secondary cheating episodes not acknowledged to date.
Next time out it's a re-visit to the topic of the hand histories provided to cheated UB players.
Monday, May 17, 2010
Just Conjecturin', Volume 16: The Curious Case of 'brainwashdodo'
One of the most intriguing episodes in the annals of the UltimateBet scandal was the appearance on the 2+2 poker forums in late 2007 of a poster named "brainwashdodo", a poster who shared, via screengrabs and anecdotal tales, a tantalizing helping of inside information connected to the cheating. Information posted by brainwashdodo at the time was vital to the wronged poker players' investigative efforts in covering some of the user accounts and possible money trails used in the scandal, and in fact directly contributed to the uncovering of Russ Hamilton himself. Hamilton may well have been outed via other lines of inquiry that were also underway at the time, but the information brainwashdodo provided all but removed any doubt in the matter.
What was perhaps most intriguing, however, was that brainwashdodo himself disappeared from the scene, as abruptly as he first appeared. Even stranger was that many of the screen grabs this poster served up on a file-sharing service were quickly deleted as well, leading onlookers to question brainwashdodo's motives in posting about the matter in the first place. Brainwashdodo posted 14 times between June 30 and July 8, 2008, disappeared for almost five months, then served up three more quick posts on December 2, 2008 before vanishing forever into the electronic ether.
Here's a quick visual overview of brainwashdodo's posting history on 2+2. [While the forum's owners retain proprietary rights to content in its entirety, the nature of this tale involves 2+2 itself, and because there is another part to this, these images fall under "fair use" for editorial purposes.] The list is presented in reverse chronological order (most recent posts at top), and clicking on any of these images should bring up a larger version:





Brainwashdodo's final December posts on 2+2, in fact, were little more than a wish for happy holidays for posters amid what might have been a veiled threat: "Anyway, more cht to hit t fan, will be back tmrw." In a July post, with much more gravitas, brainwashdodo had written this: "Out of curiosity, I have started my own audit within, since I saw no KGC or any other investigator coming or going. All the results will be shared with you soon, a website is coming together." However, Brainwashdodo's first series of posts ceased that very day, and after the no-new-information return in December, brainwashdodo never posted again. The hosted images were long gone as well, with nothing more than unreadable Google thumbnails to hint at the account information that once was opened to all.
It was in those earlier summer posts, of course, that other hard information was presented, with scathing and lengthy account-transfer histories that directly implicated Russ Hamilton at the heart of the cheating scandal and to many of the accounts later included in the Kahnawake Gaming Commission's "official" final report on the matter. Those histories had been posted in text format on 2+2, an independent site, and were thus no longer so easily removed. The transfer and play histories ran many hundreds of lines and included entries such as these, taken from an internal transfer account called "-Fred-", which was allegedly solely controlled by UB employee Fred David, but which was in fact under the direction of one or more top-level UB people, including Russ Hamilton. A second internal transfer account, "-russh-" (standing for Russ H[amilton]) was also directly tied via the -Fred- account to many of the proven and acknowledged cheating accounts, in transactions such as these:
377361587 40000.00 Transfer From -russh- 2006-SEP-03 05:40:03 PM customer req
377269310 -10000.00 Transfer To ShaqTack 2006-SEP-03 04:26:02 PM customer req
33412309 70000.00 Transfer From HeadKase01 2006-MAR-19 02:30:16 PM
31566264 50000.00 Transfer From RussHamilton 2006-MAR-18 04:02:45 PM customer req
The reason the -fred- account was used is that it was already a familiar account internally for high rollers to swap money back and forth for big games. Many of these big players were and are peripherally tied to the scandal despite being wholly innocent of the cheating. Since the -fred- account had lots of high-dollar swaps running through it, it would have served well as camouflage for similar-sized, illegitimate transfers. These transfers to cheating accounts were done amid this larger sea of far more legitimate swaps, which were done to help get big games running. It's possible, perhaps even likely, that the majority of the cheating transfers weren't done through the -fred- account at all, but rather the -russh- one.
These transactions first appeared via brainwashdodo's posts, and brainwashdodo himself disappeared within days, all but without a trace. So what was up with that? The comments in July about doing a personal audit implied a good motive, but the subsequent removal of associated screen grabs and the veiled threat in December -- "Anyway, more cht to hit t fan, will be back tmrw." -- instead lent credence to the blackmail theory, the one since confirmed by a confidential but proven source. It's been alleged to me that brainwashdodo was paid off, for some $80,000, by an important figure long since implicated in the matter. Brainwashdodo has even been reported to have made a second, more recent attempt to obtain additional funds for remaining quiet.
Brainwashdodo's real name has been provided to me, though I'll refrain from publishing it here on the very slim chance (perhaps 1 in 1,000) that the blackmail tale, though reported to me with specific names, was somehow altered along the way. It's not the only such tale to come out of the UB and AP messes, though the others can wait for future telling.
As for brainwashdodo, it's easy enough for a 2+2 owner or moderator to do a quick IP check and verify that the account did indeed post to the forum from somewhere in Costa Rica. This actually wasn't my first guessed location for the account, though I suspected all along the posting was done with less than altruistic motives.
Though the money involved may not seem like much, the brainwashdodo episode deserves a historical footnote. It will likely go down as the first time that a poker forum (2+2) was itself used as a tool of blackmail. Such a revelation should be of interest to 2+2's owners and to interested followers throughout the poker world.
Tuesday, May 11, 2010
Just Conjecturin', Volume 15: The Graycat File
I also reported that while cheating accounts such as the infamous "PotRipper" and "doubledrag" were relatively new, the history of known cheating account "graycat" was much older, being an account controlled primarily by Scott Tom and dating back to the early days of AP itself. The following series of images shows the transfer history for the "graycat" account, presented in reverse chronological order, newest to oldest.
A thoughtful examination of this account shows that the cheating may have been the final stage of a much longer process of losing control. While the large transfers to fellow cheating accounts "payup" on 8/20/07 and "doubledrag" on 9/02/07 are further evidence of the interrelated nature of these accounts, they're far from the only curious transactions. One can presume, that the money transferred in came from some internal AP general-funds account, which makes the many in-transfers noted as "overlay reduction" seem odd: Why would an overlay reduction involve transferring funds from a general account into a private one, even one controlled by a top management player? (Update: one possible explanation has been offered by a blog commenter.)
Also curious is the single transaction marked as an affiliate transfer; it could certainly be a legitimate transaction, but its timing (during the 2007 WSOP) and solo nature could've raised at least a red flag to double-check for any accounting-style inquiries.
In any event, the images speak for themselves:







Tuesday, May 04, 2010
Just Conjecturin', Volume 14: More Snared Images from Absolute
This time we return to two more of the top-level images of cheating accounts, to hammer home the point that there was a coordinated, perhaps even frantic cover-up of the cheating taking place at AP in the days immediately following the PotRipper tourney in September in 2007. Weeks of denials and cover stories followed, until the company finally conceded to the statistical evidence demonstrated in Michael Josem's won-loss charts and acknowledged the affair. But as to responsibility, disinformation has been disseminated for weeks, months, even years. It's high time it stopped.
Presented next is the account overview for "doubledrag", another acknowledged cheating account. Here's the snared image:

(Larger version of image available at http://img220.imageshack.us/img220/764/doubledragacctinfo.jpg)
Included just in that are: Another warning to general customer-service workers to not touch the account on the orders of management; a couple of irate calls from customers about the doubledrag cheating; and the September 17, 2007 closure of the account itself, by "AJ" -- referring to AJ Green, the member of the inner circle who took the hit when the bus of public opinion had to run over somebody. The cover-up, however, clearly extended across top management. The following image shows that when the doubledrag account was shut down, some $34,000 had been pulled back from the account:

(Larger version of image available at http://img443.imageshack.us/img443/8485/doubledragacctbals.jpg)
Remember that the Potripper account was blacklisted at the same time:

(Larger version of image available at http://img80.imageshack.us/img80/3180/scottom6.jpg)
And then there was "graycat" (a reference, I've been told, to Phil Tom's cat). First comes the overview, another one that features AP's own customer-service number in the phone field, along with plenty of other phony information:

(Larger version of image available at http://img443.imageshack.us/img443/9256/graycat1.jpg)
Here's the account balances overview, showing the final adjusted cash after certain adjustments had been made, leaving a nice round $15,000:

(Larger version of image available at http://img153.imageshack.us/img153/3910/graycat3.jpg)
The problem, though, was that graycat was an older and well known account, prompting another probe into the details of graycat's then-recent history. Here's what another glimpse into the graycat transaction file provided:

(Larger version of image available at http://img153.imageshack.us/img153/3910/graycat3.jpg)
There was another blacklisting and forced withdrawal on this account, with the funds moved off into the online wallet service ePassporte, to the account "SPTOM", likely short for Scott Philip Tom, his full name. That withdrawal went through on late 9/16 or early 9/17 (the screens likely track different aspects of the transaction) but was tied to the 9/16 blacklisting. Then, later on 9/17, a second withdrawal or series of withdrawals was denied, per AJ Green's (Allan Grimard's) request.
However, it's a secondary look into the transactions file of graycat that offers a clearer glimpse into that last tangle of transactions:

(Larger version of image available at http://img404.imageshack.us/img404/7961/graycat4.jpg)
The image indicates that a majority ($150,000) of the money that was in the account was moved off the site, with a smaller amount -- a bit over $30,000 -- remaining when the account was blacklisted. Again, published claims that no money left the site are false and are a further indicator of the larger cover-up.
At some point, $15,000 remained in the account, when the earlier screen was snared. It's important to note that as of 9/17, graycat was one of only several accounts under suspicion, and denials were still the order of the day. It would be several more weeks before even the most generalized admissions of insider cheating were acknowledged.
Still, it may have been necessary to keep the graycat account functioning, since it was an important house account at Absolute. Next time out, a historical look at graycat, the little house account that could.
Saturday, May 01, 2010
Just Conjecturin', Volume 13: Absolute and the Snared Screen Names
GRAYCAT
PAYUP
STEAMROLLER
POTRIPPER
XXCASHMONEYXX also known as SUPERCARDM55
DOUBLEDRAG
RONFALDOXXB also known as ROMNALDO
Each of these accounts, per the KGC's report, was directly and inextricably tied to the cheating through analysis of hand histories, including impossible win rates and blatant chip-dumping between the accounts. The problem, though, is that no outsider truly knows how much other cheating might have occurred. The KGC, elsewhere in the same report, admitted that other gaming logs had been intentionally destroyed.
Meanwhile, the vaunted ieSnare software program implemented by ieLogic at UltimateBet as an anti-fraud detection tool had also been in use at Absolute Poker. One aspect of ieSnare's capabilities, as it was represented to me, was shown in the first handful of screen grabs presented two posts back. Another was the program's capability to develop more complex inter-relational matrices between various accounts, and thus fine-tune the connections between these accounts. ieSnare's capabilities were highly touted in a number of industry pieces, and indeed, the software was an effective anti-fraud tool.
As generalized earlier, a snare of the PotRipper cheating account at Absolute was done sometime shortly after it became the focus of attention, and it indeed showed connections to other cheating accounts. However, the list snared as directly associational to PotRipper and the list of cheating accounts published by the KGC differ a bit. Here's what the PotRipper ieSnare seems to have shown:


(Larger versions of images also available at http://img100.imageshack.us/img100/339/potrippersnare1.jpg and http://img98.imageshack.us/img98/3340/potrippersnare2.jpg)
Clearly, those account names present in the PotRipper snare but absent from the KGC list would be the logical targets into any further investigations. (One additional account from the lengthy list below, "baller", shows a high correlation to each of the other known cheating accounts and should also be upgraded for additional scrutiny.)
The PotRipper account, however, had a very brief lifespan as an AP account, as previously shown in that earlier post. Another of the cheating accounts, "doubledrag", was similarly short-lived. By comparison, cheating accounts "graycat" and "steamroller" existed for much longer, and as a result, generated their own longer lists of associated devices and accounts when those screen names were similarly snared.
It's one of those open-ended questions one must ponder when considering candidates for other possible cheating accounts. The farther one chases down a given tree branch, the less likely any single link would be to be involved in the scandal, yet it seems first-level associations with known cheating accounts beg for more detailed investigation. That list is quite extensive, even if most or all of the new screen names presented below may turn out to be uninvolved in the cheating itself.
However, when one combines the direct device-usage correlations between PotRipper, PotChopper, graycat and steamroller against all directly associated accounts, as many as 147 other AP account screen names emerge. Showing complete imagery for all of these snares and screen names would kill this post's readability, but I'll upload the images for public scrutiny as opportunity arises. Here's a sample or two, though, to illustrate the snares' existence:


(Larger version of images also available at http://img594.imageshack.us/img594/4827/graycatassoc1.jpg and http://img594.imageshack.us/img594/8228/steamrollerassoc1.jpg)
While many of these accounts were likely used for testing purposes, or are innocent altogether, it's possible that some among these may have had illicit use in either known or unknown cheating affairs or related chip-dumping, hence their inclusion here. The total list of accounts meriting examination is closer to 150 than 10, including both the screen names already acknowledged by the KGC and a handful of probable duplicates in this list, likely caused by system-data mismatches in processing capitalized and uncapitalized letters. With those duplicates accounted for and that original KGC list added in, it's around 145 or 150 screen names, all told. Readers can sift it if desired.
Again, note that the inclusion of a screen name on this list that follows does not necessarily mean that the account was used for cheating. One such account bearing special mention is the "chairman" entry, which has been alleged to me to be associated with Scott Tom's father, Phil, who has in turn been alleged to be a primary investor at AP's inception. The inclusion of such an account in the ieSnare may have been caused through something as simple as a log-on from a different computer, but the account was snared, nonetheless, in both lower-case and ALL CAPS versions. To repeat, inclusion here does not necessarily equal cheating; inclusion is merely an indicator of an account probably needing another look. Likewise, since two of the accounts acknowledged by the KGC to be involved (SUPERCARDM55 and ROMNALDO) are not on the combined list, the ongoing issue of still other accounts possibly used for chip-dumping remains an open question.
One also has to chuckle at the names made up in imitation of many well-known players or real-life people, including "negreanu", "jen harman", "dave barry", "lou kreiger", "ted forrest", "andy beal", "humberto." and "mikemizrachi". All fakes, to the best of my knowledge; these are not connected to the real players of similar name. Poor Lou, his name wasn't even spelled right, and I checked with him -- he's never played on AP anyway.
Anyway, here's the list:
(KGC entries)
GRAYCAT
PAYUP
STEAMROLLER
POTRIPPER
XXCASHMONEYXX also known as SUPERCARDM55
DOUBLEDRAG
RONFALDOXXB also known as ROMNALDO
Additional ieSnare entries:
PotChopper
sox
chairman
annaash2day
STEAMROLLER (ALL CAPS version)
pmckenna
chickenliver
cashslasher
innocoman4009
fatraiser
billznik
chipripper
philskitten
CHAIRMAN
ANNAASH2DAY
happy chappy
innocoman4025
slapchipstac
chipslammer
baller
leroy
SOX
ramramram
potsmasher
playonap
mikemizrachi
wowowaj
goodfella
busta
drhuynh
biggtime
db9007
doubledrag
p0kerher0
gballerbcp
BALLER
vegasballer1
eddognj
bigwwoorrmm
negreanu
benmag
rivergod
innocoman4003
paraglider
ari179
astro179
kaisersoze
dave barry
guinndexter
kirgo
lister
kyle gass
heinlein
jenharman
a
xxx
lita
its on!!!
up with ap!
apupgpdn
guinn
abdullah
school of glen
gphunter
pfhamilton
ohhh snap!
kill me!
alcoholicaa
bj03
bj010
heduzhavit!
ap fan
room watcher
please sir!
gosh!
omahamaster
zenmaster.
stevesux
diego$5
humberto.
ohhhsnap!
gotmy$20gian
theshadow
APFAN
OHHHSNAP!
THESHADOW
crtchsnfr-->
h20-u-up-2
dave barry^
^%$(&%(*
roomwatcher
dexter.
trnydirector
super grover
come on!!
otchbay
andy beal
lou kreiger
a.e. neuman
nice catch
bountysteve
takeshi.
omahalic
miltonwaddam
poker
what the%&*#
steve...$50?
x
q-bert
ohhhhsnap
diestevedie
let's see
on tilt
oy vay
dubyaisgay
sigh!
no mrniceguy
rainmaker.
imsum1sbich
ivey who?
good grief!
iq at zero
hotty
BIGPIMPIN
ted forrest
apbj01
bigpimpin
blackbetty1
durden1
DONBROAF
jannelle2
goalballer
ramcharger
ballznmouf
onlinefun
innocoman4015
bj014
bcpballer2
brentdotnet
asman
innocoman4001
innocoman4011
panama red
1dollarbill
scheissenein
VEGASBALLER1
GBALLERBCP
chestr0ckwel
Wednesday, April 28, 2010
Just Conjecturin', Volume 12: The Absolute Scandal and the Day Occam Rolled Over in His Grave

(Larger version of image also available at http://img80.imageshack.us/img80/8643/coffbscott01.jpg)
I chuckled when I saw this, for not only did I know what it was, but I doubted that the sources I'd received the data from knew that I'd already seen the same thing, way back when the scandal was breaking. It made the information that I'd received that much more believable -- an unknown seal of authenticity, if you will. Matter of fact, I'd had that different version of the same information in my AP scandal archives ever since: It also appears, in different form, within Marco "CrazyMarco" Johnson's famous spreadsheet of the PotRipper affair.
I've recopied those lines from the original spreadsheet Johnson received into a separate spreadsheet page, which look like this (the extra fields are associated with the chip counts themselves during tourney play, and were "0" for all non-playing observers):

(Larger version of image also available at http://img80.imageshack.us/img80/3558/coffbscottcrazymarco.jpg)
What both images show are the "observer" table log-ins for the famed "PotRipper" cheating tournament, for IP address 200.122.181.104, one of the same IP already tied to Scott Tom through other means. The PotRipper account itself played at Table 13 for almost the entire duration of the tourney history captured in that spreadsheet, and it was the "coffb@msn.com" account, whatever its name was, that by all indications was logged in from the same computer that had access to the "superuser" software. While I would normally redact an address such as that, its involvement in the PotRipper fraud was so seminal that it cannot be omitted from this story.
There were lots of people poring over that spreadsheet back in the last part of October, 2007 -- players, a couple of writers (including me), and other interested observers. It was obvious that the "coffb@msn.com" account was the key, for the bizarre, obviously-cheating play by PotRipper not only began the very hand after "coffb@msn.com" began to monitor the action, but this observing account never left Table 13 after that point. That in itself was highly unusual behavior, because the spreadsheet captured well over an hour of the entire tournament play, and nowhere else, to my recollection, did an observing account sweat any other table in this manner. It stood out in a big way.
Other investigators were looking into some of the other players, as was I, and I got the idea to search on that IP address: 200.122.181.104. That's when the single check-in/check-out of the same IP address popped up, but with a different e-mail address (scott@rivieraltd.com) and at a different table (Table 9). I was in chat that evening with other people searching into various things, and I typed something like "Hey, check out that scott@rivieraltd.com address and domain. It might lead to something."
It was my one small contribution to that investigation back then, though others did far more, and for all I know, someone else also might have been searching on that domain already. Still, if not for that brief, one-second click-in to check something at another table, perhaps even done by mistake when some tables were broken down into others, the scott@rivieraltd.com connection to all of this might never have emerged. At least that's how I remember it.
The chat came back to me all excited, and again, this is a re-creation based on my memory, as I'm not even sure which chat system we were using though I think it was MSN Messenger back then. It went something like, "That's it! That domain points to another company with Absolute Poker! How did you know?"
And I responded that I didn't know, it was just that the domain part seemed odd to me. It smelled bad, seeming to be out of place in an exceptionally corporate way in a sea of so many yahoo.com and msn.com and similar log-ons as used by most Internet players. I'd had experience with holding companies, and this address just seemed wrong. I'd scratched at that itch.
Within minutes the information had found its way into the investigatory threads then going on at 2+2 and PocketFives, but it was only a short time later -- perhaps an hour -- that I received another chat. It went something like, "They've just changed the domain info! They're covering it up!"
And indeed, to this day I believe that's what happened; the cheater(s) was or were in panic mode and when they saw the "rivieraltd.com" name mentioned on the forums, they immediately went into their domain registration access and changed the entry. It was either that, or they had changed it hours or days before and it had not just propagated yet, which would have made our find extremely timely and lucky. A simple search on that domain info today provides nothing of value; one would have to purchase the historical domain records to access the changes that have occurred, though that's hardly a prohibitive expense.
In any event, it was still just a bit later that very same evening that I received yet another chat message, which was something like: "We had a way to check that IP address, and it goes right to Scott Tom's house!"
What??? Well.
To say I was flabbergasted at that news was an understatement. I fully expected at that point that the domain would trace to Canada or Costa Rica, perhaps even to a corporate block of addresses connected to AP, but to have it be reported back to me as a Costa Rican residential IP just floored me. It made no sense. If someone was doing it to set up another person -- in other words, to frame Scott Tom -- then they had to be both brilliant enough to plant some random phone-company or ISP dude to tell us the IP address traced to Scott Tom's house, while at the same time being stupid enough to cheat in the ridiculous manner demonstrated in the PotRipper tourney.
Occam, as you surely know, refers to Occam's Razor, that idiom that states that the simplest explanation for a series of events is also the most likely. The contrapositive to the idiom (the other true statement that can be derived, if one believes ol' Occam) is that as an explanation becomes exceedingly complex, it also becomes exceedingly unlikely. Expecting someone to have framed Scott Tom in the way the evidence rolled out would have required planting evidence in a whole bunch of different files, including this specific one-second click-in on a different table during this table, somehow setting up some faked home-ISP stuff in advance, being powerful enough to be able to change domain registrations on the fly, yet being so lacking in oversight as to think that calling an all-in bluff with 10-high for several tens of thousands of dollars of real prize money wouldn't arouse suspicion. And mind that this wasn't the only episode of cheating going on; it happened to be the one that drew the most attention, and even this one was denied by AP for weeks afterword.
The greater question was, if Scott Tom somehow were being framed, how could someone set up such a ridiculously perfect frame and still have no knowledge of how the core game -- poker, and how it is played... or badly cheated -- would be an impetus for others to search for the cheaters?
The overall mix clearly violated Occam's Razor. The far simpler explanation was that the cheating was done with arrogance and impunity by a person or several people with enough internal power to strangle any inquiries, should they arise. The problem with that attitude has to do with human nature; when people get screwed, they have this curious tendency to fight back. It instead likely meant that it wasn't a frame, and that people were getting fed up with whatever brazen shenanigans were going on.
As for those addresses, and related matters....
The "coffb@msn.com" address, to the best of my knowledge, has never been publicly released, though it is of course vital, given the later cover-up by AP, Blast-Off (Tokwiro) and quite probably the KGC.
Note that the "scott@rivieraltd.com" address is not the same address that adorned the PotRipper account when the screen grab that I published (previous post) was obtained. This would not be absolving or incriminating on its own in either event. Not only was an active coverup in progress in the days immediately following the PotRipper affair, meaning account information could have been changed, there's also no reason to assume that Scott Tom and/or cohorts used only two computers. There always had to be at least two -- one for playing and one for observing -- but the fact that there was excessive chip-dumping between cheating accounts during other episodes suggests that three or more could have been in play, at least two of which would have been active at the same table.
In addition, Scott Tom had access to many dozens of accounts that were created, all of which were shown be associated through the company's own internal ieSnare traces. Each of those would have had a separate e-mail address, so there had to have been lots and lots of extra e-mail addresses being used in connection with these accounts. I have info regarding some of those accounts, and will share that the next time out.
Saturday, April 24, 2010
Just Conjecturin', Volume 11: Meanwhile, Over at Absolute Poker, It Seems Scott Tom Really Did It
In any event, in trying to remain professional, I temporarily shelved the scandal involving my personal animosity in order to focus on the one that in solving would greater benefit the public good. While Scott Tom ran around threatening his silly libel suits against anyone that dared mention his name, trying to bully his way back into a position of industry responsibility, I let it be, even though I knew it was his name and e-mail account that was tied to the "observer" account monitoring the action in that infamous "Potripper" tournament cheating episode. Even though the IP address linked to that observing account was in turn traced to Scott Tom's house, it was hearsay evidence that wouldn't hold up in court on its own (like there was a court waiting to investigate this stuff, har-de-har), despite it being specific enough that falsification was unlikely.
Also, the preposterous stories that (a) it was A.J. Green (real name Allan Grimard) using Scott's house while Scotty was away on extended vacation, or (b) Scott's computers had been hacked into by another unknown villain, were just barely plausible enough in the absence of more evidence that they had to be let slide in major news outlets. Even if the ridiculous excuses were true, Scott Tom would still have been guilty of something best described as criminal negligence, for allowing his personal resources, as CEO or whatever of Absolute at the time, to be used in the theft of millions from Absolute Poker customers. It was almost as preposterous as the "low-level employee trying to prove a point" BS that Scott tried to peddle when the AP scandal first broke.
Yes, there were supposedly screen grabs showing some of the stuff, but they were quashed, too. Until today, that is. It's taken more than two years for me to obtain these, but I've managed to do so. With a little bit more of the background to follow, let's move on with this.
When the KGC handed down its punishments in the Absolute matter, they identified one person as receiving a lifetime ban from online gaming as regulated by the KGC, while a second person got the boot for a one-year period. Neither person was named, to the KGC's lasting shame. It was always presumed by observers that Green/Grimard got the lifetime ban, while Scott Tom received the shorter penalty, which he then subsequently was able to argue the remainder of away before the year was fully served by continuing to press his mostly spurious case... and perhaps apply other financial pressures.
The greater truth? Grimard and others may or may not have been heavily involved in the cheating, but Scott Tom was the real force behind the ongoing scandal at AP. While there is a miniscule chance that the evidence was somehow doctored itself before it reached me, its content correlates so well with what I'd already learned elsewhere that I believe it to be genuine. In full and honest faith, I believe the images you'll see to undoctored, and that Scott Tom himself was the primary Absolute Poker cheater.
One of the things that happened after AP bought UB was that UB's "ieSnare" anti-fraud tool was enhanced, to be able to look at the AP customer base as well. The snares were done by screen name, not player ID #, and could be directed to look at games running on either UB or AP, or both.
Scott Tom created a UB account, "PotChopper", in June of 2005, about the time UB and AP began to get buddy-buddy. The basis of that growing closeness was a budding friendship between Tom and UB boss Greg Pierson, though for the moment that digresses from this storyline. I normally would black out certain items of personal info but it hardly seems necessary here, since:
a) The given street address is an SBO box;
b) the home phone number given was actually that of AP's customer-service switchboard at the time;
c) Scott's "stom@fiducix.com" e-mail address is already all over the web anyway in connection to the scandal.
Yeah, go ahead and chuckle at the "PotChopper" bit. Here's that screen grab:

Clicking on the image should open a larger version of the above, and it's also stored independently online at: http://img18.imageshack.us/img18/6416/scotttom1.jpg
Now, part of the ieSnare's capabilities was, that as it built its relational database, it assigned a sequential device number to all new computers ("devices") that logged in. I believe this was derived from each computer's physical MAC address, one of the unique identifiers that a modern computer carries. In any event, Scott Tom's primary computer was assigned an ieSnare ID of "11451887" as it related to his account at UltimateBet. Here's visual evidence showing his log-ons at UB via his "potchopper" account:

(Larger version at http://img88.imageshack.us/img88/3750/scotttom2.jpg)
The snare also grabbed the originating IP address for each log-in and assigned an "NUID", an internal identifier, based on the computer's physical ID. The exact nature of the "NUID" field has not been explained to me, but it may include a modifier based on the type of hook-up itself (i.e.: being hard-wired in versus using a wireless modem, or something similar). In any event, no matter where in the Caribbean Scott Tom logged in from, he was assigned either "24877017" or "24902502" when doing so as PotChopper. I suspect that "24877017" indicated his laptop in wireless mode, given Tom's island-hopping nature.
Now, when the ieSnare query was extended down the AP side of operations, based on Scott Tom's user ID of "11451887", it showed a direct link to several of the major cheating accounts. When run against that AP side, that same ieSnare produced the following for the account "PotRipper", that infamous account used in the cheated tournament that polarized the whole investigation. Here's the screen grab of that snare:

(Larger version at http://img219.imageshack.us/img219/2089/scotttom3.jpg)
It's the same device number, and in four of the five cases, the same NUID Set # as well. The fifth was generated at almost the same time as the one immediately below it in the list, suggesting that the two log-ins were related in another way. The top line in the screen grab, for September 13th, 2007, is for the span of time covering the $1,000-buyin Sunday tourney that PotRipper won through blatant cheating, meaning this is indeed a snare of the computer physically used to do that cheating.
But wait, there's more, much much more, though I'm only publishing a small percentage of it today. Device "11451887" (a/k/a Scott Tom) was tied to more than just the PotRipper account; it enjoyed a lengthy relationship over long stretches of time with several of the major cheating accounts. Here's how the "11451887" snare connected to cheating account "Graycat":

(Larger version at http://img219.imageshack.us/img219/2046/scotttom4.jpg)
Same user IDs, same NUID assignments, same originating IP addresses, etc., and this screen grab just shows the final two weeks of what was a much longer history for the account. As you'll see in a bit, the "hacking" story doesn't wash, not that it ever did.
Here's the same thing for cheating account "Doubledrag":

(Larger version at http://img219.imageshack.us/img219/5341/scotttom5.jpg)
The question that the doubter should be asking is, "Okay, maybe we have reason to place Scott Tom at the computer, but can we really say he was in control of all these cheating accounts?" Yes, yes we can. While he likely held significant help from one or more other high-level cheaters at AP, Scott Tom was pulling the strings directly regarding several of these cheating accounts.
Here's a screen grab showing the entire financial transaction history for the infamous "PotRipper" account. It had a notably brief life span, for obvious reasons:

(Larger version at http://img80.imageshack.us/img80/3180/scottom6.jpg)
Note that the above is a financial-transactions history of the PotRipper account, not a recording of what happened at the tables. Here, $70,000 was transferred in from another cheating account, which seemingly immediately triggered an automatic black-list in the system, based on the transaction's size. That was immediately overridden by an operations supervisor based on directives from upper management (Scott Tom and others) for this and for all of the cheating accounts.
I'll get to these directives in a moment, but let's first examine the PotRipper account history. The account was first used on September 11th, 2007, had a large sum dumped into it from another cheating account, and two days later, was used to take down a large tournament score. That win on September 13th would have swelled the account balance to something like $150,000, barring other activity, so what must have happened between September 13th and 16th is that money was chip-dumped to other accounts during live play at the tables. Many of these affiliated accounts -- "ROMNALDO" is one of these, just off the top of my head -- were used in this manner, and chip dumping at the tables would not be captured by the transactions inquiry shown here.
In any event, there must have been plenty of internal heat at AP in the days immediately following the PotRipper escapade, because on September 16th, Scott Tom cashed out most of the remaining money in the PotRipper account, leaving enough behind and then re-blacklisting it, so it appeared there was still active play should anyone investigate at a later date. (He did the same thing with other accounts as well.) By then, of course, the vast majority of cheated monies had been siphoned off the site.
I mentioned those internal high-level directives to handle these cheating accounts with kid gloves. Several such accounts carried special notations like PotRipper's: "Please do not close this account for any reason. Issues please consult with Brent, Adrian or Nolan." So the customer-level support staff was being warned to leave these accounts alone, and this Brent is believed to be Brent Beckley, Scott Tom's step-brother, also involved with AP from its inception.
Here's the account overview for "PotRipper", the famed cheating account. I've gone ahead and redacted most of the name and street address, though I believe this to be one of Scott Tom's college buddies being used for money-laundering purposes. That said, a lot of the information here was still faked, from the mismatch between state and zip code to the use -- again -- of AP's own customer-service number in the phone field.

(Larger version at http://img90.imageshack.us/img90/6580/scotttompotripperacctin.jpg)
Okay, that's enough of a "Ka-Boom!" for today. There will be plenty more in future posts, on both AP and UB. I've always believed that the truth in these matters would come out, and here's one piece of it, right here.
* Not its name at that point in time, but I can't help but create some artificial link candy.
Just Conjecturin', Volume 10: Defaults and Dividends, Chorus #2
Document 1:
XMT Liquidations Inc.
1155, boul René-Lévesque ouest, bureau 2010
Montréal, Québec H3B 2J8
To: Shareholders of 6356095 Canada Inc. (formerly Excapsa Software Inc.)
From: XMT Liquidations, Inc. (its Court-appointed liquidator)
As you know, Blast Off Limited ("Blast Off") is indebted to 6356095 Canada Inc. (formerly known as Excapsa Software Inc.) in virtue of two Promissory Notes, each dated June 30th, 2009, in the respective amounts of US$41,900,000.00 and US$64,469,257.00.
On November 30th, 2009, Blast Off failed to make an instalment [sic] payment of US$500,000.00. In virtue of such default, the Liquidator, after consultation with the inspectors, and through its attorneys, sent a formal demand letter:
1) claiming payment of the sum of US$500,000.00;
2) advising Blast off that unlesss [sic] said default and all and any subsequent defaults were cured with the ninety (90) day-period allowed under the Promissory Notes, the entire amount of both Promissory Notes would become due and payable, and;
3) further advising Blast Off that the Liquidator intended to exercise all of its recourses to recover the sume due under the Promissory Notes, including the Liquidator's rights under the Malta Pledge, the CL Escrow Agreement and the DN Security Agreement.
Under the Malta Pledge, the shares in Blast Off are pledged as security for the Notes. Such shares are issued by Blast Off under the laws of Malta. Accordingly, the Liquidator has engaged legal counsel in Malta with a view, if necessary, to eventually exercising the security held over the Blast Off shares.
The Liquidator is also considering exercising its rights and remedies under the CL Escrow Agreement (in virtue of which the non-US customer base was placed in escrow as collateral security for the Notes) and the DN Security Agreement (in virtue of which certain domain names were given as collateral security).
The Liquidator will continue to update shareholders as developments occur.
The 90-day cure period expires on March 11, 2010. Prior to such time, shareholders are requested to keep the contents hereof confidential and not to disclose Blast Off's default or discuss same with anybody but another shareholder, or the Liquidator.
Dated this 26th day of January, 2010,
XMT Liquidations, Inc.
Per: (signed)
Sheldon W. Krakower, C.A.
So much for the initial notice. That was sent out to shareholders and negotiations with Blast Off commenced, with the following update (Document 2) coming just a few days back:
XMT Liquidations Inc.
1155, boul René-Lévesque ouest, bureau 2010
Montréal, Québec H3B 2J8
To: Shareholders of 6356095 Canada Inc. (formerly Excapsa Software Inc.)
From: XMT Liquidations, Inc. (its Court-appointed liquidator)
In our last communication dated January 26, 2010 (copy attached), we advised you of the suspension of payments by Blast Off Limited ("Blast Off") under the first Promissory Note and the onset of a 90-day cure expiring on March 11, 2010. Negotiations followed and culminated in an arrangement whereby Blast Off will pay US$1,150,000.00 to the Liquidator by monthly installments ending on May 31, 2010, of which U$450,000.00 has been received, plus an additional US$100,000.00 for costs due on June 15, 2010. The Liquidator has informed Blast Off that acceptance of any payments is not to be taken as a tacit forbearance, nor an acceptance, renunciation or waiver of any conditions, rights or obligations. Assuming that these payments are made on time and no other defaults occur under the Promissory Notes, the Liquidator does not intend to pursue any of its rights and remedies prior to June 1, 2010.
The US$1,150,000.00, together with the US$250,000.00 paid by Blast Off earlier this year, will cover the November and December 2009 monthly installments plus $400,000.00 on account of the January 2010 installment. This will leave arrears of $2,100,000.00 owing as of May 31, 2010 (i.e. $100,000.00 for January 2010 and $2,000,000.00 for February through May 2010). There is no agreement in place with Blast Off relating to payment of this sum and, failing an agreement, the Luquidator shall be entitled to exercise its rights and remedies under the Porimissory Notes and related security. The Liquidator anticipates further discussions with Blast Off and will continue to update shareholders as matters progress.
The Liquidator recently received a clearance certificate from Canada Revenue Agency authorizing a further distribution of up to $US10,000,000.00 to shareholders. The Liquidator hopes to make a distribution within the next 90 days, but will make this decision based upon the level of payments received and committed from Blast Off up to and following May 31, 2010.
Dates this 12th day of April, 2010,
XMT Liquidations, Inc.
Per: (signed)
Sheldon W. Krakower, C.A.