From Alias to Identity: Following the Digital Footprints Behind a Telegram Drug Seller
Telegram has become an increasingly convenient marketplace for illicit drug sellers. The same features that make the platform useful for ordinary communication, including public channels, direct messaging and easy-to-create accounts, also allow dealers to advertise products, reach potential buyers and operate behind usernames that reveal very little about who is actually running them. Cannabis sellers are particularly easy to come across, with accounts openly posting photographs of marijuana, prices and contact details while maintaining little obvious connection to a real-world identity.
But an alias is only as anonymous as the digital history behind it.
This investigation began with one such Telegram-based drug seller. At first glance, there was little to distinguish the account from countless others advertising cannabis through the platform. Rather than treating the visible Telegram profile as the end of the trail, the investigation used StealthMole to look beyond what was currently available and examine the historical traces surrounding the account.
This report follows that investigation from its starting point, showing how a trail scattered across Telegram history, leaked data and other online records was pieced together one artifact at a time.
The Account That Started It All
The investigation began with a deliberately broad search. Using StealthMole’s Telegram Tracker, we searched for “weed dealer” to see whether an openly advertised drug-selling account could be taken beyond what was immediately visible on Telegram. The query returned 14 user records and approximately 80 messages, providing several possible starting points.
One account stood out almost immediately. It appeared in the results under the name “Weed Dealer | UG 🆓 🌱SEED 🐦 🍅 🐾/WAVE 🌊”, with the Telegram username @tieuho****0. Unlike accounts that merely mentioned cannabis or appeared in conversations about drugs, this profile was notable because it presented itself directly as a weed dealer. That made it a more relevant target for examining whether an apparently pseudonymous Telegram seller could be followed through StealthMole’s historical data.
Looking at the account as it exists more recently, however, revealed surprisingly little. The profile displayed the name “Tiêu Hồ”, carried no profile photograph, and offered few obvious clues about the person behind it. Searching the account itself in Telegram Tracker changed that picture.
StealthMole associated the account with the persistent Telegram ID 1068143976 and preserved 25 historical name records, showing that its visible identity had changed repeatedly over the years. The historical snapshots were considerably more revealing than the current profile. Earlier versions contained multiple photographs of what appeared to be the same individual, while other snapshots shifted toward cannabis-related imagery and drug-oriented profile names.
Some of those historical photographs also exposed details that would no longer be apparent from viewing the account today. In a snapshot dated 22 December 2022, the individual was photographed standing in front of a dark vehicle with the registration plate 79A-2******8 clearly visible. Another snapshot, dated 28 February 2023, showed him alongside a white Mercedes-Benz displaying a second plate, 79A-3*****7.
The first plate offered an immediate external point of comparison. A search for 79A-2******8 produced an exact match on PlatesMania, where an independently photographed dark Lamborghini Urus, first generation (2018–2022) carried the same registration. The listing identified the plate as Vietnamese, registered in Khánh Hòa Province, and placed the photographed vehicle in Phước Long, Nha Trang. The image had been posted by a contributor using the name Bún bò on 17 January 2025 at 1:08:27 PM.
A Wallet That Wasn’t a Wallet
With the profile history offering several clues but no clear identity, the investigation moved to another artifact associated with tieuho****0: an Ethereum address.
- 0x09c*****************************638
At first, the address looked like a promising cryptocurrency lead. If it belonged to the seller, its transaction history could potentially reveal another part of the account’s digital footprint. Consequently, the address was searched further in StealthMole’s Telegram Tracker.
The search returned several user records and messages mentioning the address. Among them was one result that could be tied directly back to the account being investigated. On 13 May 2023, Telegram ID 1068143976, appearing at the time as Seller | UG//@tieuho****0, had posted the address in a channel. The message read “Happy mother's day”, followed by the Ethereum address and an attached photograph.
The direct match confirmed that the address had indeed been shared by tieuho****0, but a closer examination changed what the artifact meant. Etherscan identified it not as a personal Ethereum wallet, but as a smart contract associated with the ERC-20 token mother (MOTHER). At the time of examination, the contract showed 1,436 transactions. Other Telegram results provided further context, including a message from the 0xGemi channel that referred to the same address as “Mother Contact” while discussing the token.
A search through StealthMole’s Dark Web Tracker produced another apparent lead. The contract address appeared within an indexed onion page containing Polygon ERC-1155/NFT transaction data. The record included Polygon transaction:
- 0x09************************************************3a43
and was indexed from:
- 3xplor3****************************************xyd.onion
One Alias, More Than One Footprint
After investigating the cryptocurrency, the investigation returned to the simplest artifact available: tieuho****0. This time, instead of looking at Telegram, the username was searched through StealthMole’s Dark Web Tracker to determine whether it had surfaced in previously leaked or indexed data.
One leaked document contained a record for tieuho****0 that matched the same Telegram ID 1068143976 already established through Telegram Tracker. That match was important because it provided continuity between the Telegram profile and the newly discovered record. More importantly, the entry contained several fields that had never been visible from the Telegram account itself:
- Telegram Username: tieuho****0
- Telegram ID: 1068143976
- Referrer Username: thuytienbtc
- Referrer ID: 5071132186
- Invited: 0
- Tokens: 2000
- Email: tieuho****0@gmail.com
- Wallet: 0xdFc**********************************695
- Twitter: https://mobile.twitter.com/tieuho****0
- Review: https://twitter.com/AirdropDet/status/1509606654905421833
The wallet field was more immediately actionable. Unlike the MOTHER contract encountered earlier, the record explicitly labelled the new ETH wallet as associated with the tieuho****0 entry. The combination of the exact username and Telegram ID made this a substantially stronger lead, although the leaked dataset alone could not establish that the person controlling the Telegram account also controlled the address.
- 0xdFc******************************695
The wallet was therefore checked independently. Etherscan showed an address with 165 transactions, rather than another token contract. It held no ETH at the time of examination and approximately $0.07 across 18 token holdings, while its historical activity showed both incoming and outgoing transactions. Etherscan also indicated that the address had originally been funded by Binance 17.
StealthMole’s Wallet Risk Check provided a different view of the same activity. The address was flagged as Medium Risk. Of the 147 transactions analyzed by the platform, 22 were flagged as suspicious, representing 15% of the analyzed transactions and approximately 6.7% of the analyzed ETH volume. No blacklisted contacts were identified.
The behavioral indicators were more notable. StealthMole flagged Abnormal Relaying, Abnormal Mixing, and Relaying and Mixing, alongside a dormant transaction status. The last transaction recorded by the platform was dated 18 April 2025.
The transaction graph also showed how widely the address had interacted across the cryptocurrency ecosystem. Labeled nodes included Binance Exchange, Bitget Exchange, Bybit Exchange, MEXC Global Exchange, OKEx Exchange, Uniswap, Orbiter Finance Bridge, MetaMask-related contracts and routers, and a Binance User Wallet.
None of those labels, or the Medium Risk score itself, demonstrated that the wallet had been used to receive proceeds from drug sales. Likewise, StealthMole's detection of mixing and relaying patterns should not be treated as proof of money laundering. What the analysis established was narrower but still valuable: a wallet explicitly attributed to tieuho****0 by a leaked record had an extensive transaction history and displayed several behaviors that StealthMole considered worthy of additional scrutiny.
The leaked record had also introduced something the blockchain could not answer: an email address. That provided the investigation with a completely different route away from cryptocurrency and toward the identity behind the account.
The Password That Connected Two Identities
The email tieuho****0@gmail.com found in the leaked record opened a different line of investigation. Instead of looking for more blockchain activity, the next step was to determine whether tieuho****0 had appeared in credential data indexed by StealthMole.
A search in Combo Binder returned 63 results. tieuho****0@gmail.com appeared with several variations of the same password, built around Ban*****5, including versions with different capitalization and special characters.
Rather than treating the credential itself as the finding, the password became another search term. Searching the exact leaked password in Combo Binder produced a second email address:
- ban*******5@gmail.com
This was more interesting than a simple similarity between usernames. Both tieuho****0@gmail.com and ban*******5@gmail.com appeared in compromised credential data with the same exact password. The ban******5 identifier was also embedded directly in the password family repeatedly associated with the first email address.
With ban*******5@gmail.com now providing a second account to examine, the investigation moved beyond leaked credentials to see what was publicly associated with the two email addresses. Checking the addresses through Google produced profile photographs for both accounts. The profile associated with tieuho****0@gmail.com displayed a photograph of a man, while ban*******5@gmail.com displayed a photograph of a woman.
The second image was particularly important because it introduced uncertainty rather than resolving it. Although ban*******5@gmail.com shared the exact leaked password associated with tieuho****0@gmail.com, its Google profile did not provide additional evidence that the address was controlled by the same individual. Instead, it reinforced the need to treat the email as a connected account or investigative lead rather than automatically assigning ownership to the person behind tieuho****0.
When the Alias Finally Had a Name
The search for tieuho****0@gmail.com in Dark Web Tracker produced another leaked CSV record. Unlike the earlier dataset, which had mainly exposed online identifiers, this entry contained information that appeared to move the investigation much closer to a real-world identity.
The matching record contained:
- Location: Khánh Hòa
- Name: Hồ Quốc Thanh
- Email: tieuho****0@gmail.com
- Phone: +84*********39
- User/Record ID: 60e****************48
- Code: qeabag8
- Related ID: 60e06f9e9c9bb00d4bbc9ae2
- Related Name: Lê Xuân Ngọc
- Related Number: 382966254
- Related Code: ykbpyy6
- Status: NO
For the first time, Hồ Quốc Thanh appeared directly alongside the email address that had already been connected to tieuho****0 through the previous searches. The record also introduced a Vietnamese phone number and listed Khánh Hòa as the location.
The location was particularly notable in light of an earlier, completely different part of the investigation. The two vehicle plates visible in the historical Telegram photographs carried the 79 Khánh Hòa registration code, and the independent PlatesMania sighting of 79A-2******8 had placed that Lamborghini Urus in Phước Long, Nha Trang. Now, a leaked record connected to the account's email independently pointed to Khánh Hòa as well. Neither finding proved where the individual lived, but the same region emerging through unrelated artifacts made the geographic connection harder to dismiss as incidental.
The more immediate question was whether Hồ Quốc Thanh existed elsewhere in StealthMole's indexed data.
Searching the name in Dark Web Tracker produced a social-media record for the Twitter account:
- https://twitter.com/ban*****5
The account was indexed under the name Hồ Quốc Thanh, with the Twitter ID ban****5 and email address:
- ban*******5@gmail.com
That result brought the investigation back to an identifier discovered through an entirely different route. ban*******5@gmail.com was the same second email uncovered when the leaked credential associated with tieuho****0@gmail.com was pivoted through Combo Binder.
The connection had therefore come together from two directions. Credential data had linked tieuho****0@gmail.com and ban*******5@gmail.com through exact password reuse. Separately, Dark Web Tracker associated tieuho****0@gmail.com with the name Hồ Quốc Thanh, while another indexed record associated ban*******5@gmail.com and Twitter ID ban******5 with that same name.
Conclusion
What began as a broad search for a weed dealer on Telegram eventually moved far beyond the profile that first appeared in the results. Historical Telegram data exposed earlier photographs and vehicle registrations, cryptocurrency artifacts opened additional investigative paths, and leaked records introduced identifiers that were no longer visible from the account itself. Some of those leads went nowhere, while others became more meaningful only when they appeared again through a completely different source.
The strongest point of convergence was Hồ Quốc Thanh. The name appeared in a leaked record alongside tieuho****0@gmail.com, while the same email had already emerged through the investigation of the Telegram account and compromised credential data. A separate record then associated the same name with the ban******5 Twitter identity and ban*******5@gmail.com, an address independently connected to tieuho****0@gmail.com through exact password reuse. The geographic evidence added another layer: the leaked record placed Hồ Quốc Thanh in Khánh Hòa, the same province indicated by both vehicle registrations recovered from historical Telegram photographs.
Together, these findings provide a credible basis for assessing Hồ Quốc Thanh as a likely real-world identity associated with tieuho****0, but they stop short of definitive attribution. The investigation does not establish ownership of the photographed vehicles, prove that the attributed cryptocurrency wallet received proceeds from drug sales, or demonstrate that every connected email and social-media account was controlled by the same individual.
That distinction matters. The value of this investigation was not simply finding a name at the end of a search. It was seeing how an account that currently reveals very little had accumulated enough fragments across Telegram history, leaked databases, credentials, cryptocurrency records and other online sources for an alias to gradually become much less anonymous.
Editorial Note
Attribution in underground ecosystems is rarely absolute. Usernames change, infrastructure is shared, and associations do not always imply common ownership. This investigation shows how StealthMole's historical records and cross-source pivots can help navigate that uncertainty, connecting activity across changing identities while keeping the line between what the evidence establishes and what remains unknown.
To access the unmasked report or full details, please reach out to us separately.
Contact us: support@stealthmole.com
Labels: Drug Seller, Featured