On July 20, 2017, Europol and the FBI announced the simultaneous takedown of AlphaBay and Hansa Market - the two largest dark web drug markets in the world. The announcement was carefully choreographed: AlphaBay had actually been seized three weeks earlier, and Hansa had been secretly operated by Dutch police for an entire month before being taken down. The operation, named Bayonet, was the most sophisticated law enforcement operation against dark web markets to date, and its strategy of using one seized marketplace to surveil users fleeing to another was a first for the industry.

AlphaBay had risen to fill the void left by the FBI's 2013 Silk Road takedown. At its peak it had over 200,000 users, 40,000 vendor accounts, and was processing over $600,000 in daily transactions across drugs, stolen data, counterfeit goods, and malware. Hansa was smaller but well-regarded for security. Together they represented the largest concentration of dark web marketplace activity in the world. Their simultaneous loss removed approximately 80% of the operating dark web market capacity in a single week.

AlphaBay: The Arrest of Alexandre Cazes

AlphaBay's founder and operator was Alexandre Cazes, a 25-year-old Canadian living in Bangkok, Thailand under the alias "Alpha02." Despite operating the largest dark web market in history, Cazes made a fundamental opsec error that law enforcement exploited to identify him: he had registered AlphaBay's original servers in 2014 using the email address "[email protected]" for a new member welcome message. That email address was linked to his real identity through online research - it appeared in older public posts under his real name.

The FBI and Thai authorities surveilled Cazes in Bangkok, identified his residence, and arrested him on July 5, 2017. The timing of the arrest was critical: Thai police entered his home while his laptop was open and unlocked, connected to the AlphaBay administrator interface. This allowed law enforcement to seize the private keys, database access, and backend infrastructure while it was live - rather than having to crack encrypted devices after the fact.

Cazes was found dead in a Thai jail cell on July 12, 2017, a week after his arrest. Authorities ruled the death a suicide. He had been awaiting extradition to the United States. His wife, Sunita Hazine-Cazes, was also arrested; she had been the nominal owner of much of the couple's property purchased with AlphaBay proceeds.

[IOC]
Alexandre Cazes (Alpha02) opsec failures: (1) Used real-name-linked email [email protected] in AlphaBay's automated new member welcome emails - a 2014 registration error that persisted as evidence. (2) Purchased luxury property in Thailand and Canada under his wife's name using clearly laundered proceeds, creating a financial paper trail. (3) Operated from Thailand in proximity to his real identity while making no significant effort to obscure his location beyond the Tor administration interface. (4) Did not separate his dark web operator identity from his real-world financial footprint. The pattern matches nearly every successful dark web operator identification: a single early opsec failure that persists as an identifier, combined with proceeds that eventually enter the traceable financial system.

Hansa: The Honeypot Operation

The more operationally sophisticated element of Operation Bayonet was what Dutch police did with Hansa Market. Dutch law enforcement had identified Hansa's servers in the Netherlands in June 2017 and had the ability to seize them. Instead of doing so immediately, they kept the seizure secret, planted undercover operators, and ran the market themselves for 27 days while gathering intelligence on vendors and buyers.

This timing was deliberate. Dutch police knew from intelligence sharing with US counterparts that AlphaBay was about to be seized. When AlphaBay went dark on July 5, 2017, its 200,000 users immediately began migrating to Hansa and other platforms. Hansa's traffic increased eightfold in the days following AlphaBay's seizure. Dutch police used this migration period to collect the data they needed: vendor addresses, cryptocurrency wallets, buyer shipping addresses, and identifying information provided to the market.

During the 27 days of covert operation, Dutch police made several modifications to Hansa's code. They disabled PGP encryption of vendor messages on certain internal communications, allowing them to read messages they would otherwise have been unable to decrypt. They captured vendor PGP public keys. They logged login timestamps and session data that could correlate with IP addresses despite Tor. They downloaded copies of all vendor and buyer account data.

[WARNING]
The Hansa honeypot operation established a new law enforcement doctrine: seized market infrastructure can be used as a trap rather than simply taken offline. This has significant implications for dark web market users. When a market goes offline unexpectedly, migrating to the next platform immediately increases rather than decreases risk if law enforcement is already operating that platform. The doctrine was later applied in other operations - including elements of Operation Disruptor (2020, 179 arrests across 6 countries) and Operation SpecTor (2023, 288 arrests). The counterintelligence implication: a dark web market that is suspiciously well-run and does not exit-scam may be law enforcement-operated. There is no reliable way to distinguish.

Arrests and Aftermath

When Hansa was publicly taken down on July 20, Dutch police announced they had obtained the real names and addresses of thousands of vendors who had registered on the platform - through a combination of the data collected during the honeypot period and active investigation of leads. They also had buyer shipping addresses for orders placed during the 27-day operation.

Hansa's German operators, Thomas and Bjorn - whose surnames were not publicly disclosed - were arrested in Germany before the public announcement. They had operated Hansa since 2015.

The aftermath of Operation Bayonet was the largest dark web drug arrest wave since the original Silk Road takedown. Europol's Operation Disruptor in 2020 directly credited data from Operation Bayonet for hundreds of its arrests - evidence obtained from the Hansa honeypot had a multi-year investigative tail.

The Market Cycle Continues

The market vacuum left by AlphaBay and Hansa was filled within months. Dream Market had been operating quietly and became the dominant platform. Wall Street Market rose and then exit-scammed in 2019. Empire Market rose and then exit-scammed in 2020. Hydra, operating primarily in Russian-speaking markets, became the largest dark web market by revenue before being seized by German and US authorities in April 2022.

AlphaBay itself eventually relaunched. DeSnake, who had been AlphaBay's other administrator and had evaded arrest in 2017, brought the market back online in August 2021. The relaunched AlphaBay took precautions the original had not: DeSnake used the Monero cryptocurrency exclusively rather than Bitcoin, moved servers to more privacy-protective jurisdictions, and implemented stronger operational security practices. As of 2023, it remained operational.

The broader pattern - market seizure, user migration to alternatives, new markets rising - has repeated every major law enforcement operation since 2013. Studies of cryptocurrency flows consistently show that dark web market activity returns to pre-seizure levels within months of any takedown. The demand for the markets' services does not go away; the supply adapts.

[TECHNICAL NOTE]
Monero versus Bitcoin in dark web markets: AlphaBay originally used Bitcoin, as did Silk Road. Bitcoin's transparent blockchain allows chain analysis firms to trace transactions across the entire ledger - firms like Chainalysis and Elliptic have provided analysis that has been used in numerous prosecutions. Monero uses ring signatures, stealth addresses, and RingCT to obscure sender, receiver, and amount. DeSnake's decision to use Monero exclusively for the relaunched AlphaBay reflected a real improvement in financial privacy. The IRS has offered contracts worth up to $625,000 to crack Monero's privacy - Chainalysis and Integra FEC both won contracts in 2020. The effectiveness of Monero tracing by law enforcement in operational settings remains classified. Bitcoin's traceability has directly contributed to arrests in virtually every major dark web market case since 2013; Monero has not produced the same documented prosecution trail, though law enforcement claims some success.