The rapid, volatile world of cryptocurrency promised financial liberation and unparalleled returns, especially in emerging markets like South Africa. Yet, this new technological frontier harbored massive risks, nowhere more evident than in the catastrophic collapse of Africrypt in 2021. This event, orchestrated by two teenage brothers, exposed a dangerous intersection of human greed, technological opacity, and a fatal regulatory vacuum. What began as a seductive promise of daily double-digit returns ended as a global manhunt, leaving investors fleeced and authorities flat-footed.
The investigation into Africrypt demonstrates that the supposed “hack” was, in fact, an exquisitely timed exit strategy—a modern rug pull executed within a system designed for total impunity. This analysis draws on forensic data, legal filings, and investor testimonies to provide a comprehensive, cautionary overview of one of the most significant alleged financial implosions in South African history.
I. Case Summary: The Illusion of AI and the April Collapse

Africrypt was founded in 2019 by brothers Raees Cajee and Ameer Cajee. Raees, the CEO, was 21 at the time of the collapse, and Ameer was 19, serving as COO. The brothers marketed themselves as prodigious crypto entrepreneurs with sufficient experience in the crypto industry to attract clients through marketing campaigns.
The platform’s central appeal was a claim of revolutionary artificial intelligence (AI) cryptocurrency trading software developed by Raees. They claimed this system, which also utilized algorithmic trading and arbitrage, could deliver “astronomical growth” and unprecedented returns. The pitch was simple but aggressive: investors were promised returns as high as 10% every day (or up to 13% per month on the “Aggressive” plan), figures authorities later deemed “unbelievable and unrealistic”.
Africrypt successfully engaged high-net-worth individuals and the richest population in South Africa, many of whom invested millions in Bitcoin pools. By 2020, the brothers claimed to manage hundreds of millions of rands.
The scheme came crashing down rapidly in April 2021. A week before the entirety of the Bitcoin pool was drained, Africrypt employees were demoted and lost access to back-end platforms without explanation. Then, on April 13, 2021, investors received an email, signed by Ameer Cajee, announcing that the platform had been attacked and funds were lost.
Crucially, the email cautioned victims against legal action, stating that the involvement of authorities could “hinder the process of acquiring the lost BTC”. Within days, the company’s website was shut down, its Durban offices were emptied, and the Cajee brothers went off the radar, apparently fleeing to destinations including the UK, Dubai, and Tanzania.
II. Scam Mechanism (Core Focus): The Inside Job and Digital Clean-up
While the Cajee brothers vehemently denied all responsibility, claiming their platform was genuinely hacked, forensic investigation and whistleblower data strongly contradicted the narrative of an external breach. Instead, analysis pointed to a textbook “rug pull”—an internal theft carried out by the operators.

The core of the fraud lay in the structural opacity and centralization of Africrypt. Cryptocurrency analyst Wiehann Olivier noted that Africrypt was a “centralised system pretending to be decentralised,” lacking oversight, third-party security testing, or asset segregation. The Cajee brothers maintained complete control over the platform’s wallet infrastructure and funds. Incoming investor funds were reportedly pooled and moved at will, sometimes routed through personal or trust structures, blurring the line between client capital and operator revenue.
Evidence confirming internal foul play included:
- Pre-meditated Access Removal: The pre-collapse demotion of employees, removing their back-end access, was undertaken to mask the eventual transfer of funds and render them untraceable.
- Internal Wallet Transfers: Inquiry by Hanekom Attorneys revealed that the initial transfer of stolen funds was into wallets owned by the Cajee brothers.
- Post-Hack Logins: Despite publicly claiming the system was compromised, administrative sessions linked to devices associated with Raees and Ameer Cajee remained active for at least 72 hours after the April 13 announcement. Forensic records showed successful logins to legacy Africrypt admin panels months later, suggesting someone with prior system access retained operational awareness.
- Digital Laundering: The assets were deliberately obscured. Blockchain analysis confirmed that funds were mixed and tumbled before being distributed randomly into larger Bitcoin wallets, making them essentially untraceable. The funds were split into smaller amounts, routed through privacy-focused applications such as Wasabi Wallet, and dispersed to platforms like Binance, Kraken, Huobi, and unregistered, non-KYC compliant exchanges. This activity spiked between April 14 and 18, 2021, the same window during which major cryptocurrency withdrawals occurred.
Hamilton Cheong, a South African-born forensic sleuth whose firm developed a blockchain track-and-trace program called God’s View, stated that the evidence did not support the story of a hack originating from Ukraine, as claimed by Raees Cajee. Cheong noted that funds were being depleted from Africrypt-controlled wallets months before the alleged hack, suggesting an orchestrated depletion. Furthermore, disturbing tie-ins were found between Africrypt and the previous major South African crypto scam, Mirror Trading International (MTI), as some of the same “tumblers” used to hide the origin of funds were utilized by both entities.
III. Warning Signs (Red Flags): The Lure of Guaranteed Wealth
For the general crypto-interested public, the Africrypt saga provides a critical lesson in due diligence. The platform exhibited multiple glaring warning signs, often characteristics of a classic Ponzi scheme:
- Unrealistic Returns and Guarantees: Africrypt’s promise of 10% daily or 13% monthly guaranteed returns was the primary red flag. Authorities subsequently questioned the investors’ judgment for trusting such “unbelievable and unrealistic” promises.
- Centralized, Unregulated Custody: Africrypt was a shadow exchange. There were no audited statements, no external custodians, and no formal financial licensing. Investors deposited money directly into accounts controlled by the Cajees, believing it would be traded on their behalf, a model with zero oversight. The failure to separate client and operational accounts was a fundamental breach of financial integrity.
- Youth and Lack of Credentials: The company was run by two teenagers who claimed to be prodigies. While Raees Cajee claimed to have sufficient crypto experience and was rumored to have impressed Chinese crypto platforms, relying on the perceived genius of very young, unaudited operators should serve as a cautionary signal.
- The “Hush Money” Tactic: The immediate advice given by the Cajee brothers to victims—to avoid contacting authorities—is a common tactic used in crypto rug pulls designed to buy time for the perpetrators to complete their exit and cover their tracks.

IV. Consequences & Legal Status: The Pursuit and the Payout
The initial reports of the funds lost were dramatically inflated. Media stories initially cited figures up to $3.6 billion (R54 billion). This figure was based on an error by an amateur sleuth hired by victims’ lawyers, who mistakenly identified a wallet belonging to Luno, a large South African exchange, as Africrypt’s.
While the true amount is disputed, court-appointed liquidators later confirmed the loss to be closer to R3.6 billion. Creditors filed claims of approximately R200 million. The Cajee brothers, conversely, argued that the maximum sum they ever traded was $200 million, and only $5 million was lost in the alleged hack.
Legal Proceedings and Flight
Africrypt was put under a provisional liquidation order in April 2021. However, the legal landscape in South Africa was complex. At the time of the collapse, crypto assets were not regulated, meaning the Financial Sector Conduct Authority (FSCA) initially lacked jurisdiction to intervene in the fund recovery. The regulatory paralysis gave the Cajees the “perfect cover”.
The brothers used Vanuatu-issued passports to facilitate their international travel to the UK, Dubai, Turkey, and Zurich. Despite having fled, one brother, Raees, surfaced briefly in Tanzania in July 2021 to stamp court documents opposing the liquidation.
In November 2021, one of the brothers was arrested in Zurich (Switzerland) on suspicion of money laundering. This arrest occurred while he was allegedly attempting to access hardware wallets (Trezor devices) suspected of containing missing Bitcoin. He was placed under supervised release and later released on bail, but criminal proceedings for money laundering remain ongoing in Zurich against both brothers.
The Mysterious Settlement
In late 2021, an anonymous “white-knight” investor emerged, offering a settlement to claimants. This entity was unmasked as Pennython Project Management LLC, a foreign entity registered in Dubai. Pennython committed to buying up the debt, offering claimants 65 cents in the rand. Claims totaling R131 million were in the process of being paid out to 199 creditors under this settlement, which was not required to be sanctioned by a court.
An earlier, failed settlement attempt required investors to drop criminal charges against the Cajees. While many investors accepted the Pennython offer—seeing it as preferable to a long, uncertain legal fight—some, like major investor Juan Meyer (who had R177 million invested), refused the terms that involved dropping charges.

The identity of the director(s) of Pennython remains confidential, but two investors consulted by ITWeb confirmed it was a Dubai-registered LLC. Critically, one investor expressed belief that the Cajee brothers were ultimately behind the settlement offer. Raees Cajee’s location was reportedly Dubai when he signed a supplementary affidavit in October 2021. Their attorney, Shaheed Dollie, also stated that the Cajees saw the conclusion of the agreement as an “opportunity to resuscitate the business”.
V. Writer’s Commentary: The Price of Trust in the Grey Zone
The Africrypt scandal is more than a cautionary tale of theft; it is a vivid illustration of how regulatory paralysis amplifies risk in nascent financial sectors.
Core Cause Assessment
The scam’s success hinged on the perfect storm created by three factors: unfettered centralization, investor susceptibility, and the regulatory void.
Firstly, the system was built as a “fully enclosed ecosystem”. By controlling the wallets, servers, trading, and audits, the Cajees effectively “recreated a bank without any of the obligations that come with banking”. The immediate consequence of this radical centralization was that when the operators decided to leave, there was no independent custodian, no compliance check, and thus, no audit trail to stop them.
Secondly, the promise of “unlimited wealth” led sophisticated investors—including the “richest population”—to ignore fundamental financial warnings, such as the unrealistic nature of the promised 10% daily return. This collective blindness, fueled by the crypto boom, allowed trust to replace accountability.
Finally, the lack of formal regulation at the time allowed the Cajees to operate as an unlicensed, accountable institution, bypassing critical Know Your Customer (KYC) and Anti-Money Laundering (AML) oversight required of traditional finance. The Financial Sector Conduct Authority (FSCA) and the Financial Intelligence Centre (FIC) were “paralysed by a legal grey zone,” granting operators like Africrypt total impunity.
Proposals for Prevention
While South Africa has since classified crypto assets as financial products (2022) and now requires platforms to register, the Africrypt case demands further structural and technological safeguards, particularly because new legislation does not operate retrospectively.
- Mandatory Third-Party Audited Custody: Regulation must move beyond licensing the service provider to mandating external, independent, and frequent auditing of asset custody. For any platform promising passive returns, client funds must be held by an accredited third-party custodian separate from the trading or management entity. This segregation prevents the kind of commingling and unilateral draining that occurred at Africrypt.
- Harmonized Global Crypto AML/Fugitive Tracing: Given the ease with which funds were laundered through global non-KYC exchanges and the Cajees used international travel documents (Vanuatu passports), national regulation is insufficient. Global financial bodies (like the FATF and Interpol) need mandatory, near-real-time data sharing protocols with international crypto exchanges (like Binance and Huobi) to flag suspicious wallet activity tied to jurisdictions undergoing mass fund withdrawals immediately.
- Liquidation Priority and Asset Preservation: Legal frameworks must allow provisional liquidators to immediately gain authority to freeze and seize crypto assets globally upon the first evidence of mass withdrawal, regardless of whether the platform is regulated as a “financial product.” The current system allowed the perpetrators days to launder hundreds of millions while liquidation proceedings lagged.
The story of Africrypt is a stark reminder that in the crypto wilderness, if the returns sound too good to be true, the fine print likely reads: You are the product, and your trust is the commodity being stolen. The only true defense against sophisticated scams built in regulatory grey zones is rigorous, mandatory oversight and a collective commitment from investors to reject promises that defy economic reality.
REFERENCES
- dailymaverick – How Africrypt investors were fleeced and left high and dry
- mybroadband – Big development in Bitcoin Brothers case in South Africa
- writersroom – Meet the 29-year-old South African unravelling the multi-billion-rand Africrypt theft
- itweb – South Africans lose ‘billions’ in Africrypt crypto scam
- coinmarketcap – Africrypt Hack – One of the Biggest Crypto Hacks in History