Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
enforcement-actioncybercrime-service-ecosystemcryptocurrency-platform-risk

Empire Market Co-Founder Pleads Guilty to Federal Drug Conspiracy Charges

Updated 3mo agoFirst seen Jan 30, 20262 sources

Empire Market co-creator Raheim Hamilton (aka “Sydney”/“Zero Angel”) pleaded guilty in U.S. federal court in Chicago to a drug conspiracy charge tied to operating the dark web marketplace from 2018–2020. Prosecutors said the Tor-hidden service facilitated over 4 million transactions totaling more than $430 million, primarily illegal drug sales (~$375 million), and also enabled sales of stolen credentials, personal data, counterfeit currency, and hacking tools; Hamilton admitted the platform was designed to evade law enforcement and launder proceeds via cryptocurrency-only payments.

Hamilton and co-defendant Thomas Pavey (aka “Dopenugget”) were previously charged for running the market and allegedly had earlier involvement selling counterfeit currency on AlphaBay before launching Empire Market. Reporting indicates law enforcement conducted undercover purchases (including heroin and methamphetamine), and the investigation resulted in significant cryptocurrency seizures (reported at ~$75 million) and forfeiture commitments including Bitcoin, Ether, and property; Hamilton faces a mandatory minimum of 10 years and up to life in prison, with sentencing scheduled for June 17, 2026.

Share:
Empire Market Co-Founder Pleads Guilty to Federal Drug Conspiracy Charges
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Jun 17, 20266d ago

Hamilton sentencing scheduled for June 2026

Following his guilty plea, Raheim Hamilton's sentencing was set for June 17, 2026. The charge carries a mandatory minimum sentence of 10 years and a maximum of life in prison.

Jan 29, 20265mo ago

Raheim Hamilton pleads guilty in Empire Market case

Raheim Hamilton, identified as a co-founder and operator of Empire Market, pleaded guilty in Chicago to a federal drug conspiracy charge. He admitted the marketplace was designed to evade law enforcement and launder proceeds through cryptocurrency, and agreed to forfeit significant cryptocurrency holdings and properties.

Jun 1, 20242y ago

Federal charges filed against alleged Empire Market operators

U.S. prosecutors filed federal charges in June 2024 against Raheim Hamilton and Thomas Pavey for their alleged roles in creating and operating Empire Market. The case centered on a drug conspiracy tied to facilitating large-scale illicit commerce on the marketplace.

Dec 31, 20205y ago

U.S. investigators conduct undercover purchases and seize assets

During the federal investigation into Empire Market, U.S. authorities made undercover purchases on the platform and seized substantial criminal proceeds. Reported seizures included about $75 million in cryptocurrency at the time of seizure, as well as cash and precious metals.

Jan 1, 20188y ago

Empire Market operates as a major dark web marketplace

Empire Market operated from 2018 to 2020 as a Tor-hidden dark web marketplace and allegedly processed more than four million transactions worth over $430 million. Most sales involved illegal drugs, though the site also offered stolen credentials, personal data, counterfeit currency, and hacking tools.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

1 LINKEDOpen in app
Organizations
1 linked
BleepingComputer
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.