Dyslexic
| Primary name | Dyslexic |
|---|---|
| Stylized handle | DysIexic |
| Historical / linked identity | Disposal / disposaI |
| Primary platform | Telegram |
| Primary project | Naz API |
| Project type | Breach-data repository, combo/search API, target-data brokerage system |
| Known activity window | 2021-10-31 to 2024-09-23 |
| Core environments | Naz Api Chat, BlackForums Chat, $CAMZ Chat, Osint.pw Chat, Brotherhood, Red Team United |
| Role assessment | Data-market builder, parser/API operator, breach-data broker, OSINT-adjacent toolsmith |
| Technical assessment | Strongest in data aggregation, parsing, lookup tooling, and market logistics; more uneven on exploit/malware claims |
Aliases
@Dyslexic— Primary public identity@DysIexic— Stylized handle using a capital-I substitution@Disposal— Historical linked identity@disposaI— Historical stylized handle using a capital-I substitution
Summary
Dyslexic is the creator and principal operator of Naz API, a Telegram-centered breach-data repository built around massive credential collections, stealer-log material, combo lists, domain lookups, target filtering, and private data sales. Naz API began as a successor-style project to earlier “Naz” material, then evolved into a broader data-access system with bot/API plans, parser work, custom combo orders, targeted line sales, and later Naz v2 resale activity.
The cleanest description is not “elite exploit developer.” It is sharper than that and less cinematic: Dyslexic is a breach-data engineer with a marketplace mouth. His practical value sits in acquiring, sorting, parsing, deduplicating, packaging, and selling large quantities of compromised or scraped data. He understands what buyers want: fresh combos, URL:user:pass material, country-targeted records, salary-filtered leads, full logs, bank/crypto targets, OSINT-style lookups, and “TLO-like” personal-data reports.
Naz API’s power was its boring layer: ingestion, parsing, lookup, filtering, sorting, and resale. That is the part people underrate because it does not look like a skull-mask hacker movie. Bad instinct. Data plumbing is infrastructure. Whoever controls the searchable pile controls the market around it.
Identity
| Identifier | Assessment | Notes |
|---|---|---|
Dyslexic | Primary identity | The actor openly treats “dyslexic” as his name. |
DysIexic | Stylized handle | Rendered with a capital-I substitution, making it visually similar to Dyslexic. |
Disposal | Historical / linked alias | Earlier marketplace identity. Used in connection with access products and later self-referenced. |
disposaI | Historical stylized handle | Capital-I substitution again. Appears in earlier sales material. |
The identity style is deliberate: short, ugly, memorable, and typo-proof in the worst way. DysIexic and disposaI both use the same visual trick, swapping lowercase “l” with uppercase “I”. Cute? No. Effective? Annoyingly, yes.
Primary Project: Naz API
Naz API was a breach-data repository and lookup service. Its advertised and discussed functions included:
- domain-based lookup;
- URL:user:pass search;
- combo generation;
- fresh-data access;
- custom buyer-exclusive combo orders;
- targeted lines by country, date, salary, job, workplace, industry, and related attributes;
- stealer-log-derived data;
- raw database ingestion;
- parsed output formats;
- bot-based access;
- planned or active API access;
- private data sales;
- OSINT-style expansion modules;
- TLO-like personal-data reports.
Dyslexic initially described the name as a meme because the project functioned like “Naz 2.” He then directly claimed to have made Naz API, called himself its developer, and said he had the database on his own drives. Early public sizing put Naz API around 2B lines. Later claims fluctuated: raw working piles were described as tens of billions of lines, while later deduped or canonical Naz counts were described closer to 2.7B. Those numbers should be treated as self-reported scale claims, not audited counts.
The important point is not the exact number. The important point is the model: Naz API took messy stolen or scraped material and turned it into a searchable product.
Product Model
Naz API was not simply a dump channel. It was closer to a data-access business with several layers.
| Layer | Description |
|---|---|
| Free / public drops | Public combo drops and free lines used for attention, reputation, and channel growth. |
| Custom combos | Buyer-specific combo orders based on domains or requested targets. |
| Private data | Higher-value data sold directly rather than dumped publicly. |
| Targeted lines | Filtered people/target records by country, salary, job, employer, industry, and other selectors. |
| Full logs | Larger stealer-log-style bundles and rawer materials. |
| Bot access | Telegram bot interface for searches, custom orders, and line buying. |
| API access | Planned or offered programmatic access, with pricing based on lookup volume. |
| OSINT expansion | TLO-style and personal-data lookup modules adjacent to Naz API. |
| Reseller model | Later Naz v2 sales were routed through a third-party seller/broker. |
This is what made Naz API more significant than another random paste pile. A paste pile sits there. Naz API tried to turn breach material into a queryable market.
Data Types
Naz API and adjacent projects handled or advertised access to:
- URL:user:pass credential lines;
- combo lists;
- fresh stealer-log material;
- domain-targeted credential output;
- email lists;
- bank/crypto target leads;
- LinkedIn-style employment records;
- Facebook-style identity records;
- credit-derived personal-data records;
- names, addresses, phone numbers, emails, salaries, jobs, employers, counties, and industries;
- government-worker or government-adjacent filters;
- TLO-like personal-data reports;
- country-segmented target sets.
Dyslexic repeatedly framed the hard part as sorting and parsing. That tracks. Large breach corpuses are not useful because they are large; they are useful once they are searchable, deduped, normalized, filtered, and packaged. Naz API’s value was not just possession. It was conversion.
Scale Claims
| Date / Period | Claimed Scale | Interpretation |
|---|---|---|
| 2023-09 | Around 2B Naz API lines | Early public scale claim attached to the launch/rebuild period. |
| 2023-11 | Tens of billions of raw URL:user:pass lines | Likely raw, messy, duplicate-heavy working material. |
| 2024-01 | 71M emails clarified as emails, not logins | Shows distinction between email-only lists and credential records. |
| 2024-05 | 160K logs currently in Naz | Likely current stealer-log inventory, not total historical repository size. |
| 2024-08 | 2.7B Naz size claim | Later canonical/deduped-style scale claim. |
| 2024-09 | Millions of country-sorted targets advertised | Target-data brokerage phase, not just credential search. |
The numbers are inconsistent because the categories are inconsistent: raw lines, deduped lines, emails, logs, combos, and target records are not the same thing. Dyslexic talks like someone who knows that distinction but does not always care whether the audience does. Convenient for marketing. Annoying for accounting. Very Telegram.
Technical Profile
Dyslexic’s strongest technical lane is data engineering for criminal markets.
Core competencies:
- parsing large breach corpuses;
- deduplicating credential material;
- building simple data-access bots;
- working with API-style lookup access;
- organizing custom combo generation;
- sorting records by useful buyer fields;
- handling raw and parsed database material;
- packaging private data for sale;
- coordinating small dev/database roles;
- understanding buyer demand in fraud, OSINT, and credential markets.
He also claims or discusses offensive capability around exploits, malware, stealer logs, worms, RCEs, droppers, and C2 concepts. Those claims are noisier. Some are plausible as scene experience; some read like flexing; some are likely exaggerated. The reliable part is the data operation. The exploit mythology is less clean.
A fair technical read:
Dyslexic is credible as a data-market builder and parser/operator. He is less cleanly proven as a high-end exploit developer.
Naz API Architecture
Naz API moved through several shapes:
- initial data repository / combo-drop identity;
- Telegram bot concept;
- domain-search and custom-combo service;
- parser-backed data store;
- API-access plan;
- OSINT/TLO-style adjacent service;
- site-based direction when bot reliability became questionable;
- v2 resale/brokerage model.
The architecture was messy but practical. Dyslexic repeatedly complained about rebuilding, unfinished bots, parser work, memory issues, deduplication, and people not working on Naz. That is exactly what a chaotic data service looks like behind the curtain: less “evil genius console,” more “three broken parsers, two unpaid devs, one server bill, and a group chat full of goblins asking when it drops.”
Commercial Model
Dyslexic’s sales model combined public attention with private monetization.
Common sales patterns:
- “DMs” for private negotiation;
- custom amounts and filters;
- buyer-requested domains;
- salary-range filtering;
- country-based target selection;
- full-database offers;
- fresh stealer-log combos;
- paid API access;
- monthly lookup-volume pricing;
- free drops to attract users;
- reseller-driven Naz v2 sales.
He understood that different buyers wanted different levels of refinement. Low-end buyers wanted combo lists. Higher-value buyers wanted filtered people, fresh logs, bank or crypto relevance, private access, or API-style lookup volume. Naz API sat between those layers.
Development and Operations
Dyslexic presents himself as the originator and central operator, but Naz API was not a one-person fantasy box. He discusses dividing work between bot-side development, database-side work, parser creation, and exploit/data acquisition. He also repeatedly complains about unfinished components, lazy collaborators, and the endless grind of sorting.
The most realistic operational picture:
- Dyslexic created and drove the project.
- Other people contributed bot/database pieces.
- Dyslexic handled or supervised data acquisition, parsing, sales, and direction.
- The project suffered constant rebuilds, delays, and tooling churn.
- Public chat activity doubled as marketing, customer support, reputation management, and chaos control.
Dyslexic’s role was not just “coder.” It was product owner, data broker, loud salesman, annoyed project manager, and janitor of the breach pile. The janitor part matters. The money is in making the pile usable.
Timeline
2021: Search-Bot and OSINT Curiosity
Dyslexic’s earliest visible activity is search-bot usage and crude lookup behavior in OSINT-style environments. The pattern is already there: query things, test bot outputs, play with search commands, and treat identity data as something to be retrieved on demand.
This phase is not sophisticated, but it sets the foundation. The later Naz API idea did not appear out of nowhere. It grew from the same instinct: make data searchable, then make searchable data useful.
2023-03: Marketplace Identity and Access Sales
Under the historical disposaI identity, Dyslexic appears around access-product sales involving government-style emails, EDR-like access, and custom account creation. This establishes an earlier marketplace footprint before Naz API became the main identity center.
The tone is already commercial: product list, price, replacements, buyer contact, and niche access categories. Not polished. Not subtle. But definitely market-aware.
2023-09: Naz API Appears
Naz API publicly takes shape in late September 2023. Dyslexic says the project is not yet fully up, describes it as “Naz 2,” says fresh data is being sold, directly claims “I made Naz API,” calls himself its developer, and claims the database is on his own drives. Early size claims place it around 2B lines.
This is the foundation point. Naz API is not just a chat name here; it is presented as a data product with ownership, a database, and a coming API/bot layer.
2023-10: Combo Drops and Bot Plans
By October 2023, Naz API is pushing combo drops, including game and food-service themed combos, with plans for a bot that would let buyers order custom combo sets. Dyslexic emphasizes exclusivity: custom data sold to one buyer rather than dumped broadly.
This is where Naz API starts looking like a product instead of a pile. The pitch is simple: ask for a target, domain, or category; get fresh or filtered credential material.
2023-11: Raw Scale and Parser Burden
In November 2023, Dyslexic describes enormous raw URL:user:pass holdings and explains that the team has to parse different database formats over time. He distinguishes between raw database lines and parsed combo/log output.
This is a key maturity marker. The operator understands that raw data is not the same as usable data. He talks about parsing formats, dealing with different record types, and converting large dumps into useful search output.
2024-01: Rebuild, OSINT Expansion, and TLO-Style Direction
January 2024 is a major development period. Dyslexic talks about rebuilding the bot, sorting by email, URL, date, and country, offering targeted lines, and selling full logs. He also discusses OSINT expansion, TLO-style lookup concepts, credit-derived personal-data corpuses, and lookup-volume pricing.
The project direction becomes broader: not just credentials, but identity intelligence. Naz API begins bleeding into OSINT-as-a-service and people-search tooling. That is the dangerous turn. Credential search is bad enough; full identity enrichment is worse.
2024-02: Dev Split and Exploit Claims
By February, Dyslexic describes separate development tracks for Naz and OSINT work, with different people assigned to bot and database pieces. He claims to be the only dev but admits others handle major components, while he focuses on exploit-related work and project direction.
He also makes claims involving exploits and malware-adjacent work. The claims are significant but should be treated carefully. His demonstrated strength remains data infrastructure and marketplace coordination, not cleanly verified exploit authorship.
2024-03: Sorting Over Money
In March 2024, Dyslexic says the point of Naz is not only money but sorting data. That sentence is one of the best summaries of the whole project. The sales matter, obviously. But the strategic value is the repository: making chaotic breach material searchable enough to monetize repeatedly.
He also pushes back against unrelated promotion in Naz spaces, telling people to work on Naz instead. That reads like an operator trying to keep a chaotic room pointed at the product.
2024-04: Parser Work, Fresh Logs, and Dyslexic Identity Anchor
April 2024 shows heavy activity: basic parser creation, unfinished bot work, fresh stealer-log combo sales across multiple chats, data-sales routing, and the clear “Dyslexic” identity marker. The actor says he is “literally dyslexic” and that it is his name; around the same period, the stylized DysIexic handle is used as a point of reference.
April is also the month where high-risk claims spike: fresh stealer logs, custom malware talk, exploit claims, and data for banks/crypto targets. Some of it may be bragging. Some of it is probably not. Either way, it sits around the core Naz business: fresh compromised data in, searchable/targeted products out.
2024-05: Logs, Burnout, and Project Sprawl
In May 2024, Dyslexic says Naz has around 160K logs at that moment and complains about boredom, unfinished work, and project overload. He discusses possibly shifting away from the bot model and toward a site. He also describes working on many projects at once, including Naz 2, OSINT, and other unrelated builds.
The pattern is classic: talented enough to build useful things, chaotic enough to half-bury himself under unfinished ones. Still, the repository keeps moving.
2024-07: Reputation Fights and Dox Exposure
By July 2024, Dyslexic is involved in reputation disputes, public-dox chatter, and arguments over who has the full database. He acknowledges parts of his personal identity being public but treats much of the surrounding dox material as incomplete or wrong.
This phase shows the social cost of being a visible data-market operator. A person who sells lookup power eventually becomes a lookup target. Shockingly, the leopard did look back.
2024-08: Deduplication and Owner Claim
In August 2024, Dyslexic comments that deduplicating Naz was difficult and later states that Naz was 2.7B. He also directly identifies himself as the owner. This is the late-stage confirmation point: he is no longer only the guy who made it; he is still publicly tied to ownership.
The 2.7B claim likely reflects a more processed or deduplicated view than the huge raw-line claims from 2023. Treat it as a product-scale claim, not a forensic count.
2024-09: Naz v2 and Target-Data Brokerage
By September 2024, Naz v2 is being sold through a reseller/broker channel, while Dyslexic separately advertises target records by geography and salary range. A country-by-country inventory lists millions of targets across major regions, including the United States, United Kingdom, Mexico, India, Spain, the Netherlands, South Africa, and many others.
This is the mature data-broker phase. The repository is no longer just about “can I find logins for this domain.” It is about filtering people by country, likely income, job context, and target value.
Technical Strengths
- Large-scale breach-data handling.
- Parser creation and format normalization.
- Credential corpus deduplication.
- Domain-targeted lookup logic.
- Telegram bot/product design.
- API-access planning.
- Buyer-specific combo generation.
- Fresh-data sourcing and packaging.
- OSINT-style enrichment concepts.
- Understanding of fraud-market demand.
- Marketplace timing and promotion.
Dyslexic’s best skill is turning messy compromise material into products people can search, buy, and reuse.
Technical Weaknesses
- Chaotic project management.
- Inconsistent claims around scale and capability.
- Reliance on other developers for bot/database pieces.
- Frequent unfinished components.
- Public overexposure.
- Poor separation between product support, bragging, and self-incrimination.
- Uneven credibility on exploit and malware claims.
- Impulsive communication style.
He is not a polished operator. He is productive, messy, loud, and often far too comfortable saying the quiet part in a public room.
Behavioral Profile
Dyslexic’s communication style is abrasive, fast, and hostile. He uses heavy slurs, mocks rivals, complains constantly, and treats chaos as normal operating weather. That ugliness should not distract from the practical competence underneath it. He is rude, but not useless. A lot of people in these scenes are both; he is simply louder about it.
Recurring behaviors:
- public flexing over data size;
- blunt sales posts;
- “DMs” routing;
- argument-driven reputation management;
- dismissing rivals as skids or scammers;
- complaining about unfinished work;
- casually discussing backend problems;
- using free drops as promotion;
- turning every chat into a support desk;
- mixing real technical comments with obvious bravado.
The result is a profile with two layers: the clownish surface and the functional machinery underneath. Do not be fooled by the clowning. Naz API was machinery.
Risk Assessment
| Risk Area | Assessment |
|---|---|
| Breach-data aggregation | High. Naz API centralized massive credential and identity corpuses. |
| Searchability | High. Domain, country, date, salary, and identity filters increase harm. |
| Fresh stealer-log sales | High. Fresh credentials are more immediately useful for account takeover. |
| OSINT enrichment | High. TLO-style reports and credit-derived data enable targeting beyond passwords. |
| API access | High. Programmatic lookup access scales abuse. |
| Marketplace reach | Medium-to-high. Activity spans Naz, BlackForums, $CAMZ, Osint.pw, Brotherhood, and related chats. |
| Exploit capability | Medium. Multiple claims exist, but verification is uneven. |
| Malware capability | Medium-to-high concern. Malware and stealer-log claims recur, though some are likely inflated. |
| OPSEC | Poor. Dyslexic repeatedly links identity, ownership, project state, sales, and claims in public. |
| Real-world identity exposure | Medium. Personal identity disputes appear, but many details are contested or low-value. |
The highest-risk feature is not one exploit claim. It is the repository model. A searchable breach-data platform with buyer filters and API access can empower many smaller actors at once. That is infrastructure risk.
Claims vs. Evidence
| Claim | Assessment |
|---|---|
| Dyslexic made Naz API | Strongly supported by direct self-claims. |
| Dyslexic was the developer/operator of Naz API | Strongly supported by repeated dev/owner language and operational control behavior. |
| Naz API held around 2B lines at launch | Supported as a self-reported claim. |
| Naz later reached around 2.7B lines | Supported as a later self-reported claim. |
| Raw holdings reached tens of billions of lines | Possible but noisy; likely raw, duplicate-heavy material. |
| Naz API included bot/API access | Strongly supported by repeated product-direction discussion. |
| Naz API sold fresh and private data | Strongly supported. |
| Naz API offered target filtering | Strongly supported. |
| Dyslexic personally built every component | Not supported; he describes help on bot and database work. |
| Dyslexic is a verified elite exploit developer | Not established. Claims exist, but evidence is uneven. |
| Dyslexic is primarily a data-market operator | Strongly supported. |
Operational Interpretation
Dyslexic should be understood as a data-market infrastructure actor.
He is not merely selling random text files. He is building the middle layer between breach acquisition and buyer action:
- collect messy data;
- parse it;
- dedupe it;
- index it;
- filter it;
- expose it through bot/API interfaces;
- sell broad or targeted access;
- use free drops to pull users into the market;
- route higher-value buyers into private sales.
That middle layer is where harm multiplies. One stolen credential list is one incident. A searchable repository becomes a service. A service becomes an ecosystem. Naz API lived in that ecosystem.
Overall Assessment
Dyslexic is a high-risk breach-data operator and the creator of Naz API, a repository/search product that converted large credential and identity corpuses into usable marketplace inventory. His strongest demonstrated abilities are not glamorous exploit wizardry; they are data ingestion, parsing, packaging, filtering, and sales logistics.
The exploit and malware claims deserve attention, but they are secondary to the core threat. Naz API’s danger is scale and accessibility. It lowers the friction for other actors to find credentials, identify targets, enrich victims, and buy filtered data without doing the acquisition work themselves.
The cleanest one-line assessment:
Dyslexic is the breach-data plumber behind Naz API: messy, abrasive, technically uneven, but dangerous because he turned stolen data into searchable infrastructure.
Confidence
| Finding | Confidence |
|---|---|
Dyslexic is linked to the DysIexic handle. | High |
| Dyslexic created Naz API. | High |
| Dyslexic operated or owned Naz API. | High |
| Naz API functioned as a breach-data repository and search/brokerage service. | High |
| Naz API supported or planned bot/API access. | High |
| Naz API handled URL:user:pass, combos, logs, and targeted lines. | High |
| Naz API scale reached billions of lines. | Medium-to-high; exact counts are self-reported. |
| Dyslexic had strong data-engineering and parser/operator capability. | Medium-to-high |
| Dyslexic had elite exploit capability. | Low-to-medium |
| Dyslexic’s public OPSEC was strong. | Very low |
See Also
Record created: 2026-06-12.
