Trends

APX Betting Network, Mule Accounts and a ₹800-Crore Crypto Trail: ED Arrest of Ram U. Ramdhani Puts the Fintech Facade Under a Harsh Spotlight

An investigative examination of All Panel Exchange, the alleged betting-fraud architecture, Edsom Fintech, the movement of hundreds of crores and the uncomfortable questions that law-enforcement agencies now need to answer

There is nothing particularly sophisticated about the oldest trick in the fraudster’s handbook: first create confidence, then increase the victim’s exposure, and finally make the money disappear.

What makes the alleged All Panel Exchange (APX) network disturbing is not merely the allegation of online betting or even the alleged cheating of victims of crores of rupees. It is the financial architecture behind the operation that deserves far greater scrutiny: mule bank accounts, layering, fintech/payment channels, alleged shell entities, cryptocurrency, offshore transfers and an alleged money trail running into hundreds of crores.

On 6 October 2026, the Enforcement Directorate’s Mumbai Zonal Office disclosed that it had arrested Ram U. Ramdhani on 28 September 2026 under the Prevention of Money Laundering Act, 2002, in connection with an ongoing investigation into an online gaming/betting scam linked to All Panel Exchange (APX) and related cyber-fraud activities. The Special Court (PMLA), Mumbai, first remanded him to seven days of ED custody and subsequently to judicial custody. 24f7a75a-664e-4ce4-9e29-b245be3…

The language of the agency is significant. ED says the investigation did not merely discover a betting website. It alleges a financial pipeline through which proceeds of crime travelled through mule accounts and ultimately reached Edsom Fintech Pvt. Ltd., which the agency says was founded and controlled by Ram U. Ramdhani. ED further says evidence indicated that he exercised management and control over the company’s business and overall operations. 24f7a75a-664e-4ce4-9e29-b245be3…

That is where the story stops looking like an ordinary online-betting case and starts looking like a much larger question about who moved the money, who controlled the pipes, who benefited and who was supposed to be asking questions while those pipes remained open.

Online promotional material carrying All Panel Exchange branding has been found on the internet. Its existence, by itself, does not establish ownership, control or criminal liability; the investigative significance lies in the financial and operational evidence being examined by authorities.


From a WhatsApp message to a disappearing withdrawal button

Independent reporting on the underlying investigation describes a remarkably familiar alleged fraud pattern.

According to the reporting, one of the complaints involved a person being approached through WhatsApp, introduced to the betting platform and supplied with login credentials. The victim was reportedly allowed to withdraw a relatively small amount initially. That is hardly accidental from a fraud-design perspective: a small successful withdrawal can create a psychological illusion of legitimacy.

Then comes the bait.

The victim is encouraged to put in more money. Once the amount becomes substantial, withdrawals allegedly stop, requests remain pending or are blocked, and the people behind the platform become unreachable. Free Press Journal

In other words, the alleged model was not simply “place a bet.”

It was allegedly:

Attract → build confidence → increase exposure → trap the money → disappear.

That distinction matters.

A genuine financial or gaming transaction can produce a loss because of market movement or the user’s own decision. A platform that allegedly allows small withdrawals to establish trust and then blocks withdrawals after larger deposits presents an entirely different investigative question: was the customer’s money ever intended to remain withdrawable in the first place?

That is precisely why the victim-side evidence, transaction records, IP logs, chats, KYC documents, account ledgers and server data must now be treated as critical evidence rather than peripheral paperwork.


Two FIRs, multiple cities and a rapidly widening investigation

ED says the PMLA investigation was initiated on the basis of two FIRs concerning online gaming/betting and cyber fraud, with complainants allegedly losing crores of rupees. 24f7a75a-664e-4ce4-9e29-b245be3…

Independent reporting provides greater chronology.

One FIR was reported as having been registered by Jalgaon Cyber Police in January 2025, concerning alleged operation of the All Panel Exchange platform through allpanelexch.com. A second FIR was reported as having been registered by HSR Layout Police, Bengaluru, in February 2026, concerning similar allegations. Free Press Journal

The ED then escalated matters dramatically.

On 21 July 2026, according to the Free Press Journal’s reporting, the agency conducted searches at 11 premises across Maharashtra and Karnataka—three in Mumbai, six in Pune and two in Bengaluru. The locations reportedly included alleged platform operators, payment handlers, mule-account providers, entities suspected of supplying bank accounts, technical developers and others allegedly facilitating the network. Free Press Journal

That geography alone is instructive.

This was not an allegation confined to a single laptop in a single room.

Mumbai. Pune. Bengaluru. Maharashtra. Karnataka. Bank accounts. Payment channels. Digital devices. Multiple intermediaries. Overseas infrastructure.

That is the anatomy of a network requiring financial intelligence, digital forensics and inter-state coordination.


The alleged APX architecture: not just a betting website, but a franchise model

Perhaps one of the most important pieces of reporting from the July searches concerns the alleged structure of the APX ecosystem.

According to the Free Press Journal, ED’s findings indicated that All Panel Exchange operated as a franchise-based, white-label betting ecosystem, rather than as a simple centrally operated website.

The alleged model involved an overseas technical backbone, with branded versions of the platform being leased to local operators under profit-sharing arrangements. Below that sat a hierarchy described as “master”, “super master” and agent-level operators. Those lower levels allegedly distributed betting IDs, handled customer accounts, collected deposits, extended betting credit and settled payouts. Free Press Journal

That alleged architecture is strategically important.

Why?

Because decentralisation creates distance.

The person talking to the customer may be several layers removed from the people controlling the backend.

The account receiving a deposit may not be the account belonging to the person running the platform.

The company through which the money passes may not openly advertise itself as a betting operation.

And the ultimate beneficiary can therefore be several transactions—and several corporate names—away from the victim.

It is precisely this kind of fragmentation that money-laundering investigations are designed to penetrate.


Enter Edsom Fintech: the alleged financial bridge

The most uncomfortable part of the ED’s October announcement concerns Edsom Fintech Pvt. Ltd.

ED alleges that funds from the betting/cyber-fraud ecosystem were routed through multiple mule accounts and subsequently transferred to Edsom Fintech. The agency says the company’s bank accounts were linked with multiple categories of cybercrime and that hundreds of crores of rupees were routed and layered through its accounts. 24f7a75a-664e-4ce4-9e29-b245be3…

The company itself publicly describes its business very differently.

On its website, Edsom Fintech says it provides financial services, taxation services, utility payments and payment aggregation and UPI-related services, describing itself as a fintech company providing digital financial solutions. Edsom Fintech

And that contrast is precisely why the investigation has become so consequential.

There is nothing inherently suspicious about being a fintech company.

There is nothing inherently suspicious about processing payments.

There is nothing inherently suspicious about using payment gateways.

But when an enforcement agency says that a company’s bank accounts were allegedly used as a conduit through which hundreds of crores linked to cybercrime were routed and layered, the obvious question becomes brutally simple:

What exactly was the company processing—and for whom?

ED says Edsom Fintech provided PayIn/PayOut services through gateways including Easebuzz, Cashfree and PineLabs, as well as payment channels of Muslim Cooperative Bank, and that funds associated with the alleged gaming/betting and cyber-fraud activity moved ultimately through the Edsom banking/payment network. 24f7a75a-664e-4ce4-9e29-b245be3…

That allegation does not mean that these named payment companies or the bank were accused by ED of committing fraud. The important point is narrower: ED says the payment infrastructure was used in the alleged money flow. The responsibility now is to establish, transaction by transaction, who initiated payments, under whose merchant relationship, against what KYC, to which beneficiary and after what compliance checks.

That trail should not end at “payment gateway.”

It should end at the ultimate beneficial recipient.


Hundreds of crores in a company with a modest statutory capital base: coincidence, explanation or forensic question?

Public corporate-information databases identify Edsom Fintech Pvt. Ltd. as an unlisted private company incorporated on 22 December 2020, with authorised capital of ₹10 lakh and paid-up capital of ₹1 lakh. Some corporate databases report FY2024 revenue of roughly ₹9.23 lakh. The Company Check

That information, by itself, proves nothing improper.

A payment-processing company can, in principle, move transaction volumes vastly larger than its own accounting revenue because customer money may be pass-through funds rather than company income.

But this is precisely why the numbers demand forensic reconciliation.

If ED says hundreds of crores were routed and layered through company accounts, investigators need to establish:

What proportion was genuine business turnover?

What proportion was pass-through money?

Which transactions corresponded to genuine merchants?

Which merchants had valid KYC?

Who were the ultimate beneficial owners?

What were the settlement instructions?

How much money was retained as fees and where did the balance go?

And most importantly:

Why did a fintech infrastructure allegedly connected to multiple categories of cybercrime continue to appear in the financial chain?

Those are not sensationalist questions.

Those are the questions a serious financial investigation is supposed to answer.


The corporate-control question cannot be brushed aside

Another issue deserves attention.

Ram U. Ramdhani’s public LinkedIn profile describes him as Founder and CEO of Edsom Fintech Pvt. Ltd. LinkedIn

ED’s October 2026 press release goes further, stating that he founded and controlled the company and that evidence indicated he exercised management and operational control. 24f7a75a-664e-4ce4-9e29-b245be3…

At the same time, publicly available corporate-information databases have listed other individuals as statutory directors of Edsom Fintech. Different databases also show changes in the director information over time, which makes the underlying MCA filings particularly important. ZaubaCorp

That discrepancy is not proof of wrongdoing.

But it is an obvious investigative avenue.

Who signed?

Who authorised?

Who negotiated merchant relationships?

Who controlled bank accounts?

Who had access to payment dashboards?

Who approved onboarding?

Who controlled settlement instructions?

Who was the ultimate beneficial owner?

The difference between a statutory designation on paper and actual operational control is precisely the kind of distinction that a sophisticated money-laundering investigation must establish.


The ₹800-crore crypto trail makes the story considerably darker

The July investigation produced an even more startling allegation.

Free Press Journal and Aaj Tak both reported that ED had identified an alleged ₹800-crore money trail involving a credit cooperative society’s account and a cryptocurrency wallet, with allegedly fabricated KYC documents being used to open the wallet. Aaj Tak reported that the agency believed a substantial part of that money was connected with proceeds arising from illegal online gaming and betting activity. Free Press Journal

This number must be handled carefully.

The ED’s 6 October arrest release does not say that ₹800 crore is the amount of the APX proceeds. The official October statement describes the Edsom flows as “hundreds of crores”, whereas the ₹800-crore figure comes from separate July reporting on the wider crypto-linked investigation. 24f7a75a-664e-4ce4-9e29-b245be3… Free Press Journal

That distinction matters.

But even with that caveat, the reported ₹800-crore crypto trail radically raises the stakes.

Because moving money through a bank account is one problem.

Converting funds into virtual digital assets and moving them offshore is a very different level of opacity.

The alleged sequence reported in July was:

Victim money → mule accounts → layering entities → fintech/payment channels → crypto conversion → offshore transfer.

That is not a simple betting ledger.

That is the kind of chain that can take investigators through banks, fintechs, corporate registries, mobile numbers, devices, cryptocurrency exchanges, wallet addresses, KYC records and foreign jurisdictions.


Shell companies, dummy directors and addresses where nobody allegedly existed

The July reporting also contained another troubling element.

ED allegedly found that some entities used in the money trail were paper companies without genuine business activity, that some had allegedly dummy directors, and that certain entities were reportedly not found at their registered addresses. Free Press Journal

Again, these are allegations emerging from an ongoing investigation, not findings of conviction.

But from an investigative standpoint, shell structures are important because they can produce exactly the camouflage that a money-laundering chain needs.

One company receives.

Another transfers.

A third “invoices.”

A fourth settles.

A fifth converts money.

And by the time the investigator reaches the final account, the original victim transaction can be buried under dozens—or hundreds—of apparently ordinary entries.

The answer to such a network is not another press conference.

It is forensic reconstruction.


All Panel Exchange’s online footprint is another piece of the puzzle

Public domain records show allpanelexch.com was registered on 16 April 2024 through NameCheap, with the registrant shielded by a privacy service. The domain has also had TLS certificates issued at various points in 2025 and 2026. Whois

That is not evidence that the registrant committed a crime.

Privacy-protected domain registrations are commonplace.

But in a serious investigation involving an alleged online network, investigators should obviously obtain the underlying registrar records, historical DNS information, hosting records, payment records, administrator accounts and associated technical identifiers.

A betting brand may disappear from a browser in seconds.

Its transaction history does not disappear so easily.


And this is happening under a much tougher online-gaming regime

The legal environment has also changed dramatically.

The Promotion and Regulation of Online Gaming Act, 2025 prohibits online money games and also prohibits their offering, facilitation, advertising, promotion and participation; the law additionally bars financial transactions towards online money gaming services. The government states that the Act and its framework were operationalised in 2026, with the Online Gaming Rules coming into force on 1 May 2026. Press Information Bureau

The relevance to APX is obvious.

The investigation is no longer unfolding in a regulatory vacuum.

There is now a clear national legislative framework aimed at prohibiting online money gaming and cutting off the financial plumbing that supports it.

So the question for enforcement is increasingly uncomfortable:

When the law says the financial rails themselves must not facilitate prohibited online money games, how did alleged betting proceeds continue moving through sophisticated payment infrastructure?

That question deserves more than generic answers about compliance.


The ₹60 lakh freeze is important—but it is not the whole story

During earlier searches, ED says it recovered incriminating documents and froze approximately ₹60 lakh in various bank accounts. 24f7a75a-664e-4ce4-9e29-b245be3…

On its face, ₹60 lakh may look modest when the same investigation speaks of hundreds of crores in alleged flows.

But freezing ₹60 lakh and tracing hundreds of crores are not competing figures.

One is an immediate restraint measure.

The other is a reconstruction of historical transactions.

The real test of the investigation will therefore not be the headline amount frozen.

It will be whether authorities can answer:

Where did the money originate?

How much came from victims?

How much was genuine business?

How much was layered?

How much was converted into crypto?

How much went offshore?

Who finally received it?

What assets were purchased with it?

Which intermediaries knowingly facilitated the flow?

And ultimately:

Where is the money now?


The investigation cannot end with one arrest

The arrest of Ram U. Ramdhani is significant, but it should not become the convenient conclusion of the story.

ED itself says further investigation is under progress. 24f7a75a-664e-4ce4-9e29-b245be3…

That sentence is arguably the most important sentence in the entire press release.

Because if the allegations are ultimately established, the public interest is not served merely by identifying one person.

A network allegedly involving betting operators, master and super-master layers, agents, mule accounts, payment channels, fintech structures, shell entities, crypto wallets and offshore beneficiaries cannot reasonably be described as solved because one alleged controller has been arrested.

The entire chain must be exposed.


Enforcement agencies should follow the money—not just the names

The authorities should now work backwards and forwards simultaneously.

Backwards: from Edsom accounts into the originating mule accounts and ultimately to the victims.

Forwards: from the victim deposits into the eventual beneficiaries, crypto wallets and offshore entities.

The investigation should include a transaction-level reconciliation of every material account; beneficial-ownership verification of every intermediary company; forensic examination of phones, laptops and payment dashboards; examination of merchant onboarding records; KYC/AML trails; IP and device fingerprints; crypto wallet attribution; exchange records; UTRs and settlement instructions; and the complete chain of communications between masters, agents and financial intermediaries.

This is precisely the kind of investigation in which delay is dangerous.

Digital evidence can disappear.

Servers can move.

Domains can be replaced.

Wallets can be emptied.

Shell companies can be abandoned.

Money can cross borders in minutes.

A case that involves potentially hundreds of crores therefore cannot move at the speed of an ordinary paperwork-heavy prosecution.


India does not need another spectacular raid. It needs a spectacularly complete prosecution.

There is a familiar cycle in financial crime cases.

Raid.

Press release.

Arrest.

Headlines.

Then silence.

Then years of litigation.

Then witnesses disappear from public view, digital evidence becomes harder to interpret, victims lose hope and the central question—where did the money go?—gets buried under procedural history.

That cannot be allowed to happen here.

The agencies should move with greater speed, tighter coordination and forensic depth.

The prosecution should be built so that the final court proceeding is not a collection of newspaper headlines and dramatic allegations, but a documented reconstruction of:

victim → account → entity → intermediary → payment rail → crypto wallet → offshore destination → beneficial owner.

That is what a complete money-laundering case should look like.

Anything less risks producing the worst possible outcome: a very loud investigation with a very quiet ending.


A final uncomfortable question

If the ED’s allegations are ultimately substantiated, the APX matter would illustrate something far more serious than illegal betting.

It would demonstrate how a supposedly modern digital ecosystem can allegedly combine the psychology of online fraud, the reach of social messaging, the speed of fintech, the opacity of layered corporate structures, and the borderless movement of cryptocurrency into one highly scalable financial crime architecture.

And if that is what the evidence eventually establishes, then the uncomfortable question will not merely be:

Who ran APX?

It will be:

Who opened the financial doors?

Who failed to see the red flags?

Who processed the money?

Who supplied the accounts?

Who created the corporate layers?

Who converted it into crypto?

Who moved it offshore?

And who ultimately got rich while victims were being told that their withdrawals were “processing”?

Those questions deserve answers—not eventually, not after years, but now.

The public does not need another carefully worded assurance that the investigation is “ongoing.”

It needs identification of the entire network, recovery of the proceeds, prosecution of every person against whom admissible evidence is established, and speedy trials consistent with due process.

Because if hundreds of crores really travelled through the alleged machinery described by the investigators, then arresting one person is merely the opening act.

The real investigation begins where the money trail ends.


STRONG LEGAL & EDITORIAL DISCLAIMER

This article is based on the Enforcement Directorate’s official press release dated 6 October 2026, publicly available corporate information and published media reports concerning an ongoing investigation. The allegations described herein are allegations/investigative findings attributed to the concerned enforcement authorities and reported sources. Allegation does not equal conviction. Ram U. Ramdhani is an accused in an ongoing investigation, and the material reviewed for this article does not establish that he has been convicted by any court of law. No statement in this article should be construed as a judicial finding of guilt.

The references to Edsom Fintech, All Panel Exchange, payment gateways, banks, shell entities, cryptocurrency transactions and other persons/entities are presented only to the extent supported by the cited investigative material and should not be read as an allegation of criminal liability against any entity merely because its name appears in the reported money trail. The investigation remains ongoing, and every accused person is entitled to due process and the presumption of innocence until guilt is established in accordance with law.

At the same time, given the scale and nature of the allegations reported by the Enforcement Directorate, there is a compelling public-interest case for a tightly coordinated, time-bound and professionally rigorous investigation, rapid tracing and preservation of digital and financial evidence, aggressive recovery of alleged proceeds of crime, identification of ultimate beneficiaries and expeditious judicial proceedings—without compromising the rights of the accused or the evidentiary standards required for conviction.

Sources reviewed

The principal evidence base for this article includes the ED’s official 6 October 2026 press release, the July 2026 reporting on ED searches and the alleged ₹800-crore crypto trail, public corporate information concerning Edsom Fintech, the company’s own website disclosures, the All Panel Exchange digital footprint, relevant court reporting concerning APX-linked betting activity, and the current national online-gaming regulatory framework. 

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button