← Back to Venezuela Cyber Tour

About Crystal Vault

Crystal Vault documents Venezuela's centralized surveillance database announced in December 2024. The system, built by Chinese company ZTE, merges citizen identity records, banking data, and social program participation for over 30 million Venezuelans. The regime exposed their infrastructure through unsecured WordPress REST APIs. Approximately 178 GB of data was retrieved without authentication, including government office locations, staff GPS coordinates from phone metadata, and operational statistics across seven federal agencies.

178 GB
Data Exfiltrated
72,883
Media Files
13,209
EXIF-Tagged Images
345
Staff GPS Locations
470
OFAC Sanctions Matches
154
CNE Intranet Routes
35
Cracked Gravatar Emails
1,550
Personnel Records

Interactive Reports

Explore the Crystal Vault data through interactive dashboards

Data Sources

Government agencies exposed through unsecured WordPress REST APIs

AgencyDescriptionData Retrieved
SAIMEImmigration & ID Services134 office locations
INCESWorker Training InstituteMedia files
AVNState News AgencyMedia files
SARENNotary RegistryMedia files
VTVState TelevisionMedia files
CANTVState TelecomMedia files
Sistema PatriaSocial Control SystemApp ecosystem data
CNENational Electoral Council154 intranet routes exposed
EjércitoVenezuelan ArmyPersonnel & media

Exposed Endpoints

Technical details of the misconfigured infrastructure

WordPress REST API Exposure

All data was accessible without authentication through misconfigured public APIs. Key endpoints included /wp-json/wp/v2/users for user enumeration, /wp-json/wp/v2/media for bulk media download with EXIF metadata intact, various geographic data routes, and 154 CNE intranet routes that were publicly reachable. Gravatar hashes were cracked to recover 35 government email addresses tied to webmaster and official accounts.

Raw Downloads

Browse the full Crystal Vault data archive

📂
Full Crystal Vault Archive
Browse all data directories — exfiltrated media, OFAC sanctions, DGCIM intel, GPS photos, and more
Browse
CSV
OFAC Venezuela Sanctions
470 sanctioned individuals — US Treasury SDN list cross-reference
Download
TXT
Cracked Gravatar Emails
35 recovered email addresses from MD5/SHA256 hashes
Download
TXT
SEBIN Cyberspace Dossier
Intelligence dossier on SEBIN cyber operations
Download
TXT
All Hashes
Complete hash database from enumerated endpoints
Download

Published Articles

Investigation coverage and analysis

📰
The Unlocked Vault: How Venezuela Exposed 188GB of Sensitive Data
Full breakdown on Substack — WordPress API exposure, Gravatar hash cracking, EXIF metadata leaks, build manifest exposure
Read
Donate