Ukraine shuts crypto investment scam with up to $1M monthly turnover

Binance
fiverr



Ukraine has dismantled a network of fake crypto investment platforms that allegedly drained wallets belonging to people in more than 20 countries, with investigators identifying 62 victims so far.

Summary

  • Ukraine dismantled fake crypto investment platforms that targeted victims across more than 20 countries.
  • Investigators have identified 62 victims, while the network reportedly handled up to $1 million a month at its peak.
  • Victims were shown fake investment gains before a wallet drainer stole their crypto when they tried to withdraw funds.
  • Police conducted 34 searches and seized more than 100 computers, over 100 phones and 15 vehicles.

The National Police of Ukraine said investigators from its Main Investigation Department worked with the Security Service of Ukraine and the Office of the Prosecutor General to uncover the operation, which maintained several offices in Kyiv and the surrounding region.

Betfury

More than 46 Ukrainians were recruited into the network, while authorities are still identifying other participants, victims and the total amount stolen.

Fake crypto investment platforms targeted more than 20 countries

Investigators said the group created websites designed to look like legitimate investment platforms and used them to offer supposedly profitable cryptocurrency projects.

The Security Service said the scheme began with advertising distributed through Telegram, where potential customers were offered opportunities to invest in crypto projects. Users who registered were instructed to connect a cryptocurrency wallet and transfer funds to the platform.

Behind the websites, developers maintained the infrastructure and worked to keep the platforms accessible when attempts were made to block them. Other members of the group staffed offices, communicated with customers and provided security for the operation.

Once funds were deposited, employees manually simulated investment activity. Customers could see account balances rising inside their dashboards, although investigators said the displayed trading activity was fabricated.

A 25-year-old IT specialist organized the network, according to the Security Service. At its peak, the operation had monthly turnover of up to $1 million.

Authorities have so far identified 62 victims from more than 20 countries. They included citizens of Germany, Poland, Lithuania, Latvia, Spain, France, the UK, Canada and Israel.

The number could rise as investigators continue examining information recovered from the network’s infrastructure and determining how many people transferred cryptocurrency through its websites.

Wallet drainer activated during withdrawal attempts

The alleged theft entered another stage when customers attempted to withdraw their funds.

Operators blocked withdrawal requests and told victims that another verification procedure was required before their money could be released. Users were instructed to connect their primary cryptocurrency wallet and approve a small test transaction to demonstrate that the platform was functioning.

Investigators said the websites contained a wallet drainer that used the authorization to transfer assets from a connected wallet to addresses controlled by the group. After the cryptocurrency had been moved, the victim lost access to the investment platform.

The method relied on the same type of malicious authorization used in wallet drainer attacks, where users can unknowingly give an attacker-controlled contract permission to move their tokens. As crypto.news previously reported in July, approval phishing can involve token approvals, permit signatures and other authorizations that allow assets to be transferred without an attacker obtaining the wallet owner’s private key.

A similar technique surfaced in August when a Hyperliquid user lost roughly 550,000 USDC after interacting with a fraudulent website promoted through a Google advertisement. Security firm Salus later connected the fake Hyperliquid website to infrastructure associated with the Inferno drainer ecosystem.

Salus said that operation included malicious scripts, approval-command generation, automated draining, cross-chain withdrawals and tools for consolidating stolen funds. The Ukrainian case used a different investment pitch, but investigators similarly said victims were induced to authorize a transaction before assets were removed from their wallets.

The fake platforms collected more than cryptocurrency. Registration and verification procedures gathered victims’ passport information, phone numbers, email addresses, account logins, passwords and photographs, according to Ukrainian authorities.

Netherlands servers held records of victims and stolen crypto

Investigators traced server equipment used by the network to the Netherlands and obtained access to a database stored there.

The records contained information about victims, including cryptocurrency wallet addresses and the amounts allegedly stolen from individual users. Authorities said the servers held internal correspondence between members of the group and records describing how the fraudulent platforms operated.

Access to the database helped investigators trace the network across several countries and identify people who had interacted with the websites.

The international element follows several law enforcement operations targeting online investment fraud and crypto-linked social engineering schemes. INTERPOL said in August that Operation Jackal IV resulted in 58 arrests and identified 263 suspects after authorities in 22 countries targeted investment scams, romance fraud and related money laundering networks.

South African authorities seized $2.67 million during that operation and blocked 257 bank accounts, while Romanian police arrested 11 suspects in an investment scheme associated with an estimated €143 million, according to INTERPOL.

A larger INTERPOL crackdown reported in July produced 5,811 arrests across 97 countries and territories. Operation First Light intercepted $293 million in illicit assets, blocked more than 31,000 bank accounts and identified over 142,000 victims while targeting investment fraud, romance scams, impersonation and other forms of social engineering.

Investigators in that operation uncovered crypto laundering activity that used several digital assets and cross-chain swaps. INTERPOL said one wallet linked to a Thai investigation had processed more than $122.5 million over a 10-month period.

Approval phishing has drawn separate enforcement attention. A UK-led operation involving authorities in the United States and Canada froze more than $12 million in suspected scam proceeds earlier this year and identified more than 20,000 potential victims.

The operation focused on schemes in which victims were persuaded to sign malicious blockchain authorizations that gave scammers permission to move cryptocurrency from their wallets.

Police seized more than 200 computers and phones

Ukrainian officers carried out 34 searches at homes, offices and vehicles across Kyiv and the surrounding region as part of the investigation.

More than 100 computers and other pieces of computer equipment were seized along with over 100 mobile phones, 79 SIM cards and a GSM gateway. Police recovered cash and records connected with the operation, while 15 vehicles were taken during the searches.

Some cars and real estate used by members of the network had been registered in the names of suspects’ wives and other relatives, investigators said. The alleged organizer traveled with armed guards.

The criminal proceedings are being conducted under Part 5 of Article 190 of Ukraine’s Criminal Code, which covers fraud. Authorities have not disclosed a final loss figure because they are continuing to identify suspected members of the network and additional victims.

Ukraine has separately been developing procedures for handling cryptocurrency recovered through criminal cases. Authorities transferred more than $8.3 million in seized USDT to a state-managed wallet in June, the first time confiscated cryptocurrency had been placed under direct state management.

The Royal United Services Institute has estimated that stronger rules for tracing, seizing and managing illicit cryptocurrency could help Ukraine recover at least $10 billion in stolen funds and lost tax revenue.

Police said investigators are continuing to identify everyone involved in the fake investment network, locate further victims and determine the total value of cryptocurrency stolen through the platforms.





Source link

Changelly

Be the first to comment

Leave a Reply

Your email address will not be published.


*