Ukraine Busts Crypto Scam With $1M Monthly Turnover, 62 Victims

Ukraine crypto scam

Ukraine dismantles a crypto investment scam targeting 20+ countries, with 62 victims identified and up to $1M in monthly turnover.

Ukrainian authorities have shut down a network of fake cryptocurrency investment platforms accused of deceiving investors and draining funds directly from their crypto wallets.

The operation was uncovered by investigators from Ukraine’s National Police in cooperation with the Security Service of Ukraine (SSU), under the procedural supervision of the Office of the Prosecutor General.

Authorities have so far identified 62 victims across more than 20 countries, although investigators believe the number could increase as they continue analysing seized data and tracing the network’s activities.

Fake Crypto Platforms Used to Lure Investors

According to investigators, the group created websites designed to resemble legitimate cryptocurrency investment platforms. The operation reportedly recruited potential victims through advertisements and messages circulated on Telegram channels promoting supposedly profitable crypto projects.

Users were encouraged to register on the fake platforms, connect their cryptocurrency wallets and transfer funds to participate in investment opportunities.

The websites then displayed fabricated trading activity and rising account balances, creating the impression that investors were making substantial profits.

Investigators said the investment activity shown on the platforms was entirely simulated.

The network was allegedly organised by a 25-year-old IT specialist from Kyiv, who recruited more than 46 Ukrainian citizens to participate in different parts of the operation. At its peak, the scheme reportedly generated turnover of up to $1 million per month.

Wallet Drainer Activated When Victims Tried to Withdraw

The fraud allegedly escalated when victims attempted to withdraw their supposed investment profits.

According to Ukrainian authorities, operators blocked withdrawal requests and told users that an additional verification procedure was necessary.

Victims were then instructed to connect their primary crypto wallets and approve a small transaction.

Behind the scenes, the websites reportedly contained malicious code known as a crypto wallet drainer. Once users approved the transaction, the attackers could transfer digital assets from connected wallets to addresses controlled by the criminal network.

This technique is particularly dangerous because victims do not necessarily have to reveal their private keys. Instead, they can unknowingly grant malicious contracts or applications permission to move assets from their wallets.

After the crypto was allegedly drained, victims lost access to the fake investment platforms.

Personal Data Also Collected

The operation allegedly went beyond cryptocurrency theft.

Ukrainian investigators said the fake platforms collected sensitive customer information during registration and verification, including passport details, phone numbers, email addresses, usernames, passwords and photographs.

Investigators also discovered server infrastructure in the Netherlands containing a database with information about victims, cryptocurrency wallet addresses and the amounts allegedly stolen.

The database reportedly included internal communications between members of the network and records explaining how the fraudulent platforms operated.

Victims Across Europe and Beyond

Authorities have identified victims from countries including Germany, Poland, Lithuania, Latvia, Spain, France, the United Kingdom, Canada and Israel, among others.

The international footprint highlights a growing challenge for law enforcement: crypto scams can be operated from one jurisdiction while targeting victims and moving digital assets across several others.

Investigators are continuing to analyse the seized infrastructure to determine the full number of victims and the total amount of cryptocurrency stolen.

34 Searches Conducted Across Kyiv Region

Ukrainian law enforcement conducted 34 searches at the suspects’ homes, offices and vehicles across Kyiv and the surrounding region.

Authorities seized:

  • More than 100 computers and other pieces of computer equipment
  • More than 100 mobile phones
  • 79 SIM cards
  • A GSM gateway
  • Documents and handwritten records
  • Cash
  • 15 vehicles

Investigators also said some vehicles and real estate allegedly connected to the suspects were registered in the names of relatives, including wives. The alleged organiser was reportedly accompanied by armed security.

Crypto Fraud Remains a Growing Law-Enforcement Challenge

The Ukrainian case illustrates how cryptocurrency scams are increasingly combining traditional investment fraud with blockchain-specific attack techniques.

Instead of simply convincing victims to send crypto to a scammer-controlled address, criminals can first build trust through professional-looking investment dashboards and fabricated returns. The final stage then uses malicious wallet permissions to extract assets directly from victims’ wallets.

For crypto investors, the incident underscores a critical security principle: connecting a wallet or signing a blockchain transaction can carry significant risks even when the transaction itself appears small or routine.

Investors should independently verify investment platforms, avoid unsolicited investment offers distributed through messaging apps and carefully examine every wallet approval before signing.

Ukrainian authorities said the investigation remains ongoing. Police are working to identify additional members of the network, locate further victims and establish the total financial damage caused by the scheme.

Tagged:

Leave a Reply

Your email address will not be published. Required fields are marked *