Ukraine has dismantled a network of fake cryptocurrency investment platforms that allegedly stole digital assets from victims in more than 20 countries, with investigators so far identifying 62 people affected.
The operation reportedly generated turnover of up to $1m (£750,000) a month at its peak. More than 46 Ukrainians were recruited to work across the network, while authorities continue to establish the full number of participants, victims and the value of cryptocurrency stolen.
Ukrainian police carried out 34 searches in Kyiv and the surrounding region, seizing more than 100 computers, over 100 mobile phones, 79 SIM cards, a GSM gateway, cash, documents and 15 vehicles.
The National Police of Ukraine said the investigation was conducted by its Main Investigation Department in cooperation with the Security Service of Ukraine and the Office of the Prosecutor General. Several offices linked to the operation had been set up in Kyiv and the surrounding area.
Investigators said a 25-year-old IT specialist organised the network.
Fake profits shown to crypto investors
The group created websites that were designed to resemble genuine cryptocurrency investment platforms. Potential customers were directed to the sites through advertising posted on Telegram and were offered apparently profitable opportunities to invest in crypto projects.
People who registered were told to connect a cryptocurrency wallet and transfer funds to the platform. Once the deposits had been made, members of the network manually created the appearance of successful trading.
Victims could see their balances increasing on online dashboards, but police said the investment activity was fabricated. Developers maintained the websites’ technical infrastructure and worked to keep them available when attempts were made to block access.
Other members of the organisation dealt with customers in offices and provided security for the operation.
The alleged fraud escalated when victims tried to withdraw their money. Their requests were blocked and they were told that an additional verification process was needed before funds could be released.
They were then instructed to connect their main cryptocurrency wallet and authorise a small test transaction to show that the platform was functioning correctly.
According to investigators, the websites contained a wallet drainer. The malicious software used the authorisation to transfer cryptocurrency from the connected wallet to addresses controlled by the network. After the assets had been moved, victims lost access to the investment platform.
The technique is associated with approval phishing, in which users unknowingly give an attacker-controlled smart contract permission to transfer their tokens. Such attacks can rely on token approvals, permit signatures and other blockchain authorisations, without the attacker needing to obtain the wallet owner’s private key.
A similar method was reported in August, when a Hyperliquid user lost about 550,000 USDC after visiting a fraudulent website promoted through a Google advertisement. Security firm Salus later linked that fake Hyperliquid website to infrastructure connected with the Inferno drainer ecosystem.
Salus said the operation involved malicious scripts, tools for generating approval commands, automated draining, cross-chain withdrawals and systems for bringing stolen funds together. The Ukrainian network used a different investment pitch, but investigators said the victims were likewise persuaded to authorise a transaction before their assets were taken.
Victims’ personal data also collected
The fake platforms gathered more than cryptocurrency. Ukrainian authorities said registration and verification processes collected passport details, telephone numbers, email addresses, account logins, passwords and photographs.
The 62 victims identified so far were from more than 20 countries. They included citizens of Germany, Poland, Lithuania, Latvia, Spain, France, the UK, Canada and Israel.
Investigators are examining information recovered from the network’s technical infrastructure to determine whether further victims can be identified and how much cryptocurrency was transferred through the websites.
Server equipment used by the group was traced to the Netherlands. Authorities gained access to a database held there containing information about victims, including wallet addresses and the amounts allegedly taken from individual users.
The database also included internal correspondence between members of the network and records explaining how the fraudulent platforms operated. Investigators said access to the material helped them track the organisation across several countries and identify people who had used the websites.
Seized vehicles and property
Police searched homes, offices and vehicles as part of the investigation. Alongside the computers and phones, officers recovered 79 SIM cards, a GSM gateway, cash and documents believed to be connected with the operation.
Investigators said some vehicles and real estate used by members of the network had been registered in the names of suspects’ wives and other relatives. The alleged organiser travelled with armed guards.
The criminal proceedings are being conducted under Part 5 of Article 190 of Ukraine’s Criminal Code, which covers fraud. Authorities have not yet released a final estimate of the losses because the investigation into the network and its victims is continuing.
The case comes amid a series of international operations against online investment fraud, cryptocurrency-related social engineering and money laundering.
INTERPOL said in August that Operation Jackal IV led to 58 arrests and the identification of 263 suspects after authorities in 22 countries targeted investment scams, romance fraud and connected money-laundering networks. South African authorities seized $2.67m and blocked 257 bank accounts, while Romanian police arrested 11 suspects in an investment scheme believed to involve about €143m.
In July, a wider INTERPOL operation, Operation First Light, resulted in 5,811 arrests across 97 countries and territories. More than $293m in illicit assets was intercepted, over 31,000 bank accounts were blocked and more than 142,000 victims were identified. The operation targeted investment fraud, romance scams, impersonation and other forms of social engineering.
Investigators also found cryptocurrency laundering involving several digital assets and cross-chain swaps. INTERPOL said one wallet connected to an investigation in Thailand had processed more than $122.5m over a 10-month period.
A separate UK-led operation involving authorities in the United States and Canada froze more than $12m in suspected scam proceeds earlier this year and identified more than 20,000 potential victims. That investigation focused on approval-phishing schemes in which people were persuaded to sign malicious blockchain authorisations allowing scammers to transfer cryptocurrency from their wallets.
Ukraine is also developing procedures for managing digital assets recovered in criminal investigations. In June, authorities moved more than $8.3m in seized USDT to a state-managed wallet. It was the first time confiscated cryptocurrency had been placed under direct state management.
The Royal United Services Institute has estimated that stronger systems for tracing, seizing and managing illicit cryptocurrency could help Ukraine recover at least $10bn in stolen funds and lost tax revenue.
Ukrainian police said investigators were continuing to identify all those involved, locate additional victims and calculate the total value of cryptocurrency allegedly stolen through the fake platforms.
