The National Police of Ukraine, the Security Service of Ukraine, and the Prosecutor General’s Office have dismantled a fake crypto investment syndicate in Kyiv that generated up to $1 million per month. This cross-border criminal operation targeted users in more than 20 countries, with 62 initial victims identified across Germany, Poland, Lithuania, Latvia, Spain, France, the UK, Canada, and Israel.
Masterminded by a 25-year-old IT specialist, the structured fraud network recruited at least 46 local Ukrainian citizens. Law enforcement agencies are continuing their investigation to track down additional suspects and victims.
Manual Simulations Behind the Scenes
The ring’s modus operandi began with Telegram advertisements promoting crypto investment opportunities. Interested users were directed to connect their crypto wallets to a platform and deposit funds.
The profit figures displayed on the user dashboard were not tied to actual asset price movements. Syndicate employees manually faked investment activity behind the scenes, creating the illusion of a growing portfolio to lure victims into depositing more capital.
The asset-draining phase began when victims attempted to withdraw their funds. The system immediately blocked withdrawal requests and required victims to complete an additional verification process. Under the pretext of identity verification, victims were prompted to connect their primary wallet and approve a small nominal transaction.
Malicious Contract Approval Trap
That verification step served as the trigger for a wallet drainer attack. Victims fell prey to approval phishing, where their transaction signature granted a malicious contract permission to transfer all remaining tokens in the wallet. Users unwittingly surrendered full access to their own assets.
Beyond stealing tokens, the fraudulent platform also harvested private data. The syndicate collected passport photos, phone numbers, email addresses, and login credentials from victims.
Digital Footprint on Dutch Servers
Investigators successfully traced the network’s technical infrastructure to servers located in the Netherlands. Dismantling the server gave investigators direct access to the operation’s core database.
From the database, police obtained a full list of victims’ crypto wallet addresses and estimated losses. The server also stored internal correspondence between members and video recordings demonstrating how the scam platform operated.
Wallet attacks like this demonstrate that modern cybercriminals do not need to breach blockchain systems. All they need is a single approval click from an unsuspecting user during an identity verification process.
Reported by crypto.news.
Also read: Hacker Drains Nearly All of Solana Aquifer TVL - Given Three Days to Take 20%
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




