BTCETHBNBSOLXRPUSDCTRXADADOGE
Data by CoinGecko
Scam WatchBearish

Police Dismantle $1M Monthly Crypto Drainer Syndicate

Authorities in Ukraine have shut down a sprawling network of fraudulent digital asset investment platforms that generated up to $1 million in monthly turnover by utilizing wallet drainers.

Organized by a 25-year-old information technology specialist, the syndicate maintained multiple offices in and around Kyiv. The Security Service of Ukraine, working alongside the National Police and the Office of the Prosecutor General, found that the operation recruited more than 46 Ukrainian nationals to staff the facilities, communicate with targets, and provide security.

The scheme initiated contact with prospective victims through Telegram advertisements. Users were directed to register on platforms designed to mimic legitimate investment websites and instructed to deposit cryptocurrency. Once the funds were transferred, employees manually fabricated trading activity on user dashboards to simulate growing account balances.

The theft escalated when users attempted to withdraw their digital assets. Operators blocked the requests, claiming a verification procedure was necessary before funds could be released. Victims were instructed to connect their primary wallets and authorize a small test transaction. Instead of verifying the account, this authorization utilized malicious approval phishing to execute a wallet drainer script, allowing attackers to move the tokens without obtaining the victims' private keys.

After the assets were siphoned, users lost all access to the investment platform. The network also harvested sensitive personal data during its registration process, collecting passport information, photographs, passwords, email addresses, and phone numbers.

Tracing the Infrastructure

Police Dismantle $1M Monthly Crypto Drainer Syndicate
Organized by a 25-year-old information technology specialist, the syndicate maintained multiple offices in and around Kyiv.

Investigators tracked the syndicate's server equipment to the Netherlands. Accessing a database stored there, authorities uncovered internal communications, operational records, and extensive victim data, including cryptocurrency wallet addresses and specific amounts stolen.

The recovered data has so far allowed authorities to identify 62 victims across more than 20 countries. Affected individuals include citizens of the United Kingdom, Canada, Israel, France, Spain, Germany, Poland, Lithuania, and Latvia. Officials note that the victim count could rise as they continue analyzing the offshore server data.

The technical mechanism mirrors other recent approval phishing attacks. Security firm Salus noted a similar event in August when a fraudulent Hyperliquid website, promoted via Google advertisements, drained approximately 550,000 USDC from a user. Salus linked that specific infrastructure to the broader Inferno drainer ecosystem, which utilizes automated draining scripts and cross-chain withdrawals.

Global Enforcement Context

The Ukrainian bust follows a string of massive international law enforcement actions targeting cryptocurrency-linked social engineering and investment fraud. In July, INTERPOL reported that Operation First Light led to 5,811 arrests across 97 countries and territories, intercepting $293 million in illicit assets. During that operation, investigators identified a wallet tied to a Thai investigation that had processed over $122.5 million during a 10-month period.

Subsequent enforcement in August under INTERPOL's Operation Jackal IV targeted related money laundering networks across 22 countries. That sweep resulted in 58 arrests and 257 blocked bank accounts, with South African authorities seizing $2.67 million and Romanian police apprehending 11 suspects connected to an estimated €143 million investment scheme.

← All stories