Ukrainian police and the Security Service of Ukraine (SBU) dismantled a crypto fraud network that used fake investment platforms and hidden wallet-draining software to steal from victims in more than 20 countries. Investigators put the operation’s turnover at up to $1 million a month.
The scheme worked on a simple deception. Victims saw balances climbing on screen and took it as proof their investments were growing. Ukrainian authorities said operators manually created transactions and adjusted account balances to fake that growth. When users tried to withdraw, the platforms asked them to connect their main crypto wallets and approve what looked like a small test transaction.
That approval was the trap. A crypto drainer hidden inside the websites then moved the users’ funds to wallets controlled by the operators. Once the transfer went through, the victim was locked out of the platform entirely, with no way back in and no customer support to appeal to.
A structured operation
Police described the network as an organized business rather than a loose crew of hackers. The lead organizer, a 25-year-old IT specialist, recruited more than 46 Ukrainian citizens and ran several offices in Kyiv and the surrounding region. Staff had defined roles: technical teams built and maintained the fake websites, others contacted potential victims by phone and message, and some handled office management and security.
The platforms collected more than crypto. During registration and identity checks, operators gathered passport information, phone numbers, email addresses, login credentials, passwords and photographs. That gave the group both digital assets and personal data that could feed further fraud, including identity theft and follow-up scams targeting the same victims a second time.
Investigators identified 62 victims so far, spread across Germany, Poland, Lithuania, Latvia, Spain, France, the UK, Canada, Israel and other countries. The SBU said the investigation remains open and the full scale of the theft is still being tallied, since many victims may never report their losses.
The raids
A key breakthrough came when investigators traced the group’s server infrastructure outside Ukraine, to the Netherlands. There they gained access to a database containing victim lists, crypto wallet addresses, amounts allegedly stolen, and internal communications between the operators. That database gave police a map of the entire operation, from which countries the victims came from to how the offices divided their work.
Ukrainian police and the SBU then carried out 34 searches in Kyiv and the surrounding region. Seizures included more than 100 computers, more than 100 mobile phones, 79 SIM cards, documents, cash and 15 vehicles. The case proceeds under Ukraine’s fraud laws, and police are still working to identify other participants, locate additional victims and determine the total cryptocurrency stolen.
| Detail | Finding |
|---|---|
| Monthly turnover | Up to $1 million |
| Victims identified | 62, across 20+ countries |
| Suspects involved | More than 46 Ukrainians |
| Searches conducted | 34, in Kyiv region |
| Devices seized | 100+ computers, 100+ phones, 79 SIM cards |
Part of a larger pattern
The case fits a broader pattern across the region. Crypto investment scams remain one of the most profitable forms of online fraud because they exploit trust and the appearance of returns rather than technical flaws in the blockchain itself. Ukraine’s cyberpolice have run a string of similar takedowns. Earlier this year, the National Police dismantled a fake “Ukrainian Financial Academy” that defrauded nearly 1,000 Ukrainians of more than $1.1 million through promoted crypto courses on Facebook and Instagram. Some of those victims were pressured into taking out loans or investing savings set aside for homes and medical treatment.
Cross-border cooperation made this week’s raid possible. Ukrainian investigators noted that an upgraded enforcement network allowed them to track operations that spanned multiple jurisdictions, something that was far harder when the same groups operated a few years ago. Server infrastructure in the Netherlands, operators in Kyiv, and victims across three continents now sit inside a single case file.
For crypto users, the lesson from the SBU’s writeup is narrow but practical. A withdrawal request asking you to connect your primary wallet, especially one framed as a test transaction, is the moment to stop and question everything. A legitimate platform does not need active approval to move funds out of a wallet it should never touch. Wallet drainers depend on that one signature, and denying it breaks the entire scheme.

discussion