Mastodon Skip to content
pulseofnations. Real News. Global Impact.
Subscribe
live markets
BTC$79,163▼ 0.82%ETH$2,494▲ 0.05%SOL$103.84▼ 2.46%TOTAL CRYPTO$2.68T▼ 3.14%S&P 5007,718.60▼ 0.23%NASDAQ26,506.99▼ 0.29%DOW53,414.25▼ 1.24%GOLD4,476.60▲ 5.53%WTI91.48▲ 18.36%BRENT96.28▲ 16.72%EUR/USD1.1629▲ 0.90%USD/JPY154.35▼ 2.56%DXY98.91▼ 1.06%

Ukraine Busts Crypto Drainer Ring Stealing $1M Monthly

Ukrainian police and the SBU shut down fake investment platforms that drained crypto from victims in over 20 countries, with 62 victims identified so far.

PartnerSurfshark VPN

Ukrainian police and the SBU security service have shut down a network of fake investment platforms that drained cryptocurrency from victims in more than 20 countries. Investigators have identified 62 victims so far and estimate the operation’s turnover at up to $1 million a month.

The scheme ran on fabricated trading dashboards. New users saw account balances that appeared to grow over time, with operators adjusting the numbers by hand to keep the illusion of returns alive. When a victim tried to withdraw, the platform asked them to connect their main crypto wallet and approve what looked like a small test transaction. A hidden wallet stealer embedded in the site then moved the funds to operator-controlled wallets and ejected the user from the platform, according to a CoinDesk report citing Ukrainian authorities.

Registration and identity checks harvested more than money. Users handed over passport details, phone numbers, email addresses, account credentials, passwords and photographs, according to the Ukrainian National Police. That data supported identity theft and follow-on fraud long after a single wallet was emptied.

“Police halted the activity of a network of fake investment platforms through which fraudsters stole cryptocurrency from citizens of more than 20 countries,” the National Police said in a statement.

Who ran it and how it fell

Investigators identified a 25-year-old IT specialist as the lead organizer. He recruited more than 46 Ukrainian citizens and ran several offices in Kyiv and the surrounding region, with staff split into builders who maintained the fake sites, agents who contacted potential victims, and handlers for office management and security. The structure resembled a small company more than a loose hacking crew, with division of labor down to a security function.

The break came from infrastructure abroad. Authorities traced server equipment used by the group to the Netherlands and obtained access to a database stored there. Records included victim lists, crypto wallet addresses, amounts stolen, internal communications and documentation of how the platforms operated. Those files let investigators reconstruct the scheme, map the money flow and identify victims country by country.

Police carried out 34 searches across Kyiv and the surrounding region, covering 23 offices and homes. Seizures listed by authorities:

Item Quantity seized
Computers More than 100
Phones More than 100
SIM cards 79
Vehicles, including Porsche, BMW and Mercedes-Benz models 15
Documents and cash Unspecified amounts

Victims across borders

Confirmed victims come from Germany, Poland, Lithuania, Latvia, Spain, France, the United Kingdom, Canada and Israel, among other countries. Police say the real number is likely higher, and the search for additional victims and for the total amount stolen continues. No suspects have been publicly named. The case remains open under Ukraine’s fraud statutes.

The platforms reached victims the ordinary way: search ads and social media promotions promising high daily returns on crypto deposits, a pattern investigators documented across the seized communications. The fake balances on screen were the retention mechanism. A victim who believes the account is compounding has every incentive to deposit more rather than withdraw, which is why the drain typically triggered only when someone finally tried to take money out.

Ukraine’s cyberpolice have built an enforcement track record on these cases. Earlier this year the service dismantled call-center rings that talked victims into fake exchange deposits, and in July it shut down a phishing-as-a-service operation renting out ready-made scam kits. The Netherlands server trace in the latest case required cross-border cooperation with Dutch hosts, and investigators described an upgraded enforcement network that made tracking a cross-border operation of this size feasible.

The drainer playbook has spread fast because it requires no theft of credentials. The victim signs the fatal transaction themselves, which leaves few traces for exchanges to flag at deposit time. Chainalysis and other analytics firms have tracked drainer gangs moving hundreds of millions of dollars a year, and the Kyiv ring’s use of small test approvals matches the standard kit.

For users the takeaway from investigators is narrow and practical: a withdrawal page asking to connect a primary wallet and sign a test approval is the exact moment a drainer strikes. Platforms that show balances rising without verifiable market data are fabricating them.

The SBU said the monthly turnover figure of up to $1 million is an estimate based on records recovered from the Dutch servers, and that work continues to map the full flow of stolen funds through exchanges and mixers.

SourcesCoinDesk, Sept 6, 2026; Ukrainian National Police statement; Security Service of Ukraine statement; FinCEN digital asset investment scam analysis, August 2026.
React to this dispatch
Share this dispatch X WhatsApp Bluesky Report an error
Written by

Founder and editor of Pulse of Nations, an independent wire service covering war, geopolitics, markets and technology.

discussion

Leave a Reply

Next dispatch DBS and Citi Settle Weekend Dollar Payment on Swift Ledger Read →