Ukrainian police and the Security Service of Ukraine shut down a network of fake crypto investment platforms that stole as much as $1 million a month from victims in more than 20 countries. Investigators have identified 62 victims so far and say more than 46 Ukrainian citizens worked in the operation, which ran out of several offices in Kyiv and the surrounding region.
The platforms showed users account balances that appeared to grow over time. Operators adjusted those balances by hand to make the investments look profitable. When a victim tried to withdraw, the site asked them to connect their main crypto wallet and approve what looked like a small test transaction. A hidden wallet drainer inside the site then moved the funds to wallets controlled by the operators, and the victim was locked out of the platform within seconds.
According to CoinDesk, the scheme collected more than money. Registration and identity checks harvested passport data, phone numbers, email addresses, login credentials, passwords and photographs, material that can feed identity theft and other fraud long after the initial theft.
How investigators broke the case
The breakthrough came from infrastructure outside Ukraine. Authorities traced server equipment used by the group to the Netherlands and got access to a database stored there. It contained victim lists, wallet addresses, amounts stolen, internal communications and details on how the fake platforms operated. Those records let investigators reconstruct the scheme and identify people whose money had vanished months earlier.
Police and the SBU then carried out 34 searches across Kyiv and the region. They seized more than 100 computers, more than 100 phones, 79 SIM cards, documents, cash and 15 vehicles. The National Police of Ukraine announced the takedown on its own site at the start of September, days before the full details of the drainer mechanism became public.
An organized operation, not a lone actor
Investigators identified a 25-year-old IT specialist as the lead organizer. He recruited more than 46 Ukrainians and ran several offices. Technical staff built and maintained the fake sites and kept them online. Other employees contacted potential victims, managed the offices or provided security. The division of labor looked more like a call-center business than a hacker collective, with payrolls, offices and shifts.
Victims came from Germany, Poland, Lithuania, Latvia, Spain, France, the United Kingdom, Canada, Israel and other countries. The Security Service of Ukraine said the operation turnover could reach $1 million a month, and that the total stolen is still being counted because many victims have not come forward.
Why this matters for crypto users
The case is a reminder that display balances on an unverified platform mean nothing. Operators typed the numbers themselves. The drainer pattern, where a small approval drains the whole wallet, has become standard tooling for scammers and works on any chain that supports token approvals, which is effectively all of them. A single signature is enough, and it usually looks harmless.
Ukrainian police said the investigation remains open under the country fraud laws, and they are still looking for additional people involved, more victims and a full accounting of what was taken. Anyone who signed approvals on an unfamiliar site can check and revoke active allowances through approval-scanning tools. The deeper protection is simpler: connect a main wallet only to platforms with an established track record, and keep trading funds in a separate wallet with no long-term holdings.
The takedown also shows how far cross-border cooperation has come. Server traces in the Netherlands, a seized database and coordinated raids across a metro area were enough to map the whole operation. Fraud networks that treat crypto as an exit route are increasingly finding that the trail does not end at the exchange, and that office-based operations leave physical evidence a purely online scheme would not.

discussion