Ukrainian authorities say they have dismantled a network of fake crypto investment platforms that targeted users in more than 20 countries. Investigators have identified 62 victims so far and said the operation involved more than 46 Ukrainian citizens.
According to police, the scheme relied on fraudulent websites that showed fabricated profits while secretly using wallet-draining software. The investigation is still ongoing, and authorities have not yet given a final figure for the total amount of cryptocurrency stolen.
How the alleged scheme worked
Investigators said the platforms were designed to look like legitimate investment services. Victims were persuaded to approve what appeared to be a small test transaction, but hidden software then allowed the operators to move cryptocurrency from their wallets.
Police said the account growth shown on the sites was not real. Operators allegedly created transactions manually and changed account balances to make it appear that investments were performing well, a tactic intended to build trust and encourage further deposits.
Authorities also said the group collected extensive personal information during sign-up and identity verification. That included passport data, phone numbers, email addresses, login credentials, passwords and photographs, potentially giving the operators access not only to digital assets but also to information that could be used in other forms of fraud.
Organization and international reach
Investigators identified the alleged lead organizer as a 25-year-old IT specialist. Police said he recruited more than 46 Ukrainians and oversaw several offices in Kyiv and the surrounding region.
According to the investigation, the operation assigned different roles to participants. Technical staff built and maintained the fake platforms, while other members contacted prospective victims, managed offices or handled security.
Authorities said victims were located in Germany, Poland, Lithuania, Latvia, Spain, France, the U.K., Canada, Israel and other countries, underscoring the cross-border nature of the case.
Servers traced to the Netherlands
A key development came when investigators followed the operation’s technical infrastructure outside Ukraine. Authorities said they traced server equipment to the Netherlands and gained access to a database linked to the scheme.
Police said the database contained victim lists, wallet addresses, amounts believed to have been stolen, internal communications and operational details about the fake platforms. That evidence appears to have helped authorities map out how the network functioned and identify additional participants.
Searches, seizures and what comes next
Ukrainian police and the Security Service of Ukraine, or SBU, carried out 34 searches in Kyiv and the surrounding region. During those raids, authorities seized more than 100 computers, more than 100 mobile phones, 79 SIM cards, documents, cash and 15 vehicles.
The case remains under investigation under Ukraine’s fraud laws. Police said they are continuing to identify other people who may have been involved, locate additional victims and determine the full amount of cryptocurrency taken through the alleged scheme.
For now, the confirmed next step is the continuation of that investigation. While authorities have outlined the structure of the operation and recovered evidence from offices and servers, they have not yet released a final estimate of losses or a complete accounting of everyone affected.
Source: www.coindesk.com