Article is online

Ukraine Shuts Down Kyiv-Based Crypto Draining Ring That Netted Up to $1M Monthly

Ukraine Shuts Down Kyiv-Based Crypto Draining Ring That Netted Up to $1M Monthly

Highlights



Ukraine’s National Police and Security Service dismantled a network of fraudulent crypto investment platforms operating from Kyiv that targeted victims in over 20 countries. Investigators have so far identified 62 victims and say the scheme at its peak moved up to $1 million per month. Operators lured users via Telegram, faked trading dashboards, blocked withdrawals, and tricked users into approving a "test" transaction that allowed a hidden drainer to seize wallet funds. Authorities seized numerous devices and continue to identify suspects and victims.


Sentiment Analysis




  • The overall sentiment of this report is negative, reflecting the serious financial harm and organized criminality revealed by the investigation. The tone emphasizes law enforcement action and recovery efforts rather than sensationalism. The story highlights cross-border victimization and the technical sophistication of the fraudsters, which contributes to concern among potential crypto users and regulators. Authorities are portrayed as proactive, conducting searches, seizing assets, and pursuing legal action—providing some reassurance.



    75%





Article Text


Ukraine’s National Police together with the Security Service announced they had dismantled a fraudulent crypto investment network based in Kyiv that targeted people in more than 20 countries. According to investigators, the operation ran multiple fake trading platforms and recruited dozens of local operatives to staff offices, manage communications, and maintain the sites. Law enforcement identified 62 victims so far, including citizens of Germany, Poland, Lithuania, Latvia, Spain, France, the United Kingdom, Canada and Israel. The organizers are accused of using coordinated technical and social-engineering tactics to steal cryptocurrency from users who believed they were investing.



The scheme reportedly began with outreach on Telegram, where the group promoted seemingly lucrative crypto projects. Interested users were directed to register on the platforms and to connect their crypto wallets. To create the impression of real trading, staff manually manipulated account dashboards so balances appeared to grow. When victims attempted to withdraw funds, the platforms blocked withdrawals and instructed victims to approve a small verification or "test" transaction to demonstrate that withdrawals were functioning. That approval activated a hidden drainer embedded in the site, which transferred tokens to addresses controlled by the criminals and locked victims out of their wallets.



Investigators traced the group’s server infrastructure to the Netherlands and were able to access a database containing details of victims, wallet addresses, amounts taken, internal communications, and operational records. The database also held personally identifying information harvested during registration and verification processes, including passport scans, phone numbers, email addresses, login credentials, and photographs. These records furnished investigators with evidence of the scheme’s scope and the identities of those involved.



Police executed 34 search warrants across Kyiv and nearby areas, seizing more than 100 computers and over 100 mobile phones, along with 79 SIM cards, a GSM gateway, cash, and 15 vehicles. Some assets appeared registered to relatives of suspects. Authorities described the alleged ringleader as a 25-year-old IT specialist and said the operation employed more than 46 Ukrainians in various roles, from development to phone support and physical security. The organizer reportedly operated with armed guards.



The case has been opened under Part 5 of Article 190 of Ukraine’s criminal code, which covers large-scale fraud. Police continue to identify additional suspects, locate more victims, and calculate the total amount stolen. The investigation follows broader efforts by Ukrainian authorities to bring seized crypto assets under state control: in June, the government moved over $8.3 million in confiscated USDT into a state-managed wallet, marking a significant precedent. Analysts have suggested that stronger controls and recovery mechanisms could help recover substantial sums lost to fraud and improve tax collection.



This incident underscores persistent risks in the cryptocurrency ecosystem: fraudulent platforms can combine convincing user interfaces, aggressive marketing on social channels, and technical methods to bypass protections and drain user funds. Users are advised to exercise caution when responding to unsolicited investment pitches, to verify platform legitimacy independently, and to avoid connecting primary wallets to unverified services. The use of a purported "test" transaction to obtain wallet approvals is a notable tactic that victims and security professionals should watch for.



Law enforcement agencies internationally continue to collaborate on cross-border cybercrime, but investigations can be complex due to jurisdictional challenges and the pseudonymous nature of many crypto transactions. The Kyiv takedown demonstrates the value of technical forensics, international cooperation, and robust investigative work in disrupting organized cyber-enabled financial crime.



Key Insights Table































Aspect Description
Scope Targets in over 20 countries with at least 62 identified victims.
Modus Operandi Fake investment platforms, manipulated dashboards, and a hidden drainer activated by a "test" transaction.
Financial Scale Reported turnover up to $1 million per month at peak.
Law Enforcement Action 34 searches, seizure of devices, SIMs, cash, and vehicles; ongoing criminal case under Ukrainian law.
Key Warning Avoid connecting primary wallets to unverified platforms and be wary of "test" transactions requesting approvals.
Last edited at:2026/9/3
#USDT

Power Trader

ZNews Columnist