Summary

  • Ukraine's National Police and Security Service announced the dismantling of a fraudulent investment network operating from Kyiv.
  • So far, 62 victims have been identified from over 20 different countries, including Germany, Poland, France, the UK, Canada, and Israel.
  • Victims were initially blocked from withdrawing funds, then coerced into approving a small "test" transaction that compromised their wallets.

Authorities in Ukraine have successfully shut down a fraudulent investment scheme that siphoned cryptocurrency from individuals across more than 20 nations, as reported by the National Police and Security Service on Tuesday.

Currently, 62 victims have been identified, hailing from countries such as Germany, Poland, Lithuania, Latvia, Spain, France, the UK, Canada, and Israel. The operation was orchestrated by a group of over 46 Ukrainians who managed multiple offices in Kyiv and nearby areas. The developers maintained the fraudulent platforms online despite attempts to block them, while others handled customer interactions and security.

“Police have put a stop to the activities of a network of fake investment platforms through which scammers stole cryptocurrency from citizens of over 20 countries,”

“Currently, police have identified 62 victims.”

🔗 Details: https://t.co/e4OZtqg0gB pic.twitter.com/QblK1EWXi8

— National Police of Ukraine (@NPU_GOV_UA) September 1, 2026

The Security Service described the mastermind of the operation as a 25-year-old IT professional, estimating the scheme's peak monthly turnover at nearly $1 million. The operation reportedly began on Telegram, where the group promoted fake but enticing crypto investment opportunities.

Individuals who registered were instructed to connect their wallets and transfer funds under the guise of investing. The staff then manually fabricated trading activity, showing inflated balances in users’ accounts.

Tracing the Funds

Withdrawal requests were systematically denied. Victims were told that to confirm the platform's legitimacy, they needed to link their primary wallet and authorize a minor test transaction. This action triggered a hidden drainer within the site, transferring the assets to wallets controlled by the scammers, effectively locking the victims out.

Investigators traced the group’s server infrastructure located in the Netherlands, which contained a database listing victims, their wallet addresses, amounts stolen, internal communications, and operational records. Additionally, registration and verification processes had captured sensitive information such as passport details, phone numbers, email addresses, usernames, passwords, and photographs.

Law enforcement conducted 34 searches in Kyiv and the surrounding areas, confiscating over 100 computers, more than 100 mobile phones, 79 SIM cards, a GSM gateway, cash, and 15 vehicles. Some of the vehicles and properties were found to be registered under the names of the suspects' spouses and relatives, and the organizer was known to travel with armed security.

The case is being prosecuted under Part 5 of Article 190 of Ukraine’s criminal code. Authorities are continuing to identify all individuals involved, additional victims, and the total amount of funds stolen.

In June, Ukraine transferred over $8.3 million in confiscated USDT into a state-managed wallet, marking the first instance of seized cryptocurrency being placed under government control. The Royal United Services Institute has estimated that stricter regulations could potentially recover at least $10 billion in stolen assets and lost tax revenue for the nation.

Daily Debrief Newsletter

Stay updated with the latest news stories, original features, podcasts, videos, and more.