International Cryptocurrency Scam
3 min read · Last updated
A social-engineering operation ran across messaging platforms and a cloned trading interface, collecting deposits from victims in three continents.
Executive Summary
Contact was initiated over messaging platforms and moved to a cloned trading interface that mirrored a legitimate brand. Deposits were requested in stablecoins, and further deposits were requested as release fees once withdrawals were attempted.
SEQRIA reconstructed the deposit flow, attributed downstream movement to service categories, and produced an evidence package for exchange compliance teams and law enforcement intake.
Investigation Scope
Scope was limited to technical reconstruction and evidentiary documentation.
- ›Reconstruction of all deposits made by the affected parties
- ›Downstream fund-flow tracing to the first attributable service
- ›Preservation of the cloned interface and the messaging record
- ›Structured reporting for exchange compliance submission
Technical Challenges
Deposits crossed several chains, which broke a single-ledger view of the flow. Bridge events had to be matched on both sides using value, timing and contract data rather than a shared transaction identifier.
The cloned interface was taken offline during the engagement, which made early preservation the difference between a documented and an undocumented claim.
Investigation Methodology
The engagement followed a fixed sequence so that each finding could be traced back to the artefact that produced it.
- ›Intake and normalisation of victim-supplied transaction identifiers
- ›Verification of every identifier against the relevant public ledger
- ›Hop-by-hop tracing with documented heuristics and stated confidence levels
- ›Cross-referencing of infrastructure indicators across affected parties
Blockchain Analysis
Deposits were traced from victim wallets to a receiving layer of short-lived addresses, then consolidated. Consolidation wallets showed a repeating operational rhythm consistent with a single controlling process rather than independent actors.
Cross-chain movement was reconstructed by pairing outbound bridge deposits with inbound mints on the destination chain, using amount, fee and timing correlation. Each pairing was recorded with its confidence basis.
Evidence Collection
Interface material, messaging exports and transaction data were preserved with hashes and acquisition notes before any third-party contact was made.
- ›Rendered and raw captures of the cloned platform prior to takedown
- ›Structured exports of the messaging record with metadata retained
- ›Ledger exports for every traced transaction with block confirmations
Findings
The investigation documented a single operational cluster behind interfaces presented to victims as unrelated brands, and established that consolidated funds reached deposit addresses attributable to centralised services on two chains.
Where tracing depended on heuristics, the report stated the heuristic and its limitations rather than presenting the result as certain.
Outcome
Compliance-ready submissions were delivered for each identified service, and a consolidated report was provided for law enforcement intake in the victims' home jurisdictions.
No outcome is promised in any engagement. The deliverable is a documented, verifiable evidentiary record.
Lessons Learned
Speed of preservation determines what can later be proven. Interfaces disappear; ledgers do not.
- ›Capture the platform and the conversation before reporting it anywhere
- ›Never send an additional payment to release a balance
- ›Record the exact transaction hashes rather than screenshots of balances
Frequently asked questions
- Can cross-chain movement still be traced?
- In most cases yes, but the link between chains is reconstructed rather than read directly. Bridge events are matched on value, timing and contract behaviour, and the confidence of each match must be stated explicitly.
- Is a screenshot of the platform enough evidence?
- A screenshot is weak evidence on its own. Preserved captures with timestamps, acquisition notes and hashes carry substantially more weight with institutions.
- What happens after funds reach an exchange?
- The exchange becomes the relevant point of institutional escalation. Whether it acts is determined by its compliance obligations and by legal process, not by the investigator.

- Cyber Intelligence
- Blockchain Investigations
- Digital Forensics
The SEQRIA Research Team is the investigative research unit of SEQRIA, specialising in cyber intelligence, blockchain investigations and digital forensics.
Its work focuses on digital asset investigations, blockchain transaction analysis, cyber incident investigations and technical evidence collection. Published material is reviewed internally before release.
About the research teamRelated case studies
Request Confidential Consultation
SEQRIA provides technical investigation, forensic analysis and evidentiary documentation. Outcomes are never guaranteed. Case intake is confidential and handled by email.
cybersec@securida.info