REF-2026-0127 · Anonymised case record

    International Cryptocurrency Scam

    3 min read · Last updated

    A social-engineering operation ran across messaging platforms and a cloned trading interface, collecting deposits from victims in three continents.

    Executive Summary

    Contact was initiated over messaging platforms and moved to a cloned trading interface that mirrored a legitimate brand. Deposits were requested in stablecoins, and further deposits were requested as release fees once withdrawals were attempted.

    SEQRIA reconstructed the deposit flow, attributed downstream movement to service categories, and produced an evidence package for exchange compliance teams and law enforcement intake.

    Investigation Scope

    Scope was limited to technical reconstruction and evidentiary documentation.

    • Reconstruction of all deposits made by the affected parties
    • Downstream fund-flow tracing to the first attributable service
    • Preservation of the cloned interface and the messaging record
    • Structured reporting for exchange compliance submission

    Technical Challenges

    Deposits crossed several chains, which broke a single-ledger view of the flow. Bridge events had to be matched on both sides using value, timing and contract data rather than a shared transaction identifier.

    The cloned interface was taken offline during the engagement, which made early preservation the difference between a documented and an undocumented claim.

    Investigation Methodology

    The engagement followed a fixed sequence so that each finding could be traced back to the artefact that produced it.

    • Intake and normalisation of victim-supplied transaction identifiers
    • Verification of every identifier against the relevant public ledger
    • Hop-by-hop tracing with documented heuristics and stated confidence levels
    • Cross-referencing of infrastructure indicators across affected parties

    Blockchain Analysis

    Deposits were traced from victim wallets to a receiving layer of short-lived addresses, then consolidated. Consolidation wallets showed a repeating operational rhythm consistent with a single controlling process rather than independent actors.

    Cross-chain movement was reconstructed by pairing outbound bridge deposits with inbound mints on the destination chain, using amount, fee and timing correlation. Each pairing was recorded with its confidence basis.

    Evidence Collection

    Interface material, messaging exports and transaction data were preserved with hashes and acquisition notes before any third-party contact was made.

    • Rendered and raw captures of the cloned platform prior to takedown
    • Structured exports of the messaging record with metadata retained
    • Ledger exports for every traced transaction with block confirmations

    Findings

    The investigation documented a single operational cluster behind interfaces presented to victims as unrelated brands, and established that consolidated funds reached deposit addresses attributable to centralised services on two chains.

    Where tracing depended on heuristics, the report stated the heuristic and its limitations rather than presenting the result as certain.

    Outcome

    Compliance-ready submissions were delivered for each identified service, and a consolidated report was provided for law enforcement intake in the victims' home jurisdictions.

    No outcome is promised in any engagement. The deliverable is a documented, verifiable evidentiary record.

    Lessons Learned

    Speed of preservation determines what can later be proven. Interfaces disappear; ledgers do not.

    • Capture the platform and the conversation before reporting it anywhere
    • Never send an additional payment to release a balance
    • Record the exact transaction hashes rather than screenshots of balances

    Frequently asked questions

    Can cross-chain movement still be traced?
    In most cases yes, but the link between chains is reconstructed rather than read directly. Bridge events are matched on value, timing and contract behaviour, and the confidence of each match must be stated explicitly.
    Is a screenshot of the platform enough evidence?
    A screenshot is weak evidence on its own. Preserved captures with timestamps, acquisition notes and hashes carry substantially more weight with institutions.
    What happens after funds reach an exchange?
    The exchange becomes the relevant point of institutional escalation. Whether it acts is determined by its compliance obligations and by legal process, not by the investigator.
    Author
    SEQRIA Research Team emblem
    SEQRIA Research TeamInvestigative research unit, SEQRIA
    • Cyber Intelligence
    • Blockchain Investigations
    • Digital Forensics

    The SEQRIA Research Team is the investigative research unit of SEQRIA, specialising in cyber intelligence, blockchain investigations and digital forensics.

    Its work focuses on digital asset investigations, blockchain transaction analysis, cyber incident investigations and technical evidence collection. Published material is reviewed internally before release.

    About the research team

    Related case studies

    Request Confidential Consultation

    SEQRIA provides technical investigation, forensic analysis and evidentiary documentation. Outcomes are never guaranteed. Case intake is confidential and handled by email.

    cybersec@securida.info
    Intelligence Center