The numbers on the display kept rising.
For people utilizing a network of portals presently under scrutiny in Ukraine, this signified that their capital was expanding.
Yet, those increasing figures merely fostered a false sense of security. When the moment arrived to cash out, the situation shifted entirely.
According to Ukrainian officials, once the prospective investors tried to withdraw funds, these portals prompted individuals to link their primary digital wallets. Upon granting this permission, the connection was exploited to authorize what seemed to be a minor test transaction.
Abruptly, their assets vanished.
Ukrainian law enforcement reported that the scheme utilized a cryptocurrency drainer embedded within the web pages, so granting access to the users’ accounts automatically transferred their capital to addresses controlled by the perpetrators.
Once the funds moved, the targeted individual was locked out of the system. Ukrainian law enforcement stated they dismantled the syndicate, which allegedly targeted individuals across more than 20 nations. Detectives have identified 62 victims thus far, and the Security Service of Ukraine (SBU) reported that the operation’s monthly turnover could hit $1 million.
The manufactured profits shown prior to the theft formed a core component of the plot. Officers noted that administrators manually generated transactions and altered user balances to create the illusion of flourishing investments.
The portals pursued more than just digital currency. Throughout registration and identity verification procedures, the administrators gathered passport details, phone numbers, email addresses, login credentials, passwords, and photographs, according to authorities.
This granted the alleged operation access to both crypto assets and private data that could potentially facilitate additional fraudulent schemes.
Investigators indicated that the primary architect, a 25-year-old software developer, enlisted upwards of 46 Ukrainian nationals and managed multiple workspaces throughout Kyiv and the neighboring district. Technical personnel developed and supported the fraudulent websites while working to keep them online. Other personnel contacted prospective victims, oversaw the facilities, or provided physical security.
Officials stated that the victims hailed from Germany, Poland, Lithuania, Latvia, Spain, France, the United Kingdom, Canada, Israel, and additional countries.
Infrastructure clues
A major breakthrough in the inquiry stemmed from digital infrastructure located outside Ukraine.
Authorities traced server hardware utilized by the collective to the Netherlands and secured access to a database housed there. The files contained victim registries, crypto addresses, alleged theft totals, internal chats, and details regarding the operational mechanics of the fake portals.
Detectives stated that these files facilitated the reconstruction of the plot and the identification of those affected.
Ukrainian law enforcement and the SBU subsequently conducted 34 raids across Kyiv and the surrounding area. Authorities confiscated over 100 computers, upwards of 100 mobile phones, 79 SIM cards, paperwork, physical currency, and 15 automobiles.
The inquiry remains active under Ukrainian fraud legislation.
Law enforcement continues working to pinpoint other participants, uncover additional victims, and calculate the total amount of cryptocurrency stolen by the syndicate.
Originally published at https://www.coindesk.com/business/2026/09/06/ukrainian-police-took-down-a-crypto-scam-that-stole-up-to-usd1-million-a-month.