Ukraine’s National Police and Security Service said Sept. 1 that they had dismantled a network of fake cryptocurrency investment platforms operating out of Kyiv, an operation investigators say generated up to $1 million a month and defrauded at least 62 victims across more than 20 countries.
The incident shows how modern crypto theft is increasingly moving away from breaking into wallets and toward manipulating the person holding the wallet.
How did the operation begin?
The investigation suggests this was built to look like a legitimate investment business rather than an obvious cyberattack.
The operators allegedly used Telegram channels to promote supposedly profitable cryptocurrency projects. Potential victims were then directed to websites designed to look like real investment platforms.
Once registered, users could see trading activity and apparently growing balances but those profits were not real.
According to Ukrainian investigators, members of the operation manually simulated financial activity on the platforms, giving victims the impression that their investments were increasing.
A victim who sees $1,000 become $1,500 on a professional-looking investment dashboard is more likely to believe the platform is working.
When victims attempted to withdraw their supposed profits, the platform allegedly blocked the withdrawal and gave them another instruction, connect their main cryptocurrency wallet and approve what appeared to be a small test transaction.
That was the moment the investment scam became a wallet attack.
The “test transaction” was allegedly the real weapon
A wallet drainer does not necessarily need a criminal to steal someone’s seed phrase or private key.
Instead, it can exploit the permissions created when a user approves a malicious transaction.
Chainalysis describes approval phishing as a technique in which victims are manipulated into signing a transaction that gives an attacker permission to move assets from their wallet. The transaction can look harmless to the victim while giving the attacker much greater control than expected.
That appears to be the central idea behind the Ukrainian operation.The victim thought they were confirming a small transaction.
The software allegedly treated that approval as permission to transfer assets.The result could be a wallet emptied almost immediately.
The attacker does not always have to defeat the wallet’s security.Sometimes the attacker only needs to convince the owner to use that security against themselves.
Why the fake profits mattered
The drainer was only one part of the operation.The psychological manipulation came first.
The victim had already been shown apparently successful trades. The platform had already created the expectation of profit. By the time the withdrawal stage arrived, the victim was not interacting with an obviously suspicious website.
They were trying to collect money they believed they had already earned.
That makes the final transaction easier to sell.
This is why cybersecurity researchers increasingly describe these attacks as a combination of social engineering and technical exploitation, rather than simply hacking.
Chainalysis says investment scams increasingly overlap with impersonation, phishing and wallet-focused attacks. Its 2026 research estimates that crypto scams and fraud generated at least $14 billion in on-chain activity in 2025, with the figure potentially rising above $17 billion as more illicit addresses are identified.
Approval phishing alone has become a major problem. Chainalysis said its investigators have identified more than $2.7 billion lost to approval-phishing schemes since May 2021.
So the Ukrainian case is not an isolated technical trick.
It fits into a much larger change in how crypto criminals operate.
The operation looked more like a company than a small scam
This may be the most revealing part of the investigation.
Ukrainian authorities say the organiser recruited more than 46 people and established several offices in Kyiv and the surrounding region.
Different people allegedly performed different jobs.
Some built and maintained the fake investment platforms. Others communicated with potential victims. Others handled office administration and security.
That structure suggests something closer to an organised fraud business than an individual hacker working from a laptop.
It also explains how an operation could target people in more than 20 countries.
One person does not need to find every victim.
One technical team can maintain the infrastructure.Another group can generate leads.Another can communicate with victims.
The technology effectively becomes the back office of the scam.
And that is where the case becomes more worrying.
The investigation may have uncovered only part of the operation
Authorities have identified 62 victims so far, including people from Germany, Poland, Lithuania, Latvia, Spain, France, the United Kingdom, Canada and Israel.
But 62 victims should not automatically be treated as the final number.
The investigation is still ongoing, and Ukrainian authorities have not publicly disclosed the total amount actually stolen from victims. They have described the operation’s peak monthly turnover as up to $1 million, which is not the same thing as proving that $1 million was stolen every month.
A turnover figure describes the scale of activity investigators believe passed through the operation.It does not establish the final amount of losses.
The number of victims could also increase as investigators examine the seized equipment and server infrastructure.
What investigators found could be more important than the raid itself
One of the most significant breakthroughs was access to infrastructure in the Netherlands.
Reports say investigators obtained a database containing victim information, wallet addresses, amounts allegedly stolen and internal communications.
That could give investigators something far more valuable than a list of computers.
It could provide a map of the operation.
Which wallets received the funds?
Where did those funds go afterwards?
Which people communicated with victims?
Which platforms were connected to the same operators?
Were there other websites?
Were there additional victims?
And did the same wallets receive funds from other scams?
Those questions could determine whether this was a single criminal operation or one part of a wider network.
Why the personal data could become the next problem
The alleged theft did not stop at cryptocurrency.
Investigators say the platforms also collected passport information, phone numbers, email addresses, login credentials, passwords and photographs.
A victim who loses cryptocurrency loses money. A victim whose passport information and login credentials are also exposed may face a longer-term problem.
Those details could potentially be reused for identity fraud, account takeover or additional phishing attacks.
This means investigators may eventually have to follow two different trails, the movement of the cryptocurrency and the movement or use of the victims’ personal information.
What could happen next?
The immediate investigation is not finished.
Ukrainian authorities say the investigation remains ongoing, and suspects face potentially severe penalties if charged and convicted. The authorities have also indicated that the process of formally naming suspects in the case was still pending when the initial announcement was made.
The next important development could therefore come from the digital evidence rather than another dramatic raid.
Investigators may identify additional victims.They may connect more wallets to the operation.They may discover other platforms or criminal groups.
And if the wallet addresses used by the suspects can be traced to exchanges or other identifiable services, investigators could potentially attempt to freeze or recover some of the stolen assets.
Blockchain’s transparency can help here.
Unlike cash, cryptocurrency transactions leave a public record. The challenge is connecting those addresses to real people and following the money as criminals move it between wallets, exchanges, decentralised platforms and other services.
Chainalysis says law-enforcement agencies have become increasingly capable of tracing and seizing crypto linked to criminal activity, even as criminals adapt their laundering methods.
Could this type of scam become more dangerous?
Probably.
Not necessarily because wallet drainers themselves are new, but because criminals are combining them with increasingly convincing social engineering.
The Ukrainian case combines several ingredients:
A fake investment opportunity.
Fabricated profits.
Telegram-based recruitment.
Professional-looking websites.
Human operators.
A malicious wallet transaction.
And the collection of personal information.
The broader crypto-crime data suggests the same direction. Chainalysis found that AI-enabled scams were significantly more profitable than scams without an observed AI connection, while impersonation scams grew dramatically in 2025.
That means future operations may not simply have better drainers.
They could have better conversations with victims, more convincing websites, AI-generated customer-service agents and more sophisticated impersonation.
The technology may become harder to recognise.
The bigger question for crypto security
The obvious lesson from Ukraine is simple, never approve a transaction you do not understand.
The deeper problem is that cryptocurrency systems often place an enormous amount of responsibility on the user.
A bank customer may have a bank investigate a suspicious transfer.A crypto user may simply sign one transaction and discover moments later that the assets are gone.
The blockchain can prove where the funds went.It cannot necessarily reverse the decision.That is why approval phishing is so effective.The system may technically be doing exactly what the user authorised.
The problem is that the user did not understand what they were authorising.
And that raises a bigger question.
If criminals can build an entire investment business around convincing people to approve the transaction that drains their own wallets, is crypto security still focused too heavily on protecting the wallet and not enough on protecting the decision made before the wallet is used?
The Ukrainian case suggests that the next major battle in crypto security may not be about breaking encryption.
It may be about stopping criminals from convincing people to open the door themselves.