Ukrainian police and the Security Service of Ukraine (SBU) dismantled a fake crypto investment ring on Sept. 1, 2026, accused of draining wallets from at least 62 victims across more than 20 countries and generating up to $1 million a month at its peak.
Ukrainian police and the Security Service of Ukraine (SBU) said they dismantled the alleged operation after tracing its infrastructure, conducting dozens of searches and seizing computers, phones, documents, cash and vehicles.
Authorities said the crypto investment scheme was designed to make victims believe their deposits were generating profits before using access to their wallets to transfer their funds.
How the crypto investment scheme lured victims
The operation allegedly relied on a network of websites presented as legitimate investment platforms. Users were shown account balances that appeared to increase over time, creating the impression that their investments were performing well.
According to Ukrainian authorities, those gains were fabricated.
Operators allegedly created transactions manually and adjusted account balances to make the platforms appear active and profitable. The deception continued until victims attempted to withdraw their funds.
At that point, users were reportedly instructed to connect their main cryptocurrency wallets to the platforms. They were then asked to approve what appeared to be a small test transaction.
Instead, investigators said, the websites contained cryptocurrency-draining software that could use the authorization to move funds from victims’ wallets into wallets controlled by the alleged operators.
Once the cryptocurrency had been transferred, victims were locked out of the platforms.
The National Police of Ukraine announced the operation on Sept. 1, stating: “Поліцейські припинили діяльність мережі фейкових інвестиційних платформ, через які шахраї викрадали криптовалюту у громадян понад 20 країн” National Police of Ukraine.
The same police announcement said: “Наразі поліцейські встановили 62 потерпілих.” National Police of Ukraine.
The authorities said the crypto investment scheme had victims in Germany, Poland, Lithuania, Latvia, Spain, France, the United Kingdom, Canada, Israel and other countries.
Personal data was also collected
The alleged operation did not focus solely on cryptocurrency.
During registration and identity-verification procedures, victims were asked to provide personal information, including passport details, phone numbers, email addresses, login information, passwords and photographs, according to police.
That information potentially gave the operators access to more than victims’ digital assets. Investigators said the collected data could also be used for other types of fraudulent activity.
Authorities said the operation was organized by a 25-year-old IT specialist who allegedly recruited more than 46 Ukrainian citizens. The group reportedly maintained several offices in Kyiv and the surrounding region.
Different participants allegedly performed separate roles. Technical workers were responsible for developing and maintaining the fraudulent websites and keeping them operational. Other members reportedly contacted prospective victims, managed offices or provided security.
The structure described by investigators suggests the crypto investment scheme operated as an organized network rather than as an isolated online fraud operation.
The scale of the alleged activity was reflected in the number of people investigators say were involved. More than 46 Ukrainian citizens were reportedly recruited, while authorities continue examining the roles played by members of the network.
The SBU said the operation’s turnover could reach as much as $1 million per month, although investigators are still working to establish the total amount of cryptocurrency allegedly stolen.
Dutch servers provided key evidence
Investigators said an important breakthrough came from infrastructure located outside Ukraine.
Authorities traced server equipment allegedly used by the network to the Netherlands. They subsequently obtained access to a database stored there that contained information connected to the operation.
The database reportedly included lists of victims, cryptocurrency wallet addresses, amounts allegedly stolen, internal communications and details about how the fraudulent platforms functioned.
Investigators said those records helped them reconstruct the operation and identify people who had allegedly been victimized.
The evidence also helped authorities establish how the crypto investment scheme operated, from attracting users to manipulating displayed balances and ultimately transferring cryptocurrency from connected wallets.
Ukrainian police and the SBU later conducted 34 searches in Kyiv and the surrounding region as part of the investigation.
During those searches, authorities seized more than 100 computers, more than 100 mobile phones, 79 SIM cards, documents, cash and 15 vehicles.
The seizures are expected to provide investigators with additional evidence as they work to determine the full scope of the alleged operation.
Investigation continues as authorities seek more victims
The crackdown has not brought the investigation to an end.
Ukrainian authorities said the case remains open under the country’s fraud laws. Investigators are continuing to identify other people who may have participated in the network and are searching for additional victims.
Authorities are also seeking to establish the total amount of cryptocurrency allegedly taken by the crypto investment scheme.
The case highlights the risks created when fraudulent investment websites are combined with wallet-draining technology. In the alleged Ukrainian operation, fabricated account balances were used to build trust before victims were directed toward transactions that investigators say ultimately enabled the theft of their digital assets.
The investigation could therefore reveal a broader victim pool than the 62 people identified so far.
For cryptocurrency users, the alleged operation also demonstrates how an apparently profitable account can be manipulated on a fraudulent platform. In this case, investigators say the displayed gains were not genuine investments but part of the mechanism used to persuade users to continue interacting with the websites.
As Ukrainian authorities continue examining the seized equipment and database records, the crypto investment scheme remains under investigation, with officials working to determine the network’s complete financial impact and identify any additional participants.
The allegations remain subject to the ongoing investigation and legal process.