Ukrainian police shut down a network of fake cryptocurrency investment platforms that targeted victims across more than 20 countries, the National Police of Ukraine announced on September 1. Investigators from the Main Investigation Department worked alongside the Security Service of Ukraine under procedural guidance from the Prosecutor General's Office. So far, 62 victims have been identified, with citizens of Germany, Poland, Lithuania, Latvia, Spain, France, the United Kingdom, Canada, and Israel among those confirmed.
Поліцейські припинили діяльність мережі фейкових інвестиційних платформ, через які шахраї викрадали криптовалюту у громадян понад 20 країн
— Національна поліція України (@NPU_GOV_UA) September 1, 2026
Наразі поліцейські встановили 62 потерпілих.
🔗 Деталі: https://t.co/e4OZtqg0gB pic.twitter.com/QblK1EWXi8
A 25-year-old IT specialist organized the operation, which at its peak generated monthly turnover of up to $1 million, according to the Security Service. The organizer recruited more than 46 Ukrainian citizens into the scheme and established several fraudulent offices in Kyiv and the surrounding region. He traveled with armed security, and investigators found that cars and real estate connected to the suspects had been registered in the names of wives and other relatives.
How the fraud worked from first contact to final theft
The scheme began with advertising distributed through Telegram, where potential customers received offers to participate in cryptocurrency investment projects. Users who responded were directed to register on one of the fake platforms, connect a cryptocurrency wallet, and transfer funds to take part in what appeared to be legitimate investment activity.
Once funds arrived, employees inside the fraudulent offices manually simulated trading activity and displayed fabricated account balance growth inside each user's personal dashboard. Victims could watch their supposed investments increase in value, but the displayed figures had no connection to real market activity.
The critical moment came when a user attempted to withdraw funds. The platform blocked the withdrawal and told the victim that a verification procedure was required first. Users were instructed to connect their primary cryptocurrency wallet and approve a small test transaction to confirm the platform was operational.
The websites contained a wallet drainer, a hidden mechanism that used the authorization granted during the supposed test transaction to transfer assets from the connected wallet to addresses controlled by the group. After the transfer completed, the victim lost access to the platform entirely.
What wallet drainers do and how they are built
Wallet drainer attacks exploit the token approval mechanism built into smart contract networks. When a user approves a transaction, they grant a contract permission to move a specified amount of tokens on their behalf. A malicious contract uses that permission to move the maximum authorized amount to an attacker-controlled address. The victim sees only a small test transaction in the initial approval request but has unknowingly authorized the full drain. Approval phishing of this type does not require an attacker to obtain a wallet's private key. The authorization itself is sufficient.
The Inferno drainer, one of the most widely documented drainer-as-a-service tools, operated from 2022 until its operators announced a shutdown in November 2023, having stolen an estimated $80 million from approximately 5,000 victims. After the shutdown, successor tools including Pink drainer and Angel drainer filled the same market. Security firm Salus connected a fake Hyperliquid website promoted through a Google advertisement in August 2026 to infrastructure associated with the Inferno drainer ecosystem, demonstrating the tool remains in active use through successor operations despite the original operators' exit.
Beyond cryptocurrency, the Ukrainian platforms collected victims' passport information, phone numbers, email addresses, account logins, passwords, and photographs during registration and verification. That personal data gave the group a secondary asset beyond stolen crypto, one usable for identity fraud or resale on illicit markets.
The server seizure that broke the investigation open
Investigators traced the network's infrastructure to server equipment located in the Netherlands. After gaining access to the database stored there, authorities recovered lists of victims, cryptocurrency wallet addresses, amounts stolen from individual users, internal correspondence between network members, and records describing how the platforms operated. That material allowed investigators to document the scheme in detail and identify victims across multiple countries.
Ukrainian officers conducted 34 searches at residences, fraudulent offices, and vehicles across Kyiv and the surrounding region. More than 100 computers and pieces of equipment were seized alongside over 100 mobile phones, 79 SIM cards, a GSM gateway, cash, documents, and 15 vehicles.
Where this case fits within broader international enforcement
INTERPOL's Operation First Light, reported in July 2026, produced 5,811 arrests across 97 countries and intercepted $293 million in illicit assets while targeting investment fraud, romance scams, and social engineering schemes. One wallet linked to a Thai investigation had processed more than $122.5 million over a ten-month period. A separate UK-led operation involving US and Canadian authorities froze more than $12 million in suspected scam proceeds and identified more than 20,000 potential victims of approval phishing schemes earlier in 2026.
The Ukrainian case is being prosecuted under Part 5 of Article 190 of Ukraine's Criminal Code, which covers fraud. Investigators have not disclosed a total loss figure. The full range of suspects, additional victims, and the complete value of stolen cryptocurrency remain under investigation.

Disclaimer: All materials on this site are for informational purposes only. None of the material should be interpreted as investment advice. Please note that, despite the nature of much of the material created and hosted on this website, HODL FM operates as a media and informational platform, not a provider of financial advisory services. The opinions of authors and other contributors are their own and should not be taken as financial advice. If you require advice, HODL FM strongly recommends contacting a qualified industry professional.





