Crypto Scams

Real Wallet Drainer Scam Examples and How They Were Caught | ICAR

A wallet drainer is malicious code, usually delivered through a phishing website or a fake token claim, that tricks a victim into signing a transaction that hands control of their crypto assets to an attacker. This isn’t a hypothetical threat. It’s an active criminal industry with named operations, known operators, and a documented history of takedowns that never quite stops the underlying activity. This guide walks through five real cases, how each was actually discovered and disrupted, and what the pattern across all of them means for anyone holding crypto today. 83% Drop Wallet drainer losses fell from $494 million in 2024 to $83.85 million in 2025, according to Scam Sniffer data. Real progress, but still tens of millions stolen every year Source: Scam Sniffer, Group-IB, and SlowMist annual reporting Case 1: Inferno Drainer, the $80 Million Operation Caught by Researchers, Not Police Inferno Drainer ran from November 2022 to November 2023 as a scam as a service operation, meaning the people who built the drainer software rented it out to affiliates who kept 80 percent of what they stole while the operators took a 20 percent cut. It’s estimated to have stolen more than $80 million from roughly 137,000 victims, using more than 16,000 phishing domains that impersonated over a hundred real crypto brands and projects. Here’s the part worth understanding about how this got caught. It wasn’t a law enforcement raid. It was Group-IB’s High-Tech Crime Investigation unit, a private cybersecurity research team, publishing a detailed technical exposure of the operation’s infrastructure in January 2024, two months after the operators had already announced their own shutdown. The public research made it dramatically harder for the same operators to relaunch under the same identity, but it didn’t end the underlying threat. Inferno Drainer’s code and reputation resurfaced in 2025, and in just six months it struck more than 30,000 wallets and stole over $9 million more. Case 2: Monkey Drainer, Shut Down by a Single Independent Investigator Monkey Drainer was one of the earliest scaled drainer operations, and it shut down voluntarily in March 2023 after independent on chain investigator ZachXBT published a public investigation identifying the operator. This case is worth including specifically because it shows that formal law enforcement isn’t the only force that disrupts these operations. A single researcher, working publicly and sharing findings openly, applied enough pressure and public exposure that the operator chose to announce a shutdown via Telegram rather than continue operating under scrutiny. Case 3: Pink Drainer, $85 Million and 21,000 Victims Before a Quiet Retirement Pink Drainer is linked to more than $85 million stolen from over 21,000 victims before announcing its own wind down in 2024. Like Inferno, it operated as a service, meaning the technical skill barrier for running a drainer campaign was almost nonexistent for affiliates, who mainly needed to drive traffic to phishing pages through hacked social media accounts, paid ads, or spam. The retirement of both Pink and Inferno within roughly the same period didn’t reduce the total number of active drainer campaigns much, since the affiliate pool simply migrated to whichever kit was still available. Case 4: Angel Drainer and the Ledger Connect Kit Supply Chain Attack Angel Drainer’s most notable moment wasn’t a phishing site at all. On December 14, 2023, attackers compromised Ledger’s Connect Kit, a piece of legitimate, widely used code that many real crypto applications rely on to let wallets connect to them. Because the compromised code was distributed through official channels, a large number of genuine, reputable applications briefly served malicious code to their own users without either the applications or the users doing anything wrong on the surface. This is a meaningfully different attack pattern than a fake website, since it demonstrates that even careful users interacting only with applications they already trusted could still have been exposed, at least for the narrow window before the compromise was identified and reverted. Case 5: The September 2025 Case That Shows Even Experienced Users Get Caught In September 2025, a long time DeFi trader with a wallet tied to years of activity on respected protocols lost $6.5 million in a single incident. The attack began through a phishing link shared in a community channel, and the actual theft happened through a single malicious permit approval, a type of signature that grants a smart contract ongoing permission to move specific tokens on a wallet’s behalf. That one approval looked routine at the moment it was signed. The attackers then chained that permission across multiple contracts, moving funds in quick bursts before the victim could intervene. This case matters because the victim wasn’t a beginner. Long standing wallet history and familiarity with major protocols didn’t prevent the loss, because the vulnerability wasn’t a lack of crypto experience. It was a single signature, requested in a moment that felt ordinary, that granted more access than the victim understood they were granting. The Pattern Across Every Case None of these five cases involved a stolen private key or password in the traditional sense. Every one of them worked by getting the victim to actively sign something, a wallet connection, a token approval, a permit signature, that handed the attacker legitimate on chain permission to move funds. This is why so much wallet security advice now focuses on what you’re approving, not just what you’re clicking. A phishing site doesn’t need to steal your credentials if it can convince you to sign a transaction that does the same job with your own authorization attached to it. How These Operations Actually Get Disrupted Independent researchers publishing public investigations, as with ZachXBT and Monkey Drainer, which can pressure an operator into shutting down even without a formal arrest Cybersecurity firms exposing infrastructure through detailed technical reports, as Group-IB did with Inferno Drainer, which damages an operation’s ability to relaunch under the same identity Real time threat detection platforms that flag malicious addresses within hours of new activity, as Hypernative did within a day of Inferno Drainer’s 2025

Real Wallet Drainer Scam Examples and How They Were Caught | ICAR Read More »

Wallet Drainer

Cryptocurrency Investment Scams: How They Work in 2026

Cryptocurrency investment scams caused over $11.3 billion in reported losses in the US alone in 2025, according to the FBI’s Internet Crime Complaint Center, making them the single largest category within an already-record year for investment fraud. Globally, blockchain intelligence firm TRM Labs estimates roughly $35 billion was sent to fraud schemes in 2025, with crypto-based pig butchering accounting for a significant share of that total. This article is a deep dive into exactly how these schemes work at a technical level, the 2026 law-enforcement crackdown now underway, and what to do if you’ve been targeted. (For the full picture of investment fraud beyond crypto, see our complete guide: Investment Scams — The Complete Guide for Victims in 2026.) $11.3B Cryptocurrency-related fraud losses reported to the FBI’s IC3 in 2025 — the largest single fraud category in the US that year Source: FBI Internet Crime Complaint Center, 2025 Annual Report How the Scam Actually Works Understanding the mechanics makes the warning signs much easier to spot. In a typical crypto investment scam most commonly a “pig butchering” operation, a victim is first contacted through what looks like a wrong-number text, a dating app match, or a social media connection. The scammer invests weeks, sometimes months, building a friendship or romantic relationship before ever mentioning money. When the pivot finally comes, it’s to a “can’t-lose” crypto trading platform. The dashboard looks completely real live charts, a rising balance, professional design. None of it reflects an actual market. One FBI Cyber Division threat intelligence briefing described the operation bluntly: the platforms display simulated profits while routing the victim’s real cryptocurrency straight into automated mixing services within seconds of deposit. Technically, this works because the deposit address generated by the fake app is a non-custodial wallet controlled entirely by the scam operation, never an account actually associated with the victim’s name. The moment funds land in that wallet, they can be moved, split across dozens of addresses, and routed toward laundering services before a victim has even finished refreshing their “portfolio” screen.   Common Types of Crypto Investment Scams Pig butchering platforms Fake trading apps built specifically around a manufactured relationship, as described above, currently the most damaging and fastest-growing variant. Fake exchanges and wallet apps Convincing clones of real exchange platforms that accept deposits but never allow genuine withdrawals, often surfacing via search ads or sponsored social posts rather than a personal relationship. Rug pulls A token or project is heavily promoted, liquidity is pulled by the developers once enough investors have bought in, and the token’s value collapses to near zero within minutes. Wallet drainer scams Malicious smart contracts disguised as NFT mints, airdrops, or token claims that, once a wallet is connected and a transaction is approved, drain its contents directly. Fake ICOs and token presales Professional-looking whitepapers and websites promoting a token launch that never delivers a real product, with the presale funds simply disappearing. AI deepfake endorsement scams AI-generated video or audio of recognisable business figures “endorsing” a platform  a tactic that regulators say has removed one of the last reliable tells, since scammers can now generate convincing, localized, error-free video at scale. The 2026 Crackdown: What Law Enforcement Is Now Seeing The scale of the enforcement response this year reflects the scale of the problem. In one operation, a global task force involving the FBI, Dubai Police, and Chinese authorities arrested 276 suspects and dismantled nine scam centers used to run crypto investment schemes. The FBI’s proactive victim-notification initiative, Operation Level Up, had by March 2026 identified and contacted 8,935 victims of cryptocurrency investment fraud — 77% of whom had no idea they were being scammed, an intervention credited with saving an estimated $562 million before it was lost. In March 2026, the US Secret Service, the UK’s National Crime Agency, and Canadian authorities launched a joint effort, Operation Atlantic, in response to escalating victim losses. That followed an October 2025 milestone: a $15 billion Bitcoin forfeiture tied to Cambodia’s Prince Group, one of the largest crypto-fraud asset seizures on record. On the laundering side, Chainalysis’s January 2026 Crypto Crime Report found that Chinese-language money laundering networks increased their share of known illicit crypto activity to roughly 20% in 2025, processing an estimated $16.1 billion — about $44 million a day, across more than 1,799 active wallets. That infrastructure is precisely what allows stolen funds to move so quickly once a victim deposits. Red Flags Specific to Crypto Investment Scams A trading app or “exchange” that isn’t listed on any independent, verifiable exchange ranking site A contact who took weeks to build a relationship before ever mentioning an investment A dashboard balance that only ever goes up, with no visible losing trades A withdrawal that suddenly requires a “tax,” “gas fee,” or “compliance charge” paid separately Pressure to connect your wallet to claim an NFT, airdrop, or token you weren’t actively seeking out What To Do If You’ve Sent Crypto to a Scam Stop sending any further funds, including any “fee” required to unlock a withdrawal. Record every wallet address and transaction hash involved before the platform disappears. Contact the exchange you sent funds from directly to flag the destination address, in case it’s already known to their compliance team. Report to IC3 (US), Action Fraud’s successor Report Fraud (UK), the CAFC (Canada), or your national equivalent. Avoid unsolicited “recovery” contacts demanding upfront payment, this is a near-universal secondary scam. Get a professional case assessment for blockchain tracing before funds move further through mixing services. How ICAR Traces Crypto Funds Because blockchain transactions are public and permanent, even funds routed through non-custodial wallets and mixing services leave a traceable path. ICAR’s blockchain tracing follows fund movement across wallets and exchanges to identify consolidation points and cash-out attempts, while wallet clustering often reveals that a single operation is behind far more victims than any one case suggests, intelligence that matters for exchange cooperation requests and law enforcement referrals. Speed matters: funds that haven’t yet been laundered through

Cryptocurrency Investment Scams: How They Work in 2026 Read More »

Cryptocurrency Investment Scams 1

Pig Butchering Scams Explained: How It Works

A pig butchering scam is a long-con fraud that combines a manufactured romance or friendship with a fraudulent crypto investment pitch, named for the Chinese term sha zhu pan  “killing pig plate”  a reference to fattening a pig before slaughter. US authorities now attribute at least $10 billion in 2024 American losses alone to Southeast Asia-linked scam networks running this exact model, with Cambodia’s compound-based scam industry estimated to generate up to $19 billion a year, nearly 40% of the country’s GDP. This article covers how the scam actually unfolds relationship by relationship, the forced-labor system powering it, and what makes it different from the crypto-mechanics we covered in our companion Hub article. 100,000–150,000 People the United Nations estimates are held and forced to run online scam operations inside Cambodian compounds alone Source: UN Office of the High Commissioner for Human Rights; Amnesty International, June 2025 Why the Term Is Changing In December 2024, INTERPOL formally urged media and investigators to retire the term “pig butchering” in favor of “romance baiting,” arguing that the original phrase re-victimizes people who were deliberately, professionally manipulated by comparing them to livestock. We use both terms in this guide because “pig butchering” remains the most widely searched and recognized term, but the shift in language reflects something important: these are not victims who were foolish. They were targeted by an industrial-scale operation built specifically to exploit trust. How the Scam Unfolds Stage 1 — Contact Most cases begin with something small and unremarkable: a text to the “wrong number,” a match on a dating app, a follow from a stranger on social media. The opening message is never about money. Stage 2 — The relationship Over weeks or months, a genuine-feeling bond forms: daily messages, shared photos, video calls that are frequently avoided or cut short with excuses. Investigators say this stage alone can run for three to six months before money is ever mentioned. Stage 3 — The reveal The new partner or friend mentions, almost reluctantly, a trading platform or crypto opportunity that’s “changed their life.” They may show screenshots of their own supposed gains. Stage 4 — The small win A modest first investment is allowed to “succeed,” often with a real, small withdrawal permitted to build confidence, the only funds a victim typically ever gets back. Stage 5 — Escalation Larger and larger deposits follow, often framed as needed to “unlock higher tiers” or take advantage of a limited-time opportunity. Some victims are told to recruit friends or family into the same platform. Stage 6 — The wall A withdrawal attempt triggers a sudden “tax,” “compliance fee,” or account freeze. The relationship, and the money, disappear at roughly the same time. The Forced-Labor System Behind the Scam What makes pig butchering distinct from most other fraud categories is who’s actually typing the messages. Multiple government and human-rights investigations: the US Treasury’s OFAC, the UN Human Rights Office, and Amnesty International among them, have documented that a large share of these operations are staffed by trafficking victims themselves, held in guarded compounds across Cambodia, Myanmar, and Laos and forced to run scripts under threat of violence. The UN estimates 100,000 to 150,000 people are held in Cambodian compounds alone, with a further estimated 120,000 in Myanmar. Amnesty International’s June 2025 investigation, based on interviews with 423 survivors, documented torture, electric shocks, and “dark rooms” used to punish workers who missed targets across at least 53 compounds. In September 2025, the US Treasury sanctioned 19 entities across Myanmar and Cambodia, including operations in Shwe Kokko and Sihanoukville  specifically for running forced-labor scam compounds targeting American victims. This matters for victims to understand for one reason above all: the person on the other end of the relationship is frequently a coerced worker, not the mastermind profiting from the scheme. The organizers are often protected by local corruption and armed groups, are the ones law enforcement is now targeting through sanctions and cross-border operations. Who Gets Targeted Investigators note that victims most often fall between ages 30 and 60, primarily elderly victims, though older adults remain heavily targeted in the broader investment-scam category. Professionals, recently divorced or widowed individuals, and people newly active on dating apps are all disproportionately represented, largely because the scam’s success depends on genuine loneliness or a genuine desire for connection, not financial naivety. Learn more about Online Scamming: Signs, Prevention & Safety. Red Flags Specific to Pig Butchering A new online relationship that consistently avoids video calls or in-person meetings A partner who always has a reason they’re unavailable: working overseas, on a ship, deployed An investment “tip” that arrives only after weeks or months of relationship-building Pressure, gentle or otherwise, to recruit friends or family into the same platform A profile photo that reverse-image-searches to a different name or a modeling/stock site What To Do If You’re in One of These Relationships Do not send more money, regardless of how the relationship is framed, a real partner will not ask you to fund an investment. Reverse-image-search their photos and ask directly for an unscheduled video call. Preserve every message, transaction ID, and platform screenshot before accounts disappear. Talk to someone outside the relationship, isolation is a core part of how this scam sustains itself. Report to your national fraud authority (IC3 in the US, Report Fraud in the UK, CAFC in Canada, Scamwatch in Australia)  some funds are now being traced and seized through international operations. Get a professional case assessment for blockchain tracing if crypto was involved. Frequently Asked Questions What does “pig butchering” actually mean? It’s a translation of the Chinese term sha zhu pan, referring to fattening a pig before slaughter, a description of how victims are built up emotionally and financially before being drained. INTERPOL now recommends “romance baiting” instead. Is the person messaging me actually the scammer? Frequently not. Investigations have found large portions of these operations are staffed by trafficking victims forced to work under threat of violence, the organizers profiting

Pig Butchering Scams Explained: How It Works Read More »

Pig Butchering 1

LinkedIn Forex Scam: How Fraudsters Target Professionals

LinkedIn forex scams are among the most sophisticated investment fraud operations ICAR investigates. They target a demographic rarely associated with fraud vulnerability, senior professionals, business owners, executives, and financially experienced individuals in their 40s and 50s, and they do so using the one platform that professional targets trust most: LinkedIn. According to the FBI’s IC3 2025 Annual Report, investment fraud remains the single largest cybercrime loss category, with cryptocurrency investment fraud alone accounting for $7.2 billion in losses. The FTC has documented consistent growth in social media-enabled investment fraud, noting that professionals who would never respond to a cold email scam are systematically deceived through relationship-based approaches on professional networks. This article presents a forensically accurate case study of a LinkedIn forex scam, how it began, how it escalated, what ICAR’s investigation found, and what it tells us about the broader threat to professionals across the UK, US, Canada, Australia, Singapore, and Hong Kong. $7.2 Billion Lost to cryptocurrency investment fraud in the US alone in 2025 Source: FBI IC3 2025 Annual Report The Case: Marcus and the Trading Expert Marcus Chen is 51. He is the managing director of a mid-sized logistics company in Birmingham. He has used LinkedIn daily for twelve years  for business development, industry news, and professional networking. He considers himself financially literate: he has a pension, ISAs, and a modest share portfolio managed by an IFA. In February 2026, he received a LinkedIn connection request from a profile called James Whitfield  described as a ‘Senior FX Strategist | Algorithmic Trading | 14 Years Market Experience’. The profile had a professional headshot, 4,287 connections, a complete employment history at named financial firms, and eleven endorsements for ‘Forex Trading’ and ‘Portfolio Management’. Two of Marcus’s existing connections were mutual contacts. STAGE 1  The Connection February 2026 — Initial contact and relationship building James’s first message was low-pressure and professionally framed: ‘Hi Marcus — I noticed we share connections with [Name 1] and [Name 2]. I work in FX strategy and occasionally share market insights with professionals in complementary sectors. Happy to connect if that’s useful.’ Marcus accepted. Over the following three weeks, James sent six messages, short, considered, market-relevant. He shared commentary on GBP volatility following a Bank of England announcement. He sent a note on a regulatory change affecting institutional forex trading. Nothing about investment opportunities. Nothing about his own returns. âš‘ RED FLAG: Professional credibility was manufactured, not earned The 4,287 connections, the endorsements, the employment history at named firms — all fabricated or inflated. Mutual connections create a false sense of verification. In ICAR’s OSINT investigation, the LinkedIn profile had been created 74 days before the connection request. The headshot was a stock image from a photography subscription service. STAGE 2  The Introduction March 2026 — The investment conversation begins In late March, James mentioned briefly and without pressure, that his team had been running an algorithmic forex strategy with strong results in Q1. He was considering opening a small number of external positions for ‘trusted contacts’ at a flat management fee. He named the platform: PrimeForex Capital. Marcus looked it up. The website was professional. Registered address in London. FCA registration number in the footer. A ‘Regulatory’ section with documentation. Client testimonials with photographs. He checked the FCA register. He searched for ‘PrimeForex Capital.’ It appeared. He read the entry. The name matched. The registration number matched. What Marcus did not notice because he did not know to look, was that the FCA registration belonged to a different firm: a legitimate, authorised brokerage that had nothing to do with PrimeForex Capital. The fraudulent platform had copied the registration number and company details of a real FCA-authorised firm. This is a clone firm impersonation, one of the most common techniques used in UK investment fraud. âš‘ RED FLAG: Clone firm impersonation — FCA number belongs to a different authorised entity The FCA maintains a warning list of known clone firms at fca.org.uk/scamsmart. Verifying requires matching the company NAME, registration NUMBER, and contact details simultaneously, a number that matches but belongs to a different firm is impersonation, not authorisation. Always verify all three elements independently. How PrimeForex Capital Was Built ICAR’s subsequent OSINT investigation of PrimeForex Capital revealed the following: â–Œ OSINT INVESTIGATION — PRIMEFOREX CAPITAL (FICTIONAL) // Domain analysis Domain: primeforexcapital.com Domain age:          61 days at victim first contact Registrar:           Namecheap (privacy-protected) Registrant:          REDACTED — Panamanian privacy service SSL certificate:     Let’s Encrypt (automated, free)   // FCA impersonation FCA number claimed:  [6-digit number from legitimate firm] Actual FCA holder:   Different authorised brokerage (11 years registered) FCA ScamSmart:       Clone firm warning NOT yet issued (platform too new) FCA register check:  Number exists — but belongs to different entity   // LinkedIn profile — ‘James Whitfield’ Profile created:     74 days before connection request Headshot:            Stock image — Getty Images subscription library Employment history:  Named real firms — no verifiable tenure at any Connections:         4,287 — many purchased via third-party connection service Mutual connections:  2 — both passive LinkedIn users unlikely to be contacted   // Platform interface Interface clone:     Matched EU-regulated forex broker (83% CSS similarity) Testimonial photos:  Stock images — identified via reverse image search Regulatory section:  Copied verbatim from legitimate broker’s compliance page   // Infrastructure Shared hosting IP:   Resolved to known fraudulent domain cluster (14 domains) Server location:     Netherlands — masked via Cloudflare CDN STAGE 3  The Deposit Ladder April–May 2026 — £95,000 transferred across 9 transactions Marcus’s first deposit was £5,000. His dashboard showed a 4.2 percent return in the first week. James sent a brief note: ‘Q1 was strong. We are anticipating continued momentum in GBPUSD positioning. Pleased with how your allocation performed.’ Over the next six weeks, Marcus made eight further transfers. The deposits escalated: £8,000, then £12,000, then £18,000. Each was accompanied by updated portfolio statements showing consistent gains. Each time Marcus suggested withdrawing some profit to test the platform, James advised patience  ‘reinvestment compounds the position’  and Marcus complied. Total deposited by 15 May: £95,000. âš‘ RED

LinkedIn Forex Scam: How Fraudsters Target Professionals Read More »

LinkedIn Forex Scam

Fake Crypto Exchange Warning Signs: How Fraudulent Platforms Are Built to Fool You

The single most important thing to understand about fake crypto exchange warning signs is this: fraudulent trading platforms in 2025 are not crude forgeries. They are sophisticated, professionally constructed systems designed to pass casual and even attentive scrutiny. They have live market data. They have customer support. They have FCA branding, MAS logos, and SEC registration numbers — all fabricated. According to OFAC’s May 2025 sanctions action against Funnull Technology — a Philippines-based infrastructure provider linked to more than $200 million in US pig butchering losses — the fraudulent platforms its infrastructure supported used 200,000 unique domain hostnames and cloned interfaces from legitimate financial platforms. The same investigation by Chainalysis found that the majority of crypto investment scam sites reported to the FBI were built on Funnull’s domain-generation infrastructure. At ICAR, our investigators have examined dozens of fraudulent trading platforms across cases originating in the UK, US, Canada, Australia, Singapore, and Hong Kong. The architecture of these platforms follows consistent, identifiable patterns. This article documents those patterns — the seven warning signs that distinguish a fraudulent platform from a legitimate one, a side-by-side comparison of real versus fake exchange features, and a per-jurisdiction guide to verifying any platform before committing funds. 200,000+ Unique fraudulent domain hostnames operated by Funnull Technology alone Source: OFAC Sanctions Action · May 2025 Why Fake Crypto Exchanges Look Legitimate The primary design objective of a fake crypto exchange is not to conduct trading — it is to conduct convincing. The platform’s entire purpose is to persuade a victim to deposit funds, and then to persuade them to deposit more, while creating every possible obstacle to withdrawal. Modern fake exchanges achieve this through several technical and design mechanisms: Interface cloning: the front-end design of established exchanges — Binance, Coinbase, Kraken, eToro — is copied with high fidelity using publicly available CSS and HTML. Chainalysis identified an 87 percent CSS similarity between one fraudulent platform and a legitimate EU broker in a 2025 case analysis. Live data feeds: legitimate-looking price charts and market data are generated using free APIs from real financial data providers. The data is real; the trading is not. Fabricated account balances: the victim’s portfolio dashboard shows real-time updating balances and returns. These numbers are entries in a database — not the result of any actual trade. They can be set to any value the operator chooses. Professional support infrastructure: many fake platforms include live chat support, email help desks, and even phone numbers staffed by the criminal operation’s employees — some of whom are themselves trafficked workers. Regulatory branding: FCA logos, SEC registration numbers, and central bank certifications are copied from legitimate platforms or fabricated entirely. These images are screenshots or downloaded assets — they confer no actual authorisation. The 7 Warning Signs of a Fake Crypto Exchange The following seven red flags are present in virtually every fraudulent platform ICAR has investigated. No single flag is definitive in isolation but encountering two or more simultaneously should trigger immediate verification before any further action. âš‘ 1 The Platform Cannot Be Verified on Any Official Regulatory Register Every legitimate investment platform or crypto exchange operating in a regulated jurisdiction must be authorised by the relevant financial regulator. In the UK, this means FCA authorisation (or registration for crypto firms under the Money Laundering Regulations). In the US, registration with the SEC, CFTC, or FinCEN. In Australia, an ASIC licence. In Singapore, MAS authorisation. In Hong Kong, SFC registration. In Canada, registration with IIROC or provincial securities commissions. If a platform cannot be found on any of these registers — regardless of how convincing its regulatory branding appears — it is not authorised. ✓ CHECK: UK: fca.org.uk/register · US: sec.gov/check-an-investment-professional · AU: moneysmart.gov.au/check-register · SG: mas.gov.sg/investor-alert-list · HK: sfc.hk/en/Regulatory-Functions/Intermediaries/Licensing/Register-of-licensed-persons · CA: aretheyregistered.ca âš‘ 2 The Domain Was Registered Recently — Weeks or Months Before First Contact Every fraudulent platform ICAR has investigated was registered within months — often weeks — of the victim’s first contact with the scammer who introduced it. A legitimate exchange like Binance (est. 2017), Coinbase (est. 2012), or Kraken (est. 2011) has a domain age measured in years and a well-documented public history. A platform with a domain registered 30–60 days ago is almost certainly fraudulent, regardless of how established it claims to be. ✓ CHECK: Check: whois.domaintools.com — enter the platform URL and check ‘Created’ date. A legitimate major exchange will show years of history. âš‘ 3 Withdrawal Requests Are Blocked, Delayed, or Subject to Fees The most reliable single indicator of a fraudulent platform is a blocked or fee-conditioned withdrawal. Legitimate exchanges process withdrawals — they may have verification requirements, but they do not charge ‘tax clearance fees’, ‘compliance deposits’, ‘insurance premiums’, or ‘capital gains release charges’ as conditions for releasing your own funds. If any withdrawal attempt results in a request for additional payment, the platform is fraudulent. This is the mechanism by which the fraud extracts the final layer of value from the victim. ✓ CHECK: Action: attempt a small test withdrawal (e.g. £100 or equivalent) before making any significant deposit. If the withdrawal is blocked or subject to a fee, cease all activity immediately.   âš‘ 4 The Platform Was Introduced Through a Social or Romantic Contact Legitimate investment platforms are not introduced through dating apps, social media contacts, or messaging applications by individuals who have been cultivating a relationship. No genuine exchange requires a personal introduction from a trusted contact to access it — they are publicly available, regulated services. If your awareness of a platform came through a WhatsApp conversation, a dating app match, or a social media connection who mentioned a family member’s success, the introduction itself is a red flag — regardless of what the platform looks like. ✓ CHECK: Verify independently: search the platform name + ‘scam’ or ‘review’ on Google, Reddit, and Trustpilot. Check the FCA’s ScamSmart warning list at fca.org.uk/scamsmart.   âš‘ 5 The Platform’s Interface Is a Clone of a Known Legitimate Exchange Advanced forensic comparison of

Fake Crypto Exchange Warning Signs: How Fraudulent Platforms Are Built to Fool You Read More »

Fake crypto Exchanges

Pig Butchering Scam Recovery Guide for Australia Victims

Introduction: The Anatomy of a Modern Investment Fraud David Hartley was sixty-three years old when his wife of thirty-one years died of cancer. Fourteen months later, a woman named ‘Linda Chen’ appeared on his dating app profile — widowed herself, she said, a retired pharmacist living in Manchester. She had kind eyes and a careful way of writing messages that felt nothing like the clipped, transactional exchanges David had come to expect from the app. By the time David realised that Linda Chen did not exist — that she had never existed, that every conversation had been generated by a criminal operation running out of a compound in Southeast Asia — he had transferred £180,000 into a fraudulent platform called EdgeStrategies FX. He had done it over eleven weeks, in twelve separate transactions, each one feeling more rational than the last. This is how pig butchering works. Not through technical trickery or implausible promises — but through patience, relationship, and the precise exploitation of human vulnerability at its most acute. £180,000 Total loss · 11 weeks · 12 transactions · EdgeStrategies FX (fraudulent) Stage 1: The Approach — Weeks 1 and 2 WEEK 1–2   Contact, Trust, and the Illusion of Coincidence David had joined the dating app reluctantly, at the suggestion of his daughter. He was not actively looking for a relationship — he was, in his own words, ‘just seeing what was there.’ The app’s algorithm served him Linda Chen’s profile on his third day. Linda’s opening message was disarming in its ordinariness. She commented on a book visible in one of his profile photographs — a history of the Second World War — and mentioned that her late husband had been a keen reader too. The conversation that followed was warm, unhurried, and notably free of any financial content whatsoever. This is the first and most important phase of a pig butchering scam: the cultivation period. The criminal operation — which forensic analysis would later suggest was coordinated from a compound in Cambodia — maintains detailed scripts and character profiles for each persona. Linda’s profile had been carefully constructed to appeal to a recently widowed British professional in his early sixties: cultured, educated, emotionally cautious, financially comfortable. By the end of Week 2, David and Linda had exchanged over 400 messages. They had moved from the dating app to WhatsApp — standard practice in these operations, as it removes the platform’s monitoring systems and creates a more intimate communication channel. They had discussed their respective losses, their children, their retirement plans. Linda had mentioned, once and briefly, that she had a modest investment portfolio.  1 The move to WhatsApp within two weeks Moving conversation off a monitored platform to a private channel is a consistent first-stage tactic. It removes protective oversight and creates an illusion of deepened intimacy. Stage 2: The Introduction — Weeks 3 and 4 WEEK 3–4   The Investment Mention and the Expert Uncle In Week 3, Linda mentioned that her brother-in-law — a man she called ‘Uncle James’ — had been helping her manage her late husband’s investments. She described him as a quiet, brilliant man who had worked in quantitative finance in Hong Kong. She was embarrassed to have so little understanding of what he did, she said. The money had grown substantially. This figure — the expert intermediary — is a standard structural element of pig butchering scripts. Uncle James existed to provide credibility for the investment claim while keeping Linda’s persona sympathetically naive. She was not pitching David. She was confiding in him. In Week 4, David asked about the investment. Linda said she would ask Uncle James if he minded explaining it. A few days later, she sent David a screenshot of her EdgeStrategies FX dashboard — showing a balance of approximately £340,000 and a monthly return of 6.8 percent. She seemed almost apologetic about sharing it. She did not ask David to invest.  2 Unsolicited display of investment returns — without a direct pitch Showing profitable returns without immediately pitching is a deliberate psychological technique. It creates curiosity and desire without triggering the victim’s fraud defences. The absence of a pitch makes the eventual pitch feel more credible. Stage 3: The First Deposit — Weeks 5 and 6 WEEK 5–6   The Voluntary First Step and the Small Win David asked to be introduced to EdgeStrategies FX. Linda connected him with Uncle James via WhatsApp. James was measured, professional, and unhurried. He explained that EdgeStrategies FX was a hybrid forex and cryptocurrency trading platform operating across UK, EU, and Asian markets. He sent David a link to the platform — which had a professional interface, live market data feeds, FCA branding in the footer, and a clean, sophisticated user experience. The FCA branding was fraudulent. The platform’s actual domain — edgestrategiesfx.com — had been registered eleven weeks prior to David’s first contact, via a privacy-protected registrar in the Seychelles. It was a clone of a legitimate trading platform’s front end, with all withdrawal functionality disabled. David transferred £5,000 as a first deposit. Within forty-eight hours, his dashboard showed a return of £340 — a 6.8 percent gain. James sent him a congratulatory message. Linda expressed delight. David transferred another £15,000.  3 An FCA-branded platform with no FCA registration The FCA maintains a public register at fca.org.uk/register. EdgeStrategies FX appeared nowhere in it. Any platform displaying FCA branding should be verified against this register before any deposit is made. â–Œ OSINT FINDING — Domain Registration Domain: edgestrategiesfx.com Registered: 47 days before victim first contact Registrar: NameSilo LLC (privacy-protected) Registrant: REDACTED (Seychelles privacy service) SSL cert issued: Let’s Encrypt (automated, free) Hosting: Cloudflare CDN — origin IP masked Cloned interface: Detected match to legitimate EU trading platform (87% CSS similarity) FCA registration: NOT FOUND Stage 4: Escalation — Weeks 7 and 9 WEEK 7–9   The Deposit Ladder and the Sunk Cost Trap Over the following three weeks, David made eight further transfers totalling £142,000. The mechanism driving each transfer was consistent: his

Pig Butchering Scam Recovery Guide for Australia Victims Read More »

FBI IC3 2025 Annual Report: $20.9 Billion in Cybercrime Losses and What It Means for Victims

In April 2026, the Federal Bureau of Investigation released its 2025 Internet Crime Complaint Center Annual Report — and the numbers it contained were, by any measure, the most alarming in the history of the document. Americans reported losing $20.877 billion to cybercrime in 2025. That figure represents a 26 percent increase on the previous year, and it marks the first time in the IC3’s history that annual complaints exceeded one million. These are not abstract statistics. Behind every billion dollars in that report is a collection of individuals who trusted the wrong platform, the wrong person, or the wrong investment opportunity. They are victims of crypto investment fraud, romance scams, fake trading platforms, employment schemes, and the growing category of artificial intelligence-enabled fraud that the FBI introduced as a crime descriptor for the first time in this report. At ICAR, we work with fraud victims across the United Kingdom, Europe, and Asia. We trace stolen assets, build forensic evidence packages, coordinate with exchanges and law enforcement, and pursue every legal avenue available to the people who come to us. We read the IC3 report not as an academic exercise but as a professional briefing — a map of the threat landscape we operate within every day. This article breaks down the key findings of the FBI IC3 2025 Annual Report, explains what they mean for fraud victims, and provides the context that turns statistics into understanding. The Headline Number: $20.877 Billion The total loss figure of $20.877 billion across 1,008,597 complaints is significant for several reasons beyond the sheer scale of the number. First, it represents the first year ever that the IC3 received more than one million complaints. The milestone matters because it reflects not only the growth of cybercrime but also, potentially, an increase in reporting — which has historically captured only a fraction of actual fraud. Researchers consistently estimate that fewer than 20 percent of fraud victims report to official channels. If that ratio holds, the true scale of cybercrime loss in the United States alone in 2025 could exceed $100 billion. Second, the 26 percent year-on-year increase is not an aberration. It continues a multi-year trajectory. In 2024, the IC3 reported $16.6 billion in losses. In 2023, it was $12.5 billion. The curve is not flattening. Third, the average loss per complaint — $20,699 — tells a story about who is being targeted. These are not low-value scams. The fraudsters operating at scale today are patient, organized, and targeting individuals with meaningful savings and assets. $20,877,000,000 Total cybercrime losses reported to FBI IC3 · 2025 · Source: FBI IC3 2025 Annual Report Cryptocurrency: The Dominant Loss Category Of the $20.877 billion in total losses, cryptocurrency-related fraud accounted for $11.366 billion — nearly 55 percent of all reported losses — across 181,565 complaints. This represents a 22 percent increase in cryptocurrency losses year on year. Within that cryptocurrency total, investment fraud dominated. The IC3 recorded $7.2 billion in losses attributed specifically to cryptocurrency investment fraud — a category that encompasses the schemes known variously as pig butchering, romance baiting, and fake crypto trading platforms. The mechanics of these schemes are well documented. A victim is contacted — typically through a dating application, social media platform, or a seemingly misdirected text message — by someone who gradually builds a relationship over days or weeks. The conversation eventually turns to investment, and the victim is introduced to what appears to be a sophisticated and profitable cryptocurrency trading platform. Initial deposits show impressive returns. The victim deposits more. Family members are sometimes encouraged to invest. When the victim attempts to withdraw funds, they discover that the platform was fraudulent from the first transaction. What makes these schemes particularly devastating is their psychological architecture. They are not primarily technical frauds — they are relationship frauds that happen to use cryptocurrency as their instrument. The average individual loss in pig butchering schemes is estimated at approximately $177,000, according to data from the Global Anti-Scam Organization. The FBI’s Operation Level Up, which proactively identifies and contacts active pig butchering victims, notified 3,780 people in 2025 alone — 78 percent of whom had no idea they were currently being scammed. Thirty-eight of those individuals were referred for suicide intervention. $11,366,000,000 Cryptocurrency fraud losses reported to FBI IC3 · 181,565 complaints · 2025 Investment Fraud: The Single Largest Loss Category Investment fraud as a whole — including but not limited to cryptocurrency investment fraud — was the largest loss category in the IC3 2025 report at $8.649 billion. This represents approximately 49 percent of all scam-related losses. The overlap between cryptocurrency and investment fraud is substantial. The majority of high-value investment fraud cases reported to the IC3 involve fake cryptocurrency platforms, fake trading accounts showing fabricated returns, and the particular cruelty of withdrawal fees — where victims who attempt to access their funds are told they must pay additional sums to release their money. Those additional sums are also stolen. The IC3 2025 data confirms what ICAR’s own casework reflects: investment fraud is no longer primarily targeting elderly or financially unsophisticated victims. The 30-to-49 age cohort is now among the most heavily affected demographic, and victims frequently include educated professionals, business owners, and individuals with prior financial market experience. Scammers have adapted their targeting accordingly — constructing elaborate professional personas, generating fake trading credentials, and building platforms that mimic the user experience of legitimate exchanges with sophisticated technical precision. AI-Related Fraud: A New Category for a New Era For the first time in its history, the FBI IC3 introduced ‘AI-related’ as a formal crime descriptor in its 2025 report. This is not a minor administrative development — it represents the FBI’s formal acknowledgement that artificial intelligence has become a material enabler of cybercrime. The AI-related crime category recorded 22,364 complaints and $893,346,472 in losses. Within that total, AI-enabled investment fraud accounted for $632 million — confirming that AI is being deployed most aggressively in the same space that has driven the overall growth

FBI IC3 2025 Annual Report: $20.9 Billion in Cybercrime Losses and What It Means for Victims Read More »

Cybercrime losses in 2025