Authorities have busted an alleged Ukrainian crypto scam network targeting victims across over 20 countries. The scam investment operation used platforms, returns, identity-data collection and wallet draining technology to steal cryptocurrency.
On 7 September 2026, The Security Service of Ukraine (SSU) reported this scam network generated a monthly turnover of about $1 million during their peak periods. To date, the investigators have found 62 victims with more than 46 Ukrainian citizens recruited into the operation as alleged perpetrators.
How the Crypto Investment Scam Worked
This Ukrainian crypto scam first began on Telegram. Some channels that were seemingly promoting profitable cryptocurrency investments were leading victims into an enticing trap. They were directed to fraudulent websites that were mimicking real investment platforms. People could still register, deposit funds, and monitor their apparent returns.
According to investigators, operators were manually creating fake transactions and apparently increased the balances that were displayed to users in their accounts. This built up the confidence of users in the platform before they tried to withdraw their “profits”.

It was at the withdrawal stage that victims were most compromised. Police found that at that point, users were asked to connect their main cryptocurrency wallet to approve a small test transaction. Shortly after, a hidden crypto drainer took the opportunity to transfer assets to wallets that were controlled by the alleged operators.
This is where linking multiple signals can become incredibly valuable. For example, a single customer action may look okay in isolation, but with additional context flag for greater risk. As a result, an exchange or financial provider could flag any transfers to wallet addresses already connected to drainer activity, odd transaction speed, or any other abnormal patterns on receiving accounts.
The Ukrainian crypto scam demonstrates how some investment fraud systems can build trust instead of relying on an immediate suspicious transaction. Before the victims were asked to approve a small wallet transaction, they had already seemingly seen returns and expected to receive money.
Fake KYC Added Another Layer of Risk
The biggest standout from the Ukrainian crypto scam was how modern crypto can exploit both identity and transaction flows. Its strong imitation of real Know Your Customer (KYC) and Identity Verification (IDV) processes reinforces the value of combining document, biometric, device, behavioral, and financial risk signals.. The National Police says that these fraudulent platforms gathered passport information, photographs, and other sensitive information during the whole registration and verification process.
For some customers, an identity check can make a service appear much more credible. These crypto scam networks seemingly exploited that expectation by creating the appearance of a familiar, regulated onboarding journey while gathering personal information.
This fake KYC process potentially exposes victims to subsequent identity theft or account takeover. Ukrainian authorities have not yet confirmed if the information was reused later. However, its collection creates a strong identity-fraud risk.
A Cross-Border Ukrainian Crypto Scam Network
The Ukrainian crypto scam also had the baseline structure of an organized fraud network. For example, the police reported that a 25-year old IT specialist was able to recruit over 46 people to do web development, victim communication, office administration, and security.
Victims were found all over the world in countries such as Germany, Latvia, the UK, and Canada. This case shows how quickly online investment fraud can cross jurisdictions with operators, infrastructure, victims, and cryptocurrency flows located in different countries. Thus far, the Ukrainian authorities carried out 34 searches and seized computers, phones, documents, cash, and vehicles are part of the wider investigation.
What Crypto Firms Can Take From The Case
Today, fraudsters are increasingly copying processes that make real financial services look trustworthy. Fraudulent investment returns establish credibility and fake verification mirrors regulated onboarding. That is how a routine-looking wallet request becomes a mechanism to steal assets.
Businesses need to be able to assess identity information alongside wider fraud signals. Passing an identity check should not be enough evidence that all activity is low risk. Moreover, identity information needs to be protected as a high-value asset. Teams must combine document, biometric, device, and behavioral signals where needed. The biggest lesson from the Ukrainian crypto scam for real firms is to ensure that authentic verification journeys be clearly differentiated from fraudulent ones.

Find out more AML news in ComplyCube’s CryptoCubed newsletter. We explore the latest in developments across identity verification and AML globally.



