When a crypto investor lost about $25,000 in USDT, the theft itself took seconds. Tracing it took much longer and led a private investigation team into a closed online community run by the people behind the scam.
The setup was simple. The victim was selling some USDT to a buyer he’d met online. Before paying, the buyer asked him to prove the coins weren’t linked to crime and sent a link to an “AML check” website. The victim connected his wallet and approved the transaction the site asked for. That approval handed over his funds.
Here is what the investigation that followed shows about how these scams work, and what it takes to look inside one.
1. The attack is a signature, not a hack
Connecting a wallet to a site reveals its address and little else. The real risk is approving a transaction. A malicious approval gives another address the right to move your tokens, sometimes the whole balance, and it stays valid until you revoke it. No password was stolen here and no system was breached. The victim was simply talked into signing.
2. Scammers run it like a business
On-chain tracing connected the fake AML site to a Drainer-as-a-Service operation. One team builds the phishing pages, the draining code and the dashboards. Affiliates rent the tools and bring in victims, keeping a share of each theft. In some publicly documented drainer operations, that share has reached 80%.
The money trail led to an invite-only community where the people behind the campaign appeared to coordinate and recruit new affiliates.
3. Getting in is an investigation of its own
Joining that community with a real account would have exposed the investigators. Platforms also screen new accounts for signals like network origin, browser setup, account history and phone number type, and they block anything that looks off.
So the team built a research identity from scratch: a new email address, a consistent browser profile and a network connection that matched the region under investigation.
The final hurdle was phone verification. A personal number was out. A foreign SIM card would have taken too long. VoIP numbers are often flagged as risky. Free public SMS sites were no good either, since anyone can read the codes and the numbers have been used countless times.
The team used a temporary mobile number from Get SMS verification service, which passed verification without linking the account to anyone real. Since temporary numbers can later be reassigned, the standard follow-up is to move two-factor authentication to an authenticator app as soon as the platform allows it.
4. Evidence is only as good as its paper trail
Inside, the team mapped three layers of the operation. Organizers and affiliates coordinated in private channels, sharing instructions and payout screenshots. Affiliates spread links to fake AML and compliance tools through local Facebook groups, Telegram communities and crypto forums. And on-chain analysis pointed to suspected P2P traders converting the proceeds into cash.
Every finding was saved with usernames and numeric user IDs, timestamps, message links, screenshots and file hashes proving nothing was changed afterward. Restraint mattered just as much. A shared wallet or referral code proves a technical link, not a shared identity, and a trader who handled stolen funds isn’t automatically a criminal.
5. OSINT builds the case, lawyers make it count
The tools that got the team inside, like proxies and temporary phone numbers, were the easy part, as long as they paid for good ones. The hard part is keeping a research identity believable for weeks or months, knowing that nothing is guaranteed. Accounts can be flagged long after sign-up, and a research persona can break a platform’s rules even when the investigation is legal.
Even a complete map of the network doesn’t return a single dollar on its own. Investigators can’t freeze funds or issue subpoenas. What they can do is give lawyers a well-documented record to take to exchanges, courts or law enforcement.
For most readers, though, the lesson that matters most is the first one. If anyone asks you to prove your funds are clean on a website they picked, don’t sign.

