Blockchain Crypto-scam Investigation OSINT

An Analysis of a Cryptocurrency Giveaway Scam: Use Case

Cartoon illustration of a gift box with a bitcoin coin being pulled out on a fishing hook, next to a warning triangle
Co-authored with: Louise Leenen (University of the Western Cape / CAIR).

A giveaway scam is a type of fraud leveraging social media platforms and phishing campaigns. These scams have become increasingly common and are now prevalent in the crypto community, where attackers attempt to gain crypto-enthusiasts' trust with the promise of high-yield giveaways. Giveaway scams target individuals who lack technical familiarity with the blockchain, often presenting as genuine cryptocurrency giveaways endorsed by prominent figures or organisations. Scammers entice victims by promising substantial returns on a nominal investment — victims are manipulated into sending cryptocurrency under the pretext of paying "verification" or "processing fees." Once the funds have been sent, the scammers disappear and leave victims empty-handed.

This study employs essential blockchain tools and techniques to explore the mechanics of giveaway scams. A crucial aspect of an investigation is to meticulously trace the movement of funds within the blockchain so that illicit gains can be tracked. At some point a scammer wants to "cash-out" by transferring the funds to an off-ramp, such as an exchange — if the investigator can establish a link to such an exchange, the identity behind the cryptocurrency address could be revealed. However, in organised scams, criminals make use of mules and do not use their own identities.

Introduction and Background

Cryptocurrency giveaway scams are one of the most common scams, in which an attacker lures a victim by announcing a giveaway of a certain cryptocurrency or digital asset. These types of scams have been a major problem for the crypto community since late 2017. A giveaway scam is a form of social engineering where a scammer attempts to deceive an investor into believing some major crypto exchange, such as Coinbase or Binance, is hosting a giveaway. To participate, the investor is asked to send a specified amount of cryptocurrency to a given address so the platform can "verify" the investor's wallet and the legitimacy of their account. Crypto transactions are irreversible — once a victim has sent funds to the scammer's address, the transaction cannot be reversed. Legitimate exchanges do run real promotions from time to time, but they never request cryptocurrency contributions to participate.

Scammers make use of social media to advertise their fake giveaways, and a giveaway scam is often linked to an impersonation scam — of a company, a celebrity, or a famous influencer. An example involving a company impersonation may involve a Twitter account supposedly belonging to Coinbase, promoting a 5000 Bitcoin giveaway via a tweet containing a link to a fraudulent page. Celebrities frequently impersonated in giveaway scams include Elon Musk and Michael Saylor, among others. The scammer will pretend to have benefited from a giveaway by supposedly thanking the impersonated celebrity in a tweet — the example below shows a manipulated tweet supposedly posted by Musk, promoting a cryptocurrency giveaway hosted by Tesla. The image was manipulated and did not originate from Musk; the link redirects to a landing page offering "free" Bitcoin and Ethereum.

A fake tweet impersonating Elon Musk announcing a Tesla crypto giveaway, marked with a red X to show it is a scam
Figure 1. Celebrity Twitter Impersonation (Hauer, 2020)

Another method scammers use is to send a direct message (DM) on a social media platform, pretending to be a celebrity or an ambassador of that celebrity, advising a potential victim to participate in a crypto investment or giveaway. When a victim engages, they are asked to message a given cell phone number so "assistance" can be provided — a more personal approach containing a link with further participation details. When a target opts in, a crypto address is provided to which coins can be sent to receive, for example, double the reward in return. The scam continues after the victim sends money: the attacker sends fake proof of generated profits, then requests a withdrawal fee. By the time the victim realises no payment is coming, it is too late.

Fake Tesla-branded website promoting a biggest crypto giveaway of $100,000,000 featuring a photo of Elon Musk
Figure 2. Tesla Crypto Giveaway (Guez, 2023)

YouTube live streams are a newer technique used by scammers to lure victims. A scammer creates a YouTube video using an older interview with a famous person or CEO, overlays it with giveaway promotion details, and sets it up to appear as a live stream — enticing viewers to participate immediately. A link or QR code in the description directs viewers to a page with more details on the fake giveaway. It will also appear as if thousands of people are participating, but these are generally bots. The YouTube account will often appear verified — in these cases the real account was hacked, its contents deleted, and the attackers run their own livestream. The example below is a screenshot of a YouTube live stream using a video of an actual interview with Coinbase CEO Brian Armstrong.

A fake YouTube live stream using footage of Coinbase CEO Brian Armstrong, promoting a 5,000 BTC giveaway, marked with a red X to show it is a scam
Figure 3. YouTube Live Stream

A more traditional way scammers lure victims is via phishing email, attempting to convince a user that a crypto giveaway is being hosted. Scammers have been around long before crypto, but find some of its characteristics very appealing — crypto has no middleman as with bank transactions, and direct transactions occur between two individuals. Investigating and exploring cryptocurrency transactions remains intractably hard due to their pseudonymous nature, with every cryptocurrency having its own protocol and blockchain.

Use Case Selection

During the search for a relevant use case, various websites and data sources were considered. Bitcoinabuse.com, now merged with Chainabuse.com, is currently the leading platform for reporting malicious cryptocurrency activities. Upon filtering the results to impersonation scams, similar to giveaway scams, one particular scam impersonated Michael Saylor, the former CEO of MicroStrategy. This scam was selected as the use case because Saylor is a popular figure in the crypto space, a billionaire with a net worth of $2.9 billion (as of 8 January 2024), one of the biggest Bitcoin Maxis, and one of the biggest Bitcoin holders via MicroStrategy. The scam was reported on 6 January 2024. The two contributing crypto addresses were:

The scam was announced on a YouTube channel called "Super DJ Sound," where a live video of an interview with Mr Saylor regarding the Bitcoin ETF approval had been manipulated with added giveaway information directing participants to the landing page. In the chat section, Mr Saylor was impersonated, interacting directly with participants. The link to the actual video no longer works and has since been removed.

Manipulated YouTube live stream of Michael Saylor discussing a Bitcoin ETF, with a fake chat impersonating him promoting a giveaway link
Figure 4. Live YouTube Video — Bitcoin ETF — Michael Saylor

The channel displayed a QR code that took participants to a fake MicroStrategy website, announcing a giveaway of crypto assets worth $1 billion. The website looked exactly like the Tesla giveaway example above, apart from the impersonated individual's photo — indicating the same scammer is running multiple scams using the same website template with different impersonations swapped in. At the time of writing, Windows Defender reported the website as unsafe, though it could still be accessed by ignoring the warning.

Fake MicroStrategy-branded website promoting a biggest crypto giveaway of $100,000,000 featuring a photo of Michael Saylor
Figure 5. MicroStrategy Crypto Giveaway

On the fake website, a giveaway of 1000 BTC and 10,000 ETH was promised. To participate, users were told to send between 0.1–15 BTC or 1–200 ETH to the contributing address, and MicroStrategy would "send back" double the amount. A list of supposedly successful payback transactions was shown on the landing page, with the addresses deliberately not displayed in full so they could not be verified.

Fake transaction list on the scam website showing supposedly completed BTC and ETH payback transactions with partially hidden addresses
Figure 6. Completed Payback Transaction List

Analysis and Investigation of the Use Case

A popular misunderstanding regarding blockchain transactions is that they are completely anonymous. Bitcoin is the most popular cryptocurrency blockchain and all its transactions are visible to the public — but only transactional data are visible, with no personal information linked to any transaction available. Ethereum is the second most popular blockchain; in 2022, 80% of crypto theft was calculated to have involved it. Since no personal information is directly available, other techniques and tools are needed to identify entities behind transactions. Five popular techniques are used when analysing and investigating a cryptocurrency crime:

Crypto Transaction Tracing

Also referred to as "following the flow of funds" — analysing transaction metadata such as the from and to addresses, the amount transacted and the timestamp to build a hypothesis, identify hidden relationships, and detect suspicious activity.

Address Clustering

Grouping addresses likely to belong to the same person or entity, since people tend to reuse a set of addresses rather than creating a new one for every transaction. The technique considers the frequency, amount and timing of transactions.

Graph Analysis

Visualising the flow of funds using nodes for addresses and connecting lines for transactions, helping investigators identify clusters, patterns and relationships between addresses.

Heuristics

Using functions based on domain knowledge to enhance pattern-finding algorithms. For address clustering, the multi-input-heuristic (MIH) method is the most effective and widely studied: it assumes that if two addresses (A and B) are used as inputs into the same transaction, and one of them (B) is also used with another address (C) as inputs into a different transaction, then all three addresses must be controlled by the same actor, who holds the private keys to all three.

Diagram showing addresses A and B as inputs to transaction T1, and B and C as inputs to transaction T2, illustrating the multi-input clustering heuristic
Figure 7. Multi-Input Clustering Heuristics (Fröwis, 2020)

Data Analysis

Studying patterns, relationships and anomalies in transaction data that could be key to closing complex cases — uncovering hidden relationships in large volumes of data.

To perform this kind of analysis, a capable tool is needed — options include Maltego, QLUE, Tatum, CipherTrace and Breadcrumbs. Most are quite expensive; Breadcrumbs has a more affordable option and was selected for this investigation.

The investigation had two angles to start from: the scammer's BTC contributing address, and the scammer's ETH contributing address, both found on the fake landing page. Entering the BTC address into the tool revealed no transactions at all — no funds had ever been received or sent, suggesting no one fell for the BTC side of the scam, possibly because 1 BTC was too expensive for targets who found it cheaper to participate via Ethereum instead. Entering the ETH address, however, revealed three incoming transactions: one from an address linked to Coinbase, one from a standalone wallet address, and one from an address linked to Binance.

Breadcrumbs graph showing three incoming transactions from Coinbase, a wallet address, and Binance into the scammer's ETH address, with four outgoing transactions
Figure 8. Scammer's ETH Address Incoming and Outgoing Transactions
Table 1. Direct Incoming Transactions into Scammer's Address
SourceFrom AddressSent (ETH)Timestamp
Coinbase0xa9d1…3e431.16977 Jan 2024, 18:54
Wallet Address0x1ba2…f6900.90787 Jan 2024, 23:18
Binance0x21a3…55490.24875 Jan 2024, 18:30

A total of 2.3264 ETH had been sent to the scammer's address, matching the sum from the three sources above. The first transaction was made on 5 January 2024, suggesting a newly created address probably intended only for the lifetime of this scam. The address still holds a residual balance of 0.0039 ETH; most of the incoming funds were moved quickly, with the last outgoing transaction executed on 8 January 2024.

Breadcrumbs address panel for the scammer's ETH address showing a balance of 0.039 ETH, first transaction 5 January 2024, last transaction 8 January 2024, and incoming/outgoing volume donut charts
Figure 9. Scammer's ETH Incoming and Outgoing Volume

Four outgoing transactions were made from the scammer's address to four separate cryptocurrency wallet addresses. The table below lists each, including their total received and sent at the time of writing — note that amounts may change if funds are moved again in future.

Table 2. Direct Outgoing Transactions from Scammer's Address
To AddressReceived (ETH)TimestampTotal Received (ETH)Total Sent (ETH)Balance (ETH)
(1) 0x5007…004f0.98257 Jan 2024, 23:370.98250.98140
(2) 0x3a35…cdf40.77 Jan 2024, 23:461.68141.67940
(3) 0x44da…50b70.38748 Jan 2024, 19:5138.705132.11146.527
(4) 0x7e5a…a0740.21468 Jan 2024, 20:382.33282.30190

An interesting observation: the full amount received in address (1) was passed straight on to address (2), and both ended with a 0 ETH balance — following the flow further using Breadcrumbs, a transaction was found leading into an exchange called FixedFloat. Since address (1) and (2) both settled to 0 ETH, the funds had clearly moved on. Any address with a balance greater than 0 ETH is marked as an address of interest for a potential subpoena, since the next step is to determine whether the linked exchange requires Know Your Customer (KYC) information.

Address (3) had received 38.7051 ETH in total — far more than the 0.3874 ETH sent from the scammer's address alone — indicating funds were received from other sources as well, and that this is likely a more permanent address the scammer uses across multiple scams, rather than one created for this scam's lifetime alone. Only 32.1114 ETH had been sent back out, leaving a balance of 6.527 ETH — since this balance is not 0, the address is marked of high interest and monitored for future movement. One of its outgoing transactions linked to an address on Kucoin, an exchange that requires KYC; tracing further showed a transfer into the Kucoin Main Wallet address, which was also fed by a separate FixedFloat address — suggesting the scammer performs a form of mixing, funnelling funds through multiple addresses and exchanges before consolidating them back into one wallet.

Continuing to trace from the Kucoin Main Wallet and beyond revealed transactions fanning out into further wallets and exchanges — Binance, OKX, MXC, FixedFloat, HitBTC, WhiteBit and Bitget among them — several with non-zero balances and therefore marked as addresses of high interest, each a candidate for a subpoena. Address (4) showed a similar pattern: it had received 2.3328 ETH in total but only 0.2146 ETH from the scammer directly, again suggesting it receives funds from more than one scam. The full reconstructed trace below shows the complete picture uncovered across all four outgoing paths.

Full Breadcrumbs transaction tracing graph showing the scammer's address branching through numbered intermediate addresses into Kucoin, FixedFloat, Binance, HitBTC, WhiteBit, OKX, MXC and Bitget exchange wallets
Figure 10. Transaction Tracing

None of the ETH addresses uncovered during this analysis matched the visible (truncated) parts of the addresses shown in the fake payback transaction list on the scam site — confirming those listed transactions were fabricated and never occurred on the Ethereum blockchain.

Protection Against and Avoiding Giveaway Scams

Scammers are drawn to cryptocurrency because there is no bank or centralised body to flag suspicious transactions, and transactions cannot be reversed. Giveaway scams are normally run via impersonation of a legitimate platform or celebrity. Legitimate platforms do run real promotions, but never request a crypto contribution in exchange for a larger return, and no celebrity or influencer will DM an unknown individual offering to "help" with a trading or investment scheme.

Scammers increasingly leverage AI-powered tools to amplify their reach and simulate a fanbase of thousands of fake interactions, and even use AI-driven bots to run "pig butchering" scams — spending days building trust with a target before scamming them. Fortunately, AI is also being used defensively: a system called GiveawayScamHunter, developed by researchers at San Diego State University, identified over 95,000 scam lists created by more than 87,000 accounts between June 2022 and June 2023, and reported 365 victims losing over $872,000 during that period.

Common red flags to watch for:

If you believe you have been scammed, report it immediately — to your country's Internet crime or complaints centre, a relevant federal trade commission or organisation, the exchange involved if one was used, or on Chainabuse. To avoid these scams altogether: understand that no one on the Internet is going to give something away for free, and no one will double your investment in exchange for a crypto payment. If it sounds too good to be true, it usually is.

Conclusion

Blockchain adoption continues to increase, and so do crypto-crimes and scams. This study provided examples of known crypto giveaway scams and raised awareness of the pattern. A use case was selected from Chainabuse.com — a crypto giveaway scam promoted via a manipulated YouTube live stream of an interview with former MicroStrategy CEO Michael Saylor, directing participants to a fake giveaway webpage. Once a user sent crypto to the specified address, they had been scammed.

Using Breadcrumbs to trace address clustering, graph analysis, heuristics and data analysis, the investigation traced the scammer's ETH address through several exchanges — Kucoin, FixedFloat, Binance, OKX, MXC, HitBTC, WhiteBit and Bitget — up to the point where a link could be made to an exchange requiring KYC. From there, in collaboration with law enforcement, a subpoena could be issued to reveal the personal information behind those addresses. Since there is no official legislation in place to guard against crypto scams, it remains a very significant international threat that cannot be ignored.

Read the full published paper this article is based on on Google Scholar → or ResearchGate →, or browse the author's full research profile on Google Scholar → or ResearchGate →

Loading ratings…
Found this useful? Rate this post:
Thanks for rating!

Comments (0)

Loading comments…

Leave a comment

Your email address will not be published. Comments are reviewed before appearing publicly.