This paper evaluates a previously proposed investigative process for cryptocurrency-related crimes, originally introduced by the authors, through the application of a real-world case study. The process covers crime reporting and case registration, on-chain analysis, off-chain analysis, and the transformation of investigative intelligence into court-admissible evidence.
This study focuses on a new, active case involving an elderly South African woman who was defrauded of a substantial portion of her pension through a fraudulent investment scheme, referred to throughout this paper as ###-Platform (redacted, as the case remains under active investigation). The case is presently being investigated by the Directorate for Priority Crime Investigation (DPCI) — a specialised unit of the South African Police Service tasked with addressing serious economic crimes, commonly known as the Hawks. By systematically applying the proposed investigative process to this case, the study assesses the framework's practical utility, adaptability, and effectiveness under real-world conditions, and reflects on the legal, technical and procedural challenges encountered.
Introduction
The adoption of blockchain technology has surged in recent years, and with it, a rise in criminal activity whereby fraudsters and organised crime use the complexities of blockchains to mask their activities. Cryptocurrency trading or investment scams typically begin on social media or through messaging apps — unsolicited contact from an unknown individual or online acquaintance introducing an unfamiliar trading platform significantly increases the likelihood of fraudulent activity.
This paper examines a case centred on the fraudulent investment platform ###-Platform, whose website is currently inactive. The case adheres to the phases and steps outlined in the authors' proposed methodology, "A Proposed Bitcoin Blockchain Investigation Methodology: Based on a Case Study Approach." The study presents the case background, analyses the case both on and off the blockchain according to the proposed process steps, conducts a link analysis once sufficient intelligence has been gathered to profile the target entity, and finally explores the law enforcement procedures required to convert actionable intelligence into evidence. Feedback on the process itself is provided throughout, discussing its strengths, weaknesses and potential improvements.
Case Background
An elderly woman contacted one of the authors to assist in the investigation and analysis of a fraudulent case in which she had fallen victim. She was persuaded to invest in ###-Platform, portrayed as a global online trading entity based in the United Kingdom, integrating traditional investments with crypto-based funding and trading mechanisms. The platform promised to manage elderly victims' pensions and generate large profits from the proceeds, advertising leveraged trading across assets including Bitcoin, Ethereum, the S&P 500 and Tesla — asserting significant growth, international clients, and access to top-tier liquidity and trading tools.
In March 2023, a criminal case was opened and assigned to a DPCI investigating officer. The victim had opened an account with VALR, a South African cryptocurrency exchange with no connection to ###-Platform, completing full Know Your Customer (KYC) onboarding. While depositing funds, VALR flagged unusual deposit patterns given her risk profile and age — but when asked, the victim assured VALR she was not being assisted or scammed, and her deposits proceeded unrestricted. She acquired cryptocurrency and transferred her funds to ###-Platform.
Once she realised she had been defrauded, her account of events changed. She informed VALR of her use of ###-Platform and the substantial returns she had been promised, and revealed that the scammers had accessed her personal computer via the remote-desktop application AnyDesk — according to the victim, the scammers purportedly executed trades on her behalf, as she was unfamiliar with the process herself. She provided the cryptocurrency address used at VALR and claimed to have lost close to ZAR 4,950,000 (roughly US $281,312) over two years — a figure corroborated by her bank statements and the police statement.
Analysis of the Case
The investigative process previously proposed by the authors serves as the foundation for this analysis. The process has five phases: data collection, analysis, theory development and validation, suspect identification and reasonable grounds, and legal action. These phases are not strictly sequential — several steps span two or three phases simultaneously, as the diagram below illustrates.
Opening of Case
In this case, the investigation was already underway when the authors became involved, so the "opening a case" step was already complete. The victim provided the following inputs (redacted): a VALR transaction history file containing two main BTC addresses (32jC##…QaYG and 1Lac##…XFpU); the web domain www.###-platform.io; a list of names used by individuals who contacted her over WhatsApp and phone calls (almost certainly all fake); a list of SA and UK phone numbers; email addresses (including s#####e@cryptodotcom.info and a list of scammer names @###-platform.io); and a physical address in London.
On-Chain Analysis
The tool Breadcrumbs was used to perform the on-chain analysis, examining transaction history, wallet activity and smart contract interactions. The address 32jC##…QaYG in the victim's file is her BTC receiving address, with one outgoing transaction to 1Lac##…XFpU. Because this address sits within the VALR exchange, Breadcrumbs could not trace outgoing transactions directly — centralised exchanges process transfers off-chain within their own private internal ledger, breaking public traceability. With law enforcement's help, a Section 205 subpoena (a legal tool under South Africa's Criminal Procedure Act compelling a third party such as an exchange to disclose records) was issued to VALR, revealing that the scammers had transferred stolen cryptocurrency to three separate addresses.
| Scammer Address | Reference Name in Paper |
|---|---|
| 1End##…4EFo (still holds 1.14 BTC) | Scammer-Address-1 |
| 142T##…xmGo (0.28 BTC) | Scammer-Address-2 |
| 1NvB##…gHfD (12.8 BTC) | Scammer-Address-3 |
VALR also disclosed outgoing transactions from the scammer addresses linking to multiple cryptocurrency exchanges outside South Africa:
| TX | Address | Exchange |
|---|---|---|
| bc1q##…9zwn | 32Eq##…ubrF | Coinpayments.net |
| bc1q##…qd0t | 33jD##…Jen2 | Kyrrex.com |
| bc1q##…xvw5 | 3Q7h##…izCB | Kyrrex.com |
| bc1q##…4eea | 3AXC##…3Gvh | Kyrrex.com |
| bc1q##…jsnw | 31ik##…8a6J | Kyrrex.com |
| bc1q##…4vm3 | 3HG7##…xRRu | Kyrrex.com |
| bc1q##…dmgy | 33jD##…Jen2 | Kyrrex.com |
A further VALR address, 39F4##…jVDX, was found linked to Scammer-Address-3 — intelligence disclosed the name behind it as the victim's daughter's former boyfriend, the same person the victim said had introduced her to the platform. He reportedly also fell victim to the scheme himself, though he has not opened his own criminal case. This paper refers to the victim's own address as "Victim-Address-1" and the former boyfriend's as "Victim-Address-2." The figure below shows the transaction flow from both victim addresses into the three scammer addresses.
Tracing Scammer-Address-1, no direct transaction was found — but funds moved from VALR (Victim-Address-1) to a Binance deposit address, then to an external wallet, before travelling through seven further transactions to reach Scammer-Address-1, which currently still holds 1.14 BTC and is marked as a destination address (with a monitoring notification set for if the funds move again). Scammer-Address-2's funds moved through another wallet and the exchange HTX (Huobi), then through two further wallets to Kyrrex.com, from where 30,655.78 USDT was withdrawn to an external Tron-blockchain address and on to further Tron addresses, including one linked to Binance.
Scammer-Address-3's funds flowed into Kyrrex.com through several addresses — one of which, 31ik##…8a6J, Breadcrumbs flagged as a high-risk address previously linked to other scams. Funds were also converted from BTC to USDT on the Tron blockchain via two Tron addresses.
Following the same path, other transactions from Scammer-Address-3 moved into CoinPayments.net, then to an external wallet and on to the exchange Luno. The "change" from these transactions (the Unspent Transaction Output returned to the sender) was paid into a separate CoinPayments.net-linked address, with remaining BTC sent to external wallets — one of which, bc1q##…ks3y, shows traces of payments into Coinbase, Binance, HitBTC and ByBit.
Section 205 subpoenas remain outstanding for several of these downstream exchanges — until they are issued, no further tracing can be performed on those specific branches.
Off-Chain Analysis
The off-chain analysis employs OSINT techniques to attempt to unmask the suspect's identity. Google searches on the three scammer addresses returned nothing, and even Google's Gemini AI chatbot only surfaced a chainabuse.com report that the analyst had filed themselves — a useful reminder that AI search tools can circularly reference an investigator's own prior work rather than surfacing anything new.
Passive OSINT — gathering information from public sources without any direct interaction with the target — was applied to each input. Truecaller identified the SA phone numbers as VoIP numbers linked to a "###-platform ZA Office." Google searches on the names associated with the platform connected each one to negative reviews on hellopeter.com and Trustpilot, though the names themselves (typical South African and UK names) are withheld in the paper. The domain's WHOIS and DNS history yielded little beyond confirming it is now inactive, but ScamAdviser and Scam Detector both returned strongly negative trust scores, flagging high proximity to other suspicious sites and a high phishing score. The domain was registered in mid-2022, shortly before the victim's scam began, and had been active for just under two years before going dark. Complaints on hellopeter.com and Trustpilot referenced the same names and numbers the victim had provided, and noted the scammers had previously operated under at least two other domain names — indicating a long-running, rebranding operation rather than a single one-off site. The provided email address was checked against several verification tools and found not to exist.
Active OSINT — which involves directly interacting with a target under a false pretence, such as an undercover profile — was not used in this investigation, since it requires explicit law enforcement authorisation and carries a real risk of tipping off the suspect. It remains a possible next step if the appropriate legal permissions are granted.
Link Analysis
A link analysis was performed using Maltego to visually map the connections between the victim, her bank, VALR, the three scammer addresses, and the ###-Platform entity itself — including the domain, email addresses, phone number lists and the (likely pseudonymous) name list. WhatsApp chat messages between the victim and the suspects were retrieved and stored in Maltego, though they yielded no further personal details beyond the fake names already used. Connections were also drawn to hellopeter.com and Trustpilot, where the same names from the victim's list appeared in other negative reviews.
Law Enforcement Function
VALR's Section 205 subpoena response proved highly beneficial to the investigation, disclosing both the account holder's personal information and outgoing transactions. A subpoena was also sent to Kyrrex.com, though no formal response had been received at the time of writing — a law enforcement contact was nonetheless able to informally obtain the outgoing transaction data, along with an account username, "M Mpayme," which turned out to be a fabricated name and of no further use. Ultimately, the scammers' true identities remain undisclosed. As the paper puts it plainly: scammers are adept at hiding their traces, and the best hope remains following the funds on-chain in the expectation that they eventually make a mistake and leak information usable in off-chain analysis. A follow-up study focused on the off-chain side is planned.
Process Evaluation
This case is the fourth in a series of studies applying and progressively refining the same investigative process — following prior applications to the MTI crypto investment scam, a divorce case involving hidden Bitcoin mining proceeds, and a cryptocurrency giveaway scam. Each case has fed back into the process, and this study aimed to determine where it could be refined further.
The process offers a structured, systematic method for tackling cryptocurrency crime investigations, underscoring the necessity of collecting data from diverse sources to build a comprehensive picture of illegal activity. Clustering and pattern analysis are treated as fundamental to blockchain analytics, and link analysis and visualisation are highlighted as critical both for understanding complex transaction networks and for communicating findings to non-technical stakeholders such as law enforcement.
Conclusion
With the growing adoption of blockchain technology comes a corresponding rise in cryptocurrency-related crime. This paper evaluated a structured investigative process previously proposed by the authors, using a real case study involving an elderly woman deceived by a fraudulent investment scheme, currently under investigation by the CSIR in collaboration with South African law enforcement. No personal details of the victim have been disclosed, and all cryptocurrency addresses and transactions have been masked to prevent full identification.
The five-phase process — spanning data collection, on-chain and off-chain analysis, suspect identification, and legal action — was applied step by step: opening the case, tracing funds on-chain, applying passive OSINT techniques off-chain, visualising the results through link analysis, and finally engaging the law enforcement subpoena process. Online scams remain a significant international threat due to the absence of standardised, official legislation, and the borderless nature of cryptocurrency transactions continues to drive their growth across financial and cyber crime. Beyond evaluating the process itself, this paper aims to raise awareness of fake investment scams and fraudulent cryptocurrency investment platforms — particularly those targeting elderly and non-technical victims.
Comments (0)