Blockchain Chain Analysis OSINT Investment Scam

Evaluating an Investigative Process for Cryptocurrency-Related Crimes

Cartoon illustration of a magnifying glass examining a connected process flowchart, next to a validation shield checkmark and a methodology gear icon
Co-authored with: Kreaan Singh (CSIR) and Louise Leenen (University of the Western Cape / CAIR). Published in the Proceedings of the 20th International Conference on Cyber Warfare and Security (ICCWS 2025) — building on the authors' proposed Bitcoin Blockchain Investigation Methodology (Journal of Information Warfare, 2025).

This paper evaluates a previously proposed investigative process for cryptocurrency-related crimes, originally introduced by the authors, through the application of a real-world case study. The process covers crime reporting and case registration, on-chain analysis, off-chain analysis, and the transformation of investigative intelligence into court-admissible evidence.

This study focuses on a new, active case involving an elderly South African woman who was defrauded of a substantial portion of her pension through a fraudulent investment scheme, referred to throughout this paper as ###-Platform (redacted, as the case remains under active investigation). The case is presently being investigated by the Directorate for Priority Crime Investigation (DPCI) — a specialised unit of the South African Police Service tasked with addressing serious economic crimes, commonly known as the Hawks. By systematically applying the proposed investigative process to this case, the study assesses the framework's practical utility, adaptability, and effectiveness under real-world conditions, and reflects on the legal, technical and procedural challenges encountered.

Introduction

The adoption of blockchain technology has surged in recent years, and with it, a rise in criminal activity whereby fraudsters and organised crime use the complexities of blockchains to mask their activities. Cryptocurrency trading or investment scams typically begin on social media or through messaging apps — unsolicited contact from an unknown individual or online acquaintance introducing an unfamiliar trading platform significantly increases the likelihood of fraudulent activity.

This paper examines a case centred on the fraudulent investment platform ###-Platform, whose website is currently inactive. The case adheres to the phases and steps outlined in the authors' proposed methodology, "A Proposed Bitcoin Blockchain Investigation Methodology: Based on a Case Study Approach." The study presents the case background, analyses the case both on and off the blockchain according to the proposed process steps, conducts a link analysis once sufficient intelligence has been gathered to profile the target entity, and finally explores the law enforcement procedures required to convert actionable intelligence into evidence. Feedback on the process itself is provided throughout, discussing its strengths, weaknesses and potential improvements.

Case Background

An elderly woman contacted one of the authors to assist in the investigation and analysis of a fraudulent case in which she had fallen victim. She was persuaded to invest in ###-Platform, portrayed as a global online trading entity based in the United Kingdom, integrating traditional investments with crypto-based funding and trading mechanisms. The platform promised to manage elderly victims' pensions and generate large profits from the proceeds, advertising leveraged trading across assets including Bitcoin, Ethereum, the S&P 500 and Tesla — asserting significant growth, international clients, and access to top-tier liquidity and trading tools.

In March 2023, a criminal case was opened and assigned to a DPCI investigating officer. The victim had opened an account with VALR, a South African cryptocurrency exchange with no connection to ###-Platform, completing full Know Your Customer (KYC) onboarding. While depositing funds, VALR flagged unusual deposit patterns given her risk profile and age — but when asked, the victim assured VALR she was not being assisted or scammed, and her deposits proceeded unrestricted. She acquired cryptocurrency and transferred her funds to ###-Platform.

Once she realised she had been defrauded, her account of events changed. She informed VALR of her use of ###-Platform and the substantial returns she had been promised, and revealed that the scammers had accessed her personal computer via the remote-desktop application AnyDesk — according to the victim, the scammers purportedly executed trades on her behalf, as she was unfamiliar with the process herself. She provided the cryptocurrency address used at VALR and claimed to have lost close to ZAR 4,950,000 (roughly US $281,312) over two years — a figure corroborated by her bank statements and the police statement.

Analysis of the Case

The investigative process previously proposed by the authors serves as the foundation for this analysis. The process has five phases: data collection, analysis, theory development and validation, suspect identification and reasonable grounds, and legal action. These phases are not strictly sequential — several steps span two or three phases simultaneously, as the diagram below illustrates.

Flowchart of the proposed cryptocurrency crime investigation process, showing data collection, on-chain and off-chain analysis, theory development, suspect identification, and legal action phases
Figure 1. Process for Conducting Cryptocurrency Crime Investigations

Opening of Case

In this case, the investigation was already underway when the authors became involved, so the "opening a case" step was already complete. The victim provided the following inputs (redacted): a VALR transaction history file containing two main BTC addresses (32jC##…QaYG and 1Lac##…XFpU); the web domain www.###-platform.io; a list of names used by individuals who contacted her over WhatsApp and phone calls (almost certainly all fake); a list of SA and UK phone numbers; email addresses (including s#####e@cryptodotcom.info and a list of scammer names @###-platform.io); and a physical address in London.

On-Chain Analysis

The tool Breadcrumbs was used to perform the on-chain analysis, examining transaction history, wallet activity and smart contract interactions. The address 32jC##…QaYG in the victim's file is her BTC receiving address, with one outgoing transaction to 1Lac##…XFpU. Because this address sits within the VALR exchange, Breadcrumbs could not trace outgoing transactions directly — centralised exchanges process transfers off-chain within their own private internal ledger, breaking public traceability. With law enforcement's help, a Section 205 subpoena (a legal tool under South Africa's Criminal Procedure Act compelling a third party such as an exchange to disclose records) was issued to VALR, revealing that the scammers had transferred stolen cryptocurrency to three separate addresses.

Table 1. Scammer Addresses
Scammer AddressReference Name in Paper
1End##…4EFo (still holds 1.14 BTC)Scammer-Address-1
142T##…xmGo (0.28 BTC)Scammer-Address-2
1NvB##…gHfD (12.8 BTC)Scammer-Address-3

VALR also disclosed outgoing transactions from the scammer addresses linking to multiple cryptocurrency exchanges outside South Africa:

Table 2. Outgoing Transactions from Scammer Addresses
TXAddressExchange
bc1q##…9zwn32Eq##…ubrFCoinpayments.net
bc1q##…qd0t33jD##…Jen2Kyrrex.com
bc1q##…xvw53Q7h##…izCBKyrrex.com
bc1q##…4eea3AXC##…3GvhKyrrex.com
bc1q##…jsnw31ik##…8a6JKyrrex.com
bc1q##…4vm33HG7##…xRRuKyrrex.com
bc1q##…dmgy33jD##…Jen2Kyrrex.com

A further VALR address, 39F4##…jVDX, was found linked to Scammer-Address-3 — intelligence disclosed the name behind it as the victim's daughter's former boyfriend, the same person the victim said had introduced her to the platform. He reportedly also fell victim to the scheme himself, though he has not opened his own criminal case. This paper refers to the victim's own address as "Victim-Address-1" and the former boyfriend's as "Victim-Address-2." The figure below shows the transaction flow from both victim addresses into the three scammer addresses.

Breadcrumbs graph showing outgoing Bitcoin transactions from Victim Address 1 and Victim Address 2 flowing into Scammer Address 1, 2 and 3
Figure 2. Outgoing Transactions from Victim Addresses to Scammer Addresses

Tracing Scammer-Address-1, no direct transaction was found — but funds moved from VALR (Victim-Address-1) to a Binance deposit address, then to an external wallet, before travelling through seven further transactions to reach Scammer-Address-1, which currently still holds 1.14 BTC and is marked as a destination address (with a monitoring notification set for if the funds move again). Scammer-Address-2's funds moved through another wallet and the exchange HTX (Huobi), then through two further wallets to Kyrrex.com, from where 30,655.78 USDT was withdrawn to an external Tron-blockchain address and on to further Tron addresses, including one linked to Binance.

Breadcrumbs graph showing outgoing transactions from Scammer Address 2 and 3 flowing through multiple wallet addresses into the exchanges Kyrrex.com and CoinPayments.net
Figure 3. Outgoing Transactions from Scammer's Addresses to Cryptocurrency Exchanges

Scammer-Address-3's funds flowed into Kyrrex.com through several addresses — one of which, 31ik##…8a6J, Breadcrumbs flagged as a high-risk address previously linked to other scams. Funds were also converted from BTC to USDT on the Tron blockchain via two Tron addresses.

Breadcrumbs graph showing outgoing transactions from Kyrrex.com wallet addresses converting BTC to USDT on the Tron blockchain
Figure 4. Outgoing Transactions From kyrrex.com

Following the same path, other transactions from Scammer-Address-3 moved into CoinPayments.net, then to an external wallet and on to the exchange Luno. The "change" from these transactions (the Unspent Transaction Output returned to the sender) was paid into a separate CoinPayments.net-linked address, with remaining BTC sent to external wallets — one of which, bc1q##…ks3y, shows traces of payments into Coinbase, Binance, HitBTC and ByBit.

Breadcrumbs graph showing outgoing transactions from CoinPayments.net into an external wallet address that fans out into Coinbase, Binance, HitBTC and ByBit
Figure 5. Outgoing Transactions from CoinPayments.net

Section 205 subpoenas remain outstanding for several of these downstream exchanges — until they are issued, no further tracing can be performed on those specific branches.

Off-Chain Analysis

The off-chain analysis employs OSINT techniques to attempt to unmask the suspect's identity. Google searches on the three scammer addresses returned nothing, and even Google's Gemini AI chatbot only surfaced a chainabuse.com report that the analyst had filed themselves — a useful reminder that AI search tools can circularly reference an investigator's own prior work rather than surfacing anything new.

Passive OSINT — gathering information from public sources without any direct interaction with the target — was applied to each input. Truecaller identified the SA phone numbers as VoIP numbers linked to a "###-platform ZA Office." Google searches on the names associated with the platform connected each one to negative reviews on hellopeter.com and Trustpilot, though the names themselves (typical South African and UK names) are withheld in the paper. The domain's WHOIS and DNS history yielded little beyond confirming it is now inactive, but ScamAdviser and Scam Detector both returned strongly negative trust scores, flagging high proximity to other suspicious sites and a high phishing score. The domain was registered in mid-2022, shortly before the victim's scam began, and had been active for just under two years before going dark. Complaints on hellopeter.com and Trustpilot referenced the same names and numbers the victim had provided, and noted the scammers had previously operated under at least two other domain names — indicating a long-running, rebranding operation rather than a single one-off site. The provided email address was checked against several verification tools and found not to exist.

Active OSINT — which involves directly interacting with a target under a false pretence, such as an undercover profile — was not used in this investigation, since it requires explicit law enforcement authorisation and carries a real risk of tipping off the suspect. It remains a possible next step if the appropriate legal permissions are granted.

Link Analysis

A link analysis was performed using Maltego to visually map the connections between the victim, her bank, VALR, the three scammer addresses, and the ###-Platform entity itself — including the domain, email addresses, phone number lists and the (likely pseudonymous) name list. WhatsApp chat messages between the victim and the suspects were retrieved and stored in Maltego, though they yielded no further personal details beyond the fake names already used. Connections were also drawn to hellopeter.com and Trustpilot, where the same names from the victim's list appeared in other negative reviews.

Maltego link analysis graph connecting the victim, her bank account, VALR, the three scammer Bitcoin addresses, the ###-Platform entity, its domain and email addresses, and negative review sites hellopeter.com and Trustpilot
Figure 6. Link Analysis

Law Enforcement Function

VALR's Section 205 subpoena response proved highly beneficial to the investigation, disclosing both the account holder's personal information and outgoing transactions. A subpoena was also sent to Kyrrex.com, though no formal response had been received at the time of writing — a law enforcement contact was nonetheless able to informally obtain the outgoing transaction data, along with an account username, "M Mpayme," which turned out to be a fabricated name and of no further use. Ultimately, the scammers' true identities remain undisclosed. As the paper puts it plainly: scammers are adept at hiding their traces, and the best hope remains following the funds on-chain in the expectation that they eventually make a mistake and leak information usable in off-chain analysis. A follow-up study focused on the off-chain side is planned.

Process Evaluation

This case is the fourth in a series of studies applying and progressively refining the same investigative process — following prior applications to the MTI crypto investment scam, a divorce case involving hidden Bitcoin mining proceeds, and a cryptocurrency giveaway scam. Each case has fed back into the process, and this study aimed to determine where it could be refined further.

The process offers a structured, systematic method for tackling cryptocurrency crime investigations, underscoring the necessity of collecting data from diverse sources to build a comprehensive picture of illegal activity. Clustering and pattern analysis are treated as fundamental to blockchain analytics, and link analysis and visualisation are highlighted as critical both for understanding complex transaction networks and for communicating findings to non-technical stakeholders such as law enforcement.

The clearest gap identified in this evaluation is that the off-chain section of the process does not yet provide enough detail. While the on-chain analysis steps are thorough, the off-chain analysis and OSINT sections would benefit from more depth, specific technique guidance, and worked examples of suspicious transaction patterns — along with clearer metrics for how the process itself should be evaluated. As blockchain technology and investigative methods continue to advance, the process is intended to be updated regularly to keep pace.

Conclusion

With the growing adoption of blockchain technology comes a corresponding rise in cryptocurrency-related crime. This paper evaluated a structured investigative process previously proposed by the authors, using a real case study involving an elderly woman deceived by a fraudulent investment scheme, currently under investigation by the CSIR in collaboration with South African law enforcement. No personal details of the victim have been disclosed, and all cryptocurrency addresses and transactions have been masked to prevent full identification.

The five-phase process — spanning data collection, on-chain and off-chain analysis, suspect identification, and legal action — was applied step by step: opening the case, tracing funds on-chain, applying passive OSINT techniques off-chain, visualising the results through link analysis, and finally engaging the law enforcement subpoena process. Online scams remain a significant international threat due to the absence of standardised, official legislation, and the borderless nature of cryptocurrency transactions continues to drive their growth across financial and cyber crime. Beyond evaluating the process itself, this paper aims to raise awareness of fake investment scams and fraudulent cryptocurrency investment platforms — particularly those targeting elderly and non-technical victims.

Loading ratings…
Found this useful? Rate this post:
Thanks for rating!

Comments (0)

Loading comments…

Leave a comment

Your email address will not be published. Comments are reviewed before appearing publicly.