Blockchain Crime Crypto Investigation OSINT

An Analysis of the MTI Crypto Investment Scam: Use Case

Mirror Trading International logo stamped SCAM, banner reading Case Study — Analysing a $1.7bn Crypto Investment Scam
Co-authored with: Thor Pederson (TCG Forensics) and Louise Leenen (University of the Western Cape / CAIR). Reviewed by Jeff Lomas, a detective and digital forensics examiner at the Las Vegas Metropolitan Police Department.

Since the start of the Covid-19 pandemic, blockchain and cryptocurrency adoption has increased significantly — the adoption rate of blockchain-based technologies has surpassed the Internet adoption rate of the 90s and early 2000s. As this industry has grown, so too has the number of crypto scams. Mirror Trading International (MTI) has been named South Africa's biggest crypto scam of 2020, resulting in losses of $1.7 billion, and is one of the largest reported international crypto investment scams.

This paper focuses on a specific aspect of the MTI scam: an analysis of the fund movements on the blockchain from the perpetrators and the members who benefitted the most from the scheme. We used various Open-Source Intelligence (OSINT) tools, alongside QLUE, news articles and blockchain explorers to follow the money-trail on the blockchain, in search of possible mistakes made by the perpetrators. With the CEO of MTI arrested and the case still before the South African courts, this paper also proposes an investigative process for crypto crimes and scams.

Introduction

Cryptocurrencies, Non-Fungible Tokens (NFTs), Decentralised Finance (DeFi) and smart contracts are all terms associated with blockchain technology, which has been growing at a rapid pace. However, the popularity of crypto has attracted the attention of scammers and fraudsters. Illicit transactions in cryptocurrency reached a staggering $14-billion in 2021, an 80% increase from 2020 — a new record. Crypto has no middleman as with banks; direct transactions occur between two individuals and transfers are much faster than traditional finance systems. Pseudonyms are used on unregulated exchanges instead of actual personal details, making crypto transactions difficult to trace in an already relatively unregulated space.

The Covid-19 pandemic brought difficult times with job losses and salary cuts. People became desperate to invest in alternative methods, and crypto seemed like the perfect solution — a consequence being that scammers took advantage of the opportunity. Investigating cryptocurrency transactions remains intractably hard due to their pseudonymous nature, with every cryptocurrency having its own protocol and blockchain.

Cryptocurrencies are, however, based on a public blockchain visible to anyone. The flow of illicit transactions can be traced and investigated using advanced techniques, with the goal of finding the destination address that contains the stolen funds. The next step for an investigator is to unmask the owner of the address by combining OSINT and Know Your Customer (KYC) data collected from cryptocurrency exchanges, then connecting with law enforcement to have subpoenas issued in an attempt to seize or recover the stolen funds.

Some of the methods used by criminals to perform anonymous transactions on the blockchain are mixers or tumblers — services that combine cryptocurrencies from various users and send the crypto to another wallet, breaking the direct connection between the two individuals involved in a transaction. Criminals also make use of nested and unregulated exchanges that require no KYC and are not subject to Anti-Money Laundering (AML) requirements, privacy coins that are untraceable, and peer-to-peer (P2P) decentralised crypto networks that also do not require KYC. NFTs are commonly used for money laundering, and DeFi — the latest trend in crypto — has also been used by criminals to move funds from illicit wallets.

This paper analyses a specific, selected case on the Mirror Trading International (MTI) platform, selected from the website MTI-Leaks. In collaboration with TCG Forensics, a cyber-crime and digital forensics company based in South Africa, an initial process is proposed for investigating certain crypto crimes, which is then applied to the selected case.

MTI Background

MTI was a network or multi-level marketing scheme that claimed to offer automated trading services via bots, on behalf of its members, in cryptocurrency derivatives. The scheme promised a consistent monthly 10% return to members. The website shut down in December 2020, and the CEO, Johann Steynberg, vanished and fled the country. Steynberg was arrested on 29 December 2021 in Brazil and returned to South Africa a year after his disappearance, allegedly for presenting fake identification to law enforcement officers — it was then discovered that he was a wanted person by the South African Police Service (SAPS). A trusted source with knowledge of the case has reported that over 46,000 Bitcoin passed through the scheme.

Use Case Selection

Anonymous ZA, a hacker group, released explosive details regarding the scheme on a Github link, MTI-Leaks — including balance sheets, wallet addresses of founding members and top-benefitting members, Bitcoin allocated to top addresses, withdrawals, cancelled and reversed withdrawals, remaining capital and the total money owed to members. Only 63 members were designated as "Founders", 0.038% of the total userbase.

This use case was selected from the MTI-Leaks website. The target person's personal information is not revealed, but the initial address into which the target invested is. It should be noted that the selected person of interest is not one of the founders of MTI, or the masterminds of the scheme.

On the MTI Dashboard, the member could see their portfolio: total team members under their name, total direct referrals, all-time and binary bonuses, total wallet balance in MTI, and total pool balance. The selected target person had 44,419 team members and 21 direct referrals.

MTI dashboard widget showing Total Team Members 44419 and Direct Referrals 21
Figure 1. Total Team Members and Direct Referrals

The member had 21,783 members with 362.28 BTC in total on the left leg of the team, and 22,636 members with 968.65 BTC on the right leg. Clearly the target person benefitted immensely from the scheme and qualifies as a person of interest.

MTI dashboard widgets showing Left Team 21783 members with 362.28 BTC and Right Team 22636 members with 968.65 BTC
Figure 2. Left and Right Leg of Team

From the MTI dashboard, the user had a wallet section where an audit of funds added and withdrawn was kept. The investigation therefore has two angles: tracing the funds starting from the add-funds addresses (the Inputs), and starting from the withdrawal addresses (the Outputs).

The "Add Fund History" menu option on the dashboard shows all five records recorded on the platform, selected as inputs. Note that the wallet addresses and transaction IDs (TXIDs) are from the Bitcoin blockchain.

MTI Dashboard menu showing the Add Funds History screen with wallet addresses, amounts and TXIDs
Figure 3. MTI Dashboard Menu (from MTI-Leaks)
Table 1. Inputs
Wallet AddressTXIDBTCDate
3MHpHg85MGhBNKnLrWThSE54WJxfqeDWmA (In-Address-1)8675af7bb609cb926d1e1476968df20e71a3dc1920fcdf5164c13cf73ac41851 (Input-TXID-1)12020.05.17
3MHpHg85MGhBNKnLrWThSE54WJxfqeDWmA (In-Address-1)6690371a275bb3d817bb4b68e7e9ea85973c32adae33dc15e0d17058cafe2980 (Input-TXID-2)0.52020.03.29
3MHpHg85MGhBNKnLrWThSE54WJxfqeDWmA (In-Address-1)f9ad0086aebfe5c8ba4726989af6e1ea3f6840e6718a6571eacc457c87ac891a (Input-TXID-3)0.50112020.03.29
3MHpHg85MGhBNKnLrWThSE54WJxfqeDWmA (In-Address-1)cf62d79d9702120fc87ff9269c78d8550ee0170bef971d2ada98030d5bc0b8d1 (Input-TXID-4)0.52020.03.21
3MHpHg85MGhBNKnLrWThSE54WJxfqeDWmA (In-Address-1)c30f8fe74ca5afd1d3c5db7efdfd0923fe558416f7f99f742442306b52705795 (Input-TXID-5)0.12020.03.21

Following the "Wallet Withdrawal" menu option from the dashboard, the very first withdrawal record was selected, Out-Address-1. However, this address had no TXID linked to it on the blockchain. A second address, Out-Address-2, was the first one from the list with a TXID linked. The third address selected was the most-used address for pay-outs, Out-Address-3, with five transactions to start off with tracing the funds. These addresses are placed within the Outputs angle of the investigation.

Table 2. Outputs
Wallet AddressTXIDAmount (BTC)Date
1KX5f1mz8MBuCCdUyDcyRiZLH53v8cJjav (Out-Address-1)Not available1.0052019.12.12 23:06:20
3CvyH1syeBrJWLXkXpXtQtJ82wVq5naocV (Out-Address-2)7572ccc5c31b65e2eb72f62d78d42ec3ca20cf93884ec0e7664722ed54c4aa3c (Output-TXID-1)2.52020.05.11 21:43:39
17AVMgsdxb7tELKwjn4fK3MymGkUTmY6DB (Out-Address-3)58c0b545a0eac027d143eb0838fe3b59fb093d1d383124b2f80893aaf00e697d (Output-TXID-2)0.32020.07.19 22:58:01
734e6394a4bda9de8707cdcca2e8760ef028f4a33b6845b32923ed918170a91c (Output-TXID-3)0.278674932020.07.20 03:00:25
d3d743092c6968cc255c631f0179b000e0a664328642e8921ace3c6ca30e95e2 (Output-TXID-4)0.61482772020.07.26 22:47:06
885700b5c8978d1c0267244a9a69ab41009e2ef1569a611c4a8d535321d35eec (Output-TXID-5)0.12020.07.28 21:17:17

According to Pederson, from TCG Forensics, the process for investigating a cryptocurrency scheme depends on the information available both publicly and during the course of the investigation. Before beginning, it is of utmost importance to collect all information that will enable the investigator to develop, compile and expose a timeline — for example, an investor knows that over the course of the operation, the scam required deposits into a specific address, and that address changed over the course of a few months. This information alone has a massive impact on where and when to investigate.

The second most important element is the flow of funds — where they started, where they travelled, what happened to them, where they exited, and all common points along the journey. Bad actors will deliberately attempt to obscure this flow. In the case of an investment scheme, one would expect to follow the deposited funds to an investment vehicle on the blockchain, which may take the form of crypto mining, token exchanges, trades, etc.

High-Level Proposed Process

Several engagements with TCG Forensics were used to determine a high-level process an investigator could follow to investigate a crypto scam. The focus was specifically on MTI, but the process could be applied to various forms of crypto scams, crimes, money laundering and fraud. Seven steps were identified, applicable to both the input and output addresses:

  1. Identify the input addresses and the output or pay-out addresses.
  2. Follow the funds on the blockchain starting from the identified addresses.
  3. Identify key or common addresses used, their function, and determine if they are linked to exchanges.
  4. Further follow the funds from the key or common addresses identified.
  5. Determine if there are any correlations between the addresses identified, such as a certain address being used as a destination address, or linkages to exchanges.
  6. Identify the destination addresses.
  7. At this point, legal support is required — draft a forensic report detailing the scam, report to the Financial Sector Conduct Authority (FSCA), draft the legal charges, formulate and issue a subpoena on the identified linked exchanges to obtain KYC documents, and freeze the funds linked to the destination addresses if possible.
Flowchart of the seven-step investigation process for inputs and outputs, ending in a legal section
Figure 4. Investigation Process

Analysis and Investigation of the Selected MTI Case

The high-level process above was used as a base to perform the analysis and investigation on the selected target person, a member of the MTI Ponzi scheme who benefitted tremendously from it. The target person is expected to repay the funds once the required legal steps have been finalised.

The crypto investigation tool QLUE was used to follow or trace the funds on the blockchain. Inputs and outputs almost never come from the same source, and it is very difficult, without sufficient context, to know to whom a Bitcoin address belongs. The aim of this investigation is to follow the transaction flow, determine patterns, find key addresses where money was transferred to and from, and identify when a transaction was made to an exchange.

Inputs

The first part of the investigation is to investigate the funds being added onto the platform, following the input transactions up to a point where they are linked to an exchange and a person can be identified.

Entering the first input address, In-Address-1, into QLUE returned no results — an immediate red flag. Confirming this on the online blockchain explorer Blockchain.com showed the address does exist, but no transaction was ever made to it. This may indicate the MTI administrators intended to use this address as a dummy, never revealing to the public where the funds actually went.

Entering the first input TXID, Input-TXID-1, revealed that the funds went to a different address than what was indicated on the MTI platform — a Bitcoin address flagged by QLUE as an MTI address, referred to as MTI-1. Following the funds further, another interesting discovery was that the funds left MTI-1 to another address on the very same day, approximately 3.5 hours later, after which the funds were sent to thousands of addresses — indicating that mixer or tumbler services were possibly used.

Tracing Input-TXID-2 revealed the funds were transferred to a different MTI address, MTI-2. Input-TXID-3 also went to MTI-2.

QLUE graph showing Input-1 flowing to MTI-1, and Input-2 and Input-3 both flowing to MTI-2
Figure 5. Input-1, 2 & 3

Input-TXID-4 went to another MTI address, MTI-3, and Input-TXID-5 went to MTI-4.

QLUE graph showing Input-4 flowing to MTI-3 and Input-5 flowing to MTI-4
Figure 6. Input-4 & 5

Upon further tracing, the tool revealed that thousands of transactions occurred after funds moved to these addresses — from MTI-1 alone, 6,000 more transactions occurred; from MTI-2, 2,000 additional transactions occurred (only 53 were made visible in QLUE due to filtering). This further indicates that MTI was possibly making use of crypto mixing to anonymise transactions, resulting in thousands of transactions designed to confuse the investigator with multiple trails and paths on the blockchain.

After thousands of transactions had been made to several MTI-linked addresses and other random addresses, funds were transferred to South African exchanges such as Luno, VALR and AltCoinTrader, as well as exchanges outside South Africa such as Binance, Coins and Nexo. The addresses on the South African exchanges have been marked in this investigation as the destination addresses, Destination 1 and Destination 2.

QLUE graph showing MTI-2 fanning out through 53 of 2000 transactions to Destination 1 and Destination 2
Figure 7. MTI-2 → Destination 1 & 2

Depending on the jurisdiction, there are legal steps one is obliged to follow, typically involving subpoenas issued on the relevant exchanges via their compliance officer, backed by a thorough blockchain forensics report and law enforcement authority. Once the target person has been identified, a notice should be sent with a warning and court order that funds linked to specific identified addresses are not allowed to be moved — often backed up by contempt of court charges if violated. It should be noted that these people could highly likely be low-level mules located in a different jurisdiction; more context and other thresholds would be needed to reach an actual arrest.

Outputs

The second part of the investigation is to investigate the pay-outs by following the output transactions up to a point where a person can be identified.

Entering the first output address, Out-Address-1, into QLUE and tracing the funds revealed that four transactions are linked to this address, even though MTI indicated no transaction is linked to it — two input transactions of 0.005 BTC and two output transactions of the same amount were found. MTI indicated that the amount transferred into this address was 1.005 BTC — the sum of the four transactions found on the blockchain does not add up to this amount, which already raises questions.

Tracing the two input transactions backwards, one showed several links to local South African exchanges as well as international exchanges; the other showed no destination addresses, but a single path ultimately linked to several exchanges. Tracing the two output transactions forward, Output-TXID-1 revealed that funds moved to blockchain addresses on both the Luno and AltcoinTrader platforms — however, none of the addresses clustered in Luno and AltcoinTrader matched the address shown on the MTI dashboard as linked to Output-TXID-1. Out-Address-2 is in fact linked to the Bitmex exchange and not linked to Output-TXID-1 at all.

QLUE graph showing a transaction flowing from Luno up through an address to AltcoinTrader
Figure 8. Output TXID-1

Tracing Out-Address-3, the most common address used from the target person's profile, revealed it was indeed linked to transaction Output-TXID-5, but not to any of the other transactions MTI indicated were linked to it — showing that the information displayed to members on the MTI dashboard is incorrect in this instance. The address has also been flagged by QLUE as a known MTI user address.

Tracing Output-TXID-2 via QLUE returned no results. A second attempt using the tool Maltego, with the Tatum transform for blockchain integration, linked several addresses to the transaction — though none matched the address shown on the MTI dashboard. These addresses were flagged for further investigation.

Maltego graph showing a Bitcoin address transaction fanning out into eight linked addresses across two levels
Figure 9. Output-TXID-2 — Linked Addresses

Further tracing linked additional addresses to exchanges such as Binance, Coinhako, Altcoin Trader, Unocoin and Coins, as well as correlations to Coinpayments, Bitmex, Bitpoint, and links to dark market activity flagged by QLUE. Following the outputs forward uncovered links to Bitstamp, BitPay, Paymium, Bittrex, Bitmex, Binance, Changelly, HitBTC, Bitcoin.com and Bithoven. All of these addresses have been flagged as destination addresses for further investigation, with the addresses linked to Output-TXID-6 flagged as high priority due to links to a known MTI user address as well as links to victims of fraud.

By issuing subpoenas to the relevant exchanges via their compliance officers, the investigator could obtain personal information from the identified exchanges. If two or more addresses share the same personal information, there is a high possibility it belongs to the target person. Legal notices and charges would follow, with the court making a final decision on the funds — again, it should be noted that these identified persons could possibly be low-level mules and not the main target of the scam.

Conclusion

This paper focused on a selected target person who was a member of the MTI scam and benefitted immensely from it. MTI-Leaks was used for the case selection and the input/output transaction data. Discussions with TCG Forensics produced a high-level process for investigating crypto scams and crimes, used here as a baseline for the investigation. Jeff Lomas, an OSINT and crypto crimes investigator from the USA, also gave valuable insights on online criminal investigations.

The investigation followed two approaches — the funds added onto the MTI platform (inputs) and the fund withdrawals (outputs). After numerous efforts to trace the funds across all the Bitcoin addresses and transactions selected from the target person's profile, several addresses were marked as destination addresses for further investigation. Depending on the jurisdiction, subpoenas could then be issued to the linked exchanges to obtain personal information on the individuals behind those transactions, with further legal steps to follow until a decision is made by the court.

The crypto industry continues to grow, and criminals will continue to scam individuals and launder proceeds using cryptocurrencies. It is important for governments, competent authorities and law enforcement agencies to stay up to date with the methods adopted by criminals and to take advantage of blockchain analytic tools to effectively combat money laundering.
Loading ratings…
Found this useful? Rate this post:
Thanks for rating!

Comments (0)

Loading comments…

Leave a comment

Your email address will not be published. Comments are reviewed before appearing publicly.