The previous paper in this series concluded that the off-chain analysis component of the authors' proposed cryptocurrency crime investigation process needed more depth — clearer technique guidance and worked examples of how open-source intelligence can actually take an investigation from a pile of transaction data to a human suspect. This paper is that follow-up. It returns to the same fraudulent investment platform, here referred to openly as RSI-Platform, and works through a structured, iterative off-chain enrichment cycle to see how far OSINT alone can push an investigation once the blockchain trail runs cold at an exchange boundary.
Introduction
On-chain analysis is good at answering "where did the money go" — but it is frequently unable to answer "who moved it." Once stolen funds land inside a centralised exchange, the public ledger goes dark, and the only way forward is a Section 205-style subpoena, or open-source intelligence applied to whatever off-chain fragments the victim and investigators already hold: a domain name, a handful of phone numbers, some alias names, an email address, chat logs. This paper draws a distinction between passive OSINT — gathering information from public sources without directly interacting with a target — and active OSINT, which involves engaging a target directly (typically via an undercover profile), and which requires explicit law enforcement authorisation because of the risk of tipping off a suspect. Everything described in this paper is passive OSINT.
Case Background
RSI-Platform is the same fraudulent CFD and cryptocurrency trading platform examined in the authors' prior paper, where an elderly South African woman was persuaded to hand over close to two years of pension savings believing she was invested in a legitimate, UK-based trading entity. That earlier study traced the stolen Bitcoin through VALR, Kyrrex.com and CoinPayments.net using the tool Breadcrumbs, but the trail eventually reached exchange boundaries the authors could not push past without further subpoenas — and, more importantly, could not connect back to a specific human being.
This paper sets two objectives. First, to determine whether a disciplined, iterative OSINT enrichment cycle can meaningfully extend an investigation once on-chain tracing has plateaued — turning fragments such as a domain name, phone numbers and alias names into a workable suspect network. Second, to test whether that enrichment cycle, applied to this specific case, is sufficient to identify the actual human operator(s) behind RSI-Platform. Several indicators pointed toward a syndicated operation rather than a lone scammer from the outset: multiple VOIP lines and mobile numbers routed through different providers, a cluster of alias names used interchangeably across WhatsApp, Telegram and Snapchat, and a pattern of consumer complaints referencing the same names under what appeared to be at least two prior platform rebrands.
The Investigation Process
The underlying five-phase process — data collection, analysis, theory development and validation, suspect identification and reasonable grounds, and legal action — is unchanged from the authors' earlier work. This paper's contribution sits inside the analysis phase, where it proposes a tighter, explicitly iterative three-step cycle for off-chain evidence: Evidence Overview and Processing, Evidence Enrichment and Processing, and Theory Development and Validation — looping back on itself as many times as needed, with each pass feeding new nodes into a running link-analysis diagram, until the analyst either reaches a workable theory or exhausts the available leads.
Data Collection
As in the prior paper, the "opening a case" step was already complete by the time the authors became involved. The off-chain inputs carried forward for this study were (redacted): the domain rsi-platform.io; a list of SA and UK phone numbers used by individuals contacting the victim over WhatsApp, Telegram and Snapchat; the same alias names from the earlier investigation; the VALR payment-routing address; a physical address on Bank St, London; and an email address tied to the platform's own website footer.
Evidence Overview and Processing
Domain name findings. The Wayback Machine's archive of rsi-platform.io returned a full capture of the site from October 2022 — a polished, professional-looking CFD and crypto trading platform, complete with a "How does it work?" explainer on contracts for difference, a "Join Us" call to action, and a live-updating ticker of cryptocurrency prices running along the bottom of the page. Nothing about the archived site itself would have obviously flagged it as fraudulent to a prospective investor.
A WHOXY domain lookup on rsi-platform.io showed the domain had been registered on 23 June 2022 through the registrar NiceNic International Group Co., Limited, with the registrant's identity shielded behind a "redacted for privacy" WHOIS record. By the time this lookup was repeated in January 2026, the domain was no longer registered at all — an operating lifespan of well under two years, consistent with a scam site that is stood up, run until complaints accumulate, and then abandoned.
Names and contact information findings. Running the list of SA phone numbers through Truecaller produced mixed results: some numbers resolved to named individuals, others returned nothing at all, and — most tellingly — one single number returned a different name on separate lookups performed weeks apart. That kind of instability is a strong signal of a VoIP or reassigned SIM number being recycled across an operation rather than belonging to one consistent individual.
Evidence Enrichment and Processing
Domain name findings. BigDomainData and the registrar's own NiceNic hosting records were cross-referenced to identify other domains sharing the same hosting infrastructure as rsi-platform.io — several of which carried their own history of scam-related complaints once checked. Crypto payment addresses recovered from the archived site's footer and supporting pages were checked against the VALR payment-routing detail already established in the earlier on-chain paper, reinforcing the link between the website itself and the funds the victim had transferred.
Names and contact information findings. Maltego transforms run against the phone numbers and alias names surfaced further connections to HelloPeter and Trustpilot complaints referencing the same names, and to a company named Vestro Group LTD, which appeared in the platform's consumer-facing complaint trail but could not be verified as a registered entity in Seychelles, its claimed jurisdiction. IntelTechniques and Breach Directory searches against the website's contact email returned no verified breach records. An XDS credit-bureau check and a CRDB porting-history check on the flagged phone number revealed it had been ported across at least three differently registered names within a short window — read alongside the earlier Truecaller inconsistency, this is a strong indicator of an organised, syndicated operation deliberately cycling SIMs and identities rather than a single individual acting alone. WhatsApp chat logs already retrieved during the earlier on-chain investigation were re-examined specifically for off-hand personal detail leaks.
"Mr-X" findings. A distinctive alias surfaced repeatedly across the WhatsApp chats and the consumer complaint sites, prompting a dedicated sub-investigation the authors refer to throughout as "Mr-X." WhatsMyName was used to check the alias's presence across dozens of other platforms; a Pinterest account under a closely matching handle was located; a YouTube reverse-image search against a profile photo associated with the alias returned partial visual matches; targeted Google Dorking against distinctive phrasing lifted from the chat logs surfaced a small number of forum posts using the same language; and a LinkedIn profile carrying a plausible real name was found matching some, but not all, of the details gathered so far.
Theory Development and Validation
Three competing theories were developed and tested against the accumulated evidence:
Theory 1 — Mr-X is a victim. Considered first, given how often scam operations themselves recruit unwitting victims as money mules or intermediaries. Ultimately set aside: Mr-X's apparent level of platform-specific knowledge, the timing of his messages relative to the victim's transfers, and his apparent role in directing certain fund movements were not consistent with someone who was simply another defrauded party.
Theory 2 — Mr-X worked with or for RSI-Platform directly. Investigated in some depth, but ultimately refuted. His apparent physical location, financial circumstances, and the specific accounts and platforms he was actually linked to did not line up with him being an active operator of the scheme — the evidence connecting him to RSI-Platform's operational side was circumstantial and did not hold up once tested.
Theory 3 — Mr-X used the platform, or a connected identity, to hide money from his ex-wife. This is the paper's currently predominant theory, though not yet conclusively proven. It would explain why Mr-X's digital footprint overlaps with RSI-Platform's financial and technical infrastructure without him necessarily being one of its operators — he may simply have used the same rails, for entirely separate personal reasons, at the same time the platform was defrauding other victims.
Suspect Identification and Reasonable Grounds
Two findings were flagged as providing reasonable grounds for further formal action. First, the phone-number porting anomaly — one number, three different registered names in a short window — is difficult to explain innocently and points toward deliberate identity-cycling. Second, the domain's registration itself shows hallmarks of a deliberately obscured scam operation: privacy-shielded WHOIS records, a short operating lifespan, and shared hosting infrastructure with other flagged domains, none of which is consistent with a legitimate financial services business. Kyrrex.com, already implicated as a downstream destination in the earlier on-chain paper, was identified as the most promising next subpoena target, sitting at a point in the fund flow where exchange-held KYC records could plausibly connect the pseudonymous on-chain trail to a real identity.
Law Enforcement Function
The paper recommends two concrete next steps for the investigating authority: a formal subpoena to Kyrrex.com for account-holder KYC records tied to the addresses already identified, and a request to the domain registrar NiceNic International Group Co., Limited for any underlying registrant records held behind the privacy-shielded WHOIS entry. Several unknowns remain open at the time of writing — the true identity of RSI-Platform's operator or operators, whether Mr-X has any deliberate role in the scheme at all, and whether the operation is the work of a single actor or a coordinated syndicate spanning South Africa and the United Kingdom.
Link Analysis
The full off-chain link analysis, built in Maltego, maps everything gathered across both enrichment passes around a single central "Suspect" node: the flagged phone numbers, each tagged with its mobile provider (Vodacom, MTN, Telkom Mobile, Hutchison Mobile) or VOIP line; the messaging platforms used to make contact (WhatsApp, Telegram, Snapchat); the scammer alias names surfaced through Truecaller and XDS; a Bitcoin address linked via the VALR payment-routing detail; and the rsi-platform.io domain itself, connected outward to its registrar (NiceNic International Group Co., Limited), its website footer contact email, its consumer complaint trail on HelloPeter and Trustpilot, the unverifiable Vestro Group LTD entity, and a cluster of localised South African victims.
Conclusion
Returning to this paper's two objectives: on the first, whether a disciplined, iterative OSINT enrichment cycle can meaningfully extend an investigation once on-chain tracing has plateaued — the answer is yes. Applying the Evidence Overview, Evidence Enrichment and Theory Development cycle to fragments as ordinary as a domain name, a handful of phone numbers and a scattering of alias names produced a substantial, structured suspect network where the on-chain trail alone had stalled at an exchange boundary. On the second objective, whether this specific case could be resolved to a named, identified human operator — not yet. Mr-X's exact role remains unresolved, with the "hiding money from his ex-wife" theory currently the most consistent with the evidence gathered, but unproven.
The case also illustrates just how difficult transnational cryptocurrency investment scams are to pursue to a conclusion: a UK-registered address, an entity claiming Seychelles registration that cannot be verified, South African victims, a mix of local and international phone numbers and VOIP lines, and an offshore domain registrar together span at least three jurisdictions, none of which can act alone. What this paper does show is that combining structured on-chain analysis with an equally structured, iterative off-chain OSINT process gives investigators a genuinely better chance of eventually closing that gap — even when, as here, full identification isn't achieved on the first pass.
Comments (0)