Pig Butchering Romance Scam Chain Analysis OSINT

Analysis of a Cryptocurrency Investment Scam: Pig Butchering

Cartoon illustration of a piggy bank with a Bitcoin coin dropping into its coin slot and a cracked heart above it, representing a romance scam that escalated into crypto investment fraud
Co-authored with: Kreaan Singh (CSIR) and Louise Leenen (University of the Western Cape / CAIR). Published in the Proceedings of the 24th European Conference on Cyber Warfare and Security (ECCWS 2025).

This paper analyses and investigates a cryptocurrency investment scam involving the suspicious and fraudulent cryptocurrency trading platform, Elite-Bit, through a detailed case study of a victim's experience. With the rapid rise of cryptocurrency, deceptive platforms like Elite-Bit exploit unsuspecting investors by presenting a façade of legitimacy. This case study chronicles the victim's journey, beginning with a seemingly romantic connection through a dating platform, to an introduction to an investment opportunity, and subsequently a financial loss.

After investing a substantial amount, the victim faced unexpected barriers when attempting to withdraw funds, including exorbitant transaction fees and other fabricated costs. The analysis reveals how Elite-Bit employs manipulative tactics such as social engineering and false urgency to maintain control over investors, ultimately leading to significant financial loss — manipulative tactics referred to as pig butchering. An on-chain and off-chain analysis was conducted using the limited input data provided by the victim, and a link analysis was performed using the tool Maltego to visually map the entities associated with the suspect within a network of nodes and connections.

Introduction

The adoption of blockchain technology has surged in recent years. However, the unique characteristics of cryptocurrencies have also led to a rise in crime, drawing in scammers and fraudsters. The majority of frauds involving cryptocurrency trading or fake investments begin on social media or through messaging apps — unsolicited contact from an unknown individual or an online acquaintance introducing an unfamiliar trading platform significantly increases the likelihood of fraudulent activity.

The case on which this paper is based started as a romance scam that escalated into a pig-butchering cryptocurrency investment fraud. Pig butchering scams are sophisticated and well-orchestrated in deceiving and defrauding victims. These scams mostly follow a pattern of initiating contact with a potential victim through a fake persona. The scammers spend weeks, and sometimes months, building a relationship with the victim, often feigning a romantic interest. Once trust is gained, the scammer directs the conversation towards introducing investment opportunities, usually involving cryptocurrency — framing it as a good opportunity to build a future together and achieve financial freedom, while portraying themselves as an experienced investor who wants to help the victim succeed.

The scammer convinces the victim to install an investment app or register on a fraudulent platform, walking them through account creation and an initial deposit — normally a smaller amount so the victim isn't intimidated. Manipulated data and fake reports then show high returns, and the victim is encouraged to invest even higher amounts by creating urgency around a once-in-a-lifetime opportunity. Emotional manipulation tactics are used to stay in control, such as professing love and promising a shared future, and the scammer may use threats or intimidation to make the victim panic and act fast. When the scammer has extracted as much money as possible, they cut all communication and disappear — the app or website is taken down if enough gains have been accrued, or kept alive to target the next victim.

Case Background

The timeline below summarises events that occurred between 15 June 2024 and 31 July 2024. On 15 June, a female victim from the United Kingdom (UK) matched with a male suspect on Tinder, initiating a conversation on the platform. After a week of communication, they exchanged mobile phone numbers and interactions transitioned to WhatsApp. Communication persisted for a further three weeks, during which the victim mentioned wanting to visit her sister in Australia but expressed the financial burden of the trip. Seizing this opportunity, the suspect introduced her to the trading platform Elite-Bit, promising substantial returns and assuring her she would quickly accumulate the funds she needed.

The initial step involved registering an account with Elite-Bit (www.elite-bit.net) and transferring funds to the platform. Elite-Bit only accepted cryptocurrency deposits, so the victim was instructed to download MetaMask (a widely used cryptocurrency wallet) and the Crypto.com app (a well-known exchange) to facilitate transactions. She then transferred funds from her Lloyds account to Revolut, a British neobank that also facilitates conversion of fiat currency into cryptocurrency. Revolut was used to purchase cryptocurrency to send to Elite-Bit — but the victim was instructed to first route the funds through her MetaMask wallet rather than sending directly, likely to circumvent Revolut's withdrawal analysis or mask the actual destination of the funds.

Timeline infographic of events from 15 June 2024 to 31 July 2024, showing Tinder match, WhatsApp chats, Elite-Bit and Revolut registration, and multiple bank transfers and crypto transactions
Figure 1. Summarised Timeline of Events (15 Jun 2024 – 31 Jul 2024)

Elite-Bit provided a chat service through which the victim was guided through her first trade. She "won" the trade, almost doubling her initial investment, and was then coerced into making additional deposits to facilitate larger and more frequent trades. Multiple payments followed, and the victim was guided through five additional "successful" trades — her perceived account balance rising to 21,320 USD Tether (USDT), a stablecoin pegged to the US dollar.

At this stage, the victim indicated she had no additional funds to invest and requested to withdraw her balance. Elite-Bit restricted contact to its chat service, with no telephone or email details provided, and instructed her to submit a screenshot of the withdrawal address. The platform then conducted a small "test" transaction to that address — once she confirmed receipt, she trusted the full withdrawal would follow. She requested withdrawal to her Lloyds UK bank account. In response, the platform claimed withdrawals exceeding $20,000 required a $1,980 tax payment, which she paid in USDT. The platform then demanded a further $2,880 "service charge" before processing the withdrawal, promising funds within 48 hours — none arrived, and an email (from a free Gmail account) later claimed the payment had failed and asked for an alternative destination.

On the recommendation of her Tinder "acquaintance," she asked for the funds to be sent to her MetaMask ETH address instead — the platform then demanded an additional $3,400 fee to process that transaction. Elite-Bit further exploited Revolut's $500 daily withdrawal limit to force multiple payments over several days, threatening late-payment penalties if she missed the deadline. The victim panicked and asked friends to open Revolut accounts in their own names so additional $500 payments could be sent daily — one friend helped, another refused and warned her she was being scammed. Despite the help, she still missed the deadline and was charged the late fee, followed by a final charge to convert USDT to ETH. It was at this point that she finally recognised she had been scammed.

A criminal case was opened in the UK, but police indicated they would be unable to assist as the amount stolen was not substantial enough on its own, advising that evidence of additional victims and larger losses would be needed before an investigation could begin. The victim then sought the help of one of this paper's authors to assist in the analysis and investigation. Evidence of additional victims was uncovered through blockchain analysis, though that aspect falls outside the scope of this paper.

Evaluating the Trading Platform Elite-Bit

Elite-Bit claims to be a professional asset management and cryptocurrency trading platform. A thorough evaluation identified several red flags:

Additional OSINT investigation revealed further red flags. The platform is registered in Estonia, but displays a USA address in Las Vegas and a USA phone number on its website. It is not registered as a money service company, a requirement for any such service operating in the UK. It claims to hold a licence to trade forex, futures or options, and claims registration with the UK's Financial Conduct Authority (FCA) — but on inspection, it was using another company's real licence details under a different name, known as a "cloned firm."

Discussions with the victim surfaced further red flags: the website only accepted cryptocurrency deposits with no bank transfer option; investment returns increased substantially as deposits increased, a likely manipulation tactic; a large transaction fee was charged on withdrawal, followed by an additional "tax clearance certificate" fee; urgency was created via a payment time limit, with a penalty fee if missed; unrealistically large service fees were charged both for transferring ETH to the victim's wallet and for converting ETH to USDT; and email communication came from a free Gmail account, uncharacteristic of a genuine service provider. At the time of writing, the platform was still active until 10 February 2025, but now appears to be permanently offline.

Analysis of the Case

The analysis follows a methodology proposed in the authors' previous research, beginning with opening a case that integrates both on-chain and off-chain analysis, followed by a parallel path connecting each cryptocurrency address to corresponding social media accounts, and finally exploring the legal frameworks needed to transform actionable intelligence into evidence admissible in court. The victim provided the following inputs (redacted): an ETH cryptocurrency address (0x0f9f...4054), a Tinder profile name (Fr…co Ab...e), a mobile number (4474…43), the domain name www.elite-bit.net (with login details), a Gmail address (trade…net@gmail.com), and bank statements of all transactions made to fund the platform.

On-Chain Analysis

The tool Breadcrumbs was used to perform on-chain analysis. The starting point was the cryptocurrency address 0x0f9f…4054, provided by the victim as the address where she was instructed to deposit funds. Filtering out transactions from other victims and focusing only on this victim's deposits between 13–30 July 2024, Breadcrumbs identified the address used by Elite-Bit as an account held on the exchange Binance — meaning Binance can be subpoenaed to reveal the account holder's personal information and outgoing transactions.

Multiple incoming transactions to Elite-Bit's address outside the victim's date range were also identified, indicating the same address is used to receive funds from other victims. The tool revealed incoming transactions from four sources: the victim's MetaMask wallet, the victim's Revolut account, a friend's Revolut account, and a Crypto.com account. In total, 3.872 ETH was sent from the victim's MetaMask wallet, 0.4284 ETH directly from her Revolut account, and 1.1915 ETH from her friend's Revolut account — 5.4910 ETH transferred in total.

Breadcrumbs graph showing incoming transactions to Elite-Bit's address from the victim's MetaMask wallet, the victim's Revolut account, a friend's Revolut account, and a Crypto.com withdrawal account
Figure 2. Incoming Transactions to Elite-Bit's Address

Analysing Elite-Bit's Binance address shows the wallet is still actively used at the time of writing, with a last transaction dated 18 January 2025 — despite the victim's last interaction in July 2024, confirming the scammers are still actively targeting other victims. The total amount of cryptocurrency transacted through this address is 18.469 ETH, with roughly 30% of the funds in this wallet originating from the victim in this study.

Breadcrumbs address panel for Elite-Bit's ETH address showing a low risk score, first transaction May 2023, last transaction January 2025, and incoming/outgoing volume of roughly 18.4 ETH each
Figure 3. Elite-Bit – ETH Address

At the time of writing, a request had been made to the British High Commission in Pretoria to issue a subpoena to Binance — since the case is not registered in South Africa, the subpoena must be issued by a UK law enforcement entity, and no response had yet been received.

Off-Chain Analysis

This part of the analysis employs OSINT techniques to attempt to unmask the suspect's identity. Reverse image search tools such as TinEye and Google Image Search returned no positive match for the Tinder profile photo. Truecaller identified the mobile number as UK-registered, still active, and linked to service provider M-Hutchison — standard OSINT searches on the number itself yielded no results, though a subpoena to the service provider could reveal the registered owner.

ViewDNS.info revealed the domain is hosted in Kuala Lumpur, Malaysia, and was registered on 23 November 2023 — a relatively new registration, itself a red flag, since scammers often register fresh domains to facilitate fraud. ScamAdviser reported a trust score of 1/100 for the domain, strongly indicating a scam link. Using the Scam-Detector tool, the registrant's name, address, country and an additional phone number were revealed, identifying the suspect as Nigerian — a pivotal finding that opened fresh investigative leads, further supplemented by Truecaller revealing the name linked to the new number. A licence-to-trade number listed on the Elite-Bit site was also checked against the FCA register and found to belong to another, unrelated company — confirming Elite-Bit as a cloned firm.

The email header could not be obtained from the victim, which would otherwise have revealed the sending IP address and an approximate location. OSINT on the Gmail account confirmed a direct link to the Elite-Bit domain, though no further information could be extracted from the account itself.

Bank Statements and Login Details

Using the login credentials provided by the victim, the platform's own transaction log was retrieved. All payment transactions occurred between 11 and 31 July 2024. The first two trades shown were refunded — the platform claimed the market had turned against the victim and refunded the amount, a trust-building tactic — after which every subsequent trade resulted in the invested amount almost doubling.

Table 1. Elite-Bit – Transaction Log
TxTransactedAmountPost BalanceDetail
YC3TAVB8NKHB2024-07-11 22:14+441.00 USD441.00 USDDeposits
7671R3AUAYEX2024-07-12 19:12-441.00 USD0.00 USDTrade to USDT High
7671R3AUAYEX2024-07-12 19:49+441.00 USD441.00 USDTrade refund
9O6JKNUDJ75O2024-07-12 20:03-441.00 USD0.00 USDTrade to USDT High
737O8FYGK5FE2024-07-12 20:41+441.00 USD441.00 USDTrade refund
PFFNZ4KAJYE32024-07-12 20:57-441.00 USD0.00 USDTrade to USDT High
NR66A8EU2VQ42024-07-12 21:07+837.90 USD837.90 USDTrade to USDT WIN
PSDJBRUAA1N42024-07-13 12:15+627.00 USD1,464.90 USDDeposits
OXM616WYEKN82024-07-13 16:57-1,464.00 USD0.90 USDTrade to USDT High
ZPUEK7T2MYCK2024-07-13 17:17+2,781.60 USD2,782.50 USDTrade to USDT WIN
WB2MK5QZX5RH2024-07-13 17:48-2,782.00 USD0.50 USDTrade to USDT High
KUOSACS1B1XV2024-07-13 18:05+5,285.80 USD5,286.30 USDTrade to USDT WIN
G2SKHK6NSUSX2024-07-13 21:43+630.00 USD5,916.30 USDDeposit
G82WE22WMO4G2024-07-13 22:24-5,916.00 USD0.30 USDTrade to USDT High
6PYU111DAQMP2024-07-13 22:41+11,240.40 USD11,240.70 USDTrade to USDT WIN
QNMV819XRUJ12024-07-14 09:52-11,200.00 USD40.70 USDTrade to USDT High
29CVRQU7UY9S2024-07-14 10:34+21,280.00 USD21,320.70 USDTrade to USDT WIN
5V9JUFQ68HN52024-07-14 21:36-1,300.00 USD20,020.70 USDWithdraw via bank transfer
5V9JUFQ68HN52024-07-15 04:26+1,300.00 USD21,320.70 USDRefunded from withdrawal rejection
8P7FV7GO24912024-07-29 07:55+1,900.00 USD23,220.70 USDDeposit

By 14 July 2024, a total of $1,698 had been deposited for trading purposes. The victim was led to believe she had attained a trading balance of $21,320.70 and requested a withdrawal. Between 15 and 31 July 2024, the scammer then employed pig-butchering manipulation techniques to systematically extract even more money — the victim's total payments amounted to £11,000 ($13,640.37), of which $11,942.37 was allocated to phantom service fees, tax fees, conversion fees and penalty charges.

Link Analysis

Using the data gathered, a link analysis was performed with the tool Maltego, applying the 11P method (People, Places, Personalities, Past, Police, Photos, Pay, Professional Life, Politics, Prejudice) from TCG Forensics to conduct profiling on the suspect. Link analysis visually represents interconnected entities as nodes and links, enabling a clearer understanding of the data's underlying structure. The graph below maps the connections between the victim and the suspect — including cryptocurrency transactions — as well as links established from the domain registration details (the target's name and mobile number) and multiple social media accounts identified through Google Dorking techniques.

Maltego link analysis graph showing the suspect connected to LinkedIn, X, Instagram and Facebook profiles, a registered address in Nigeria, a phone number, the Elite-Bit domain, and the victim's cryptocurrency addresses and payment sources
Figure 4. Link Analysis

Case Relevance

The OSINT data gathered may assist law enforcement in identifying, arresting and prosecuting the suspect. Given that this case originated on Tinder in the UK region, there is a high likelihood other UK women are actively being targeted by the same scammer. UK law enforcement is advised to consider the on-chain analysis and OSINT gathered in this paper to assist this and other victims as soon as possible — doing so may reveal a wider ring of linked criminals focused on crimes of this nature.

Conclusion

As blockchain adoption grows, the rise in cryptocurrency-related crimes and scams follows suit. This paper analysed a romance scam used to systematically extract money from a victim under the pretence of a successful cryptocurrency investment — the romance scam escalating into a pig-butchering scam. The paper provided the case background, evaluated the fake investment platform Elite-Bit, and followed the authors' proposed methodology through on-chain analysis, off-chain OSINT investigation, and link analysis to profile the suspect.

Online scams remain a significant international threat due to the lack of standardised and official legislation. Due to the borderless nature of cryptocurrency transactions, these scams are becoming ever more prevalent in financial and cyber crime. This paper was written to raise awareness around romance scams, fake crypto investment scams, and pig butchering scams. The case is actively being investigated by the CSIR in connection with UK law enforcement.
Loading ratings…
Found this useful? Rate this post:
Thanks for rating!

Comments (0)

Loading comments…

Leave a comment

Your email address will not be published. Comments are reviewed before appearing publicly.