This paper analyses and investigates a cryptocurrency investment scam involving the suspicious and fraudulent cryptocurrency trading platform, Elite-Bit, through a detailed case study of a victim's experience. With the rapid rise of cryptocurrency, deceptive platforms like Elite-Bit exploit unsuspecting investors by presenting a façade of legitimacy. This case study chronicles the victim's journey, beginning with a seemingly romantic connection through a dating platform, to an introduction to an investment opportunity, and subsequently a financial loss.
After investing a substantial amount, the victim faced unexpected barriers when attempting to withdraw funds, including exorbitant transaction fees and other fabricated costs. The analysis reveals how Elite-Bit employs manipulative tactics such as social engineering and false urgency to maintain control over investors, ultimately leading to significant financial loss — manipulative tactics referred to as pig butchering. An on-chain and off-chain analysis was conducted using the limited input data provided by the victim, and a link analysis was performed using the tool Maltego to visually map the entities associated with the suspect within a network of nodes and connections.
Introduction
The adoption of blockchain technology has surged in recent years. However, the unique characteristics of cryptocurrencies have also led to a rise in crime, drawing in scammers and fraudsters. The majority of frauds involving cryptocurrency trading or fake investments begin on social media or through messaging apps — unsolicited contact from an unknown individual or an online acquaintance introducing an unfamiliar trading platform significantly increases the likelihood of fraudulent activity.
The case on which this paper is based started as a romance scam that escalated into a pig-butchering cryptocurrency investment fraud. Pig butchering scams are sophisticated and well-orchestrated in deceiving and defrauding victims. These scams mostly follow a pattern of initiating contact with a potential victim through a fake persona. The scammers spend weeks, and sometimes months, building a relationship with the victim, often feigning a romantic interest. Once trust is gained, the scammer directs the conversation towards introducing investment opportunities, usually involving cryptocurrency — framing it as a good opportunity to build a future together and achieve financial freedom, while portraying themselves as an experienced investor who wants to help the victim succeed.
The scammer convinces the victim to install an investment app or register on a fraudulent platform, walking them through account creation and an initial deposit — normally a smaller amount so the victim isn't intimidated. Manipulated data and fake reports then show high returns, and the victim is encouraged to invest even higher amounts by creating urgency around a once-in-a-lifetime opportunity. Emotional manipulation tactics are used to stay in control, such as professing love and promising a shared future, and the scammer may use threats or intimidation to make the victim panic and act fast. When the scammer has extracted as much money as possible, they cut all communication and disappear — the app or website is taken down if enough gains have been accrued, or kept alive to target the next victim.
Case Background
The timeline below summarises events that occurred between 15 June 2024 and 31 July 2024. On 15 June, a female victim from the United Kingdom (UK) matched with a male suspect on Tinder, initiating a conversation on the platform. After a week of communication, they exchanged mobile phone numbers and interactions transitioned to WhatsApp. Communication persisted for a further three weeks, during which the victim mentioned wanting to visit her sister in Australia but expressed the financial burden of the trip. Seizing this opportunity, the suspect introduced her to the trading platform Elite-Bit, promising substantial returns and assuring her she would quickly accumulate the funds she needed.
The initial step involved registering an account with Elite-Bit (www.elite-bit.net) and transferring funds to the platform. Elite-Bit only accepted cryptocurrency deposits, so the victim was instructed to download MetaMask (a widely used cryptocurrency wallet) and the Crypto.com app (a well-known exchange) to facilitate transactions. She then transferred funds from her Lloyds account to Revolut, a British neobank that also facilitates conversion of fiat currency into cryptocurrency. Revolut was used to purchase cryptocurrency to send to Elite-Bit — but the victim was instructed to first route the funds through her MetaMask wallet rather than sending directly, likely to circumvent Revolut's withdrawal analysis or mask the actual destination of the funds.
Elite-Bit provided a chat service through which the victim was guided through her first trade. She "won" the trade, almost doubling her initial investment, and was then coerced into making additional deposits to facilitate larger and more frequent trades. Multiple payments followed, and the victim was guided through five additional "successful" trades — her perceived account balance rising to 21,320 USD Tether (USDT), a stablecoin pegged to the US dollar.
At this stage, the victim indicated she had no additional funds to invest and requested to withdraw her balance. Elite-Bit restricted contact to its chat service, with no telephone or email details provided, and instructed her to submit a screenshot of the withdrawal address. The platform then conducted a small "test" transaction to that address — once she confirmed receipt, she trusted the full withdrawal would follow. She requested withdrawal to her Lloyds UK bank account. In response, the platform claimed withdrawals exceeding $20,000 required a $1,980 tax payment, which she paid in USDT. The platform then demanded a further $2,880 "service charge" before processing the withdrawal, promising funds within 48 hours — none arrived, and an email (from a free Gmail account) later claimed the payment had failed and asked for an alternative destination.
On the recommendation of her Tinder "acquaintance," she asked for the funds to be sent to her MetaMask ETH address instead — the platform then demanded an additional $3,400 fee to process that transaction. Elite-Bit further exploited Revolut's $500 daily withdrawal limit to force multiple payments over several days, threatening late-payment penalties if she missed the deadline. The victim panicked and asked friends to open Revolut accounts in their own names so additional $500 payments could be sent daily — one friend helped, another refused and warned her she was being scammed. Despite the help, she still missed the deadline and was charged the late fee, followed by a final charge to convert USDT to ETH. It was at this point that she finally recognised she had been scammed.
A criminal case was opened in the UK, but police indicated they would be unable to assist as the amount stolen was not substantial enough on its own, advising that evidence of additional victims and larger losses would be needed before an investigation could begin. The victim then sought the help of one of this paper's authors to assist in the analysis and investigation. Evidence of additional victims was uncovered through blockchain analysis, though that aspect falls outside the scope of this paper.
Evaluating the Trading Platform Elite-Bit
Elite-Bit claims to be a professional asset management and cryptocurrency trading platform. A thorough evaluation identified several red flags:
- Cryptocurrency prices are not updated in real time as claimed.
- Certain web links and buttons are broken, giving a "404 page not found" error.
- The platform displays no credible business details.
- Price graphs lack the tools a professional trading platform would typically offer.
- Selecting a different time interval on the price graph triggers a JavaScript method but does not actually change the data displayed.
- A lack of access to price history prevents users from comparing or objecting to price action and trade outcomes.
- User actions are limited to betting "high" or "low," resembling gambling rather than genuine trading.
- The dashboard's transaction list shows the user has "won" X amount — the first five trades were "won," with two left pending.
Additional OSINT investigation revealed further red flags. The platform is registered in Estonia, but displays a USA address in Las Vegas and a USA phone number on its website. It is not registered as a money service company, a requirement for any such service operating in the UK. It claims to hold a licence to trade forex, futures or options, and claims registration with the UK's Financial Conduct Authority (FCA) — but on inspection, it was using another company's real licence details under a different name, known as a "cloned firm."
Discussions with the victim surfaced further red flags: the website only accepted cryptocurrency deposits with no bank transfer option; investment returns increased substantially as deposits increased, a likely manipulation tactic; a large transaction fee was charged on withdrawal, followed by an additional "tax clearance certificate" fee; urgency was created via a payment time limit, with a penalty fee if missed; unrealistically large service fees were charged both for transferring ETH to the victim's wallet and for converting ETH to USDT; and email communication came from a free Gmail account, uncharacteristic of a genuine service provider. At the time of writing, the platform was still active until 10 February 2025, but now appears to be permanently offline.
Analysis of the Case
The analysis follows a methodology proposed in the authors' previous research, beginning with opening a case that integrates both on-chain and off-chain analysis, followed by a parallel path connecting each cryptocurrency address to corresponding social media accounts, and finally exploring the legal frameworks needed to transform actionable intelligence into evidence admissible in court. The victim provided the following inputs (redacted): an ETH cryptocurrency address (0x0f9f...4054), a Tinder profile name (Fr…co Ab...e), a mobile number (4474…43), the domain name www.elite-bit.net (with login details), a Gmail address (trade…net@gmail.com), and bank statements of all transactions made to fund the platform.
On-Chain Analysis
The tool Breadcrumbs was used to perform on-chain analysis. The starting point was the cryptocurrency address 0x0f9f…4054, provided by the victim as the address where she was instructed to deposit funds. Filtering out transactions from other victims and focusing only on this victim's deposits between 13–30 July 2024, Breadcrumbs identified the address used by Elite-Bit as an account held on the exchange Binance — meaning Binance can be subpoenaed to reveal the account holder's personal information and outgoing transactions.
Multiple incoming transactions to Elite-Bit's address outside the victim's date range were also identified, indicating the same address is used to receive funds from other victims. The tool revealed incoming transactions from four sources: the victim's MetaMask wallet, the victim's Revolut account, a friend's Revolut account, and a Crypto.com account. In total, 3.872 ETH was sent from the victim's MetaMask wallet, 0.4284 ETH directly from her Revolut account, and 1.1915 ETH from her friend's Revolut account — 5.4910 ETH transferred in total.
Analysing Elite-Bit's Binance address shows the wallet is still actively used at the time of writing, with a last transaction dated 18 January 2025 — despite the victim's last interaction in July 2024, confirming the scammers are still actively targeting other victims. The total amount of cryptocurrency transacted through this address is 18.469 ETH, with roughly 30% of the funds in this wallet originating from the victim in this study.
At the time of writing, a request had been made to the British High Commission in Pretoria to issue a subpoena to Binance — since the case is not registered in South Africa, the subpoena must be issued by a UK law enforcement entity, and no response had yet been received.
Off-Chain Analysis
This part of the analysis employs OSINT techniques to attempt to unmask the suspect's identity. Reverse image search tools such as TinEye and Google Image Search returned no positive match for the Tinder profile photo. Truecaller identified the mobile number as UK-registered, still active, and linked to service provider M-Hutchison — standard OSINT searches on the number itself yielded no results, though a subpoena to the service provider could reveal the registered owner.
ViewDNS.info revealed the domain is hosted in Kuala Lumpur, Malaysia, and was registered on 23 November 2023 — a relatively new registration, itself a red flag, since scammers often register fresh domains to facilitate fraud. ScamAdviser reported a trust score of 1/100 for the domain, strongly indicating a scam link. Using the Scam-Detector tool, the registrant's name, address, country and an additional phone number were revealed, identifying the suspect as Nigerian — a pivotal finding that opened fresh investigative leads, further supplemented by Truecaller revealing the name linked to the new number. A licence-to-trade number listed on the Elite-Bit site was also checked against the FCA register and found to belong to another, unrelated company — confirming Elite-Bit as a cloned firm.
The email header could not be obtained from the victim, which would otherwise have revealed the sending IP address and an approximate location. OSINT on the Gmail account confirmed a direct link to the Elite-Bit domain, though no further information could be extracted from the account itself.
Bank Statements and Login Details
Using the login credentials provided by the victim, the platform's own transaction log was retrieved. All payment transactions occurred between 11 and 31 July 2024. The first two trades shown were refunded — the platform claimed the market had turned against the victim and refunded the amount, a trust-building tactic — after which every subsequent trade resulted in the invested amount almost doubling.
| Tx | Transacted | Amount | Post Balance | Detail |
|---|---|---|---|---|
| YC3TAVB8NKHB | 2024-07-11 22:14 | +441.00 USD | 441.00 USD | Deposits |
| 7671R3AUAYEX | 2024-07-12 19:12 | -441.00 USD | 0.00 USD | Trade to USDT High |
| 7671R3AUAYEX | 2024-07-12 19:49 | +441.00 USD | 441.00 USD | Trade refund |
| 9O6JKNUDJ75O | 2024-07-12 20:03 | -441.00 USD | 0.00 USD | Trade to USDT High |
| 737O8FYGK5FE | 2024-07-12 20:41 | +441.00 USD | 441.00 USD | Trade refund |
| PFFNZ4KAJYE3 | 2024-07-12 20:57 | -441.00 USD | 0.00 USD | Trade to USDT High |
| NR66A8EU2VQ4 | 2024-07-12 21:07 | +837.90 USD | 837.90 USD | Trade to USDT WIN |
| PSDJBRUAA1N4 | 2024-07-13 12:15 | +627.00 USD | 1,464.90 USD | Deposits |
| OXM616WYEKN8 | 2024-07-13 16:57 | -1,464.00 USD | 0.90 USD | Trade to USDT High |
| ZPUEK7T2MYCK | 2024-07-13 17:17 | +2,781.60 USD | 2,782.50 USD | Trade to USDT WIN |
| WB2MK5QZX5RH | 2024-07-13 17:48 | -2,782.00 USD | 0.50 USD | Trade to USDT High |
| KUOSACS1B1XV | 2024-07-13 18:05 | +5,285.80 USD | 5,286.30 USD | Trade to USDT WIN |
| G2SKHK6NSUSX | 2024-07-13 21:43 | +630.00 USD | 5,916.30 USD | Deposit |
| G82WE22WMO4G | 2024-07-13 22:24 | -5,916.00 USD | 0.30 USD | Trade to USDT High |
| 6PYU111DAQMP | 2024-07-13 22:41 | +11,240.40 USD | 11,240.70 USD | Trade to USDT WIN |
| QNMV819XRUJ1 | 2024-07-14 09:52 | -11,200.00 USD | 40.70 USD | Trade to USDT High |
| 29CVRQU7UY9S | 2024-07-14 10:34 | +21,280.00 USD | 21,320.70 USD | Trade to USDT WIN |
| 5V9JUFQ68HN5 | 2024-07-14 21:36 | -1,300.00 USD | 20,020.70 USD | Withdraw via bank transfer |
| 5V9JUFQ68HN5 | 2024-07-15 04:26 | +1,300.00 USD | 21,320.70 USD | Refunded from withdrawal rejection |
| 8P7FV7GO2491 | 2024-07-29 07:55 | +1,900.00 USD | 23,220.70 USD | Deposit |
By 14 July 2024, a total of $1,698 had been deposited for trading purposes. The victim was led to believe she had attained a trading balance of $21,320.70 and requested a withdrawal. Between 15 and 31 July 2024, the scammer then employed pig-butchering manipulation techniques to systematically extract even more money — the victim's total payments amounted to £11,000 ($13,640.37), of which $11,942.37 was allocated to phantom service fees, tax fees, conversion fees and penalty charges.
Link Analysis
Using the data gathered, a link analysis was performed with the tool Maltego, applying the 11P method (People, Places, Personalities, Past, Police, Photos, Pay, Professional Life, Politics, Prejudice) from TCG Forensics to conduct profiling on the suspect. Link analysis visually represents interconnected entities as nodes and links, enabling a clearer understanding of the data's underlying structure. The graph below maps the connections between the victim and the suspect — including cryptocurrency transactions — as well as links established from the domain registration details (the target's name and mobile number) and multiple social media accounts identified through Google Dorking techniques.
Case Relevance
The OSINT data gathered may assist law enforcement in identifying, arresting and prosecuting the suspect. Given that this case originated on Tinder in the UK region, there is a high likelihood other UK women are actively being targeted by the same scammer. UK law enforcement is advised to consider the on-chain analysis and OSINT gathered in this paper to assist this and other victims as soon as possible — doing so may reveal a wider ring of linked criminals focused on crimes of this nature.
Conclusion
As blockchain adoption grows, the rise in cryptocurrency-related crimes and scams follows suit. This paper analysed a romance scam used to systematically extract money from a victim under the pretence of a successful cryptocurrency investment — the romance scam escalating into a pig-butchering scam. The paper provided the case background, evaluated the fake investment platform Elite-Bit, and followed the authors' proposed methodology through on-chain analysis, off-chain OSINT investigation, and link analysis to profile the suspect.
Comments (0)