Fake Crypto Investment Sites, Victims Across 20+ Countries: How a Server in the Netherlands Became Key to a Ukrainian Fraud Investigation
Ukraine's National Police and SSU say a fake crypto investment network targeted victims in more than 20 countries. Investigators identified 62 victims, a server in the Netherlands and malicious wallet-draining code.
1 / 4Ukraine's National Police announced the operation on September 1, 2026.
According to investigators, the alleged organiser recruited more than 46 Ukrainian nationals and established several offices in Kyiv and the surrounding region.
IT specialists allegedly built and maintained fake investment websites, while other participants administered the offices, contacted prospective clients and provided security.
Ukraine's Security Service, the SSU, said the alleged organiser was a 25-year-old Kyiv IT specialist.
The SSU estimates that during peak periods the monthly turnover connected with the alleged illegal activity could reach $1 million. That figure should not be confused with the total proven loss to victims, which investigators say has not yet been established.
The investment profits were allegedly fabricated
Clients were encouraged to register on the platforms, connect cryptocurrency wallets and deposit funds into supposed investment projects.
Investigators say the websites then displayed apparent growth in the clients' investments.
But according to the National Police, the financial activity shown in those accounts was manually simulated.
The real trap allegedly appeared when a customer attempted to withdraw funds.
The "drainer"
Investigators say withdrawals were blocked and clients were then asked to connect their primary crypto wallet and confirm a small transaction, supposedly to verify that the platform was working correctly.
The fake website allegedly contained a malicious mechanism commonly referred to as a crypto drainer.
In simple terms, such code can exploit a transaction approval or wallet permission to enable digital assets to be transferred from a victim's wallet.
Ukraine's police say victims believed they were approving a small test transaction while the process actually gave the operators the ability to transfer their assets to addresses under the network's control.
The SSU gives a broadly matching description of the mechanism.
Why the Netherlands matters
The most significant investigative detail may not be the searches carried out in Kyiv.
The National Police says investigators identified server equipment located in the Netherlands and obtained access to a database stored there.
According to the police, the database contained lists of victims, crypto-wallet addresses, amounts of stolen digital assets, internal communications and information on the operation of the fake platforms.
Analysis of this material allegedly allowed investigators to reconstruct the scheme and identify victims.
So far, police say there are 62.
They include nationals of Germany, Poland, Lithuania, Latvia, Spain, France, the United Kingdom, Canada, Israel and other countries.
In total, victims have been identified in more than 20 states.
That gives the case a clear international dimension.
But there is an important limitation.
Neither the National Police release nor the SSU release provides a full list of foreign law-enforcement agencies that may have assisted.
It would therefore be inaccurate to describe the case as a joint operation involving police forces from more than 20 countries.
What is confirmed is that Ukraine's National Police, the Security Service of Ukraine and the Office of the Prosecutor General were involved in the Ukrainian investigation.
One operation, two sets of official numbers
There is also an unresolved discrepancy between the two Ukrainian agencies' public statements.
The National Police says authorities conducted 34 searches at homes, offices and vehicles in Kyiv and Kyiv region.
It reports the seizure of more than 100 pieces of computer equipment, more than 100 mobile phones, 79 SIM cards, a GSM gateway, documents, records, cash and 15 vehicles.
The SSU's release on the same operation states that 23 searches were conducted at offices and residences and that 16 luxury vehicles were found.
The public releases do not explain the difference.
The agencies may be counting different categories or stages of the operation, but that cannot be established from the published information.
For that reason, both official figures should be preserved rather than silently reconciled.
No convictions — and, at the time of the announcement, suspicion notices were still being considered
This is another important boundary.
The SSU said on September 1 that authorities were still deciding on formally notifying individuals of suspicion.
The National Police said the pre-trial investigation was continuing under Part 5 of Article 190 of Ukraine's Criminal Code.
That provision covers fraud committed on an especially large scale or by an organised group and carries a potential penalty of five to 12 years' imprisonment with confiscation of property.
That is the statutory penalty, not a sentence imposed on any individual in this case.
Guilt must be determined by a court.
Why this case matters beyond Ukraine
International crypto-fraud cases create an unusually fragmented evidence trail.
An office may be in Kyiv.
A server may be in the Netherlands.
A victim may live in France or Canada.
A crypto transaction may move assets across several blockchain addresses within minutes.
Investigators then have to turn all of that into one coherent evidentiary chain.
Who controlled the website?
Who administered the server?
Who owned or controlled the destination wallets?
Which transaction belongs to which victim?
Who authorised the transfer?
And how can each digital event be connected to a specific individual?
Those questions matter more than photographs of luxury cars seized during searches.
A Porsche is easy to show.
A defensible chain connecting a victim in another country, a malicious website, a server database and a wallet controlled by a specific suspect is much harder to prove.
That is why the Dutch server may ultimately be one of the most important elements in this case.
The investigation is still ongoing.
Police say more victims may be identified, the total loss has not yet been calculated and the full circle of people involved remains under investigation.
The raids were the visible part.
The real test comes next: whether investigators can turn a multinational digital trail into evidence that survives in court.
Primary sources
Documents and statements this story is based on.