top of page

From $2M to $200M: How Web2 OSINT Connected Two Crypto-Scam Cases Into One Laundering Network

  • Writer: Blockchain Unmasked
    Blockchain Unmasked
  • Jun 23
  • 9 min read

A technical case study on fusing open-source intelligence with on-chain tracing to link two apparently unrelated victims to a single transnational laundering apparatus.


Background


We were working on a case for a leading North American law firm in support of a class action that, on paper, was narrow: a few plaintiff victims, one centralized exchange, and roughly a few million in combined losses. One day the law firm introduced a new victim whose funds had also landed up in the same exchange. But this time, the victim had subpoenaed data internal to the exchange, which allowed us to peek into all the transactions done by the scammers.

Three weeks later, the same investigation had mapped a huge scam network. On the sidelines of the class-action lawsuit, we now had our lead plaintiff and the new victim under the same umbrella of scam as well — with more than $200 million in conservatively traced flow of funds tied to the scammer's cluster, and, more importantly, we had demonstrated that two clients who appeared to be victims of entirely separate scams had in fact been funnelled through the same laundering infrastructure.


The pivot that connected the two separate victims wasn't an exotic clustering heuristic or a proprietary attribution model. It was a single scam domain, reported on a public abuse forum — a piece of ordinary Web2 evidence that most on-chain reviews never look at. This is the story of how that thread was pulled.


Note: A note on handling before we begin. Throughout this case study the two victims are referred to only as Victim 1 and Victim 2, instructing counsel as the law firm, and the centralized exchange as the exchange. Specific wallet addresses and personally identifying details have been redacted or generalized. Nothing here should be read as an allegation against the exchange, which is treated throughout as a neutral financial touchpoint, not a wrongdoer.


The starting point: Victim 1


The engagement began with a single client — the lead plaintiff in a class action against the exchange.


Victim 1 had lost approximately $725,000 in Bitcoin and Ether across multiple transactions. Our initial scope was straightforward: trace the stolen BTC and ETH and establish where it had gone. A significant portion of those funds resolved, after a short series of hops, into addresses attributed to the exchange’s deposit infrastructure.


One constraint we had in this side of case and would matter a great deal later: we held no subpoenaed records for Victim 1 — only the victim's own wallet data and the on-chain trail it produced.


A second victim, and the first real dataset: Victim 2


A few weeks into the matter, the law firm introduced a second victim whose losses were materially larger and who, counsel believed, might strengthen the class, since they were also a class member.


Victim 2 had lost approximately $1.45 million. Crucially, this is where the investigation gained its first authoritative dataset. It was discovered in our initial analysis that the victim 2 has already reached out to Law Enforcement and via their complaint, a county-level law-enforcement subpoena was served on the exchange in the United States, and the exchange produced internal records — including KYC — for three accounts (Scammers) that had received and moved the stolen funds. These are the accounts we refer to as the scammer cluster.


It is worth being explicit about provenance, because it shapes everything that follows: all of the subpoenaed exchange records, and effectively all of the OSINT enrichment described below, originate from the Victim 2 side of the investigation. Victim 1 contributed the on-chain trail and, ultimately, the artefact that closed the loop but the evidentiary spine of the network analysis came from Victim 2.


Working from the KYC profiles contained in the exchange records, on-chain analysis of the subpoenaed dataset traced approximately $72.85 million in deposits and $63.9 million in withdrawals moving through the cluster. Two points of caution belong here.


First, those figures represent gross account throughput for the reviewed cluster — not the loss suffered by either named victim. Second, the asset composition shifted markedly between the deposit and withdrawal legs, consistent with in-exchange conversion into Tron-based USDT prior to off-ramping. The three KYC identities themselves resolved to nationals of East and Southeast Asian jurisdictions — consistent with the documented operational geography of these networks.


The laundering profile — and why it was not, by itself, a breakthrough


The subpoenaed cluster's counterparty exposure read like a field guide to Southeast Asian organized crypto laundering. Within direct and near-hop distance we observed exposure to guarantee-style marketplaces and illicit financial-service ecosystems of the type recently subject to regulatory action; to mixing services, including Telegram-advertised mixers; to multiple stablecoin-blacklisted wallets; to addresses associated with terror-financing and sanctioned-adjacent infrastructure; and trace-level exposure to a regional conglomerate recently named in enforcement contexts.


This is a serious profile — but, candidly, it is also a typical one. A mature Southeast Asian threat-cluster will almost always show this fingerprint, because these services are precisely the obfuscation, laundering, and off-ramp rails such groups depend on. Exposure of this kind is a strong risk and linkage indicator; it is not, on its own, attribution, and it did not connect our two cases. The connection came from somewhere far less glamorous.


The OSINT pivot: One reported domain


While tracing the Victim 2 cluster in Global Ledger, one address associated with the scammer cluster carried something the on-chain data alone could not provide: two addresses had been publicly reported, tied to two scam domains — one address impersonating a well-known retail-trading brand, the other a generic lookalike.



That is the moment a pure on-chain review and an intelligence-led review diverge. As a node on a graph, the address was unremarkable. As a piece of Web2 evidence, it was a doorway.


We pulled both domains into open-source enrichment. One — Rep-eth[.]com — was eliminated as out of scope after review since not every time you are going to find desired results. Sometime you find nothing. This is worth dwelling on: good OSINT rules leads out as rigorously as it rules them in, and the discipline of discarding the weak lead is what gives weight to the ones you keep. As we analyzed further, the second domain — Easymarkets[.]vip — the brand-impersonation site — became the seed for everything that followed.


Expansion 1 — Reverse WHOIS


A reverse-WHOIS pivot on the surviving seed returned the first sign of scale. The domain's registrant organisation — a Chinese manufacturing company with no plausible connection to financial services — was associated with roughly 48 domains registered through a single registrar. The portfolio was a catalogue of financial-brand impersonations: lookalikes of major brokers, exchanges, and banking names, registered in tight date clusters.


Easymarkets[.]vip on row 15


A manufacturing entity holding four dozen broker- and exchange-impersonation domains is, in itself, a powerful tell. It told us we were no longer looking at a single fraudulent site but at an infrastructure portfolio.


Expansion 2 — Wayback address recovery


By the time of review, the live impersonation sites had largely been taken down or placed behind protective infrastructure. So we turned to historical snapshots.


Using the Wayback Machine, we retrieved archived captures of the sibling domains and parsed the archived page source — including the embedded front-end deposit configuration preserved in those snapshots. That archival recovery surfaced two additional deposit addresses hard-coded into the platforms' deposit flows — one on Ethereum and one on Tron.


0xb6...f938 is one of the addresses found via WayBack captures tied to Easymarkets[.]vip. 0xb0...5755 is the address we found in the scammer cluster of Victim 2


The on-chain behavior of these recovered addresses clarified their role. They functioned as victim-facing deposit addresses — the wallets a victim would be instructed to fund when "depositing" onto the fake platform. And on the Victim 2 scammer side, one corresponding address operated as an aggregator, consolidating multiple victim deposits — over $3.7 million in throughput — and forwarding them onward to the same exchange.


To be precise about what this does and does not show: it demonstrates that the impersonation infrastructure and the subpoenaed scammer cluster shared a common off-ramp destination. That is a routing relationship, not a finding of fault on the part of that destination.


Expansion 3 — From two domains to a domain network


We had started with two domains and two addresses. OSINT had eliminated one domain, and the other domain had already produced two more addresses across two chains and 50+ further scam domains. Five of those, plus the original seed, stood out as high-value, so we ran a preliminary enrichment pass across all six — drawing on urlscan, the Wayback Machine, VirusTotal, and certificate-transparency records (crt.sh).


Prelim analysis of the 6 URLs


The pattern held across the set. Most domains sat behind Cloudflare or similar protective services, yet nearly all surfaced in public scam-reporting ecosystems — Asian fraud-reporting forums and several North American reporting portals among them — which both corroborated their nature and enriched the linkage graph.


With six high-confidence seeds shortlisted, our team — supported by Adrian Cheek, founder and senior threat researcher at Coeus — ran a full open-source investigation across them. Through third- and fourth-party infrastructure linkages, the six seeds expanded to a universe of more than 1,100 associated domains, of which 674 were placed under active assessment. Corroboration came from Chainabuse records and multiple government channels, including state financial-regulatory portals and regional anti-fraud bodies.


Critically, the 1,100+ figure is an infrastructure-enrichment universe, not a list of 1,100 confirmed scams. Each domain was categorized by linkage type rather than lumped together. A representative — and deliberately redacted — view of how the active-assessment set clustered:



The value of this breakdown is methodological: it shows the network was not a guess but a structured graph, where each edge — a shared registrant, a shared IP, a reused front-end template, a naming convention — is an independently checkable relationship.


The bridge: An address that should not have meant anything


Reviewing the completed domain analysis report, our crypto-investigations team identified two further addresses tied to one of the assessed domains — one on Ethereum, one on Bitcoin.


We traced both. The Ethereum address, like so much else in this network, terminated at a deposit address belonging to the same exchange. At the time, it did not stand out. It was simply one more flow into one more exchange deposit address.


A few days later, a team member ran routine OSINT on that deposit address before finalizing the report— and, through a shadow-intelligence lead via Nominis, found it referenced in an official complaint filed in the court. We verified the intelligence lead against the underlying filing. The complaint had been lodged by the same law firm that had instructed us — and the deposit address belonged to Victim 1's scammer.


Closing the loop


This is where the on-chain and open-source threads finally met.


Because we held no subpoena for Victim 1, we could not pull that scammer's withdrawals or full address set directly. But we could work the deposit address from the other direction — tracing its inbound activity — and we could re-examine the one authoritative dataset we did hold: Victim 2's subpoenaed records. When we did, the same exchange deposit address appeared on the Victim 2 side as well, used by Victim 2's scammer cluster.


A single deposit address, carrying more than $35 million in throughput, sat at the intersection of both cases. Two victims who had walked in the door as unconnected — different scams, different losses, nothing obvious in common but the exchange where their money ultimately landed — were now demonstrably routed through shared laundering infrastructure. The link was established on-chain and corroborated through OSINT, not assumed.


What the case demonstrates


Strip the matter to its mechanics and a few lessons stand out.


Web2 evidence is on-chain evidence's missing half. The entire connection rested on artefacts that live off-chain: a public abuse report, a WHOIS registrant record, an archived web page, a court complaint surfaced through shadow intelligence. An investigation that looked only at the ledger would have traced funds into the exchange, found a typical TCO (Transnational Criminal Organization) laundering profile, and stopped. The doorway was always in Web2.


Disproportionate leverage from limited inputs. We did not begin with privileged access at scale. We began with one law firm, two victims, one shared exchange, and roughly $2 million in losses. Methodical fusion of subpoenaed records (on the Victim 2 side) with open-source enrichment turned that into hundreds of addresses, 650+ scam domains under assessment, two cases merged under one syndicate umbrella, and a wallet network whose inflows conservatively exceed $200 million.


Rigor cuts both ways. The same discipline that expanded the network also pruned it — eliminating an out-of-scope domain early, separating an infrastructure-enrichment universe from confirmed scams, and distinguishing gross account throughput from victim loss. Investigations earn their credibility as much by what they exclude as by what they claim.


Conclusion


The headline figure — roughly $2 million in named-victim losses opening onto a $200 million-plus network — is striking, but it is not really the point. The point is the method. Two cases that the documentary record treated as separate were shown to be one, and the proof did not come from a more powerful tracing engine. It came from reading the Web2 exhaust that fraud infrastructure inevitably leaves behind — reported domains, registrant records, archived pages, public complaints — and binding that open-source picture back to the chain.


For investigators, the operational takeaway is simple and, we think, urgent: treat the blockchain as one source among many, not the only one. The most consequential link in this matter was discovered off-chain and confirmed on it. Scam networks of this scale are not unraveled by tracing alone, nor by OSINT alone, but by the patient fusion of the two.


 
 

Subscribe to our newsletter

Thanks for submitting!

bottom of page