Analysis of a Cryptocurrency Investment Scam: Pig Butchering

Botha, Johannes George ; Singh, Kreaan ; Leenen, Louise (2025) — European Conference on Cyber Warfare and Security

Synopsis (AI-Generated)

A qualitative single-case investigation examined a UK victim's Elite-Bit pig-butchering experience using interviews, correspondence, bank statements, platform login records, and victim-provided identifiers. The researchers evaluated platform red flags; conducted on-chain transaction tracing with Breadcrumbs; performed off-chain OSINT on the Tinder profile, phone number, domain, Gmail account, and platform records; and applied the 11P method and Maltego link analysis to map relationships among the victim, suspect, transactions, domain, and social-media entities. The authors conclude that enhanced regulation and public awareness are urgently needed in response to cryptocurrency scams. The on-chain analysis found that the victim and her friend transferred a total of 5.4910 ETH to Elite-Bit. The investigation was constrained by limited victim-provided inputs and few transactions between victim and scammer.

Identified Gaps (AI-Generated)

The analysis lacked key attribution evidence: Binance subpoena results, Gmail headers, and subscriber information for the mobile number and protected domain registration. Transactions indicating additional victims were identified but were outside this paper’s scope. The authors also infer that other UK women may be targeted, but do not test this systematically. As a single victim case, the study does not establish the prevalence or generalisability of the identified scam pattern.

Methods (AI-Generated)

A qualitative single-case investigation examined a UK victim’s Elite-Bit pig-butchering experience using interviews, correspondence, bank statements, platform login records, and victim-provided identifiers. The researchers evaluated platform red flags; conducted on-chain transaction tracing with Breadcrumbs; performed off-chain OSINT on the Tinder profile, phone number, domain, Gmail account, and platform records; and applied the 11P method and Maltego link analysis to map relationships among the victim, suspect, transactions, domain, and social-media entities.

Limitations (AI-Generated)

The investigation was constrained by limited victim-provided inputs and few transactions between victim and scammer. Binance account-holder and outgoing-transaction data were unavailable because a subpoena required UK law-enforcement action and no response had been received. The victim could not provide the Gmail header, limiting IP/location analysis. Reverse-image and standard phone-number OSINT searches yielded no positive results. Evidence of other victims was identified but excluded from the study scope.

Future Work (AI-Generated)

Obtain a UK law-enforcement subpoena to Binance, then use account-holder information and outgoing transactions for further off-chain analysis. UK law enforcement should use the on-chain and OSINT evidence promptly to assist this and other victims and potentially identify linked offenders. The victim may also seek support and cooperation through international agencies such as Interpol and Europol.

AI-Generated Content Notice

The synopsis and research notes on this page were generated with AI from available publication information and, when available, the uploaded paper text. They may contain errors, omissions, or interpretation issues. Readers should follow the DOI or source link, review the original publication, and make their own judgment about the content.

Found a possible error? Request a correction.