Contact
← All insights
Crypto Incidents

Pig Butchering: How a Fake Investment Platform Gradually Draws in the Victim

First, trust is built and 'profit' is shown, but major losses occur after a series of voluntary transfers.

Updated 2026-10-064 min read

This scheme doesn't necessarily require a 'hack' in the usual sense. First, trust is built and 'profit' is shown, but major losses occur after a series of voluntary transfers. It is on such an ordinary action that the attack is built.

The main thing to know right away: The main thing is not to panic and not to try to 'fix' the situation with random transfers. First, stop the repeat risk, save the original data, and only then analyze what happened.

How the scheme works

In this scheme, the technical part begins after a long period of trust-building. The victim is shown a fake investment platform, sometimes allowed to withdraw a small amount, and then motivated to increase deposits. The numbers in the personal account may have no relation to real assets.

In this situation, it is important to separate two things: the attack mechanism itself and what has already happened to the assets. First, trust is built and 'profit' is shown, but major losses occur after a series of voluntary transfers. After the incident, the technical analysis begins not with guesses, but with a specific operation and its continuation on the blockchain.

What to do if this has already happened

Separate the interface of the 'investment platform' from the actual transfers. Collect all tx hashes of deposits and build a single route — that is what shows where the funds actually went.

  1. Stop repeating the action that caused the incident: do not sign new requests and do not send additional payments.
  2. Save the tx hash, full addresses, network, asset, amount, and time of the operation.
  3. Record the correspondence, domain, profile, app, or signature screen — everything that explains the context of the operation.
  4. If there is a risk of wallet compromise, move remaining assets to a new safe wallet, without using the exposed seed phrase.
  5. If the amount is significant, it makes sense to trace the further route of funds and identify service points along the way.

What to save for the investigation

For this specific topic, it is especially useful to save: deposit addresses, history of 'deposits', screenshots of the personal account, and correspondence with the curator.

For the initial analysis, prepare the data in one message or file — this reduces the risk of losing an important detail:

  • tx hash / txid
  • full sender and recipient addresses
  • network, asset, amount, and time
  • screenshots and correspondence
  • domain, profile, or app, if they are related to the incident

What you should not do

  • Do not share your seed phrase and private keys with 'helpers' or a 'recovery service'.
  • Do not pay an unknown intermediary a 'tax', 'insurance', or 'unlock fee'.
  • Do not delete correspondence and transaction history before everything is saved.

Important: a transaction and address are verifiable on-chain facts. The identity of the owner, motive, and legal status should not be automatically inferred from a single graph.

When it makes sense to involve a specialist

If the amount is significant, the route has already branched out, or exchanges, exchangers, bridges, and other services have appeared on it, a manual analysis helps separate available actions from useless ones. To start, public data is usually enough — private keys are not needed.

Frequently asked questions

If a large balance is still visible on the website, does that mean the money is there?

Not necessarily. The balance on a fraudulent website may just be a database entry or a drawn figure. Real movement is confirmed only by transactions and data from real services.

Can a confirmed transaction be canceled?

As a rule, no. Further actions depend on the route of funds and whether services have appeared on it that can restrict the movement of assets.

Can you immediately identify the scammer by the address?

No. The blockchain shows addresses and operations. Identity requires additional data: KYC from a service, public sources, case materials, or other confirmations.

In short

First, trust is built and 'profit' is shown, but major losses occur after a series of voluntary transfers. If this has already happened, first stop the repeat risk and save the original data. Then you can analyze the route and real points for further actions.

QuantoLog

Need to understand what happened and where the funds went?

Provide the tx hash, network, and a brief description of the situation. Seed phrase and private keys are not needed for the initial assessment.

Submit data for assessment