Hooked By A Pig Butchering Scam
CASE STUDIES

Hooked By A Pig Butchering Scam

Chainlabs Staff
May 12, 2026

How $500K was routed through seven wallets & cashed out via Tron

"One may smile, and smile, and be a villain." ~ Shakespeare, Hamlet

Over a period of six months in 2023, Rachel* sent nearly $500,000 of retirement savings to what she believed was a regulated crypto exchange, all on the advice of a man she had recently met on Instagram. As Rachel invested more, her ability to recover diminished. By the time she realized the scam, her funds were already being moved through a criminal architecture designed to process new victims continuously.

Rachel (victim): "I met a guy via Instagram from my comment of a picture of his mom and him as a young boy in Singapore. We followed, chatted on the private chat page of IG and later on he invited me to chat at Whatsapp. We talked about our family backgrounds, life experiences and about ourselves. Our friendly chats quickly turned to romantic dating. His name was James, said he lived in Irvine and is a co-owner of a shipping company in Los Angeles. Without my asking, he even wired $100k of his own funds from his wallet address into my assets because he wanted to help me gain more profits. Sure enough, I saw large profits but with a consequence."

James Lee was a synthetic persona. The alleged employer, 'Huangshi Logistics' in Seattle, does not exist in US records. All three phone numbers used in the scam were traced to ONVOY, a common provider of disposable VoIP (Voice over Internet Protocol) lines. 'James Lee's' Instagram profile recycled stock images from at least four countries, with mismatched styles and contexts. None of these red flags required advanced blockchain tools to uncover — a basic OSINT (Open-Source Intelligence) investigation by law enforcement could have surfaced the fiction before any funds moved, and would have if a report had been made early enough to intervene.

Yet, once the unsuspecting victim makes a deposit, things quickly become murkier. Things get a bit technical here, so if you’re not familiar with these terms, just skip to the next paragraph - you’ll still get the gist of it. Rachel’s savings are routed through disposable exchange clones—first from Crypto.com to NITO-EXCHANGE.org, a recent Dynadot registration visually cloned from HTX, then rebranded as CHE-EXCAILPRO.org through an "emergency merger." Once inside, withdrawal of R.'s funds was impossible; each retrieval attempt triggered a new fabricated demand:

The on-chain setup easily evades standard tracing tools - each layer exhausting the one before it. The infographic below illustrates how this is done. Rachel's funds moved through seven untagged addresses (L1) over three months, having first been routed via Crypto.com into fake-exchange clones (L0). Each deposit quickly converged on a few primary wallets (L2), which pooled funds from multiple sources. From there, the money was split across several other wallets, which received over 1,000 Etherium (USD500,000) in late October 2023 and traded on 1inch, MEXC, and BitFlyer (L4) (see infographic below). The pattern always ended on Tron, where low fees and weak checks allow large sums to be broken into small, hard-to-trace withdrawals. By now, the infrastructure has closed in on Rachel, and there is no happy ending for the safe return of her savings.

"I then realized that I've been scammed after I Googled about crypto scams. I am so stupid, foolish and angry with myself to fall for this. There were red flags, but I ignored it. I am really depressed. I have been experiencing mental and emotional stress, anxiety, bad headaches, loss of sleep and appetite. I feel so down, foolish, ignorant and deceived.” Rachel (victim)

Rachel’s self-blame is common among scam victims and worsened by harmful stereotypes. These elaborate scams are carefully planned by organized crime, sophisticated enough to deceive even banks and financial regulators. What appears to be seven separate scams is in fact an intricate five-stage money-laundering scheme with each step carefully designed to frustrate detection:

1778512632679

Commercial scam-intelligence feeds stop at the first-tier deposit address. The rest of the laundering architecture — consolidators, dispersion wallets, aggregators, the cross-chain cash-out — stays hidden until those wallets are eventually labelled, often weeks later.

Chainlabs begins at the first-tier deposit address, tracking flows in real time across Ethereum, Tron, and their bridges, mapping each transfer. Using observed deposits as initial seeds, we build clusters that reveal the connections between wallets and operational patterns. When addresses appear inactive or fragmented, our analysts repeatedly retrace the flow, update traces as new transactions appear, and refresh data to reconnect dormant operations as activity resumes. This iterative process ensures we track the evolving architecture of scam operations throughout their lifecycle.

Compliance and risk teams often face a structural chasm. Commercial intelligence eventually labels these wallets, but the window for intervention is 24-72 hours from the first deposit, before most feeds update. Only by recognising the architecture itself can a screening pipeline flag these operations before the consolidator is labelled, and before the next victim has finished depositing. The question is whether your scam-detection stack goes that deep.

*Names have been changed to protect participants' privacy. All wallets & timestamps are verifiable on-chain.

Research & Technical: Martín Jofré **Editorial: **Scott Mallen

*Chainlabs does not provide post-event investigation services. Instead, we provide preventative analytics and frameworks to prevent these scams from occurring in the first place.

Chainlabs Know who is behind crypto flows