View Reports
Submitted: 7 hours ago
Guest
Phishing Scam
Detection Summary The Anti-Phishing Volunteers & Associates Security Incident Response System has flagged this as a domain threat, classified as phishing attack against Atomic Wallet. Threat detected at 2026-09-11T09:37:25.697Z.
Submitted: 8 hours ago
Guest
Fake Project Investment Scam
The same individuals behind a failed platform have launched a new venture using similar tactics. XProtocol is indeed the new project created by the core team behind Finblox (including Peter Hoang and Dmitriy Paunin), using previous investment ties to advertise credibility while selling Node licenses and DePIN smartphones like XForge. After fund is raised, they are slowly abandoning the project. Phone was released 1 year later. TGE was delayed and still no update on it. Team is already moving out of social media. They have already opened another entity Xtrade and closed it, now they are venturing into Atli eSim. The Xprotocol project is basically dead and no support or update to the investors. And, I realised Xprotocol and Xtrade are basically copied from existing companies. It does feel like they are trying to confuse the investors.
Submitted: 8 hours ago
Guest
Other Fraud Scam
This is a formal report regarding an active online recruitment scam. The perpetrator utilizes a Facebook Messenger profile under the name 'Clarence hope lastrilla' to target job seekers. The scammer uses scripts disguised as fake part-time data-entry tasks to collect sensitive information. They instruct individuals to register on a malicious phishing domain (https://greenhills-shopping.shop?invite_code=KuEncs&tab=2) and demand that users submit screenshots of their created accounts. I am reporting this incident to request an immediate investigation into the fraudulent web domain and the profile involved before financial theft occurs."
Submitted: 8 hours ago
Guest
Other Hacking Scam
I received a physical, fraudulent letter via the U.S. Mail from an individual or entity impersonating the hardware wallet company, Ledger. The letter claimed that Ledger was updating its utilities and required action on my part. The letter contained a QR code instructing me to scan it and input my security data. Believing the correspondence to be legitimate corporate outreach stemming from my customer relationship with Ledger, I scanned the QR code and entered my data. Immediately upon doing so, my wallet was entirely drained of its assets. The physical letter and its mailing envelope remain in my possession as evidence. Additionally, I have preserved screen recordings of all subsequent transactions, destination wallet addresses, transaction hashes, and historical ledger movements associated with the perpetrator's addresses. Financial Loss Summary Asset Type: XRP (Ripple) Total Stolen Quantity: 50,721.658417 XRP Estimated Fiat Value: ~$68,100 USD Blockchain Identification Details Victim Wallet Address (My Account): rhoYgjb3BxdnuFqYUoeorkEFog9swkdNFD Perpetrator's Receiving Wallet Address: rBo9zHeV5viurHyahYX2iLTHcDBw8hf2xC Theft Transaction Hash (TxID): E994AD17D046494B647B4C531663AB5E3E68A83C90518DD67450347884B99CD7 On-chain analysis of the perpetrator’s address reveals a clear trail linking back to a custodial exchange, which may assist law enforcement in identifying the suspect: The criminal's receiving address (rBo9zHeV5viurHyahYX2iLTHcDBw8hf2xC) was created approximately two months ago. It was funded by an intermediary wallet address: rPGKib86uvXerhmyQ1o9Vf5M7EYHqG9e9c. That intermediary wallet was originally funded directly from a Crypto.com exchange wallet address: r4DymtkgUAh2wqRxVfdd3Xtswzim6eC6c5. The transaction hash for this specific exchange funding event is: 62119812CD704E6342BAD2A77E6E6746FB2F3BB55D63E13DCDDB36570EF3C84B.
Submitted: 10 hours ago
Guest
Phishing Scam
The PhishFort Detection System has flagged this as a domain threat, classified as null. Threat detected at 2026-09-11T07:16:11.211Z.
Submitted: 11 hours ago
Guest
Fake Project Investment Scam
KuCoin deposit address through which stolen funds entered the exchange. This is a follow-up to a previously reported cluster (same victim, same case). Victim is an elderly person in Croatia, defrauded via a fake UK-registered brokerage "FlexFlume Ltd" (flexflumeltd.net; related domain flexflume.com). Contacted daily by at least four Serbian/Montenegrin-speaking men from a rotating block of Croatian mobile numbers (+385 97 683 XXXX). Shown fabricated trading gains up to ~EUR 850,000 and a forged PDF, then asked to pay a further EUR 50,000 for a fake "trading licence" before withdrawal — an advance-fee demand that exposed the scam. Total loss approx. EUR 158,100 (July–August 2026). Fund flow (ETH portion, 22.4 ETH / EUR 50,000 paid in cash at a Croatian exchange counter): 0x16cDA3E7463B8F05f12Eed0ec617183D8B2F4293 → 0x4713C5a2D5Bb60bB7E1D9B9cA5535cbf161D910E → 0x9A644fb6F01A43db3496bBbce0505F2F7874e4f4 (consolidation wallet, spiked to ~155 ETH from multiple sources) → 0x04C9D0d6B3D3432722043b4fac336aB3e4fc9e17 → this KuCoin deposit address. Deposit occurred 11 Sep 2026, 05:53 UTC. TXID: 0xfd716157cf4e48a68d9d5e164a9a378c95db62ab33f2b5263c4ab978de0f1120. Amount 23.55 ETH (~USD 58,000). Note: this address is part of KuCoin infrastructure and carries very high transaction volume; not all activity is related to this case. It is reported because stolen victim funds were deposited here and it maps to a KuCoin account with KYC data: 0xbb2A25A0918290C501f793eD12425b3B0854295A
Submitted: 11 hours ago
Guest
Phishing Scam
The PhishFort Detection System has flagged this as a domain threat, classified as null. Threat detected at 2026-09-11T06:26:02.932Z.
Submitted: 12 hours ago
Guest
Pig Butchering Scam
Chainabuse Report Incident Type: Investment Scam / Advance-Fee Fraud / Cryptocurrency Fraud Description I am a 63-year-old senior citizen and believe I was the victim of a cryptocurrency investment fraud involving Alpha Stock Investment Training Center and Coinbridge Partners Ltd. In February 2025, I entered a 90-day investment training agreement with Alpha Stock Investment Training Center. The program provided online investment classes and cryptocurrency trading signals through a training assistant identified as Quinn Sanderson. Participants were instructed to transfer funds into the Coinbridge platform for cryptocurrency contract trading. Between February and May 2025, I transferred approximately $467,084.17 from my checking account through Coinbase and into Coinbridge accounts for investment purposes. At the conclusion of the program, Coinbridge represented that my account balance had grown to approximately $3,098,711.50. Before permitting withdrawal, I was required to pay a commission of $338,963, which I paid in full. After payment of the commission, I initiated a withdrawal of $2,861,113.27 to my Trust Wallet: 0x4B3441b11B3be6263b25becad938d5142CBA521B The withdrawal was never completed. I contacted Coinbridge customer service and was informed that I was required to pay additional "gas fees" totaling $63,180.75 before my funds could be released. This requirement was not disclosed in the investment agreement. I was instructed to send the gas fees to the following address: USDC Base Wallet 0x51f21d3ced26eb0d691826404a3384ba409149dd I paid the requested amount in three separate transactions. After payment, the withdrawal still did not occur. Coinbridge representatives then claimed that my wallet address had been altered by a hacker and changed from: 0x4B3441b11B3be6263b25becad938d5142CBA521B to 0x4B3441b11B3be6263b25becad938d5142CBA521BV The representatives stated that this alleged alteration prevented delivery of my funds. On June 26, 2025, Coinbridge customer service demanded an additional $20,000 "hacker recovery fee" to be sent to: USDC ERC-20 Wallet 0xb69f6083f40ca2c82606e4cc0085464f3e55d434 I refused to pay the additional fee. Since refusing to pay, Coinbridge has continued to block all withdrawal requests and has not released any of my funds, cryptocurrency, or account balances. I also have approximately 40.96967449 ETH reportedly held in Coinbridge custody that I cannot access. I believe this operation used false investment profits and repeated demands for additional payments to prevent withdrawal of funds and induce further transfers from victims. Associated Wallet Addresses Intended withdrawal address: 0x4B3441b11B3be6263b25becad938d5142CBA521B Allegedly altered address: 0x4B3441b11B3be6263b25becad938d5142CBA521BV Gas fee wallet: 0x51f21d3ced26eb0d691826404a3384ba409149dd Recovery fee wallet: 0xb69f6083f40ca2c82606e4cc0085464f3e55d434 Estimated Loss Initial investment deposits: $467,084.17 Commission payment: $338,963.00 Gas fee payments: $63,180.75 Additional inaccessible crypto assets: 40.96967449 ETH Total direct losses exceed $870,000, with reported account balances and digital assets remaining inaccessible. Requested Action I request that blockchain investigators, exchanges, compliance teams, and law enforcement review and trace the wallet addresses identified above, identify any connected entities or exchange accounts, and assist with recovery efforts where possible.
Submitted: 12 hours ago
Guest
Other Hacking Scam
I am reporting this address 0x5723168bfdf49d832b3a09fd028c3b03ec7bfd52 as the recipient of funds stolen from my wallet, not as a confirmed phishing website. My wallet: 0x9e66504a892fa84705c24a4bd41e67b6be581c65 (prostoxleb.eth). On 9 September 2026 at 05:12:59 UTC, 58.044144 USDT was transferred from my wallet to the reported address without my authorization. Transaction: https://etherscan.io/tx/0xf680de61175b2b14b58d7f04685a30ba92f0da19caabbcd958b4b27d2460b249 The method of compromise and the identity of the operator are unknown. Please review the transaction and consider flagging the recipient address. There also drain cases in other chains. Total lose 1500$+
Submitted: 13 hours ago
Guest
Sextortion Scam
This information about this scmaer Telegram is 8466793910
Submitted: 13 hours ago
Guest
Other Fraud Scam
I am not a victim and lost no money. I placed a test order to document the payment mechanism and did not pay. I am reporting a network of fraudulent online tobacco stores and the cryptocurrency addresses they use to collect payment. WEBSITES heat-tobacco.com tobaccobase.com cigsmoker.com cigarettesroad.com COLLECTION ADDRESSES USDT (TRC20): TC27nGjYFbxRehEQAojRBT8HTkdh1wEZ6R Bitcoin: 1P7WEgF8sZmcQ7cwiUNSV8gdP57XrYZzJv The BTC address has received 0.12697152 BTC across 161 transactions and holds a zero balance; funds are swept immediately on receipt. The TRC20 address shows 477 transactions and 373 token transfers with a near-zero balance. Outgoing USDT is sent to TDqSquXBgUCLYvYC4XZgrprLK589dkhSCf, which appears to be a Binance deposit address. Outgoing BTC is sent to bc1qgzrva028eym96uax90j28qj3aqhh3dy8gk6qvp. HOW THE FRAUD WORKS The sites sell cigarettes, IQOS and HEETS products and nicotine pouches at prices far below any lawful retail level. Until recently the published payment policy accepted only two methods: Amazon eGift Card codes, which buyers were told to email to the operator, and cryptocurrency. The gift card option has since been removed from checkout, leaving cryptocurrency as the only method. No card, PayPal or any other reversible payment method is offered. tobaccobase.com states in its payment policy that a reduced risk of payment disputes and chargebacks is a benefit of the payment method it requires. All four sites claim falsely that Visa, Mastercard and PayPal prohibit online tobacco payments industry-wide, in order to present the absence of reversible payment as an external constraint. On 10 September 2026 I placed test order #60786 on heat-tobacco.com for CAD 974.99 using fictitious details and made no payment. The order confirmation page returned the two wallet addresses above with instructions to send the exact amount and supply a transaction ID. The order is described as reserved for 24 hours pending payment. Public complaints describe buyers who paid and received no goods, in several cases after being sent tracking numbers matching no real shipment. FALSIFIED LICENSING The sites display scanned tobacco licences from 33 U.S. states presented as their own. Three that I examined in full (Arkansas permit #22890-01, New York certificate 88-3729738, Wisconsin account 411-1031149993-02) are all issued to LA Vapor Wholesale Inc, 8725 Golden Spike Ln, Houston TX 77086, a company with no apparent connection to these sites. Two of the three permits had already expired and all state that they are non-transferable. The pages invite visitors to verify the licences at ttb.gov and cdtfa.ca.gov, neither of which issued them. I have notified the company and Arkansas Tobacco Control. SINGLE OPERATOR All four domains publish an identical Brevo account verification record in their DNS TXT data (brevo-code:0504db1c71325643d8d64ea9ec9b19a0), route mail through the same provider, use the same nameserver pair, and are registered through the same registrar. Three are hosted on the same autonomous system, AS213373. I can provide screenshots, archived page copies and full technical records on request.
Submitted: 13 hours ago
Guest
Phishing Scam
I made a post on x.com about how I'd been scammed in the past, that my computer was infected with malware and all of my wallets were drained which amounted to over $6,000 stolen. I was contacted by a user who saw my post and said that they can help me recover my funds. I played along because I know that money is long gone. They then transferred 6,503 USDT from this wallet address: 0x5c3794cfE79982A30225D51254a969a64AB9bF4f to my BNB address that they requested to send the funds to: 0x8837Af23FFB59b5899DE40028941FCF25EFD345e. The token contract of the 'USDT' that was sent to me is: 0x34358D56F88d553c8A86e61ebd14baEb099A8888. I looked up the token address on bscscan.com and it says "This token has been reported for impersonating well-known cryptocurrencies. Please exercise caution when interacting with it." I was using Trust Wallet and it said something similar, "Risk -This token is a counterfeit of a mainstream asset, imitating an authentic token." I told them that the token they sent wasn't authentic and to send the funds using the correct token address (USDC): 0x8965349fb649A33a30cbFDa057D8eC2C48AbE2A2 - they then transferred another 6,552 of the same fraudulent USDT and instructed me to "1. Kindly go to blockchaintech-omega.vercel.app/recovery 2. Click Validation 3. Select TrustWallet: 4. Establish a connection 5. Proceed to validate" Which is a phishing website, but insisted I needed to "validate my wallet" to receive the funds. I told him I have 10k in another account in my Trust Wallet and changed his tune and said that it's going to cost me to receive my stolen crypto (that he "recovered" magically).
Submitted: 16 hours ago
Guest
Investment Scam
I sent several transfers to the recipient's address under the pretext that I was paying a withdrawal code fee, a release fee, and unfortunately they turned out to be fraudsters to whom I sent a lot of money, with the amount of 550 euros being a withdrawn credit. I ask for your help in recovering the amounts.
Submitted: 16 hours ago
Guest
Phishing Scam
The PhishFort Detection System has flagged this as a domain threat, classified as null. Threat detected at 2026-09-11T00:38:43.128Z.
Submitted: 16 hours ago
Guest
Impersonation Scam
Phishing: credential harvesting, impersonation, impersonating CoinGecko
