Odaily & Bitrace Joint Production: Full Breakdown of Cryptocurrency Money Laundering Chains in Southeast Asia Scam Parks

CN
3 hours ago

Original | Odaily Planet Daily (@OdailyChina)

Author | Wenser (@wenser 2010)

When mentioning Southeast Asia, many people's first reaction is islands and cuisine. However, beneath the surface, another "folded Southeast Asia" is operating at high speed — scam parks, human trafficking, online gambling, money laundering, forming a vast underground crime network.

This network can continue to operate thanks to a complete payment and settlement system. After traditional banking channels are blocked by regulatory authorities in various countries, cryptocurrencies, especially USDT, have become the core means of payment and value carrier in Southeast Asian criminal activities. From human trafficking to fraud distribution, from technical service procurement to fund laundering and cashing out, almost every link is settled using USDT.

Based on the relevant crime research and firsthand real cases conducted by the blockchain security team Bitrace, Odaily Planet Daily will detail the complete operational chain of the Southeast Asian crypto black and gray industry in this article, and accordingly organize five actionable anti-fraud guidelines for readers' reference.

May the light dispel the darkness in the corners.

The Assembly Line Hidden in Dark Corners: A Crime Map of Southeast Asia

According to Bitrace's long-term tracking investigation, organized crime in Southeast Asia has become highly industrialized and streamlined. From personnel recruitment, information collection, website construction, to traffic generation, deceptive speech, and fund laundering, each link has professional service providers and clear divisions of labor. Various cryptocurrency escrow platforms act like “dark versions of Amazon platforms,” aggregating these scattered criminal resources, providing credit endorsement and transaction matchmaking to reap huge profits.

Next, we will take the most typical “pig-butchering” scam as an example to break down the many links on this "industrial assembly line."

The Three Elements of the Criminal Chain: People, Information, and Tools

Human trafficking is the starting point of the entire criminal chain. The gray and black industry parks in Southeast Asia require a large workforce to engage in illegal activities such as scams and gambling customer service. Around this demand, a human trafficking chain has gradually formed from recruitment, transportation, to delivery.

On Telegram, such transactions are publicly conducted in the name of “labor services.” A group called “XXX Group Direct Recruitment” has nearly 5000 members, with prices openly listed: amounts range from several thousand USDT to over ten thousand USDT. Here, gender and age are irrelevant; individuals are valued solely by money, serving as part of the transaction chips.

Human trafficking groups openly quote prices, categorized by “quality” (Source: Bitrace research screenshot)

Transaction methods are usually divided into three categories:

  • “Bare-naked” transactions, where the intermediary directly delivers people to overseas merchants, and the merchant pays the intermediary's address;
  • Escrow transactions, where the buyer first deposits USDT into an illegal escrow platform, and after personnel delivery is completed, the platform releases funds and collects a commission;
  • “Second-hand” transactions, where human trafficking merchants resell again.

USDT plays the role of cross-border payment, while the escrow platform is responsible for credit endorsement and fund custody.

Once there are individuals, the next step is to acquire target information.

The black and gray industry refers to the illegal acquisition of citizens' private information as “checking files.” After receiving USDT from clients, practitioners assign query tasks to individuals with permission in internal systems such as public security, courts, banks, express delivery, and telecom operators, who illegally retrieve specific individuals' household registration, marital status, educational records, medical records, assets, and whereabouts information, returning it to the fraud group.

Bitrace's research data shows that a Telegram public group named “XXX Check Files” has over 3000 members, openly listing the types of queries available, ranging from personal household registration, family household registration, and marital records to company information such as company records, invoices, business licenses, corporate bank statements, company employees and salaries, company-owned properties, and even vehicle information like highway records, vehicle trajectories, and parking lot monitoring.

Illegal file-checking public group openly lists business categories, covering numerous types of information across individuals, companies, and vehicles (Source: Bitrace research screenshot)

Transaction records within the group show that the cost for a single file check ranges from dozens to hundreds of USDT, with order completion times of 1 to 2 days, and acceptance criteria stating “authenticity guaranteed without omissions.” These private information ultimately are used for precise scams — fraudsters, armed with the victim's true identity, family situation, and asset status, can tailor deception scripts to achieve targeted fraud.

Later, the tool preparation aspect is also highly industrialized. Fraud groups do not need to develop corresponding scam websites and fake trading applications themselves; specialized technical service providers undertake customization needs in the escrow platform's public groups. A certain “APP Development/Platform Construction Public Group” openly sells high-fidelity exchange source code: DAPP high-fidelity exchange OKX multilingual version, front-end React 18, back-end Java, fully open-source and can be modified, supporting forex, commodities, indices, stocks, spot, options, various contracts, online follow trading, NFT digital collections and even added features for DeFi lending and locked coin earning; another DAPP exchange supports multiple languages, front-end developed in Vue, includes a simulated account operation mode, contract trading, perpetual contracts, U-based contracts, forex contracts, spot trading, and more. These interfaces and functionalities closely resemble those of genuine official applications, making it difficult for ordinary users to distinguish them, and many seasoned individuals in the field might not even recognize the difference.

Technical service providers offer “customized professional services” (Source: Bitrace research screenshot)

Furthermore, when fraud groups specify target markets, fake identities, investment projects, deposit methods, and other requests, technical service providers can create counterfeit investment platforms, fake trading interfaces, or application download pages based on that, connecting to cryptocurrency payment addresses controlled by the crime groups. All related services are settled using USDT, with the escrow platform acting as a “banking system + payment system + neutral intermediary.”

Crime in Progress: From Traffic Generation to Precision Chatting

Once the tools are ready, the fraud groups will reach out to targets through traffic generation.

In cross-border fraud, “mobile entry” is the most commonly used means of voice transfer. Because overseas scammers dialing domestic numbers directly show overseas numbers, which increases victims' vigilance; mobile entry provides a convenient door for scammers. The specific method is that fraud groups use two phones connected via an audio cable, one connecting to overseas scammers through internet software, and the other inserting a domestic SIM card to call the victim, achieving real-time audio transfer—ultimately realizing the effect of “overseas scammers directly talking to the victim, but the call displays as a local number.”

The “cannon fodder” (sometimes referred to as “cannon shooters”) involved in mobile entry business usually consists of a mixed crowd and is dispersed nationwide, making it difficult to effectively crack down. The group rules for a certain “mobile entry public group” mention: video calls must be conducted for verification, with payment only after reaching at least 20 minutes, and any detected fakes will have their contracts terminated. Recruitment advertisements indicate that mobile entries from the three major telecom operators are uniformly charged 300 USDT, with breakfast provided for those who connect before 11 AM, including "lotus flowers" (euphemism for cigarettes), private arrangements for red envelopes after work, adding 5 USDT for 30 minutes, 10 USDT for 60 minutes, and 15 USDT for 100 minutes. Through an intricate collaboration of domestic and overseas gangs, fraud teams weave a web of scams.

Mobile entry public group's recruitment information (Source: Bitrace research screenshot)

In addition to mobile entry, traffic generation also has more systematic methodologies. A certain “Labor Speech” Telegram channel categorizes information into three types, with main channels including social media, online games, and online advertising. Fraud groups set traps according to populations and their alertness, making it difficult for them to guard against.

Training for traffic generation scripts channel screenshot (Source: Bitrace research screenshot)

After traffic generation, crime proceeds to the “precision chatting” stage. In this phase, fraud groups often target victims with sophisticated scripts, image materials, and forged videos, even including script writing, persona creation, and arranging conversations; as these processes require a large amount of scenic photos, character images, and copywriting as support, relevant service providers have also emerged to sell related “materials,” with beautiful men and women images from various countries available. With the explosive growth of AI deep forgery technology, many AI models have been used for script writing, photo material generation, further lowering the technical implementation threshold for fraud precision chatting.

Precision chatting material channel screenshot (Source: Bitrace research screenshot)

The Final Chapter of Crime: Turning Fraud Funds into Crypto Black U

After successfully scamming, fraud groups often quickly launder funds to evade law enforcement tracking.

The currently popular method is called “card connecting back to U,” which converts the defrauded funds into USDT. Depending on the levels of laundering transfer, this link is usually divided into “first-level” and “second-level.” The former refers to where public groups directly take in the dirty money through bank cards, such as direct transfers from victims or funds from soon-to-crash pyramid schemes; money laundering personnel quickly purchase USDT with this money and return part of it as a reward to the upstream criminal group, with the difference being the profit for the public group; the latter is the subsequent step of the former: after a first-level public group receives the dirty money, the next transfer target is a second-level public group, which is typically anonymous OTC merchants. Compared to providing cashing services for regular investors, helping money laundering groups transfer funds yields more lucrative profits, leading many OTC merchants down this irreversible path.

Thus, a sum of money transferred from the victim's bank card, after being laundered through the layers of first-level and second-level connections back to U, ultimately transforms into USDT that is difficult for law enforcement to trace, nourishing this large parasitic machine of criminal groups.

When Stablecoins Become the Circulatory Blood of Criminal Networks

In the entire criminal chain, cryptocurrency escrow platforms are the hubs connecting upstream and downstream.

Many platforms establish a vast number of “public groups” through Telegram, with upstream gathering technical service providers and material suppliers, midstream renting out to escrow merchants for scams, gambling, human trafficking, and other businesses, while downstream aggregates cashing, OTC, money laundering, and payment services. The platforms reduce the trust costs for unfamiliar trading parties through entry audits, deposits, and brand endorsements. Strictly speaking, they might not directly commit crimes but serve criminal groups, thus becoming accessories and breeding grounds for criminal activities.

The current pattern of escrow platforms has formed an oligopoly. Despite the closure of the Tu Dou Escrow under Huawang Group at the beginning of 2026, the illegal cryptocurrency trading escrow industry has not disappeared but has shifted to competitors such as New Coin Escrow and Dali Escrow. In the first half of 2026, over 3.4 billion USDT flowed into escrow platform addresses, including both deposits and monthly rents from escrow merchants and specific group deposits from ordinary traders, with over 90% of income relating to new coin escrow.

Even more appalling is that these black and gray industry platforms have begun to infiltrate domestic internet platform content.

When searching for a leading escrow platform on a short video platform, you can see a lot of related content: besides platform introductions, there are brainwashing copy using phrases like “In this society, no one cares what job you do, as long as you do well, if you can get money out when it matters, you're great.” These toxic viewpoints promote blurred criminal boundaries, leading some users to declare statements like “It's not us who are guilty, but this money-driven society,” trying to clear their connotations.

Search results on a short video platform (Source: Bitrace research screenshot)

Some black and gray industry entities will also invite domestic online celebrities for marketing promotions. A certain escrow platform openly announces in a Telegram group, “All network millions of fans' Brother X passionately endorses,” and even uses “Brother X will come to the group to perform later” as a gimmick to attract traffic. It is reported that this blogger is an abstract internet celebrity whose memes circulate widely in the black and gray market communities. Whether this internet celebrity genuinely collaborates with the fraud group or if it is the latter's forged material remains unknown for now.

Escrow platform utilizes celebrity videos for promotion (Source: Bitrace research screenshot)

The initial intent of blockchain and cryptocurrencies is to build decentralized and trustworthy financial infrastructure, yet in Southeast Asia's criminal network, the cross-border payment capability, anonymity, and difficulty in timely freezing of USDT have been exploited by fraud groups to provide settlement services for serious crimes like human trafficking, fraud, and money laundering.

When a top escrow platform collapses, relevant merchants can swiftly migrate to other platforms to continue their operations, forming a relatively independent yet easily disassembled and recombined relationship between the platform, public groups, merchants, and payment tools, making it extremely difficult for law enforcement to crack down on.

In just the first half of 2026, the inflow of funds to major escrow platforms amounted to 3.4 billion dollars; behind these figures lie countless scammed families, ordinary individuals who were trafficked, and lives ruined by fraud.

Two Real Fraud Cases: Fake Mining Pool Arbitrage and Fake DAPP Pig-Butchering

Apart from the above cases, there are countless fraud techniques related to cryptocurrency; here we will briefly introduce two real stories investigated by Bitrace.

Case One: Fake Exchange Mining Pool Arbitrage Fraud

This is an old trick with extremely low costs aimed specifically at beginners. Scammers impersonate official groups of major exchanges using bots, under the guise of “exchange rewards for users,” they require potential victims to transfer ETH to specific contract addresses, claiming to return excess BNB. In reality, the BNB returned by the scammers is fake; the main aim is to defraud victims of their real ETH. The following image is a screenshot of a fraud group provided by a victim, where multiple group members are actually part of the scam group.

Numerous pawns performing in the fraud community (Source: Bitrace research screenshot)

Previously, Bitrace had concentrated on helping a batch of victims from such scams in 2022, with defrauded amounts ranging from tens of thousands to hundreds of thousands of dollars; as of November 2025, there were still victims in the group asking about the follow-up progress, but ultimately, due to tracking difficulties and the time span, the case came to a dead end.

Even the simplest fraud techniques can cause significant losses when combined with the anonymity and cross-border characteristics of cryptocurrencies, while the chances of recovery are extremely low.

Case Two: Fake DAPP Pig-Butchering Fraud

At the end of 2024, a victim accessed a website called orcaen, which imitated the front end of Orca Dex, falsely claiming to offer high returns. The victim mistakenly believed that accessing funds via a certain exchange wallet ensured security, thus investing several thousand USDT in “arbitrage”; later, when attempting to withdraw funds, the customer service refused, and the victim finally realized they had been scammed.

This fake DAPP interface was made quite convincingly: the homepage categorizes cryptocurrencies, forex, stocks, precious metals, and energy, displaying real-time prices and K-line charts for BTC, ETH, and other coins, with “buy up” and “buy down” buttons, and at the bottom, navigational bars for homepage, trading, assets, records, and functions like recharge, withdrawal, transfer, and records, alongside a profit trend chart, but the funds were “gone without a trace.”

Homepage interface of the fake DAPP (Source: screenshot provided by the victim)

This is a classic bait-and-switch tactic: first allowing the victim to see “profits” reflected in account numbers, then setting various hurdles when attempting to withdraw—such as requiring a certain trading volume, needing to pay margins, or personal income tax—to lure the victim to continue funneling funds until they realize they can't withdraw. Bitrace's tracking investigation found that the victim's funds ultimately flowed into Huawang Payment under the Prince Group for laundering; at that time, Huawang's escrow platform was still active, and once funds entered that network, it was as good as lost.

Bitrace's fund flow tracking diagram (Source: Bitrace tracking report)

Five Anti-Fraud Guidelines for Ordinary People

After dissecting the criminal chain and real cases, ordinary individuals need to pay attention to the following five points:

First, be wary of all “online income” activities involving bank cards, phone cards, and cryptocurrency. Law enforcement agencies in various countries have implemented full-chain monitoring of the telecom fraud industry, with runners, drivers, card dealers, security personnel, traffic generators at the bottom of the chain often being arrested. Any activity, claiming to be offering pocket money, stay-at-home mom allowances, or student part-time jobs, that requests bank cards, phone cards, or aids in transferring cryptocurrency is recruiting “cannon fodder.” Do not cross the legal bottom line, nor harbor the deluded mindset of “I am just helping with a transfer.”

Second, protect personal information and reduce exposure. Personal information is a critical preparatory material for the fraud industry. When using various applications, you should minimize exposure of personal information, including facial recognition, phone numbers, blockchain addresses, physical addresses, and duplicate nicknames across platforms. Do not upload sensitive information, such as ID cards and bank cards, on untrustworthy platforms, nor click unknown links to fill out personal information. When sharing lifestyle photos on social media, be cautious not to expose your home address, workplace, frequented locations, and other information.

Third, recognize the typical features of pig-butchering scams. The core routine of a pig-butchering scheme is: establish connections through social platforms or games → create personas of high-income individuals → cultivate emotional trust → introduce “risk-free” investment opportunities → small rebates to build trust → induce large investments → refuse withdrawal under various pretenses. If you encounter the following situations, be highly cautious: the other party claims to be working overseas, engaging in financial investments, or possessing insider information; recommends downloading apps from unofficial app stores or visiting unfamiliar websites for investments; the investment platform's customer service denies withdrawals citing “insufficient trading volume,” “need to pay margin,” or “need to pay personal income tax;” the other party urges you to increase your investments, saying “if you miss this opportunity, it won't come again.” These are all tricks scammers use to exploit loss aversion psychology to ensnare you.

Fourth, use legitimate platforms for cryptocurrency investments. Do not download unknown trading apps recommended by “signal providers” in Telegram groups or WeChat groups, nor visit websites that imitate exchange domains. The domain names of legitimate exchanges are usually simple and unique, whereas counterfeit sites often play tricks on the name, such as using “orcaen.cc” to imitate “orca.” Before connecting a Web3 wallet for trading, carefully verify the website's domain and contract address before blindly authorizing. You can use reliable AI tools to assist in detecting contract code risks, verifying website domain authenticity, and differentiating fraud techniques, making AI your first line of defense.

Fifth, be wary of invisible traps around you. The promotion of black and gray industries has permeated daily online life. Searching certain keywords on Douyin might yield black and gray industry content, internet celebrities might unknowingly or knowingly endorse such industries, “online partners” in online games might be traffic-generating scammers, and “high-paying overseas jobs” on job recruitment sites could be bait for human trafficking. When you see claims like “earn 100,000 a month,” “easy money,” “internal channels,” or “high returns guaranteed,” do not get carried away; stop and think: if these opportunities were genuine, why would they come to you?

The scale of the Southeast Asian crypto black and gray industry continues to expand, and the technological means are still evolving. As ordinary people, what we can do is understand the operational logic, stay alert, not be greedy for small benefits, not harbor delusions, and stay away from traps, and may more people take this as a warning to avoid falling victim to scams.

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink