Newsroom
15 September, 2026 / News / AI / Tags: usdt, victim, telegram, compromised, trader

Scammers impersonated a business partner via a compromised Telegram account, prompting a large USDT transfer after a successful test payment
A cryptocurrency trader transferred approximately $2.1 million in USDT after falling victim to a social engineering scheme that involved the hijacking of a business partner’s Telegram account. On-chain investigator VAL outlined the incident in a detailed post, describing how the attackers gained the victim’s trust through the compromised channel.
The victim initially sent a small test transfer of $10 in USDT to verify the recipient. After receiving confirmation from the compromised Telegram account, the trader proceeded with a much larger payment of 2,151,772 USDT. The following morning, the attackers deleted the entire conversation and ceased all further communication.
Investigators determined that the stolen USDT was quickly moved to a secondary wallet. From there, a portion of the funds was converted into TRX and directed toward deposit addresses associated with the MaskEX platform. Blockchain analysis later allowed researchers to track roughly half of the total amount through subsequent withdrawal activity.
Six days after the theft, Tether froze a wallet holding about $1 million of the stolen USDT. The freeze occurred on October 29, and those funds remain locked while the victim continues efforts to recover them.
Using timing analysis of blockchain transactions, investigators identified another wallet believed to hold the remaining portion of the funds. That address has shown no activity for two months. Researchers combined transaction records with exchange data to map the movement of the assets after the initial transfer.
The case illustrates the risks associated with social engineering attacks that exploit trusted communication channels in the cryptocurrency sector. Details of the fund movements continue to be examined through available on-chain evidence.









