Skip to content

Latest commit

 

History

5 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 

Repository files navigation

The "TGR Exchange" Case: How This Crypto Cash-Out Scam Works

What this is, in plain terms

Someone sees an ad on Instagram or Facebook offering to buy their crypto for cash, with fast delivery and a bonus rate. They message the contact on Telegram, send their USDT first as instructed — and receive nothing back. That's the whole trick. This repository documents one real, ongoing instance of it, traced from a single public victim report all the way down to the wallet infrastructure moving the stolen money, the advertising campaign that lures new victims, and an attempt to identify who's behind it.

Everything here comes from public sources — a public scam report, public blockchain data, Meta's own public Ad Library, WHOIS records, and the U.S. Treasury's own public sanctions list. No hacking, no private data, no unauthorized access of any kind.

A note on how to read this report: every substantive claim below is tagged with a confidence level — CONFIRMED (directly reproducible from raw primary-source data included in this repo), HIGH (the underlying fact is confirmed, but the interpretation involves a reasonable inference), MODERATE (a heuristic judgment call, reasonable but not certain), or LOW/SPECULATIVE (a working hypothesis, flagged as such). The full definitions and a complete FATF-typology risk breakdown are in evidence/04_risk_scoring/fatf_redflag_matrix.md. Every evidence file's integrity can be independently verified against MANIFEST.sha256 — see MANIFEST.md.

Source complaint

This investigation originates from a single report submitted to Chainabuse (category: Investment Scams), titled "Suspected Crypto Scam – TGR Exchange / Telegram @tgr_manager – 1,398 USDT" (report ID 242885b0-33b2-4b07-9109-1d624803c8ef, submitted anonymously, filed 24 August 2026).

The complainant reported being directed to tgrexchange.site via an Instagram/Meta advertisement shown on Instagram Stories, then contacted on Telegram by an account presenting itself as "TGR Manager" (@tgr_manager, Telegram ID 8146193156, whose username/display name had been changed on 30 June 2026). Meta's own Ad Library disclosed, in connection with that advertisement, Advertiser ID 1089516814244665, Pixel ID 1631755732283948, Ad ID 120248243203260575, Ad Set ID 120248243203240575, and Campaign ID 120248243203220575.

On instruction from the Telegram contact, the complainant sent USDT (ERC-20) to 0xbCCFD2d86E0D55073253ab0f332f3A2Cda59d42E, which the complainant then observed forwarding to 0x63961c584CbF782d8d0BA132c0FDCeE7eb18468e in transaction 0x33d52f005da7a8017f58b1ed133d9c771428a5c3a44d7a9633d9e9486c476db6 (21 August 2026, 14:54:35 UTC, block 25804238), noting that the transaction used ERC-4337 account-abstraction infrastructure (a Pimlico bundler and EntryPoint 0.7.0). Total loss was recorded as 1,400.32 USDT and 1,398 USDT. The complainant separately observed four further transfers out of 0x63961c584CbF782d8d0BA132c0FDCeE7eb18468e on 24 August 2026, plus a small transfer to an address the complaint flagged as notable for reappearing from the original transaction — and, as an unconfirmed possible lead, a Facebook profile linking to a redirect domain (az.birplay.site) with tracking parameters. The complainant asked that the addresses and domain be checked against known exchanges, bridges, and other services, and that the trail be preserved given the funds were actively moving.

Every fact from that original report has been independently re-derived from the raw blockchain record in this repository (evidence/01_raw_onchain/) rather than taken on trust, and the fund-flow trail below extends further in both directions than the original report covered.

Fund-flow chain

Every address and amount below is exact and independently verifiable on Etherscan; the diagram at evidence/scheme_diagram_en.png shows the same chain visually.

0x26352d20e6a05e04a1ecc75d4a43ae9989272621  --  995.316487 USDT  --\
0xd47a1bdc6872ad2fd16e50149baa9924c653e624  --  373.000000 USDT  --+--> 0x3aca4c754fc517d17e39bee823f55575fcb1f059
0xcdd5363e8a4ca645e5ab734168e36a3bd980a0df  --   32.000000 USDT  --/         (consolidates to 1,400.316487 USDT)
                                                                                        |
                                                                    1,400.316487 USDT   | tx 0xd9849201c36e3b4a417e12064fd6f3adc23750e7840d1b48f910e8810b7247ae
                                                                                        v
                                                              0xbCCFD2d86E0D55073253ab0f332f3A2Cda59d42E
                                                                                        |
                                                     tx 0x33d52f005da7a8017f58b1ed133d9c771428a5c3a44d7a9633d9e9486c476db6 (21 Aug 2026, 14:54:35 UTC)
                                                              /-------------------------+-------------------------\
                                              1,398.000000 USDT                                          1.064404 USDT
                                                            v                                                       v
                                    0x63961c584CbF782d8d0BA132c0FDCeE7eb18468e                0x4b742ad5Ca91969e82AeFB80072AE59121a3d72A
                                                            |                                        (the shared fee hub, see below)
                                              (24 August 2026, splits five ways)                             ^
                       /----------------------+----------------------+----------------------\               |
                37.11 USDT              6.11 USDT              80.02 USDT            31.92 USDT       0.826234 USDT
                      v                      v                       v                      v                |
        0xdc8cA437B104C41888250aD9832d44A6294bB3C0  0xBDF263fd97d6d9C1E51f546bd1eE6E848d17fC7D  0x72F65Bd189833134d5F72A32f4B9C5ED862Cef4f  0xB096fA7b43865A00994C52dF3d2E8D5D55009cC4  ------/

The three addresses feeding 0x3aca4c754fc517d17e39bee823f55575fcb1f059 are substantial, active wallets in their own right (46.9 ETH and 158.25 ETH currently held by two of them, with 10,000+ transactions each — Etherscan's API pagination limit), consistent with being the complainant's own other wallets or exchange-withdrawal addresses rather than scam infrastructure. 0x63961c584CbF782d8d0BA132c0FDCeE7eb18468e received a total of 51 transactions from 16 distinct senders over roughly three months — this specific victim's payment is one of several. The fee hub receives a comparable small skim from both 0xbCCFD2d86E0D55073253ab0f332f3A2Cda59d42E and 0x63961c584CbF782d8d0BA132c0FDCeE7eb18468e, and — separately from this case — from 5,897 other addresses in a single ~24-hour sample of its history alone; see the Key findings below for what that hub is and is not evidence of.

The scam, step by step

Instagram/Facebook ad              Bait website             Telegram                Theft
  (geo + demographic       -->   tgrexchange.site   -->   @tgr_manager     -->   USDT is sent,
   targeting)                    "Swap USDT for            "USDT swap              nothing comes
  Tallinn / Paphos /              cash, +2.8%               manager"                back
  Larnaca / Limassol /            bonus, courier
  Benidorm; men 25-54,            delivery"
  Russian + Ukrainian ads
  running in parallel
  1. Paid, targeted social media advertising. Instagram/Facebook ads, geo- and demographically targeted (specific cities, mostly men aged 25-54), running in both Russian and Ukrainian. The pitch: exchange USDT for cash, courier delivery, a 2.8% bonus rate.
  2. The ad links to tgrexchange.site — a landing page that only serves real content to "qualified" visitors (it returns a blanket 403 to bots, scanners, and direct visits — classic cloaking to dodge researchers and automated takedown tools).
  3. The site funnels people into Telegram, to @tgr_manager ("USDT swap manager") — this is where the actual scam happens: the victim is asked to send USDT first, and the promised cash never arrives.
  4. The stolen funds move through a short chain of pass-through wallets and land in a shared fee-collection hub that skims a small cut off thousands of other, unrelated wallets too — meaning this hub is shared underlying infrastructure serving many parallel scam operations, not something built exclusively for the "TGR" brand.

The advertising itself is bought through a grey-market affiliate (CPA) network — the same ad accounts and redirect domains involved here are also used to push completely unrelated offers (I caught one redirecting to a fake mobile-game download page), so this isn't dedicated infrastructure either — it's traffic bought wholesale and pointed at whatever offer is paying that week.

Estimated number of victims

Rough estimate: on the order of 50-200 victims for the observed period (July 2026 – present), from two independent approaches that landed in the same ballpark:

Method 1 — from the transactions. One single collector wallet (likely one of several running in parallel, one per city/language) received payments from 16 distinct senders over ~2.5 months (10 June – 21 August 2026). Scaling that up across the ≥5 known target cities and 2 languages gives a rough estimate of 80-160 victims.

Method 2 — from ad reach. The disclosed reach of a single ad instance (Tallinn) was 12,887 unique accounts. The campaign ran roughly 64 separate ad instances across ≥5 cities over ~5 weeks. Applying typical conversion rates for this kind of lure (ad view -> click -> Telegram contact -> actually sending money, on the order of a few hundredths of a percent of reach) converges on a similar low tens to low hundreds of victims.

Both methods are rough order-of-magnitude estimates, not precise counts — but they agree on scale: this is low hundreds of victims specifically for the "TGR Exchange" brand, not thousands. (The shared fee hub processes far more transactions than that, but those reflect the broader shady ecosystem it serves, not victims of this specific scheme.)

Key findings

  • CONFIRMED — Full fund-flow chain mapped from the victim's payment through a collector, four pass-through wallets, and into a shared fee hub (see evidence/scheme_diagram_en.png, a diagram — an interpretation of the raw dumps in evidence/01_raw_onchain/, not itself primary evidence).
  • CONFIRMED — The fee hub (0x4b742ad5Ca91969e82AeFB80072AE59121a3d72A) has been active since 11 Nov 2024 (almost 2 years). In just the most recent ~24 hours of sampled history alone it processed 10,000+ transactions from 5,897 distinct sending addresses (the true lifetime total is certainly far larger — I hit the block explorer API's pagination limit).
  • CONFIRMED — Both the victim's payment and one downstream payout route through the verified, canonical ERC-4337 EntryPoint v0.7 contract, and one transaction shows a log from Pimlico's verified SingletonPaymasterV7 contract — independently confirming the gas-sponsorship mechanism the original victim report described, directly from transaction receipts rather than from the report's own say-so. See evidence/02_smart_contracts/.
  • CONFIRMED — The victim's payment itself is a single transaction that splits into two transfers: 1,398 USDT to the collector, and 1.064404 USDT sent directly to the same fee hub described below — the fee-skimming happens at this first hop too, not only further downstream. Tracing one step further back, the victim's own wallet (0x3aca4c754fc517d17e39bee823f55575fcb1f059) consolidated the exact payment amount (1,400.316487 USDT) from three separate incoming transfers shortly beforehand — see the Fund-flow chain above and data/00_addresses_summary.csv for all four addresses in full.
  • HIGH — The four "mule" wallets are a real controlled cluster: each has exactly one lifetime incoming transaction, all from the same collector, dispatched within a 78-minute window. I also checked the six largest payers into the fee hub for a similar common-funding link to each other and found none — full reasoning, every address in full, and both results (the confirmed mule cluster and the negative check on the top payers) are in evidence/03_clustering/clustering_analysis.md.
  • CONFIRMED — Meta Ad Library: ~64 ad instances between 20 Jul and 25 Aug 2026. Many were taken down by Meta for policy violations — the operation simply spins up a new Page and keeps running. The most recent wave (as of this writing) is running in Russian and Ukrainian simultaneously.
  • CONFIRMED — The domain tgrexchange.site was registered on 20 Jul 2026 — the same day the first ad ran — through REG.RU (a Russian registrar), with every WHOIS contact field (registrant/admin/tech/billing) listed as Russia. Raw WHOIS capture and a live TLS certificate pull are in evidence/05_offchain_infra/.
  • CONFIRMED — The bait site returns an identical 403 Access Denied to every access method I tried: a direct browser fetch, an independent third-party scanning service (urlscan.io, scanning from its own infrastructure), and a fetch from a real residential browser. See evidence/06_web_archives/site_access_control.md.
  • MODERATE — I infer this is deliberate geo/referrer-gating at the CDN layer (Cloudflare), since the same block applies even to a well-behaved, unrelated third-party crawler. I cannot see the actual firewall rule from the outside, so I label this specific mechanism — not the blocking behavior itself, which is directly observed — as an inference.
  • CONFIRMED — The Telegram contact, @tgr_manager, was confirmed live and active at the time of writing.
  • CONFIRMED (that no match was found) — I cross-checked this case against the U.S. Treasury (OFAC) sanctions list for "TGR Group" (a real, unrelated, sanctioned Russian money-laundering network designated 4 Dec 2024 — see evidence/sdn_crosscheck.md): I compared the two cryptocurrency addresses OFAC published for that case against every address in this chain, and against all 5,897 addresses that paid into the fee hub, and pulled the full transaction history of the OFAC-listed ETH address for a counterparty-overlap check. No match and no direct on-chain link were found. This rules out one specific hypothesis; it does not prove the two are unrelated in general (OFAC's designation discloses only two addresses out of a presumably much larger real infrastructure).
  • LOW/SPECULATIVE — The full FATF virtual-asset red-flag scoring, mapping every pattern above to a named typology with its own confidence rating, is in evidence/04_risk_scoring/fatf_redflag_matrix.md.

Evidence

Processed / summary data (derived from the raw dumps, for readability):

File What it shows
data/00_addresses_summary.csv Every address in the chain, with role, activity window, and notes
data/01_first_hop_transactions.csv Transaction history of the first recipient address
data/02_collector_transactions.csv Transaction history of the collector wallet
data/03_fee_hub_transactions_sample.csv 10,000 transactions of the fee hub (~last 24h of history, API limit)
data/04_fee_hub_senders_ranked.csv All 5,897 unique addresses that paid into the fee hub, ranked by payment count
data/05_sdn_crosscheck_magomedov_eth.csv Transaction history of the OFAC-listed ETH address, for the cross-check below

Raw on-chain data (unmodified API responses — every field, including nonce, gas, gas price, gas used, and method signatures, exactly as returned by Etherscan/the Ethereum node — see evidence/01_raw_onchain/):

File What it is
victim_payment_tx_full_raw.json Full eth_getTransactionByHash + eth_getTransactionReceipt + block header for the victim's original payment, including all 6 event logs
first_hop_0xbCCFD2d8_raw.json / collector_0x63961c58_raw.json / fee_hub_0x4b742ad5_raw_sample.json / sdn_magomedov_eth_raw.json Full raw transaction-list API responses for each address
victim_wallet_0x3aca4c75_raw.json Full raw transaction-list response for the victim's own wallet (the address that consolidated the three funding transfers below and sent the payment onward)
funding_source_0xcdd5363e_raw.json Full raw transaction-list response for the smallest of the three addresses that funded the victim's wallet
relevant_txs_funding_sources_raw.json Full eth_getTransactionByHash + eth_getTransactionReceipt for the two specific transactions from the other two (much larger, more active) funding addresses -- their complete transaction histories were not included, since each has 10,000+ unrelated transactions and would add repository size without evidentiary value; the specific transactions connecting them to this case are captured in full here

Smart contract evidence (evidence/02_smart_contracts/) — verified source code + ABI, pulled live from Etherscan's getsourcecode endpoint, for the three contracts whose logs appear in the victim's transaction: the canonical ERC-4337 EntryPoint v0.7, Tether's TetherToken (USDT), and Pimlico's SingletonPaymasterV7. This is direct, primary-source proof of the payment mechanics — not a description of them.

Off-chain infrastructure (evidence/05_offchain_infra/) — raw WHOIS capture for tgrexchange.site, and a live TLS certificate + connection pull (issuer, validity window, negotiated cipher, resolved IP) fetched directly from the domain.

Address clustering, risk scoring, and site-access testing — see evidence/03_clustering/, evidence/04_risk_scoring/, and evidence/06_web_archives/ respectively; each is described in its own file above.

Every Meta Ad Library entry referenced here is citable by its own Library ID, which anyone can look up directly at facebook.com/ads/library to see the original creative and its transparency data.

Sources and methodology

Every finding here was produced using public tools and APIs: Chainabuse (the original report and its Public API), Etherscan (API v2, full transaction history), Meta Ad Library, Arkham Intelligence (address attribution, manually reviewed in-browser), WHOIS / urlscan.io, and the OFAC Specially Designated Nationals list. Reach and victim-count figures are approximate extrapolations, not exact counts; the assumptions behind each are stated above.

A note on the Meta advertiser billing name

Meta's Ad Library disclosed a personal name (unrelated to "TGR") as the "payer/advertiser" on record for one of the ad accounts. As the original victim report itself noted, this most likely reflects a rented, purchased, or stolen verified advertising account rather than the actual operator of the scheme — buying access to someone else's KYC-verified ad account is a well-documented way scam operations bypass Meta's advertiser verification. I deliberately omit that name here: nothing ties that individual to the operation, and there is no public-interest reason to publish it.

Disclaimer

This is an open-source-intelligence writeup for public-interest security research and victim awareness. All wallet addresses, domains, and the Telegram handle documented here were already actively being used to defraud people at the time of writing; publishing them follows the same practice used by blockchain-analysis firms and abuse-reporting platforms (Chainabuse, Chainalysis, Elliptic, etc.). Nothing in this repository was obtained by circumventing any access control, and no private or personal victim data is included — the original report was submitted anonymously.

About

On-chain investigation into the "TGR Exchange" crypto cash-out scam, tracing a single victim report through USDT wallet fund flows, Meta ad infrastructure, and hosting/WHOIS records to identify the operators.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages