In Hong Kong, a man in his seventies watched a number grow on his phone. The number said he was winning. Over several weeks he moved more than HKD 13 million — roughly USD 1.66 million — toward that number, in two assets he had learned to pronounce correctly, through a wallet he had built himself at the instruction of someone he had never met in person. When he finally asked to withdraw, the number stopped moving. The application did not crash. It simply refused to release funds it had never held.

The most sophisticated technology in this crime was a screenshot.
That is the part I keep returning to. We spend our professional lives auditing contracts, sizing reentrancy risk, pricing oracle manipulation, arguing about whether a governance key is centralized. None of that work would have caught this. There was no exploit. No flash loan. No bridge drained, no validator colluding, no upgrade function abused. There was a man, a messaging app, and a ledger that did precisely what it was designed to do — and will never, under any circumstance, undo it.
Hong Kong police reported more than forty investment fraud cases in a single week, with aggregate losses exceeding HKD 50 million, about USD 6.4 million, of which this one case accounts for more than a quarter. The pattern is not novel. It has a name in the industry, borrowed from agriculture and slaughter: pig butchering. You feed the relationship before you take the position.
The sequence, as reported, runs like this. Contact arrives over WhatsApp. The sender introduces himself as a cryptocurrency investment expert based in Singapore. He offers a favorable exchange rate, low fees, and — this is the load-bearing clause — the ability to withdraw at any time. He then guides the victim to set up his own wallet, to buy USDT and ETH, and to transfer those assets to an address under the scammer's control. A custom application displays a portfolio that keeps climbing. When the victim attempts to redeem, the request is declined. The relationship ends, and so does the balance.
Everything about the story is mundane except its scale. And the mundanity is the point. The reason a retiree in his seventies could be separated from his savings in weeks is that the machinery required almost nothing: a messaging handle, a counterfeit interface, and the most reliable settlement layer ever built.
I want to be precise about where this belongs. It is not a protocol failure. No smart contract was exploited. USDT and ETH appear in this story not as subjects but as instruments — two highly liquid assets with global reach and irreversible finality. The philosophy of decentralization that I have spent a decade defending is not implicated in the crime. It is implicated in the recovery. Or rather, in the impossibility of one.
Start with the attack chain, because its shape tells you where the defense has to live.
There are three layers here, and only one of them is on-chain. The first is a trust layer — a messaging app, a claimed jurisdiction, a professional persona. The second is a display layer — a mock application rendering plausible numbers from a database that no one will ever audit. The third is a settlement layer — real assets moving to real addresses with real finality. The first two layers are theater. The third is the wound.
A mock application is not a wallet. It does not need to connect to a chain, hold keys, or query balances. It needs to return a string that looks like a gain. Some of the versions I have examined in adjacent contexts were barely more than a spreadsheet with a login screen; the profit column was typed by hand. There is no vulnerability to report because there is no contract to audit. When I did my first serious work in this space — six months in 2017 walking through the tokenomics of more than forty ICO projects, three of which I audited manually to their failures — I learned to read trust assumptions as the primary attack surface. Centralized upgrade keys. Opaque treasury controls. A single signer who could drain a pool. In every one of those collapses, the technical detail sat downstream of a human concentration of power. Here that concentration is total: one operator, one database, one ledger of imaginary gains.
The economic structure deserves a moment, because it is often described as a Ponzi and it is not quite that. A Ponzi requires an inflow flywheel; this requires only a deposit. There is no promise of returns paid out of new capital, because no returns are ever paid. The profits are painted pixels. The victim is not a participant in a scheme that collapses when recruitment slows. He is the entire scheme, and it ends the moment he asks for his money back. That makes it more aggressive than a Ponzi and, in a strange way, more honest about its intentions: from the first message, the design goal was extraction, and the only variable was pace.
The choice of instruments is equally deliberate, and I think the industry has under-examined it. USDT is the unit of account. Stability is the requirement: a person in his seventies needs the number to look like money, not like noise. A portfolio denominated in a stable asset produces a curve that rises smoothly, week after week, in familiar units. ETH occupies the other slot — the upside asset, the thing that appreciates, the reason to add more. It is a two-asset psychological portfolio: safety and growth. Neither is being held anywhere. Both are being moved.
Both are also irreversible. This is where the real technical maneuver of the case lives.
The instruction to build a self-custody wallet is usually reported as a minor detail. I read it as the centerpiece. A custodial platform — a licensed exchange, a regulated venue — sits inside a network of obligations. Identity checks. Transaction monitoring. Thresholds that trigger review. Freeze protocols. Subpoena-able records. Law enforcement has, on occasion, actually stopped money already in motion. Not because the chain permitted it, but because a company stood between the chain and the customer, and that company could be compelled to act.
Remove the company and the perimeter collapses. The advice to build your own wallet is not investment counsel. At the network level it is anti-forensics. It severs the link between an identity and a transfer, which is exactly the property that makes self-custody attractive for legitimate privacy and invaluable for laundered capital. Assets move out of an account a court could reach and into an address that no one can. And they move under the victim's own key, on the victim's own screen, in an operation only he can authorize.
There is no vulnerability in the code. The vulnerability is the interface between human trust and irreversible settlement.
That interface is not being audited by anyone. We maintain an entire professional discipline for contract risk and almost nothing for the moment a person decides to press confirm on a transfer he will never be able to take back. In 2020, during the DeFi summer, I sat inside a small Copenhagen DAO and spent three months interviewing twelve people who had lost savings when oracle feeds failed. None of them had been hacked. Their keys were safe. They had simply been exposed to a system whose failure mode had never been explained to them in the hour before it happened. I came away with a sentence I have repeated ever since, and it lands here with uncomfortable force: the smart contract was perfect, and the person was not.
The laundering side follows the same logic. A transfer of roughly USD 1.66 million into a fresh address does not sit still. It splits, hops, crosses chains, and eventually seeks a venue where it can become fiat — over-the-counter desks, payment channels, the soft border between regulated and unregulated service providers. Each hop raises the cost of tracing. None of these are technical exploits. They are friction, deliberately purchased with money that was already extracted. When I worked on a guide to digital provenance with a legal scholar in Copenhagen — thirty pages on who actually owns what inside a generative art collection — the hardest section was always attribution after the fact. The chain records everything and proves very little about intent. A hash is not a motive, and a timestamp is not a witness.
Which brings me to a contrast I cannot leave on the table, because it defines the asymmetry of this moment. The most aggressive crypto enforcement of recent years was aimed at people who wrote privacy tooling — developers whose artifact was public, inspectable, and published under their own names. Tornado Cash made the point sharply: code, and the people who release it, can be treated as the instrument of a crime. Yet a scheme like the one in Hong Kong requires no artifact at all. Nothing to subpoena. No repository, no maintainer, no compiler output. The most damaging fraud leaves no code behind. It leaves a chat log.
Code is law, until the law breaks the code. And the inverse turns out to be just as true: where there is no code, the law has nothing to hold.
Then there is the reputational ledger, and its accounting is brutal. The attacker captures the gain; the industry pays the bill. Forty-odd cases in a week do not stay inside a police bulletin. They become the reason a licensing regime tightens, the reason a bank refuses a corporate account, the reason a family member tells an enthusiast at dinner that this whole thing is a scam. I have watched that pattern compound since 2017. Authenticity is a signal lost in the noise — and every one of these cases adds noise. The externalities are severe, systemic, and almost perfectly misattributed.

There is one authorial trick worth naming before I move on, because it explains why otherwise careful people fall. The scammer borrows authority from a jurisdiction. Singapore is not decoration. It is a claim of regulatory seriousness, deployed by someone with no relationship to that jurisdiction at all. This is the same mechanism that makes a counterfeit licensing badge work, and I expect it to worsen as Hong Kong's own licensing framework becomes a recognizable signal. The next variant of this crime will counterfeit compliance, not just returns. Verification will have to keep pace: a real venue is checkable against a public register, and a real professional does not open a position in a private message.
So what would actually reduce the damage? Not better contracts. Nothing in the contract layer was wrong here. The interventions that map onto the actual failure mode sit at the perimeter: a deliberate delay on large first-time transfers to previously unseen addresses, address screening surfaced inside the wallet instead of buried in a block explorer, guardian and social-recovery patterns that assume the user will be targeted rather than assuming the user is careful, and a genuinely funded effort to move security education out of marketing decks and into the places where the targets actually live — community centers, family group chats, bank branches, the applications that older people already trust.

That last item is a public good, which raises the question of who pays for it. It is not a question of charity. If anti-fraud education protects the whole network and the whole network's reputation, it should be funded like infrastructure. The grant-committee model we reflexively reach for in this industry tends to reward proximity to the committee rather than proximity to the problem. The mechanism I have seen actually clear that bar is RetroPGF, allocation by observed impact rather than by application to a panel, and it is the only one I would trust to fund security work at scale without quietly turning it into a sponsorship line item.
Now the uncomfortable part, which is where most commentary on cases like this goes wrong.
The reflex in our industry is education. Teach the victim. Warn the user. Post the checklist. It sounds responsible, and it quietly relocates the failure onto the person who lost the money. But read the Hong Kong case closely and the man did what we told him to do. He held his own keys. He did not hand custody to a stranger. He diversified across a stable asset and a growth asset. He followed the onboarding instructions of a self-described expert. Every step of that is consonant with the values we broadcast: sovereignty, self-custody, decentralization, be your own bank. We celebrate those values, then treat their consequences as a personal shortfall when the bill arrives.
Faith in the protocol is not faith in the people. Self-custody, as currently packaged, is a doctrine of sovereignty with no corresponding doctrine of protection. We shipped the rights and skipped the safety rails.
The second uncomfortable point: licensing will not solve this either, and pretending otherwise is a category error. A licensing regime for virtual asset trading platforms cannot intercept money that never enters a licensed venue. The victim never touched one. Identity checks at the platform level are powerless against a transfer between two self-managed wallets. The part of the ecosystem that advocates loudest for tighter platform regulation is often the part least exposed to this crime. What is exposed is the periphery — the boundary where a self-managed wallet meets a human being who has been lied to for three weeks.
There is a version of crypto criticism that treats a case like this as proof the entire enterprise is fraudulent. I think that reading is wrong about the kind of thing that happened. Fraud found a rail; the rail did not cause the fraud. But the weakness of that rebuttal is how little comfort it offers, because this industry bills itself on one promise above all others — that the code protects you — and this case demonstrates that the code protects no one who has been lied to. Saying the technology is fine while the losses land is not a defense. It is a receipt.
The number on the phone was never money. It was a rendering. The assets underneath it were real, and they are now unavailable, irreversibly, by design. What we built was a system of perfect finality — a settlement layer that does not lie and does not forgive — and we handed it to the people least equipped to survive it.
I do not think the answer is to soften the ledger. I think the answer is to stop pretending that the ledger was ever the whole system. Irreversibility will eventually acquire human-scale interfaces, not because decentralization failed, but because it succeeded further than our judgment could carry. We built the temple, but forgot who the god is. The question for the coming decade is not whether a seventy-year-old's signature should be final. It is whether we intend to build anything that stands between that signature and its consequences — or whether we will keep explaining, after each confiscated life's savings, that the code worked exactly as intended.