Cointime

Download App
iOS & Android

Certik Report: How Developers Are Using KYC To Scam Web3 Communities

Validated Project

CertiK has unveiled an underground ring of KYC actors for hire, used by rogue developers to scam Web3 communities.

Basic KYC verifications are regularly effective at annoying honest retail users, but unfortunately less so at stopping determined criminals from defrauding victims and laundering their stolen funds. Indeed, CertiK’s investigation confirms that criminals have developed several ways to bypass regular verifications, and the existence of professional “KYC actors” illustrates how easy it is to escape accountability. From our conversation with a “KYC actor”, to our deep-dive investigation into their underground world, let’s discover the dark side of the KYC industry, along with best practices for protecting communities and organizations.

A Conversation With a KYC Actor

Among the several tactics used by crypto developers who intend to scam communities and investors, the use of a KYC actor is certainly one of the most fascinating tactics detected and investigated by CertiK. In our context, a KYC actor is an individual specifically hired to KYC on behalf of rogue project owners looking to gain trust in the crypto community prior to an insider hack or an exit scam. In a particular case, after CertiK’s investigators detected and identified a KYC actor, the subject agreed to provide detailed information about the KYC actor process and industry.

According to this actor, it is surprisingly cheap and easy to hire someone to KYC for a fraudulent endeavor. He detailed how he had been posing for fake KYCs for over 3 years, and explained how simple it was for him to pass a regular KYC verification. In addition, he provided proof of transactions for his KYC gigs, as well as links to the specialized marketplaces where he finds his criminal clients. However, the reality of this undercover life is not nearly as glamorous as portrayed by Hollywood. Our interviewee showed us around his humble surroundings, explaining that most KYC actors are based in developing countries and are paid a small amount for each ‘role’, with his earnings amounting to just 20 to 30 USD per deal. This sad situation is unfortunately not surprising as we know that the modern scamming industry has no shame in organizing human trafficking and slavery for their benefit.

KYC Actor Dark Markets

Based on this insider information, our intelligence analysts were able to launch a deep dive investigation into the dark KYC marketplaces to better assess the situation and see what we could learn from it. We thoroughly scanned the activity of over 20 over-the-counter (OTC) underground markets, most of them hosted on Telegram, Discord, as well as some low-requirement phone-based apps, along with job ads placed on gig websites. Sellers and buyers meet on these OTC marketplaces based on their specific transaction requirements, negotiate their price, and usually use an escrow service for the payment. Rogue developers who prepare crypto scams also use these service to recruit KYC actors, but they represent a marginal activity percentage compared to the number of transactions for already-KYCed bank or exchange accounts, as well as direct crypto/fiat currency deals.

The cost of a KYC actor can be as low as 8 USD if the gig requirements are low - for example, bypassing a basic KYC process to open a bank or exchange account from a developing country. The price increases if the KYC actor has to face a more complex verification process, and jumps significantly if the buyer needs an actor who is a national resident of a country that is considered low-risk for money laundering, thus having a lower probability of being flagged or rejected, as well as access to a lot more services. On certain instances, we found some KYC actor roles, such as acting as the CEO of a crypto project, paid up to 500 USD a week. Our explorations show that the global prevalence of these OTC marketplaces is significant, with an above average concentration in South-East Asia and group sizes ranging from 4,000 to 300,000 members. We counted a staggering total of more than 500,000 members who were either buyers or sellers of these underground currency exchanges and fake KYC services.

The Threat of Fake KYC Badges

As observed during our interview and the subsequent investigation into the underground industry, KYC actors are not employed to protect privacy or financial freedom, but very clearly to steal funds from investors. The Web3 industry has understood that the team behind a project can be a major source of operational, reputational and legal risk, and in response, more than 40 websites have popped up offering crypto “KYC badges”, supposedly vetting project teams, with the latest numbers showing these websites have already issued over 2000 badges.

The sad reality is that the majority of these improvised verification services are worthless, because they are either too superficial to detect fraud or simply too amateur to detect insider threats, with the KYC teams missing the necessary background investigation methodology, training and experience. This can lead to very serious consequences, as fraudulent teams can easily bypass their verification process, leverage these unreliable KYC badges to mislead and scam additional investors, and escape accountability for their crimes.

How to Truly Verify a Project Team

Partnering with or investing in a Web3 start-up requires the highest level of due diligence, and the amounts of funds at stake in crypto projects are too high to rely on a simple ID-check and namecheck which can be easily faked today by determined criminals. The only way to truly verify the team behind a project is to conduct a proper, thorough background investigation on each key member and ensure this investigation is carried out by a team of professional, experienced criminal investigators and intelligence analysts.

CertiK has built such a team and process, and their investigative unit has been able to successfully detect human insider threats within project teams several weeks before they conducted insider hacks or exit scams. CertiK’s proprietary set of discrepancy and fraud signals allows for metric based, early threat detection, even with remote employees in developing countries. The scientific methodology used is especially effective in detecting KYC actors, as well as criminal operators hiding behind secondary team-members, in addition to developers attempting to conceal their involvement in previous scams and hacks.

Comments

All Comments

Recommended for you

  • U.S. Congressman Mike Flood: Looking forward to working with the next SEC Chairman to revoke the anti-crypto banking policy SAB 121

     US House of Representatives will investigate Representative Mike Flood's recent statement: "Despite widespread opposition, SAB 121 is still operating as a regulation, even though it has never gone through the normal Administrative Procedure Act process." Flood said, "I look forward to working with the next SEC chairman to revoke SAB 121. Whether Chairman Gary Gensler resigns on his own or President Trump fulfills his promise to dismiss Gensler, the new government has an excellent opportunity to usher in a new era after Gensler's departure." He added, "It's not surprising that Gensler opposed the digital asset regulatory framework passed by the House on a bipartisan basis earlier this year. 71 Democrats and House Republicans passed this common-sense framework together. Although the Democratic-led Senate rejected it, it represented a breakthrough moment for cryptocurrency and may provide information for the work of the unified Republican government when the next Congress begins in January next year."

  • Indian billionaire Adani summoned by US SEC to explain position on bribery case

    Indian billionaire Gautam Adani and his nephew, Sahil Adani, have been subpoenaed by the US Securities and Exchange Commission (SEC) to explain allegations of paying over $250 million in bribes to win solar power contracts. According to the Press Trust of India (PTI), the subpoena has been delivered to the Adani family's residence in Ahmedabad, a city in western India, and they have been given 21 days to respond. The notice, issued on November 21 by the Eastern District Court of New York, states that if the Adani family fails to respond on time, a default judgment will be made against them.

  • U.S. Congressman: SEC Commissioner Hester Peirce may become the new acting chairman of the SEC

    US Congressman French Hill revealed at the North American Blockchain Summit (NABS) that Republican SEC Commissioner Hester Peirce is "likely" to become the new acting chair of the US Securities and Exchange Commission (SEC). He noted that current chair Gary Gensler will step down on January 20, 2025, and the Republican Party will take over the SEC, with Peirce expected to succeed him.

  • Tether spokesperson: The relationship with Cantor is purely business, and the claim that Lutnick influenced regulatory actions is pure nonsense

     a spokesperson for Tether stated: "The relationship between Tether and Cantor Fitzgerald is purely a business relationship based on managing reserves. Claims that Howard Lutnick's joining the transition team in some way implies an influence on regulatory actions are baseless."

  • Bitwise CEO warns that ETHW is not suitable for all investors and has high risks and high volatility

    Hunter Horsley, CEO of Bitwise, posted on X platform that he was happy to see capital inflows into Bitwise's Ethereum exchange-traded fund ETHW, iShares, and Fidelity this Friday. He reminded that ETHW is not a registered investment company under the U.S. Investment Company Act of 1940 and therefore is not protected by the law. ETHW is not suitable for all investors due to its high risk and volatility.

  • Musk said he liked the "WOULD" meme, and the related tokens rose 400 times in a short period of time

    Musk posted a picture on his social media platform saying he likes the "WOULD" meme. As a result, the meme coin with the same name briefly surged. According to GMGN data, the meme coin with the same name created 123 days ago surged over 400 times in a short period of time, with a current market value of 4.5 million US dollars. Reminder to users: Meme coins have no practical use cases, prices are highly volatile, and investment should be cautious.

  • Victory Securities: Funding Rates halved and fell, Bitcoin's short-term direction is not one-sided

    Zhou Lele, the Vice Chief Operating Officer of Victory Securities, analyzed that the macro and high-level negative impact risks in the cryptocurrency market have passed. The risks are now more focused on expected realization, such as the American entrepreneur Musk and the American "Efficiency Department" (DOGE) led by Ramaswamy. After media reports, the increase in Dogecoin ($DOGE) was only 5.7%, while Dogecoin rose by 83% in the week when the US election results were announced. Last week, the net inflow of off-exchange Bitcoin ETF was US$1.67 billion, and the holdings of exchange contracts and CME contracts remained high, but the funding rates halved and fell back, indicating that the direction of Bitcoin in the short term is not one-sided, and bears are also accumulating strength.

  • ECB board member Villeroy: Falling inflation allows ECB to cut interest rates

     ECB board member Villeroy de Galhau said in an interview that the decline in inflation allows the ECB to lower interest rates. In addition, the slow pace of price increases compared to average wages is also a factor in the rate cut. Villeroy de Galhau emphasized that the ECB's interest rate policy decision is independent of the Fed. Evidence shows that the ECB began to lower interest rates in early June, while the Fed lowered interest rates three months later. With the decline in inflation, we will be able to continue to lower interest rates. Currently, the market generally expects the ECB to cut interest rates by 25 basis points at the next meeting in December, but weaker data increases the possibility of a 50 basis point cut.

  • State Street warns Bitcoin craze could distract gold investors

    George Milling-Stanley, the head of gold strategy at Dominion Bank, warned that the rise of Bitcoin may mislead investors to overlook the stability of gold. He believes that Bitcoin is more like a return-driven investment, while gold provides long-term stability. He also criticized Bitcoin promoters for misleading the market by using the term "mining," and believes that gold is still a more reliable investment choice.

  • CertiK Chief Security Officer: The number of security incidents as of September 2023 has exceeded the total in 2022

    On October 23, at the ETH HK Side Event, a Web3 ecosystem security forum jointly held by CertiK and OKLink in Causeway Bay, Hong Kong, Professor Li Kang, Chief Security Officer of CertiK, shared his views on digital asset security construction. He pointed out that according to CertiK's statistics, the number of security incidents as of September 2023 has exceeded the total number in 2022. Hacking attacks and fraudulent behavior are still important threats, seriously hindering the development of the Web3 industry. Li Kang also mentioned the revolutionary feature of transparency in the Web3 field. The entire ecosystem can reduce security risks through public and transparent measures, such as asset management solutions. At the event, leaders from the Hong Kong Investment Promotion Agency, OKLink, and BlockSec shared their related work and latest developments in Web3 security construction. For example, CertiK and OKLink have received responses from multiple exchanges in asset tracking locking and data labeling. Finally, Li Kang hopes to further strengthen Hong Kong's position as a Web3 innovation gateway in the rapidly growing Asia-Pacific region through this sharing, and jointly promote the safe application and landing of Web3 technology.