An email that arrived because the scam stole our name
In late September a victim in Zhejiang, China wrote to us. The way he found us says a lot about how these operations work: the fake app he had trusted called itself “Onchain.” He searched the name and landed on this site. To be clear from the start — that app has no connection to Onchain Diary. The name was stolen. For the rest of this piece we’ll use the operation’s real storefront name: FMMR Mining, at fmmrvip.click.
On October 11 he replied to our follow-up and gave us full permission to publish his story, writing that his goal was “so more people know and fewer people get scammed.” His QQ account, city, and Bilibili handles are withheld here; the on-chain data and timeline are published as-is. They are public records anyway.
What happened to him
It started in June, with a direct message on Bilibili from an account presenting as a woman doing medical-aesthetics work in Macau. Life chat first. Investment entered the conversation “casually” once trust built, then mining, then the obvious next step: you should join.
Act one was gentle. First deposit 300 USDC. Mining “yields” showed up, and — critically — a withdrawal actually cleared. For a lot of people the math checks out: risk 300 USDC to verify a channel that appears to pay. He scaled up.
Act two changed the script. One day the miner stopped and the on-chain balance was moved out. The platform’s customer service said his IP was flagged and the funds were under regulatory review; releasing them required a 10,444 USDC “verification fee.” He recalls that 2,513 USDC of that fee was “chipped in” by the woman herself — remember this number, it becomes the sharpest piece of evidence in the whole case. Fee paid, the story changed: he was now suspected of money laundering, and needed to provide 14,560 USDC. Paid again, the story changed once more: multiple accounts detected, an 18,000 USDC deposit required. There he stopped, went to the police, and wrote to us.
His own post-mortem contains a line that deserves to be quoted to everyone who thinks they’re too sharp for this. He knew from the start that cold DMs are almost always scams — he’d even told friends he was chatting with her mainly to “occupy her time so she’d scam fewer people.” He walked in with his guard up. He stayed because the app seemed to have F1 sponsorships (no partner named Onchain appears in the public 2026 F1 partner lists — the crypto sponsors there are Crypto.com, Coinbase, and Gate); because the pool had four tiers and he was only on tier two, “too early to pull the net”; and because of one belief bigger than all the others: “the money sits in my own wallet — she can’t touch it.”
That belief is what the rest of this investigation is about. They could touch it. Without asking him.
On-chain autopsy: every number in his account exists on Ethereum
He sent us screenshots of two transfers — 10,680 USDC and 10,449 USDC. Both match mainnet records to the last digit. His wallet’s full flow between August 28 and September 12, from Etherscan:
| Time (UTC) | Event | Amount |
|---|---|---|
| 08-28 07:15 | Deposit (withdrawn from a Binance hot wallet) | 6,999.40 USDC |
| 08-28 07:20 | Deposit (same rail) | 937.40 USDC |
| 08-28 08:00 | Transfer in from the “friend’s” wallet | 2,513.00 USDC |
| 08-28 08:05 | Drained (harvest #1) | 10,449 USDC |
| 09-11 11:26 | Deposit (Binance hot wallet withdrawal, “verification fee” round) | 10,679.43 USDC |
| 09-11 11:36 | Drained (harvest #2 — ten minutes after deposit) | 10,680 USDC |
| 09-12 14:45 | Deposit | 3,835.59 USDC |
| 09-12 14:50 | Drained (harvest #3) | 3,835 USDC |
The alignments are exact. Harvest #1 (10,449) corresponds to the “verification fee” of 10,444 in his telling. Harvests #2 and #3 sum to 14,515 (10,680 + 3,835), matching the “money-laundering deposit” of 14,560 he described. The 18,000 USDC final demand was never paid — which is why there is no fourth harvest on-chain. His customer-service arguments (“is your platform even legitimate? you keep asking me for money”) took place on September 14; the 26 pages of screenshots he compiled are full of that day’s canned lines — “multiple accounts failed system review,” “refund blocked by account errors” — matching the on-chain rhythm beat for beat.
The funding rail’s identity is nailed down too: all three of his large deposits were direct withdrawals from the same Binance hot wallet, a label confirmed independently by both Etherscan and BlockSec’s AML database. The path is complete: buy USDC on Binance, withdraw to your own wallet, lose it to the pool’s standing permit.
The executor is the harvester address 0xfb6146…f76C. No exploit, no flash loan, nothing exotic — just Ethereum’s most ordinary mechanism, a signed USDC permit. The “terms” he blind-signed at pool registration granted this address the right to spend his USDC: a 10-million-token cap, expiring January 12, 2030.
After that it ran like rent collection. Every time he topped up, they came and took the balance. Fastest cycle: deposit of 10,679.43 at 11:26, drained of 10,680 at 11:36. Even the gas for that drain had been forwarded to the harvester by the operation one minute earlier.
Where the “friend’s” 2,513 USDC actually came from
This is the part of the case worth reading twice.
He told us 2,513 USDC of his verification fee “was chipped in by her.” On-chain: at 07:57 on August 28, the persona wallet received exactly 2,513.00 USDC — funded by the operation’s own treasury. Three minutes later at 08:00, the same amount moved to his wallet. Five minutes after that, the harvester took the full 10,449, that 2,513 included.
The money she “contributed” had left the scam’s treasury three minutes before it reached him. It made a perfect circle — treasury → her wallet → his wallet → collection address — returning to the same hands with eight thousand of his own USDC attached. Her wallet’s broader history shows the same pattern: periodic treasury funding (1,000, 2,000, 2,513, 3,500), each batch forwarded within hours to a victim or looped back to the cash-out address. She wasn’t a fellow miner. She was the pig-butchering handler, running on house money.
This also answers the question victims’ families ask most: “was the person chatting even aware?” In this operation, at least, the hand that lent comfort and the hand that took the money were funded from the same treasury. There was no independent person behind the persona.
Not one victim: 165 wallets, 1.54M USDC
Pull the full history of the collection address 0xec31…5578 and the operation’s true size appears: from June 1, 2026 onward, over 540 incoming USDC transfers totaling roughly 1.55M USDC from 165 distinct addresses — a count that grew by six transfers during the hours we spent re-verifying. The pool is still collecting. The mix is telling too: more than 350 transfers are under 300 USDC — the operation’s own recycling and test traffic — while the real victim-sized transfers number about 50, the largest over 50K. And the harvesting isn’t done by one wallet: at least 15 drainer addresses are confirmed running the same permit playbook, with over 100 transferFrom executions combined — our drainer’s 11 are a rounding error.

The full fund-flow map: 165 victim wallets → 15+ drainers → collection pool (1.54M USDC) → treasury/mid-level → three exits. Every figure and address in the chart is verifiable on Etherscan.
The money moves up in a clean hierarchy: the collection address forwarded 805,000 USDC to a main treasury and split 275,000 (11 transfers), 205,820, and 123,500 to mid-level wallets. Past that point, attribution gets careful: the treasury and an address labeled “Bitget: Crosschain Bridge Vault” on Etherscan have a long history of plain USDC transfers — not contract deposit calls. Within this case’s window (late July onward), the treasury sent that address about 226K and the mid-level wallet another 181K in batches: roughly 400K USDC moved peer-to-peer into this Bitget-owned address. Whether it actually crossed chains after arrival is invisible on-chain and would require exchange records. And there is a deeper layer outside the window: before this case even began, the treasury had already sent the same address 728K — this wallet plumbing served earlier rounds, not just FMMR. The cash-out prep left traces too: in a single batch-settlement transaction on July 22, the treasury swapped 10,276.50 USDC into ~5.3 WETH through Uniswap V3’s USDC/WETH pool; combined with other legs of the same transaction, ~7 WETH were routed via 1inch to an arbitrage-style wallet (tx 0xd3dc…5537 verifiable on-chain). Stablecoins to ETH — standard pre-cash-out behavior. Below the exit address, the money takes two roads. One stays on-chain, split into dozens of small transfers to a dozen-plus network addresses that carry no label in any public database. The other takes a bridge — and not just once. On August 2, the treasury itself placed a 264,700 USDC order on deBridge’s DlnSource contract (tx verifiable on-chain), destination Tron, payout in USDT — deBridge’s order page shows a market maker unlocked it in 52 seconds, delivering 263,521.33 USDT on the Tron side. Four weeks later on August 30, a relay wallet fed another 206,208 USDC into the same bridge (tx verifiable). Those two orders alone moved 470K USDC off Ethereum — exactly where single-chain tracing goes dark. We decoded the Tron-side addresses embedded in the orders; one candidate landing wallet is confirmed receiving 162,058.48 USDT on October 3. Yields, harvest, consolidation, cross-chain exit — four functions, four wallet layers, an assembly line.
The pass-through discipline deserves a line too: seven minutes before that August 2 bridge order, the treasury had just received 265K USDC in via an ERC-4337 handleOps call — collect, forward, hold nothing. Two more fingerprints were impossible before the Pectra upgrade (May 2025). First, the persona wallet still carries an EIP-7702 delegation hooking its execution logic to a smart-wallet proxy (delegate verifiable on-chain, labeled as Bitget Wallet’s 7702 logic) — off-the-shelf commercial wallet infrastructure, not custom tooling. Second, and sneakier: the treasury reads as a clean, plain EOA today — yet in that July 22 batch settlement, an operator address invoked it with a batch method and moved its funds. A plain address cannot be “called” into executing anything unless it carried a 7702 delegation at the time. Attach and detach leave no timestamp on-chain; what we can say is “it was delegated once, and isn’t now.” An operation with account-abstraction tooling and the discipline to clean up after itself is not three people clicking manually.
The domain tells its own story. fmmrvip.click was registered July 28, 2026 (NameSilo, behind Cloudflare). The harvester’s first drain came the next day, July 29 — the collection address had been receiving funds since June 1, and the operation’s gas supplier was activated as early as March 30 — seeded from a hot wallet of FixedFloat, a no-KYC instant exchanger — with 700+ outgoing transactions since (gas top-ups mixed with token shuffles), four months before this domain existed and anonymous from day one. Domains are consumables in this business, swapped out as they burn; the crew is permanent. In his latest email, the persona is already pitching him a “new pool.”
As of publication, fmmrvip.click is still serving its login page, titled “FMMR Mining,” and the collection address still holds roughly 130K USDC not yet moved.
”The money sits in my wallet” — the belief this industry runs on
Return to the sentence he used to reassure himself, because it is the entire technical core of this crime class.
Wallet signatures come in two flavors. One moves funds directly — everyone watches those. The other grants allowances (an approve, or a permit signature): after signing, nothing visibly happens. The balance doesn’t move. No alarm sounds. But the right to spend those tokens now belongs to someone else, who can act alone, later, at any moment. In this operation, every victim signed the same template: a 10-million-USDC cap on USDC, expiring January 12, 2030.
Behavioral evidence shows all seven permits were still functioning at the last harvest on October 9; a “this-moment” revocation snapshot we cannot produce (real-time allowance reads errored across multiple nodes), but unless a victim actively revoked, the permits run to 2030. Those wallets are pre-mined ground: the moment their owners deposit again, the harvest arrives within minutes. The fix is mechanical — revoke allowances via revoke.cash, or abandon the address (allowances die with the address’s relevance). Teaching him this was the first thing we did in our reply.
Four things you can do
- Audit: connect at revoke.cash and review every live allowance. Anything signed for mining, quant, or “activation” services gets revoked. Built-in approval managers in major wallet apps do the same.
- Retire: a wallet carrying a large live allowance should never hold funds again. Empty it and stop using it.
- Recognize: four signals together are conclusive — a stranger steering friendship into investing, a small first deposit that genuinely withdraws, pressure to scale, and a wallet signature demanded during onboarding. The first three fatten the pig. The fourth is the knife.
- Report: if it happens, go to the police immediately with chats, handles, and transaction hashes. USDC is centrally issued by Circle, which can freeze addresses once law enforcement engages — a real avenue, but proceeds get fragmented through DEXes within days, so speed matters. Our first-24-hours checklist walks the sequence.
His case belongs to the same family as infinite approvals and signature scams: the last line of defense in self-custody isn’t your password or your hardware. It’s the second before you sign something you haven’t read. If you can’t parse a signature request, don’t sign it.
This article is on-chain safety education, not investment advice. The victim’s account is published with his explicit permission and anonymized; all on-chain data comes from public Ethereum mainnet records, with key addresses linked to Etherscan for independent verification.
Frequently Asked Questions
How can scammers move funds out of a wallet they don't control?
Because 'activating the pool' wasn't a terms-of-service checkbox — it was a USDC permit signature. Once signed, the counterparty can transfer the tokens without you: no password, no confirmation, no further involvement on your side, until the allowance is used or expires. In this case every victim's allowance was 10 million USDC, expiring January 2030. Holding keys only means the tokens are physically in your address. The right to spend them was signed away separately.
How do I check whether my wallet has live allowances like these?
Connect your wallet at revoke.cash. It lists every active token approval: who it was granted to and the cap. Anything you don't recognize — especially from mining, quant, or 'activation' sites — should be revoked. Revoking is an ordinary on-chain transaction costing a little gas. Wallet apps such as OKX and TokenPocket ship a built-in approval manager that does the same job.
I already signed something like this. How do I protect what's left?
Two steps. First, move remaining assets to a fresh wallet immediately — allowances attach to the address that signed them. Second, revoke the allowance, or simply retire the old wallet entirely. Never top up a wallet that still carries an active allowance: in this case one victim's deposit was drained ten minutes after it arrived.
What gives a fake mining pool away?
Four signals together are conclusive: a stranger who steers a friendship toward investing; a small first deposit (this ring used ~300 USDC) that genuinely withdraws; pressure to scale up after that; and a wallet 'signature' required during registration or activation. The last one is the blade — a legitimate mining or quant service never needs your token spend rights. Also look at the domain: this operation ran on a cheap .click domain and began draining wallets the day after registering it.
Is recovery realistic after being drained this way?
On-chain tracing can locate where funds concentrate, and because USDC is centrally issued, Circle can freeze addresses once law enforcement engages — there is a real path. But the window is narrow, since proceeds are typically split through decentralized exchanges within days. Report immediately, preserve chats, account handles, and transfer hashes; the transaction hashes are what make a police file actionable. Our 24-hour checklist covers the sequence.