Pig butchering sits at an uncomfortable intersection: it is simultaneously the most devastating scam category in the FBI’s annual crime statistics and the one most people believe they would never fall for. That belief is the product’s core ingredient. The scam works precisely because it does not look like a scam for weeks — it looks like a friendship, and later, like an investment that is obviously working.
This article breaks the scam into its operating parts: the funnel, the fake platform, the on-chain money trail, and the reporting path. It is written from an on-chain analysis perspective — for people who want to understand what the money does after the deposit, whether they are victims, researchers, or investigators.
The funnel: how the conversation actually starts
Every pig butchering case follows the same sequence, refined over millions of repetitions in scam compounds:
| Stage | What happens | How long |
|---|---|---|
| Contact | Wrong-number text, dating app match, or a reply to a job post | Day 0 |
| Grooming | Daily friendly chat, no investment talk at first | 1–4 weeks |
| Seed | Scammer mentions their own trading profits, offers to teach | 2–5 weeks |
| Small win | Victim deposits a small amount, sees fake profit, withdraws it | Week 3–6 |
| Fattening | Victim deposits larger amounts, platform shows growing balance | 1–3 months |
| Butchering | Withdrawal blocked; “tax” or “fee” demanded; then silence | Final week |
The contact vector matters. The wrong-number text — an apparently misdirected friendly message — is the industry standard opener precisely because it gives the victim a plausible, low-stakes reason to reply. From the scammer’s side, a social engineering script like this is run at industrial scale: workers in compounds manage dozens of conversations simultaneously from templated playbooks, sometimes using AI translation and generation tools to operate across languages. The FBI has documented this industrialization in its awareness campaign, Operation Level Up, which describes pig butchering as a confidence-based scam run at population scale.
The one near-universal tell during grooming: the counterpart avoids live video calls. Voice is common (AI voice or a different worker), video is almost never available. The excuses are always mundane — a broken camera, a shy personality, a corporate policy.
The fake platform: a theater with a working cashier
The “trading platform” the victim is sent to is a fully fabricated website. It renders professional-looking charts, shows a live balance that grows exactly as promised, and even processes the first small withdrawal. The key insight for on-chain analysts: the balances are database entries in the scammer’s control panel, not real positions on any exchange.
The fake platform exists to solve a single problem for the scammer — making the deposit feel like an investment rather than a transfer. To that end:
- Deposits go to addresses the scammer controls, described as “your dedicated account.”
- The platform shows fake trading profits calibrated to keep the victim depositing. Modest, believable returns — 1–3% a week — are more effective than obviously impossible numbers.
- The first withdrawal request for a small amount is honored. This is the single most important trust-building step in the entire funnel, and it is deliberately budgeted as a cost of the scam.
- Fees, “taxes,” or “verification deposits” appear only when the victim tries to withdraw a large amount or shows signs of stopping deposits. This is the extraction endgame: many victims pay the fake fee believing it unlocks their balance, sometimes repeatedly.
If a platform you cannot independently verify offers custody of your funds, treat it as a custodial wallet with zero accountability — because functionally, that is what it is.
What the money trail looks like on-chain
This is where on-chain analysis earns its keep, and where the story differs from the psychology-heavy mainstream coverage.
The deposit address. The victim’s first transaction goes to a fresh address (or a deposit address inside a cluster) controlled by the operation. These addresses are usually clean — no prior history — because operations rotate them per victim or per small group of victims.
The collection layer. Deposits sit until they reach a threshold, then sweep into a collection wallet. This is the address worth flagging first: it aggregates inputs from many victim deposit addresses and is the operation’s most identifiable on-chain entity. Tools that cluster addresses by behavioral fingerprint — the approach we cover in wallet risk scoring — often catch collection wallets before labels exist.
The laundering layer. From collection, funds typically split into peel chains, pass through cross-chain bridges to other networks, and land in nested custody services at major exchanges (small merchant accounts inside a big exchange, which are faster to open and slower to freeze than direct exchange wallets). You can trace the logic of this layer in detail in how stolen crypto is tracked.
The exit. Final conversion to fiat usually happens through over-the-counter desks in jurisdictions with weak enforcement, or through stablecoins held as a store of value by the operation itself. Stablecoin issuers can freeze funds at the contract level — one reason some operations now prefer other assets — but freezes require the issuer to receive a sufficiently specific report, fast.
A practical observation from published tracing work: speed dominates everything. Exchange compliance teams act on reports within hours when funds are still sitting at a deposit address. After the first bridge hop, the realistic recovery probability collapses.
The compounds: who is on the other side
The UN Office of the High Commissioner for Human Rights published a report in August 2023 estimating that at least 120,000 people in Myanmar and around 100,000 in Cambodia were being held in scam compounds and forced to conduct online fraud — a population largely trafficked through fake job advertisements. The workers running the grooming conversations are frequently victims themselves, working under threat, which is why the FBI and NGOs consistently frame the industry as both a fraud problem and a human trafficking problem.
For analysts, this explains a pattern visible in the scripts: conversation quality is uneven. The opening messages are polished templates; improvised responses to unusual questions are where the operation shows seams. Victims consistently report that asking for a video call or an off-script question produces delays, deflection, or a change of topic — because the worker has to escalate to a supervisor.
The recovery trap that follows the scam
A victim who loses money and posts about it publicly — in a forum, a complaint site, or social media — is often contacted within days by someone claiming to be a “blockchain investigator” or “fund recovery service” who can retrieve the stolen crypto for an upfront fee. These are almost universally follow-on scams targeting the same victim list, a category we break down separately in crypto recovery scams explained. The rule: anyone who promises recovery and asks for payment upfront is running the second half of the same playbook. Legitimate paths — IC3, exchange compliance, licensed counsel — do not charge victims a recovery fee before any result.
How to protect yourself and people around you
The protective measures are unglamorous but effective:
- Treat any investment introduction from a stranger-met-online as presumptively fraudulent. The introduction channel, not the asset class, is the red flag.
- Verify custody independently. If you cannot withdraw to your own non-custodial wallet address at will, you do not control the funds — regardless of what the dashboard shows.
- Test withdrawals early and at size. A real platform lets a meaningful amount leave. A scam platform honors only trivial amounts.
- Watch for the fee wall. Any “tax,” “margin call,” or “unlocking fee” demanded before withdrawal is the standard extraction script. No legitimate exchange charges a fee to release your own balance.
- Keep custody hygiene separate from social apps. A hardware wallet used only for savings — never connected to anything a chat contact suggested — is immune to this entire category by construction.
If the loss has already happened: preserve everything (chat logs, platform URLs, deposit addresses, transaction hashes), report to IC3 at ic3.gov and your local police the same day, and send the deposit addresses and hashes to the compliance teams of any exchanges visible in the trail. It is not glamorous work, but it is the only sequence that has ever produced frozen funds.
Limitations of this analysis
On-chain analysis can trace the money, but it cannot recover sentiment or reverse a bridge hop, and it cannot identify compound workers behind nested accounts. Loss figures from IC3 reflect reported crime only — the true scale is understood to be larger. And the scam’s structure keeps evolving: recent reporting documents AI-generated persona tools shortening the grooming phase. The fingerprint described above holds as of this writing; expect the details to keep shifting.
Related reading
- Crypto recovery scams explained — the second scam that targets pig butchering victims
- How to track stolen crypto — the tracing toolkit behind the money-trail section
- AI-powered crypto scams in 2026 — how generation tools industrialize the grooming phase
- Address risk scoring explained — how collection wallets get flagged
- How to avoid crypto phishing scams — the short-con counterpart to this long con
Frequently Asked Questions
Why is it called pig butchering?
The name comes from the Chinese term sha zhu pan (杀猪盘). Scammers call the victim the pig, the weeks of relationship-building the fattening, and the final fake investment push the butchering. Western investigators kept the translation because it accurately describes the multi-stage structure: the scam invests far more time in grooming than a traditional phishing attack ever does.
How much money does pig butchering steal?
No single figure covers the category, because most victims never report. The FBI's IC3 reporting shows cryptocurrency investment fraud — which the FBI itself describes as pig butchering — as the highest-loss category in cyber-enabled fraud: total reported cybercrime losses reached $16.6 billion in 2024 and approached $21 billion in 2025. Blockchain analytics firms estimate annual crypto scam revenues in the billions of dollars globally, and the UN estimates hundreds of thousands of trafficked workers operate the conversations from compounds in Southeast Asia.
Do pig butchering victims ever get money back?
Rarely, and only partially. Once funds pass through a mule network and cross-chain bridge, recovery depends on exchange freezes happening within hours. Victims should report to local police and the FBI's IC3 (ic3.gov) immediately, and to every exchange whose deposit address received funds. Be aware that public victim lists are themselves harvested by recovery scammers, who charge upfront fees to chase money they cannot retrieve.
What are the early signs of a pig butchering scam?
The classic opening is a wrong-number text or a friendly message on WhatsApp, Telegram, or a dating app from someone who avoids video calls. Weeks of daily conversation follow, during which the scammer casually mentions their crypto or forex profits. They eventually offer to teach you, send you a link to a trading platform, and let you withdraw a small test profit once. The scam only reveals itself when you try to withdraw a large amount.
Is pig butchering only about crypto?
No. The same grooming funnel is used for fake forex platforms, gold and commodity trading schemes, and traditional bank-transfer investment fraud. Crypto is simply the preferred settlement rail because transfers are irreversible and cross-border, which is why on-chain analysis skills matter for tracing this category at all.