Case Library / Smishing (SMS Phishing) / Austin "Pig Butchering" Courier Arrest - $1.4M DAIQ Crypto Investment Scam

Austin "Pig Butchering" Courier Arrest - $1.4M DAIQ Crypto Investment Scam

A Taiwan-linked money courier was caught in an Austin bank sting after helping collect part of the $1,408,850 a local victim lost over six months to a "pig butchering" romance-investment scam run through the LINE app and a fake "DAIQ" crypto trading platform.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Austin Police arrested Tzu-Hung Hsu, 34, on April 13, 2026 in a controlled sting at a Bank of America branch on West Slaughter Lane in South Austin, after he approached the vehicle of a scam victim to collect a staged $40,000 cash/gold payment. According to a Travis County arrest affidavit reported by KXAN and the Austin American-Statesman, Hsu was a money courier for an international "pig butchering" investment-fraud network that had spent roughly six months (September 2025 to March 2026) grooming an Austin victim over the LINE messaging app, steering him into a fake crypto trading platform called "DAIQ," and ultimately extracting $1,408,850 in cash, wires, and gold before the victim realized he'd been defrauded and reported it to the FBI. Hsu was charged with engaging in organized criminal activity (a first-degree felony) and held on $200,000 bond; the broader network, including an alleged Taiwan-based handler known only as "Jerry," had not been publicly charged as of this research.

How the Attack Worked

Per the Travis County arrest affidavit (as reported by KXAN and the Austin American-Statesman), the victim, identified in records under the alias "Eduardo," was first contacted in September 2025 through the LINE messaging app by people posing as investment advisers connected to a "well-known Taiwanese businessperson." Over several months the operators built a relationship with him and steered him into a fraudulent crypto trading platform called "DAIQ," promising daily returns of 3% to 5%. As is standard in pig-butchering schemes, the victim was encouraged to invest progressively larger sums. Between October 2025 and March 2026 he paid in through three parallel channels: handing over cash in person at parking lots, wiring funds to domestic and international bank accounts, and purchasing gold bars (shipped to him via FedEx) that were then physically collected by couriers at locations around South Austin, mostly near West Slaughter Lane. In mid-March 2026, when the victim tried to withdraw money, the platform told him he first had to pay additional "fees"; he could not pay, realized he had been defrauded, and reported the scheme to the FBI's Internet Crime Complaint Center (IC3). Austin Police then worked with the victim to stage a controlled follow-up exchange: a fake $40,000 cash/gold handoff set for April 13, 2026. Officers conducted surveillance at a Bank of America branch on West Slaughter Lane, watched a man matching the expected courier's description arrive, and detained him when he approached the victim's vehicle. He was identified as Tzu-Hung Hsu, 34, and was carrying a pre-filled receipt consistent with the pattern of prior transactions. In an investigator interview, Hsu said he worked under a Taiwan-based handler he knew only as "Jerry," who directed him via messaging apps to travel around the U.S. (he cited recent trips to Los Angeles, Seattle, Atlanta, and New York City before Austin) collecting cash and gold from victims and passing it to other couriers or shipping companies; his travel costs were covered and he was paid per completed pickup. His phone reportedly held videos of cash and photos of shipped packages. During the police interview, "Jerry" contacted Hsu by messaging app and warned him not to cooperate with law enforcement.

The Lure & the Tell

The lure was a purported personal/professional connection: people posing as investment advisers linked to a "well-known Taiwanese businessperson" approached the victim on LINE and cultivated a relationship before pitching the DAIQ trading platform's guaranteed 3-5% daily returns, a classic pig-butchering "fatten before slaughter" arc mixing affinity/authority framing with too-good-to-be-true yield promises. The tell that broke the illusion: when the victim tried to withdraw his money in mid-March 2026, the platform demanded additional "fees" first: the universal pig-butchering signature of an exit that is never actually permitted without further payment. Unable to pay, he recognized the fraud and reported it to the FBI's IC3 rather than sending more money, which is what enabled the eventual sting.

Outcome

Tzu-Hung Hsu, 34, described in reporting as a Taiwan-based courier, was arrested April 13, 2026 during the staged $40,000 exchange at the Bank of America branch on West Slaughter Lane in South Austin. A magistrate found probable cause on April 14, 2026, and he was charged with engaging in organized criminal activity, a first-degree felony under Texas law, with bond set at $200,000 at the Travis County Correctional Complex. Authorities describe a multi-person conspiracy involving online "relationship" operators and multiple physical couriers, but as of this research (July 2026) no further court disposition (plea, trial, or sentencing) had been publicly reported, and the broader network's structure and the identity/location of "Jerry" remain unadjudicated allegations from the arrest affidavit rather than proven facts.

Why It Matters

This case is a well-documented, court-affidavit-backed illustration of the full pig-butchering lifecycle end to end: the digital grooming phase (LINE messaging, fabricated authority/affinity, a fake trading app with guaranteed returns) feeding directly into a physical money-laundering layer (in-person cash handoffs, gold purchases, courier pickups) that most smishing/messaging-fraud writeups treat only in the abstract. It shows why these scams are so damaging and hard to unwind once money moves, with over $1.4M extracted from a single individual over six months, while also demonstrating the one point of real leverage: victim self-reporting to FBI IC3 while a next collection is still pending let police stage a controlled handoff and intercept a courier before funds left the country. It's also a clear example of how the human "money mule"/courier layer, often treated as disposable and geographically dispersed (this courier had hit five U.S. cities in quick succession), is frequently the single most interdictable link in an otherwise offshore, hard-to-prosecute network.

Defenses

FBI guidance reiterated in coverage of this case: never send money or share financial/personal identifying information with contacts met only through messaging apps or social media; independently verify any investment platform, app, or "advisor" pitched by a new online contact rather than trusting claimed ties to a known businessperson; watch for investment apps/domains that mimic legitimate financial institutions; treat guaranteed daily returns (here, 3-5%/day) as a hard red flag; treat any demand for extra "fees" to withdraw funds as confirmation of fraud, not a solvable obstacle; report suspected losses immediately to FBI IC3 so law enforcement can attempt real-time interdiction (as happened here) before funds leave the country. For institutions: banks and law enforcement can use victim cooperation to stage controlled handoffs (as APD did) to intercept couriers before cash/gold leaves the country, but this only works if the victim reports before the network completes final collection.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and persona-building: consistent with documented pig-butchering playbooks referenced in FBI and Secret Service guidance cited in coverage of this case, operators likely used purchased or scraped contact lists and messaging-app IDs to identify a target, then built a fabricated persona posing as an investment adviser tied to a well-known Taiwanese businessperson to lend borrowed authority before any contact was made.
Countering Stage 1: reconnaissance built on scraped contact data and a fabricated authority persona is very hard to intercept before contact; the realistic control is consumer education to treat unsolicited investment approaches from any new online contact, especially ones invoking a well-known name, with default skepticism regardless of how the contact was sourced.
2
Fraud infrastructure build-out: before or during the courtship, the network stood up a branded fake crypto trading platform, DAIQ, with a convincing dashboard and payout mechanics, and separately recruited and staged a rotating bench of physical money couriers, including Hsu, who told investigators he had already collected payments in Los Angeles, Seattle, Atlanta, and New York City, to move cash and gold across the US.
Countering Stage 2: look-alike fake trading platforms and mule and courier networks can be disrupted upstream through app-store and platform vetting, bank anti-money-laundering controls that flag unusual cash and gold-purchase patterns, and law-enforcement intelligence sharing on known courier tactics, per the FBI and Secret Service guidance cited in coverage of this case.
3
Initial contact and trust cultivation: in September 2025, operators reached the victim on the LINE messaging app, posing as investment advisers connected to the Taiwanese-businessperson persona, and spent several months building rapport before introducing any financial ask.
Countering Stage 3: users should independently verify any unsolicited investment adviser contact made through a messaging app rather than trusting a claimed tie to a well-known businessperson, and should be wary of relationships that begin on LINE, WhatsApp, or similar apps with strangers.
4
Fraudulent investment pitch: once trust was established, the operators steered the victim into DAIQ and promised guaranteed daily returns of 3 to 5 percent, a return profile no legitimate investment offers, to justify escalating deposits.
Countering Stage 4: guaranteed daily returns of 3 to 5 percent are a hard, well-publicized red flag; FBI and Secret Service guidance urges treating any guaranteed high-yield crypto pitch as fraud regardless of how credible the surrounding relationship feels.
5
Escalating multi-channel extraction: between October 2025 and March 2026 the victim was walked through progressively larger payments across three parallel channels: in-person cash handoffs in parking lots, wire transfers to domestic and international accounts, and gold bars shipped via FedEx and collected by couriers, funneling funds to Hsu and other couriers who reported to the Taiwan-based handler Jerry via messaging apps.
Countering Stage 5: banks and money-service businesses can flag and interdict escalating cash withdrawals, gold-bullion purchases, and international wires tied to a single new investment narrative; front-line staff trained to ask about crypto-investment pressure at large cash or gold transactions can catch this stage before funds are fully lost.
6
Withdrawal obstruction: when the victim tried to cash out in mid-March 2026, the platform demanded an additional fee before releasing funds, the standard pig-butchering mechanism for both squeezing further payment and delaying the victim's realization that the platform was fraudulent.
Countering Stage 6: a demand for extra fees to unlock a withdrawal should be treated as confirmation of fraud, not a solvable obstacle, and reported immediately to the FBI's Internet Crime Complaint Center, exactly the response that let this case reach law enforcement.
7
Payout and objective completion via the courier network: having already extracted $1,408,850, the operators directed a further $40,000 gold and cash collection through Hsu, part of the same pattern of routing physical assets through geographically dispersed couriers to move proceeds out of reach before any single collection point could be traced; this final leg is the one law enforcement intercepted.
Countering Stage 7: once a victim reports promptly, as happened here, law enforcement can use the still-pending final collection to stage a controlled handoff and intercept the courier before cash or gold leaves the country, which is precisely the interdiction that ended this case.
Quick Facts
Victim
Anonymized Austin, Texas resident, referred to in court records and reporting by the alias "Eduardo"
Location
Austin, Texas (South Austin, near West Slaughter Lane), USA; the victim, courier, and arrest were all in Austin, while the alleged network and its "Jerry" handler are described as Taiwan-based, and the courier had reportedly made prior collection trips to Los Angeles, Seattle, Atlanta, and New York City
Date
Initial contact September 2025; financial losses October 2025-March 2026; courier arrested April 13, 2026 (probable cause found April 14, 2026)
Impact
$1,408,850 total confirmed victim loss (reported by KXAN/Statesman as "more than $1.4 million"), accumulated via cash handoffs, wire transfers, and gold purchases between October 2025 and March 2026. The arrest sting itself was staged around a further $40,000 gold/cash exchange on April 13, 2026, which was never completed with the courier (he was detained before it changed hands).
Status
Confirmed
Case Type
Real-World Incident
Sector
Consumer / General Public, Cryptocurrency & Digital Assets
Threat Actor
Organized Crime
Related

Related Cases

Susie Wiles AI Voice Impersonation via Hacked Contact List (2025)

An unidentified impersonator used an AI-cloned voice and a hacked personal-contacts list to pose as White House Chief of Staff…

Incident 2025Read →

DOJ/IRS-CI Unseal $65M "Mistaken Refund" Elder-Fraud Indictments Against 28-Member Chinese Money-Laundering Ring

DOJ/IRS-CI unsealed four indictments charging 28 members of a Chinese organized-crime money-laundering ring tied to India-based "mistaken refund" call-center scams…

Incident 2025Read →

USPS/UPS "Package Awaiting Action" Smishing Kit Exposed via Censys DNS Investigation

Censys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation, exposing 682 rotating lookalike hostnames…

Incident 2026Read →