Case Library / Smishing (SMS Phishing) / SEC v. NanoBit: WhatsApp Pig-Butchering Scam Impersonating Finance Professionals

SEC v. NanoBit: WhatsApp Pig-Butchering Scam Impersonating Finance Professionals

Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors into a fake crypto trading platform, NanoBit, wiring over $2 million to Hong Kong before the SEC secured a $5.5 million default judgment in one of its first pig-butchering enforcement actions.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Between approximately September/October 2023 and June 2024, scheme participants used at least seven WhatsApp groups to impersonate financial-industry professionals and cultivate trust with U.S. retail investors before steering them into "NanoBit," a purported cryptocurrency trading platform that in reality executed no real trades and falsely claimed an SEC-registered brokerage affiliate ("NanobitUS Securities"). The SEC's complaint alleges at least 18 investors lost a combined ~$967,835 in crypto and fiat, with more than $2 million ultimately wired by the scheme's shell-company conduits to bank accounts in Hong Kong. The case, SEC v. NanoBit Limited et al. (E.D.N.Y., No. 2:24-cv-06517), was among the SEC's first enforcement actions explicitly targeting this "relationship investment"/pig-butchering fraud model, and culminated in a June 16, 2026 default judgment of $5,518,902 against six of the seven defendants.

How the Attack Worked

Scheme participants added or drew targets into at least seven WhatsApp groups (examples named in the complaint: "VIP8012," "VIP34") where they posed as financial-industry professionals, including personas the complaint calls "Pseudo-Director A" and "Pseudo-Director B," each impersonating a real senior investment professional, and supported by fake assistants and other planted group members who reinforced the illusion of a thriving trading community. Over time this built rapport and credibility (the classic "fattening" phase of pig butchering) before participants steered members toward a purported crypto trading platform, NanoBit (previously hosted at NanoBitUS.com). To allay safety concerns, NanoBit falsely claimed its affiliate "NanobitUS Securities" was an SEC-registered broker-dealer, and the in-group "professionals" touted fake initial coin offerings, including "Cosmic Energy" and "VTrade," complete with counterfeit downloadable whitepapers, promising outsized returns. In reality no trades were ever executed on the platform: the trading interface was fabricated. When victims tried to withdraw funds, they were stalled with undisclosed "miner's fees" (one investor was told he owed $10,692 in "Ghana miners fees" before his withdrawal could be processed), told other members had successfully cashed out only after paying such fees, or simply removed from the WhatsApp group when they pushed back (the complaint cites one investor removed from "VIP8012" on March 11, 2024 after calling the scheme a fraud). Investor money was funneled through entity defendants: Radiant Horizons Limited allegedly wired over $2 million to Hong Kong bank accounts (e.g., $145,690 on Jan. 17, 2024 and $127,638 on Jan. 18, 2024), while crypto contributions went to unhosted wallet addresses, and Sweet Karma Fashion Inc. and Zhao Tropical Deli Inc. (unrelated-sounding small-business entities) served as fiat "mule" conduits.

The Lure & the Tell

The lure: strangers added victims to (or drew them into) WhatsApp "VIP" investment groups populated by seemingly successful traders and a warm, patient "senior director" figure who built a personal rapport before ever mentioning money, then vouched for a slick-looking crypto trading platform and a supposedly SEC-registered brokerage affiliate. The tell: legitimate SEC-registered brokers and investment professionals do not recruit clients through unsolicited WhatsApp group additions, group chats are not a substitute for verifying registration on Investor.gov/EDGAR, and any platform that invents new "fees" (like undisclosed miner's fees) specifically at the moment of withdrawal, or that removes a member from the group for asking hard questions, is exhibiting the textbook signature of pig-butchering fraud rather than a functioning trading venue.

Outcome

The SEC filed its civil enforcement complaint on September 17, 2024 in EDNY (SEC v. NanoBit Limited et al., No. 2:24-cv-06517), charging four entities (NanoBit Limited, Radiant Horizons Limited, Sweet Karma Fashion Inc., Zhao Tropical Deli Inc.) and three individuals (Jiajie Liu, Fei Liao, Hua Zhao) with violating the antifraud provisions of the Securities Act and Exchange Act (Section 17(a), Section 10(b)/Rule 10b-5). On June 16, 2026, the EDNY court entered a final default judgment against six of the seven defendants (all except Fei Liao, who was named in the original complaint but was not part of the default judgment), permanently enjoining them from further securities-law violations and ordering a combined $5,518,902 in disgorgement, prejudgment interest, and civil penalties. Liu and Zhao were further restricted to trading only in their own personal accounts. The SEC announced the judgment via Litigation Release No. 26576 on June 29, 2026.

Why It Matters

This is one of the SEC's first enforcement actions explicitly built around the "pig-butchering" / relationship-investment fraud model, showing that U.S. securities regulators now treat WhatsApp-group crypto scams as a distinct, prosecutable pattern rather than ordinary fraud. It illustrates how the technique blends classic long-con social engineering (patient trust-building via impersonated authority figures and a fabricated peer community) with securities-fraud tactics (a fake registered-broker claim, fake ICOs) to bypass the skepticism investors typically reserve for cold outreach. It also highlights the enforcement gap in this crime type: even a full $5.5 million default judgment is a paper win when the underlying funds have already been wired to Hong Kong and the responsible individuals may be judgment-proof or unreachable, meaning victim restitution is far from guaranteed. Finally, it validates that seemingly "boring" WhatsApp group chats revolving around finance/investing content are an active, regulator-recognized attack surface for retail investors.

Defenses

SEC's own investor alert (issued with this case, in collaboration with CFTC, FINRA, and NASAA) advises: never rely solely on information from group chats to make investment decisions; independently verify any broker-dealer's registration status via Investor.gov/SEC EDGAR rather than trusting an in-group claim of being "SEC-registered"; be suspicious of unsolicited additions to investment-themed WhatsApp/Telegram groups by strangers; treat any request for extra fees (e.g., "miner's fees") to unlock a withdrawal as a hard stop, not a hurdle to pay; and note that being removed from a group chat after questioning returns or fees is itself a fraud indicator. Financial institutions and messaging platforms are encouraged to flag patterns of newly-added contacts steering users toward off-platform "trading" links.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Infrastructure setup: Scheme participants likely registered shell companies (e.g. Sweet Karma Fashion Inc., Zhao Tropical Deli Inc.) to serve as fiat mule accounts, stood up the fake NanoBit trading platform and dashboard, prepared counterfeit ICO whitepapers, and sourced WhatsApp numbers, consistent with the infrastructure named in the SEC complaint.
Countering Stage 1: Shell-company formation and fake trading-platform builds are hard to intercept pre-launch; the realistic control sits with banks screening newly formed small-business accounts for mule-like deposit/withdrawal patterns once money starts moving, addressed at Stage 7.
2
Target/persona research: Per the SEC complaint, at least one persona ('Pseudo-Director A') borrowed the name and title of a real managing director at a legitimate global investment firm, indicating some OSINT on real financial-industry professionals to make the impersonation credible.
Countering Stage 2: Public professional profiles used for persona-borrowing are difficult to lock down at scale; the more effective control is verifying any individual's registration and firm affiliation directly on Investor.gov/SEC EDGAR rather than trusting the name and title as presented in a chat.
3
Initial contact: Scheme participants added or drew targets into private WhatsApp 'VIP' investment groups, with the SEC noting some investors were first solicited via other social media apps before being funneled into the groups.
Countering Stage 3: Treat unsolicited additions to investment-themed WhatsApp/Telegram groups by strangers as a default red flag, and decline to engage rather than waiting to see where the group leads.
4
Trust-building ('fattening'): Impersonated senior professionals, backed by planted fake assistants and other fabricated group members, gave real-sounding investment commentary over an extended period to build rapport and the appearance of a thriving trading community before ever discussing money.
Countering Stage 4: Recognize patient, no-pitch rapport-building in an investment-themed group chat as a known pig-butchering pattern in itself, per the SEC's investor alert, and avoid making investment decisions based on group-chat relationships regardless of how genuine they feel.
5
False legitimacy pitch: The group steered members toward the NanoBit platform, falsely claiming its affiliate 'NanobitUS Securities' was an SEC-registered broker-dealer tied to reputable firms, to defeat the skepticism a cold pitch would normally trigger.
Countering Stage 5: Independently verify any broker-dealer's registration status on Investor.gov/SEC EDGAR before funding an account; this single check would have exposed NanobitUS Securities as unregistered.
6
Escalation via fake ICOs: In-group 'professionals' touted fake initial coin offerings (named in reporting as 'Cosmic Energy' and 'VTrade'), backed by counterfeit whitepapers, to induce larger investments beyond the initial deposit.
Countering Stage 6: Apply the same registration/legitimacy check to any touted ICO or token before investing further, and treat a slick whitepaper alone as no substitute for verifiable registration or an independently confirmed trading history.
7
Fund extraction: Victims wired fiat and transferred crypto into the scheme; funds were routed through the shell 'mule' entities to bank accounts in Hong Kong and into unhosted crypto wallets rather than any real trading activity.
Countering Stage 7: Banks and crypto platforms can flag newly opened small-business accounts receiving many unrelated incoming wires followed quickly by large outbound transfers to overseas accounts, a recognizable mule-account signature.
8
Withdrawal stalling: When victims tried to cash out, they were charged undisclosed fees invented on the spot (e.g. one investor was told he owed $10,692 in 'Ghana miners fees') and told other members had only succeeded after paying similar fees.
Countering Stage 8: Treat any new or undisclosed fee demanded to unlock a withdrawal as a hard stop rather than a cost of doing business, per SEC/CFTC/FINRA/NASAA guidance issued alongside this case.
9
Victim silencing and payout completion: Investors who pushed back or called the platform fraudulent were removed from the WhatsApp group, cutting off further contact while the already-diverted funds remained with scheme participants overseas, completing the theft.
Countering Stage 9: Being removed from a group chat for questioning legitimacy is itself a fraud indicator that should trigger an immediate report to the SEC, FINRA, or state regulators; once funds reach overseas banks or unhosted wallets, recovery depends on cross-border law-enforcement asset tracing, which this case shows is slow and only partially effective given the still-uncollected judgment.
Quick Facts
Victim
At least 18 U.S. retail investors solicited and defrauded through WhatsApp investment groups
Location
Victims: at least 18 U.S. retail investors. Funds routed to bank accounts in Hong Kong. Case litigated in the U.S. District Court for the Eastern District of New York.
Date
Scheme ran ~September/October 2023 to June 2024 (the SEC's two litigation releases give slightly different start-date estimates); SEC complaint filed September 17, 2024; default judgment entered June 16, 2026 (SEC announced June 29, 2026)
Impact
SEC complaint alleged at least 18 investors lost a combined ~$967,835 in crypto assets and fiat currency; of this, scheme participants allegedly wired more than $2 million (aggregate, including co-mingled funds beyond the 18 named victims) to bank accounts in Hong Kong and moved roughly $725,335 in crypto to three unhosted wallet addresses, with about $242,500 in fiat received by "money mule" corporate defendants. The June 16, 2026 default judgment ordered a combined $5,518,902 in disgorgement, prejudgment interest, and civil penalties across six defendants (NanoBit Limited: $1,796,857; Radiant Horizons Limited: $1,182,251; Zhao Tropical Deli Inc.: $1,182,251; Sweet Karma Fashion Inc.: $1,182,251; Jiajie Liu: $120,088; Hua Zhao: $55,204). This is a court-ordered judgment amount, not confirmed actual recovery/collection from defendants believed to be overseas.
Status
Confirmed
Case Type
Real-World Incident
Sector
Cryptocurrency & Digital Assets, Financial Services & Insurance, Retail & E-commerce
Threat Actor
Organized Crime
Related

Related Cases

Retool smishing + deepfake vishing breach (2023)

A smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA…

Incident 2023Read →

Nationwide Toll-Road Smishing Wave (E-ZPass, SunPass, PA Turnpike, MassDOT, NTTA, Peach Pass)

A mass SMS phishing campaign impersonating dozens of U.S. toll agencies spoofed 'unpaid toll' notices to harvest payment card and…

Incident 2024Read →

Microsoft LAPSUS$ / DEV-0537 Source-Code Intrusion (2022)

A single compromised Microsoft employee account gave LAPSUS$ (DEV-0537) "limited access" to an Azure DevOps repository, from which the group…

Incident 2022Read →