Year on year, the number of criminal cases is growing in which fraudsters use cryptocurrency exchanges with a P2P module (e.g. Bybit, Binance P2P), stablecoins (e.g. USDT), and remote software to take control of victims' devices (AnyDesk, TeamViewer).
Such frauds are often initially classified as a typical fraud under Article 286 § 1 of the Polish Criminal Code, but during the analysis of the financial flows it turns out that part of the scheme is money laundering (Article 299 of the Criminal Code), in which so-called "money mules" also take part.
In such cases, the swift and correct securing of digital evidence is crucial, without which establishing the actual role of the individuals involved (victim, fraudster, intermediary) becomes very difficult or even impossible.
A typical Bybit P2P fraud scheme — a short example
1. The victim (often an elderly person) is contacted by a supposed investment adviser or an OLX seller.
2. Remote-access software (AnyDesk) is installed on the victim's phone, allowing the fraudster to log in to the victim's bank account themselves and make a transfer to the so-called mule's account.
3. The mule claims to be selling cryptocurrency through the P2P system on Bybit — accepts the money, withdraws it in cash or passes it on.
4. The victim does not know they were part of a "money-laundering chain", because they think they paid for an investment or a product.
Where the evidence is created and what should be secured
1. The victim's devices
- The phone or computer on which AnyDesk was installed.
- Browsing history, link history and cookies — they indicate whether the victim actually visited the Bybit platform.
- Bank SMS confirmations and authorisation codes — they prove who actually authorised the transfer.
2. The victim's bank account
- Bank statements with a full authorisation log.
- The login history for the online banking.
3. The mule's (defendant's) bank account
- A bank statement showing what they did with the money received.
- Evidence of onward transfer or cash withdrawal.
4. The P2P account on Bybit
- The history of P2P offers placed (USDT sales).
- Confirmations of the escrow lock and the release of the stablecoins.
- The transaction identifier in the exchange's system; the actual on-chain hash (publicly verifiable) is only created when funds are withdrawn from the exchange to an external wallet.
Failure to collect the above material makes it difficult to distinguish whether the defendant was actually a crypto seller or merely a channel for cashing out; it makes it impossible to confirm or refute the claim that the stablecoins were actually sent through the P2P platform; and it makes it impossible to prove that the victim actually intended to buy cryptocurrency — which is crucial for distinguishing between fraud (Article 286 of the Criminal Code) and money laundering (Article 299 of the Criminal Code).
In practice, this means it is harder for law enforcement to establish the actual classification of the offence — and the defendant's role may remain unexplained.
What should investigators do in such cases?
Immediately secure the victims' phones and computers — before further apps are installed and evidence is deleted.
Obtain logs from the bank — who authorised the transfers and from where.
Secure the P2P account on Bybit — demand from the platform:
- the login history,
- the offer history,
- the transaction identifier in the exchange's system (the on-chain hash is only created upon withdrawal to an external wallet),
- the correspondence in the P2P module (chat).
Examine the flow of funds — whether the funds actually went to a crypto wallet or were withdrawn in cash.
Properly securing digital evidence as early as the pre-trial stage makes it possible to distinguish the main fraudster from the intermediary (mule) and to verify whether the claim of an alleged sale of USDT stablecoins via P2P is true or serves as a line of defence. In the absence of technical evidence, the court often has to rely solely on the parties' statements, which can lead to an incorrect legal classification of the offence.
Collecting data from platforms such as Bybit P2P and from the blockchain is a standard, objectively verifiable technical path that should always be used.
A lack of diligence in securing digital evidence in cases involving P2P, stablecoins (USDT) and the remote takeover of a phone — can result in difficulty recovering the funds, a failure to hold the actual organisers of the fraud to account, and problems in establishing the defendant's role.