Fake Hong Kong Health Tech Company Absconds with 1.6 Billion USDT, On-Chain Tracking Reveals Full Picture of the Scam

marsbitPublicado a 2026-04-09Actualizado a 2026-04-09

Resumen

BlockSec's on-chain investigation exposes VerilyHK, a fraudulent platform posing as a Hong Kong health-tech company, which processed approximately $1.6 billion USDT over 16 months via the TRON network. The scheme employed a sophisticated, multi-layered infrastructure: 8 generations of receiving hot wallets, 79 intermediate addresses, and 3 generations of paired withdrawal channels. Funds were systematically funneled through thousands of disposable addresses before converging into a single centralized exchange. The operation also revealed ties to the Cambodia-based Huione Group, sanctioned by FinCEN for money laundering. This industrial-scale routing structure highlights advanced evasion tactics, including timed wallet rotations and segregated transaction pathways, underscoring the need for enhanced compliance detection of structured crypto fraud.

Author: BlockSec

Compiled by: Deep Tide TechFlow

Deep Tide Introduction: Blockchain security company BlockSec conducted a complete on-chain fund tracking of VerilyHK, a Ponzi platform disguised as a Hong Kong health technology company. Over 16 months, the platform processed approximately $1.6 billion USDT cumulatively through the TRON network, using 8 generations of receiving hot wallets, 79 intermediate addresses, and 3 generations of paired withdrawal channels to build an industrial-grade fund routing infrastructure, ultimately funneling funds into the same centralized exchange. The fund flow chain also involves the Cambodia-based Huione Group, which is sanctioned by FinCEN.

Key Findings: A platform disguised as a Hong Kong health tech group cumulatively circulated approximately $1.6 billion USDT through the TRON network over 16 months. This is an upper-limit figure that includes potential internal fund recycling. On-chain analysis reveals an industrialized fund routing infrastructure: 8 generations of receiving hot wallets, 79 intermediate transit addresses, 3 generations of paired withdrawal channels (with second-level switching), and a shared exchange exit fed by tens of thousands of suspected deposit addresses. This article fully reconstructs the entire link topology from victim deposits to exchange withdrawals.

Background

VerilyHK presented itself externally as a legitimate Hong Kong health technology investment platform. The name itself is suspiciously similar to well-known entities: one is Verily Life Sciences, a precision health company under Alphabet, focusing on AI-driven healthcare and medical devices; the other is an A-share listed environmental engineering company (stock code: 300190), which has nothing to do with health tech or cryptocurrency. VerilyHK's website copy claimed expertise in AI health, big data analysis, and medical devices, almost directly copying the public positioning of the real Verily. Its marketing rhetoric also kept changing—from immune cell therapy and portable ECG devices to AI health, health credit systems, data asset tokenization, and even claiming to have obtained Hong Kong Securities and Futures Commission (SFC) Type 4 (securities advisory) and Type 9 (asset management) licenses.

Caption: A snapshot of verilyhk.com on Wayback Machine, showing the platform's "About Us" page, claiming to provide health management solutions through AI, big data, and medical devices

In April 2025, the Heshan District government issued a risk warning,明确指出该项目具有「明显的传销和非法集资特征」,并依赖「境外加密货币交易」 (clearly stating that the project had "obvious characteristics of pyramid selling and illegal fundraising" and relied on "overseas cryptocurrency transactions"). By the end of April 2025, multiple anti-fraud monitoring platforms issued crash warnings. The platform ceased operations in February 2026.

Based on the approximately $1.6 billion in on-chain transaction volume, VerilyHK's scale far exceeds other crypto Ponzi schemes that have been pursued by regulators, including Forsage ($300 million, sued by SEC) and NovaTech ($650 million, SEC lawsuit). But until now, there has been no public on-chain analysis dissecting this crypto criminal operation.

This article does not rely on the aforementioned public warnings to draw conclusions. All content below is based on on-chain data analysis of TRON USDT stablecoin flows related to this platform, layer by layer还原其内部基础设施的真实面貌 (restoring the true appearance of its internal infrastructure).

Starting Point

The investigation began with two TRON addresses provided by a victim: one deposit address and one withdrawal address. Tracing the connection between the two revealed not just a single path, but an entire multi-level, multi-generational fund routing network.

Receiving Layer: 8 Generations of Hot Wallets Rotated Over 16 Months

VerilyHK did not rely on fixed receiving addresses. It used at least 15 addresses, organized into 8 distinct generations, rotated in chronological order over a 16-month period from October 2024 to February 2026.

These addresses did not operate in parallel. They formed a relay chain: the end date of one generation precisely matched the start date of the next. This day-precise handover pattern recurred across all 8 transitions. Beyond the handover timing, adjacent generations also shared most of the deposit address network, with an overlap rate exceeding 65%, confirming they were operated by the same entity, just rotating new wallets.

The transaction volume processed by each generation grew sharply over time. Early generations handled tens of millions of dollars monthly, but by the sixth generation, volumes had reached the hundreds of millions level. The final generation processed over $900 million in less than 4 months. The cumulative transaction volume across all generations was approximately $1.6 billion.

But these figures should be considered upper-bound references, not net user deposits. They come from complete graph aggregation,包含潜在的内部转账 (including potential internal transfers). In a Ponzi structure, "returns" paid to users might be reinvested, causing the same funds to be counted multiple times in the receiving layer. The transaction volume explosion in later stages likely reflects both real growth and increasingly intense internal fund recycling.

Caption: Receiving layer timeline, showing transaction volume climbing from $3 million to $906 million across 8 generations of hot wallets

Intermediate Layer: 79 Transit Addresses Converge to Known Hubs

Funds leaving the receiving hot wallets did not go directly to the withdrawal layer. They passed through 79 intermediate transit addresses, each with very few incoming sources, more outgoing targets, and a net retention close to zero. Over 80% of the transiting funds ultimately converged on a few identified withdrawal channel hubs.

Caption: Intermediate layer fund flow: from receiving hot wallets through transit addresses converging to identified withdrawal hubs

Most of these funds flowed towards the withdrawal layer, but one node stood out. A cross-generational hub received funds from 75% of the intermediate addresses, spanning 6 of the 8 receiving generations, accumulating about $240 million. But its downstream structure was明显不同 (clearly different) from the identified withdrawal channels.

On-chain tracking revealed direct fund connections between this hub and multiple wallet addresses of the Huione Group. Huione is a Cambodian financial group placed on the US FinCEN list prohibiting access to the US financial system. On the incoming side, at least 4 Huione Group hot wallets transferred about $4.6 million to this hub through a chain of intermediate addresses (minimum 5 hops). On the outgoing side, the hub directly transferred funds to at least 2 Huione Group deposit addresses, amounting to $4,200 and $1.5 million respectively.

The fund flow between this cross-generational hub and Huione indicates that VerilyHK's fund routing infrastructure may have utilized Huione's network as a money laundering channel. This aligns with FinCEN's designation of Huione as a "key node for laundering money from virtual currency investment scams".

Caption: Fund flow between the cross-generational hub and the sanctioned Huione Group's hot wallets and deposit addresses

Withdrawal Layer: From Paired Channels to Shared Exchange Exit

The generational structure on the withdrawal side mirrored the receiving side exactly. Three generations of withdrawal addresses were identified, with a total withdrawal volume of approximately $1.1 billion. Like the receiving layer, the切换精确到秒 (switching between generations was precise to the second): on-chain timestamps show the second-generation channel stopping and the third-generation channel starting at the exact same moment. This pattern is difficult to explain by anything other than a preset switching plan by the same operating team.

Within each generation, the architecture followed a consistent pattern: dedicated bridge addresses first aggregated funds from the intermediate layer, then forwarded them to a pair of parallel withdrawal channels—one primary, one secondary. The start times for each pair differed by minutes, the stop times by seconds, but one channel's processing volume was always significantly higher than the other's. This "bridge → paired withdrawal" structure recurred across all three generations, proving it was a designed infrastructure, not temporarily created wallets.

Caption: Withdrawal layer showing 3 generations of paired channels, each with largely independent downstream networks,最终汇聚于共享交易所出口 (ultimately converging on a shared exchange exit)

A closer look at the third-generation paired channels shows this separation more clearly. One channel's processing volume was about 2.6 times that of the other. Comparing the top 100 large downstream counterparts for both, the overlap rate was zero. Although supplied by the same upstream source and running concurrently, they operated completely independent downstream distribution networks.

What the two lines truly shared was the final exit. In their small downstream transfers, both lines showed the same pattern: funds flowed through tens of thousands of one-time addresses (each with almost only one incoming and one outgoing transaction),最终汇入同一个主要中心化交易所 (CEX) 的热钱包 (ultimately converging into the same primary centralized exchange (CEX) hot wallet). But even here, the two sets of deposit address intermediaries were almost completely independent—only 9 shared addresses out of approximately 60,000, like two separate pipelines feeding into the same exchange. On-chain data confirms the funds entered the exchange's processing pipeline, but cannot identify the specific user accounts behind these deposits.

Full Picture: Four-Layer Funnel

Summarizing all findings, VerilyHK's on-chain fund routing architecture formed a clear four-stage funnel: extremely dispersed at the front end, highly concentrated in the middle, dispersed again at the withdrawal layer, and finally exiting through the exchange.

Caption: VerilyHK's four-layer funnel architecture—Deposit Layer, Receiving Layer, Intermediate Layer, Bridge Layer, Dual-Line Withdrawal, Exchange Exit

Most striking is the huge transaction volume (cumulative ~$1.6 billion on-chain fund flow) and the sophistication of the underlying infrastructure: day-precise generational handovers, paired withdrawal channels with基本独立的下游网络 (largely independent downstream networks), tens of thousands of one-time addresses converging into a shared exchange exit.

For exchange compliance teams, the structural features documented here constitute actionable detection heuristic indicators, especially the pattern of tens of thousands of one-time deposit addresses converging to the same hot wallet. For investigators and regulators, this layered architecture illustrates why tracking illicit funds requires going beyond single transactions to reconstruct the complete network topology.

All on-chain analysis in this article was completed using the MetaSleuth on-chain analysis tool, part of BlockSec's anti-money laundering and compliance suite. The analysis follows the Highest Value Path methodology, with all conclusions annotated for evidence strength and applicability boundaries.

Preguntas relacionadas

QWhat was the total amount of USDT processed by the VerilyHK platform over 16 months, and on which blockchain network?

AThe VerilyHK platform processed approximately 1.6 billion USDT over 16 months on the TRON network.

QHow many generations of hot wallets did VerilyHK use for receiving funds, and what was a key characteristic of their operation?

AVerilyHK used 8 generations of hot wallets for receiving funds, which were rotated in a strict, sequential order with precise day-level handover dates between generations.

QWhich sanctioned financial group was the VerilyHK platform's funds linked to through a cross-generational hub, and what was the nature of this link?

AFunds were linked to the Huione Group, a Cambodian financial group sanctioned by FinCEN. A cross-generational hub received funds from and sent funds to Huione Group wallets, indicating the platform's infrastructure potentially used Huione's network for money laundering.

QDescribe the structure of the withdrawal layer and its key feature for obfuscating the final destination of funds.

AThe withdrawal layer consisted of 3 generations of paired channels (a main and a secondary line). Each pair, fed by a dedicated bridge address, operated with largely independent downstream networks. However, both lines in a pair ultimately funneled funds through tens of thousands of one-time deposit addresses into the same centralised exchange (CEX) hot wallet, creating a shared final exit.

QWhat are the four main layers of VerilyHK's fund routing infrastructure as described in the 'Panorama: Four-Tier Funnel' section?

AThe four main layers are: 1) The充值层 (Deposit Layer) with numerous user addresses, 2) The收款层 (Receiving Layer) with generational hot wallets, 3) The中间层 (Middle Layer) with transit addresses, and 4) The桥接层/出金层 (Bridge/Withdrawal Layer) with paired channels leading to the shared CEX exit.

Lecturas Relacionadas

KOL's Perspective: Why Is SOL Set to Rise from This Point?

**Summary: Why SOL is Positioned for Growth at This Level** The article argues that SOL is poised for an upward move from its current price point, citing several key factors. Primarily, SOL has just broken out of a 4-month consolidation phase. This breakout signals a return of risk appetite to the broader crypto market, as SOL is seen as a key indicator of overall crypto health. The token's ownership has reportedly shifted from short-term traders and tourists to long-term accumulators, leading to low volume. Any meaningful increase in trading activity could thus trigger significant upward momentum. Fundamental strengths include strong institutional adoption, integration with DeFi and RWAs (Real-World Assets), and the potential benefits from the Clarity Act. Despite its high volatility—having dropped 70% from its all-time high but still up 12x from its bear market low—SOL is highlighted as one of the few tokens from the last cycle to reach new highs. It boasts a robust ecosystem of applications, users, and protocols. Future catalysts include the expected influx of AI developers following the Miami Accelerate conference, which focused on AI on Solana. Furthermore, Solana is positioned as the premier chain for memecoin activity, a trend expected to continue and drive network usage and fees. The article concludes that recent price action reflects a healthy transfer to long-term holders, setting the stage for growth.

marsbitHace 10 min(s)

KOL's Perspective: Why Is SOL Set to Rise from This Point?

marsbitHace 10 min(s)

Those Pre-Bitcoin PoW Protocols Have Recently Been Reimplemented

This article details a recent surge in replicating pre-Bitcoin Proof-of-Work (PoW) protocols, specifically focusing on Hal Finney's 2004 RPOW (Reusable Proofs of Work). Within five days in May 2026, multiple independent builders in the Bitcoin/cypherpunk community launched projects inspired by this early electronic cash proposal. The initiative began with Fred Krueger's `rpow2.com`, a centralized but auditable system that replaced RPOW's original IBM 4758 hardware with Ed25519 signatures. Initially a faithful replica, it later adopted Bitcoin-like features (21M supply cap, difficulty adjustment) and a controversial 5.24% founder allocation. This sparked rapid forks, including `rpow4.com` which incorporated full Bitcoin parameters, a prediction market (`rpowmarket.com`), and a DEX (`rpow2swap.com`). Concurrently, Mike In Space created a prototype of Wei Dai's 1998 b-money proposal (`b-money.replit.app`), pushing the historical exploration even further back. The article contrasts these centralized, server-dependent experiments with Bitcoin's core innovation of decentralized, trustless consensus. It also highlights a parallel development: the `HASH` project on Ethereum, which uses smart contract hooks to enable a purely fair-launch, browser-mineable PoW token with 0% allocations to team or VCs. The collective activity is framed as a meme-driven, educational exploration of cypherpunk history rather than a serious financial movement, with all projects heavily disclaiming any investment value.

marsbitHace 14 min(s)

Those Pre-Bitcoin PoW Protocols Have Recently Been Reimplemented

marsbitHace 14 min(s)

South Korean Exchanges 'Battle' Regulators, Challenging the Boundaries of Enforcement and Legislation

South Korea's cryptocurrency industry is engaged in a rare, direct confrontation with regulators. The Financial Intelligence Unit (FIU), the primary anti-money laundering (AML) watchdog, has recently imposed heavy penalties on major exchanges like Upbit and Bithumb for alleged violations involving unregistered overseas VASPs and AML procedures. However, exchanges are now actively challenging these actions in court and through industry associations. In a significant shift, the Seoul Administrative Court ruled in favor of Upbit's operator, Dunamu, overturning part of an FIU-ordered business suspension. The court found the FIU's penalty criteria and justification insufficiently clear. Similarly, the court suspended the enforcement of a six-month business suspension against Bithumb pending a final ruling, citing potential irreversible harm to the exchange. Beyond legal battles, the industry is contesting proposed legislative amendments. The Digital Asset eXchange Alliance (DAXA) strongly opposes a draft rule that would mandate Suspicious Transaction Reports (STRs) for all crypto transfers over 10 million KRW (~$6,800). DAXA argues this "poison pill" clause violates legal principles and would overwhelm the STR system, increasing reports from 63,000 to an estimated 5.45 million annually for major exchanges, thereby crippling effective AML monitoring. This conflict highlights a structural tension in South Korea's crypto governance: comprehensive digital asset laws are still developing, while regulators rely heavily on AML enforcement. The industry's move from passive compliance to active legal and legislative challenges signifies a new phase, pressing for clearer rules and more proportionate enforcement. While short-term disputes may intensify, this clash could ultimately lead to a more mature and sustainable regulatory framework for South Korea's vibrant crypto market.

marsbitHace 1 hora(s)

South Korean Exchanges 'Battle' Regulators, Challenging the Boundaries of Enforcement and Legislation

marsbitHace 1 hora(s)

After 50x Storage Surge, Justin Sun Always Looks to the Next Decade

Sun Yuchen, known for his controversial stunts like a $30 million lunch with Warren Buffett (canceled due to a kidney stone) and eating a $6.2 million duct-taped banana, is often overshadowed by a significant fact: his decade-long track record of spotting major investment trends. In 2016, he famously advised young people to invest in Bitcoin, Nvidia, Tesla, and Tencent instead of buying property. A hypothetical $20,000 investment in Nvidia and Tesla from that list would now be worth over 50 million RMB. His latest major call was on November 6, 2025, predicting a "50x storage opportunity" tied to the AI boom, which materialized with Sandisk's stock surging nearly 50-fold by 2026. Looking ahead, Sun now focuses on the next frontier: Physical AI. He identifies four key areas: 1. **Embodied AI/Robotics**: He sees this reaching its "iPhone moment," with companies like UBTech and Galaxy General leading in commercialization. 2. **Drones**: Viewed as the first commercially viable form of Physical AI, revolutionizing sectors from warfare (e.g., AeroVironment's Switchblade) to logistics. 3. **Spatial Computing**: Beyond VR, it's about AI understanding physical space, a foundational technology for robotics and autonomous systems, exemplified by Apple's Vision Pro. 4. **Space Exploration**: After a 2025 suborbital flight with Blue Origin, Sun advocates for space as the ultimate frontier, discussing blockchain's potential role in space asset management and data transactions. His investment philosophy involves betting on entire, inevitable trends rather than single companies. For robotics, he sees Tesla (the body/manufacturer) and Nvidia (the brain/AI platform) as complementary plays. In defense drones, he highlights companies making tanks obsolete (AeroVironment) and those augmenting fighter jets (Kratos). For space, he participated in Blue Origin's flight and anticipates SpaceX's potential IPO to redefine the sector's valuation. Sun Yuchen's vision frames the next two decades not as a revolution in information flow (like the internet), but in the fundamental operation of the physical world through AI-powered robots, autonomous systems, and spatial intelligence, ultimately extending human and AI activity into space. While many still focus on conventional assets, he continues to look toward the next technological horizon.

marsbitHace 2 hora(s)

After 50x Storage Surge, Justin Sun Always Looks to the Next Decade

marsbitHace 2 hora(s)

Trading

Spot
Futuros
活动图片