Cryptocurrency scam: how Fidelilium secured the victim’s accounts and smartphone after a compromise
La situation
Everything started with financial‑education lessons shared via a WhatsApp group. The victim was following content presented as training on cryptocurrency and trading. Gradually, several PDF files were sent to her to complete this learning.
Continuing these exchanges, the group administrators asked the client to install an application called “vatradecoin” from a source outside Google’s official Play Store. The stated goal: to start investing and trading cryptocurrencies.
A few days later, to finalize her registration, the victim sent a photo ID together with her bank card. Shortly after, suspicious connections from Belgium were detected on her Binance account, which had been recently created and held about €1,000 worth of cryptocurrency.
The situation showed several typical warning signs of modern digital fraud: use of unofficial apps, social engineering, collection of personal information, and possible smartphone compromise.
Even though the financial loss was limited, the risk of the attack spreading to other online accounts was real. Email access, personal data, and phone‑linked accounts could also be exposed.
Ce que nous avons fait
Facing this situation, Fidelilium’s teams prioritized a swift intervention focused on cybersecurity, account security, and cleaning the compromised mobile device.
The first step was to verify the integrity of access to the Binance account as well as the associated email address. The teams analyzed sensitive settings that might have been altered: password, recovery addresses, login history, and logs of personal‑information changes.
Investigations confirmed multiple unusual connections on the night of 12 November 2024 from an unknown IP address located in Belgium. To limit any risk of sustained takeover, Fidelilium immediately proceeded to:
- reset passwords;
- enable two‑factor authentication via an Authenticator app;
- change the account’s recovery information;
- verify the integrity of associated email addresses.
The intervention then focused on the smartphone, considered the primary entry point of the compromise. A full data backup was performed before a total reset of the device. Essential apps and data were subsequently restored in a clean environment.
After securing the phone, a two‑factor authentication solution was configured to provide lasting protection for the sensitive accounts used by the client.
The Google and Samsung accounts linked to the smartphone also underwent a comprehensive security audit. Accesses were hardened with new passwords and the activation of multi‑factor authentication. Fidelilium also fixed a cloud‑storage saturation issue that was preventing proper email receipt, a technical detail that can become critical during account recovery.
Finally, an awareness‑building session was conducted to help the victim adopt better cybersecurity practices:
- choosing strong passwords;
- secure storage of credentials;
- importance of offline backups;
- vigilance regarding external applications;
- risks associated with unofficial platforms and sources.
The analysis also revealed that the client’s personal PC, still running Windows 10 and now outdated, should be replaced in the coming months to maintain an appropriate security level.
This intervention illustrates an increasingly common reality: cryptocurrency‑related attacks primarily target people. A single application installed outside official platforms can be enough to compromise accounts, personal data, and an entire digital environment.