The U.S. Securities and Exchange Commission (SEC) has charged three purported crypto asset trading platforms—Morocoin Tech Corp., Berge Blockchain Technology Co. Ltd., and Cirkor Inc.—along with four investment clubs—AI Wealth Inc., Lane Wealth Inc., AI Investment Education Foundation Ltd., and Zenith Asset Tech Foundation—for orchestrating a fraudulent scheme that targeted retail investors through social media. According to the SEC, these entities misappropriated over $14 million by luring victims with advertisements and group chats that promised profits from AI-generated investment tips, ultimately convincing them to invest in fake crypto trading platforms where their funds were stolen. The operation used sophisticated tactics, including the use of automated trading bots to generate massive volumes of fake transactions, creating the illusion of legitimate trading activity.
This enforcement action is part of a broader regulatory crackdown on crypto-related fraud, with the SEC imposing a record $4.98 billion in cryptocurrency penalties in 2024 alone. The case highlights the growing threat of social media-driven investment scams and the SEC's commitment to pursuing securities fraud that harms retail investors. The agency's complaint details how the fraudsters built trust in online group chats, posed as financial professionals, and systematically exploited individuals interested in cryptocurrency investments, underscoring the need for heightened vigilance among potential investors and continued regulatory oversight in the digital asset space.

See the reporting duties and controls this puts on the clock.
7 events from the most recent confirmed update back to the earliest known activity.
Alongside the enforcement action, the SEC published an investor alert warning about the risks of relying on social media, messaging apps, and group chats for investment decisions. The warning highlighted tactics used in the alleged scheme, including fake experts and fraudulent trading platforms.
On December 22, 2025, the SEC announced charges against Morocoin Tech Corp., Berge Blockchain Technology Co. Ltd., Cirkor Inc., and four related investment clubs for allegedly orchestrating the $14 million fraud scheme. The agency filed the case in the U.S. District Court for the District of Colorado and sought injunctions, civil penalties, and disgorgement.
The SEC said the fraudulent activity ran from January 2024 until January 2025, when the alleged scheme concluded. Over that period, retail investors were defrauded through fictitious platforms, fake licenses, and manipulated account information.
By the time the case was reported, the companies named by the SEC had removed their websites and other online presence. This followed the operation of the alleged scam platforms and investment clubs.
According to the SEC, stolen investor funds were funneled through bank accounts and cryptocurrency wallets tied to China, Hong Kong, Indonesia, and other parts of Southeast Asia. Some of the misappropriated money was traced to overseas accounts as the scheme operated.
Throughout the scheme, investors were directed to purported crypto trading platforms and fake security token offerings where no real trading occurred. When victims tried to withdraw funds, they were allegedly told to pay additional fees such as margin calls or other advance charges, causing total losses of at least $14 million.
Beginning in January 2024, the defendants allegedly used social media ads and WhatsApp investment clubs to lure U.S. retail investors with promises of AI-generated trading tips, fake testimonials, and fictitious crypto trading opportunities.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See what this changes for your reporting obligations and which controls it puts on the clock.
4 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcetechrepublic.com
Open sourcetherecord.media
Open sourcesec.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.