← Files C4 InvestigatorARCHIVED FILE

skills/c4-fake-trading-app-investigator/references/fake-trading-app-patterns.md

2.07 KB · Oct 7, 2026 · 00:29 UTC

↓ Download file

# Fake trading platform patterns

These are hypothesis prompts, not proof of fraud.

## Common scheme signals

- unsolicited contact followed by migration to a private messaging channel;
- claimed mentor, analyst, romantic interest, celebrity, or institutional affiliation;
- off-store APK, clone site, newly registered domain, or misleading store listing;
- dashboard profits not supported by independent broker, exchange, or blockchain records;
- small early withdrawal used to build confidence;
- deposits to changing personal accounts, mule accounts, UPI IDs, or crypto addresses;
- withdrawal blocked pending tax, verification, insurance, margin, security deposit, or liquidity fee;
- payment of one fee triggers another rather than release of funds;
- pressure, secrecy, remote-access requests, fabricated regulator documents, or support impersonation;
- reused text, images, domains, wallet addresses, phone numbers, or infrastructure across complaints.

## Evidence that may strengthen a fraud hypothesis

Independent payment records, server/app artifacts showing fabricated data, provider records, domain/app ownership links, controlled communications lawfully obtained, corroborating complaints, consistent infrastructure reuse, and traceable movement to services or actors can strengthen the assessment when properly sourced.

## Alternative explanations to test

A legitimate platform may impose documented compliance holds; an impersonator may misuse a genuine brand; a compromised victim device or account may alter communications; a wallet recipient may be a payment processor or exchange rather than an offender; and an inaccurate timeline or currency conversion may inflate the apparent loss.

## High-value distinctions

- displayed platform balance versus independently verified assets;
- trading loss versus induced transfer to an actor-controlled destination;
- platform operator versus recruiter, mule, exchanger, hosting provider, or unrelated service;
- identity claim versus verified subscriber, KYC, corporate, device, or provider record;
- common infrastructure versus exclusive control.

SHA-256: 286e01079f662beab67bc4fa19d7bf48ee954d44ece330d696138883d66329a7