The digital economy, fueled by the promise of decentralized finance and rapid wealth generation, has regrettably attracted sophisticated criminal enterprises seeking to exploit both technological complexity and human trust. A recent, massive enforcement action by the U.S. government against a Philippines-based technology firm, Funnull Technology Inc., and its administrator, Liu Lizhi, has exposed the core operational infrastructure supporting some of the world’s most costly and psychologically devastating financial frauds: “pig butchering” (or romance baiting) scams. These scams have resulted in U.S. victim-reported losses exceeding $200 million. The operation of Funnull demonstrates a dangerous evolution in cybercrime—the industrialization of fraud infrastructure, transforming isolated attacks into a massive, global digital ecosystem of deceit.
SCAM MECHANISM
The core strength of the criminal enterprise relying on Funnull was not the cryptocurrency mechanism itself, but the technical ability to create the illusion of legitimacy on an unparalleled scale. Funnull Technology Inc., headquartered in Taguig, Philippines, functioned as a massive cybercrime platform, directly facilitating the majority of virtual currency investment scam sites reported to the Federal Bureau of Investigation (FBI). Security researchers identified Funnull as a central player in a network codenamed the “Triad Nexus,” which alone encompasses over 332,000 unique domains or hostnames.
Funnull specialized in “infrastructure laundering,” a practice where legitimate digital resources are acquired and then funneled directly to criminal organizations. Specifically, Funnull enabled these virtual currency investment scams by purchasing vast quantities of IP addresses and hosting services in bulk from major, legitimate cloud service providers worldwide, including entities in the United States. These IP addresses were then sold to cybercriminals to host malicious web content and fraudulent investment platforms.
The sophistication of this service extended beyond mere hosting:
- Domain Generation and Impersonation: Funnull provided services to generate domain names for websites hosted on its purchased IP addresses using Domain Generation Algorithms (DGAs). These DGAs create a large volume of similar but unique names for websites. Coupled with providing web design templates to cybercriminals, this made it easier for scammers to impersonate trusted brands and create websites that appeared to be legitimate financial services.
- Evasion Tactics: This combination of bulk IP hosting and DGA naming allowed cybercriminals to quickly and efficiently change their operations to different domains and IP addresses whenever legitimate providers or security agencies attempted to shut down the fraudulent sites. The FBI observed multiple patterns of IP address activity between October 2023 and April 2025, including the simultaneous migration of hundreds of domains using Funnull infrastructure from one IP address to another on the exact same day.
- Supply Chain Attack: Further showcasing its malicious intent, Funnull purchased a repository of code—the widely-used Polyfill.io JavaScript library—in 2024. Funnull maliciously altered this code to redirect visitors of legitimate websites using the library to their scam websites or online gambling sites. Some of these redirected sites were allegedly linked to Chinese criminal money laundering operations.
By creating this technical layer of deceit, Funnull became the operational backbone enabling criminals, often organized groups based in Southeast Asia, to carry out the complex, high-volume “pig butchering” schemes.
CASE SUMMARY: PROJECT OVERVIEW AND COLLAPSE

Pig butchering scams, which originated in China, rely heavily on psychological manipulation to convince victims to invest substantial sums into fake cryptocurrency platforms. The name derives from the practice of “fattening up the pig” (the victim) with false promises of high returns before “butchering” them by stealing all the funds.
The process begins with scammers establishing contact, often through social media or dating apps, using fictitious identities to pose as potential friends or romantic partners. These perpetrators, sometimes victims of labor trafficking themselves, use elaborate storylines to gain trust. Modern iterations of the scam now leverage generative AI tools to improve outreach and make the communication more believable.
Once trust is established, the victim is convinced to invest in virtual currency via a platform hosted by Funnull’s infrastructure. These fake platforms are designed to mimic legitimate financial services, initially showing significant, fabricated returns to encourage the victim to invest larger and larger amounts—the “fattening” stage. When the victim is unable or unwilling to invest more, the scammer abruptly severs all communication, taking the entire investment with them.
The collapse of this specific infrastructure network was triggered by the U.S. government’s decisive action on May 29, 2025. The U.S. Treasury, the Department of State, and the FBI collectively flagged the activities of Funnull and its administrator Liu Lizhi. This coordinated action effectively targeted the infrastructural support that allowed the fraud to proliferate at scale.
WARNING SIGNS (RED FLAGS)
While the fraudulent platforms created using Funnull’s infrastructure often looked professional, the method of engagement—pig butchering—presents clear, recurring warning signs that the crypto-interested public must heed:
- Unsolicited Contact via Personal Channels: Victims are typically lured through social media or dating apps by individuals they have never met. The relationship develops quickly, often moving from a casual connection to an intense, personalized connection intended to build rapport and trust quickly.
- Mixing Romance/Friendship with Financial Advice: The core red flag is when a new acquaintance—especially a romantic one—insists or strongly encourages investing in a specific, unfamiliar, high-return cryptocurrency or financial platform.
- Fake Investment Platforms Mimicking Legitimacy: The platforms used are not well-known exchanges but fake websites designed to look like legitimate trading apps. These platforms falsely display significant, reliable returns. Victims should verify the platform’s legitimacy independently and check if it is registered with financial regulators.
- Pressure for Continuous Investment: The scammers’ goal is to maximize the “fattening” stage, constantly pressuring the victim to invest increasing amounts of capital to chase the fabricated returns.
- Lack of Transparency in Infrastructure: The infrastructure used in these scams often relies on rapidly changing domain names and IP addresses, sometimes using similar names to trusted brands (a tactic facilitated by Funnull’s DGAs). While hard for a layperson to detect, if an investment site suddenly changes its web address or requires shifting funds frequently, this is highly suspicious.
- Abrupt Communication Cutoff: When a victim indicates they cannot, or will not, invest further, the scammer immediately terminates all contact, confirming the criminal nature of the relationship.
CONSEQUENCES & LEGAL STATUS

The consequences of Funnull’s operation are measured both in massive financial damage and serious legal ramifications. U.S. victims have reported losses of over $200 million, with average losses for individuals surpassing $150,000. This amount is likely an underestimation of total losses.
The key legal consequence was the imposition of sanctions by the U.S. Treasury’s Office of Foreign Assets Control (OFAC) against Funnull Technology Inc. and administrator Liu Lizhi.
Legal and Financial Actions Taken:
- Sanctions and Blocking: The sanctions mean that all property and interests in property of Funnull and Liu Lizhi that are located in the United States, or are in the possession or control of U.S. persons, are now blocked. U.S. persons are generally prohibited from conducting transactions involving any property of the blocked parties.
- Cryptocurrency Addresses Targeted: OFAC added two specific cryptocurrency wallet addresses, associated with Funnull and based on the Ethereum (ETH) and TRON (TRX) networks, to the Specially Designated Nationals (SDN) List. These addresses, which received payments for the infrastructure services, have received over $4 million in transactions.
- Money Laundering Connections: Blockchain analysis revealed that Funnull’s crypto wallets had direct exposure to Huione Pay. Huione Pay was previously identified by the U.S. Financial Crimes Enforcement Network (FinCEN) as a major money laundering platform and a primary money laundering concern. This connection underscores how Funnull’s illicit infrastructure was integrated into sophisticated financial crime networks. Notably, Huione Pay is also linked to a high-profile Philippine case involving the killing of billionaire Anson Que, whose ransom was paid in cryptocurrency.
- Organized Crime Links: Research also found that thousands of gambling websites hosted on Funnull contained branding for the Suncity Group, which the United Nations previously named as responsible for laundering millions for the North Korean cybercriminal group Lazarus Group.
U.S. Deputy Secretary of the Treasury Michael Faulkender affirmed that these actions emphasize the commitment to disrupt criminal enterprises that enable cyber scams and deprive Americans of their savings, reinforcing the government’s intent to secure the digital asset ecosystem. By targeting infrastructure providers like Funnull, the authorities aim to dismantle the networks responsible for perpetrating these sophisticated schemes.
WRITER’S COMMENTARY
Core Cause Assessment: Why did the Funnull/Pig Butchering scam succeed to such a devastating extent, stealing over $200 million?
The success of the Funnull network did not stem merely from the psychological vulnerability of its victims, but rather from the industrialization and scale of infrastructure fraud. The primary cause for the massive scope and financial damage was the emergence of Funnull as a single, indispensable service provider—a kind of malicious Amazon Web Services for cybercriminals.
Previous generations of online scams required criminals to manually set up hosting, develop phishing sites, and manage domain rotation. Funnull eliminated these technical friction points by offering a turnkey “Fraud-as-a-Service” model. By bulk purchasing legitimate IP addresses and using DGAs, Funnull made the creation of hundreds of thousands of deceptive domains instantly scalable and highly evasive.
This efficiency allowed the criminal call centers—often linked to human trafficking operations—to focus entirely on psychological manipulation without worrying about backend technical failure or rapid domain takedowns. Essentially, Funnull provided the necessary armor of perceived legitimacy (professional-looking templates) and the shield of technical agility (rapid migration capabilities). When the fraud is conducted at this scale—a “Triad Nexus” of over 332,000 domains—the probability of capturing unsuspecting individuals skyrockets. The sanctions against Funnull, therefore, represent a crucial strategic shift: acknowledging that to stop the flood of fraud, one must target the invisible utility companies providing the water pipes, rather than just the individual faucets.
REFERENCES
- trmlabs – https://www.trmlabs.com/resources/blog/ofac-sanctions-philippines-entity-including-crypto-addresses-for-facilitating-pig-butchering
- bitpinas – https://bitpinas.com/business/us-sanctions-funnull-philippines-crypto-scam/
- cyberscoop – https://cyberscoop.com/funnull-cryptocurrency-scam-sanctions/
- thehackernews – “https://thehackernews.com/2025/05/us-sanctions-funnull-for-200m-romance.html
- chainalysis – https://www.chainalysis.com/blog/ofac-sanctions-funnull-technology-pig-butchering-scams-may-2025/
- gmanetwork – https://www.gmanetwork.com/news/pinoyabroad/dispatch/947863/us-sanctions-ph-based-firm-over-200-m-virtual-currency-scam/story/