September 12, 2026
The Exchange That Only Existed in a Database and the $870,000 It Looted Anyway.
A technical anatomy of the NamHck / GwkCap fake-trading franchise: nine brands, thousands of victims, $620Kβ$870K in verified real lossesβ¦

By Karan Dhillon
16 min read
A technical anatomy of the NamHck / GwkCap fake-trading franchise: nine brands, thousands of victims, $620Kβ$870K in verified real losses, $12M+ in stolen belief and a machine designed to convince.
It started with an app that looked expensive.
NamHck. On Google Play, it presents itself as a modern stock and futures trading terminal. Polished UI, clean charts, live order books, an "analyst" who chats with you personally. Behind it sits a platform calling itself GwkCap β a full "exchange" with its own websites, customer support, and market data that moves in real time. There's an iOS companion too. And when the store listings age out, they're swapped for fresh ones under disguised package names β the current Play listing hides behind an innocuous app ID that has nothing to do with trading.
That last part is important. The market data is real. Genuine quotes, piped in from a legitimate market-data vendor. The charts on the victim's screen match the real world, tick for tick. It is the single most convincing thing about the entire operation β and it is also the perfect lie, because nothing else is real.
What follows is what one of these operations looks like when you can see the whole machine: every brand, every database, every fake number, every real wire. This is a technical dive β no methods, just anatomy.
1. The storefront is a clone farm
The first surprise is that there isn't one platform. There are nine. GwkCap is the flagship, but it's flanked by a rotating set of near-identical clones: stead, novumx, cosmicx, rcex, spire, facai, valenridge, mypexpro β plus a queue of registered-but-unlaunched brands waiting in parking domains, and a next wave of Android apps already built and sitting in public code repositories under names like AlphyxaiKen and Trovexken.
Every clone follows the same template, and it's worth describing the template precisely because it reveals the economics of the operation:
- Backend: one RuoYi (Java/Spring) fork per brand, running as a fat jar, serving an API with hundreds of endpoints
- Frontend: a Vue H5 web app, wrapped for mobile in a WebView shell β the Android apps are literally a browser window pointed at the backend
- Data: one MySQL database per brand, on managed cloud instances β most with only tens of megabytes of real data
- Infrastructure: one virtual server per brand, fronted by Cloudflare, identical nginx configs
It's a factory. The marginal cost of launching a new fake exchange is roughly one evening of copying configs. When a brand burns β too many complaints, banks getting wary β the operator doesn't fix it. They rotate: kill the domain, park the next name, migrate the victim list, and continue.
The fleet, in full
Over the course of the investigation, the entire server fleet was mapped β sixteen virtual machines across four cloud regions, every one of them compromised, every database read. The inventory reads like an inventory of the operator's business plan:
- 1 flagship origin (Singapore) running the main platform, the fake-news crawler, and the admin console
- 5 Hong Kong boxes β brand fronts plus the market-data relays that feed "real" quotes to every clone
- 7 US boxes β one per clone brand, each with its own victim database
- 1 Malaysian box β a second platform family (the MYPE brand)
- 2 boxes terminated by the operator mid-rotation β pruned like dead branches while we watched
- 1 zombie β a brand left serving its frontend after the operator deleted its database out from under it
- 18+ managed database instances, and a shared "graveyard" cluster holding seven legacy brands' data in one place
Every box is the same template: a server-management panel, nginx, one Java fat-jar, one local MySQL, one Redis. Cloning a brand is copying the template. Burning one is deleting the database. The fleet's total victim data β every record across nine brands β weighs under a gigabyte. The machine that destroyed thousands of people's savings fits on a USB stick.
I watched one brand's lifecycle in real time. Launch. Milk. Go quiet. Then the operator logged into it one last time from a Southeast Asian border town, ran a few test accounts, and walked away. The brand stayed online, serving its frontend, with its database already deleted out from under it β a zombie storefront with no brain.
2. The market that only moved in a database
Here is the core technical truth of the whole operation: there is no trading engine.
No order matching. No liquidity. No exchange. The victim's trades never execute against anything. Every "position," every "profit," every balance is a row in a MySQL table that an administrator can edit.
The evidence, once you can see it:
- The "$150 million" deposit ledger is fabricated. The platform's own records claim enormous historical deposits. On-chain verification of the platform's deposit addresses showed zero transaction history. The ledger is theater, maintained to make the platform look busy and successful. A second database holds another "43 million USDT" ledger β same story.
- The transaction hashes are borrowed. Deposit records cite real blockchain transaction IDs β but the transactions are unrelated: the operator's own bulk-disbursement transfers, meme-token sprays, other people's payments. Real hash, fake deposit. One victim's "29,990 USDC deposit" was, on-chain, a spray of a meme coin from the operator's own wallet.
- The funds are recycled. The same few hundred thousand dollars of stablecoin get moved in loops β out of one victim address, back in, out again, six times in a day β to make wallets look alive. Alongside them, fake tokens with Unicode-homoglyph names (a "USDC" spelled with Cyrillic characters) get dusted around as noise.
- The whales are puppets. The platform shows a feed of big investors making big deposits. Several of them are operator-controlled accounts: disposable emails, nonsense ID numbers, logins from the operator's own proxy exits. Their balances get inflated on a schedule β 50,000, then 100,000, then 200,000 β so the "depositor list" always looks like it's growing. When the morning shift starts, the first thing the operators do is inject fake deposits into the puppet accounts. I watched one morning where 3.7 million USDT of fake deposits were injected across five puppet accounts in seventy minutes β social proof, manufactured.
- The investment products are props too. The flagship sells "AI Quant Strategy" plans β 500,000 USDT buys, 2β4% daily returns, 30-day lockups. Real victims bought them. The products themselves are rows created by an administrator, with an expiry date, like promotional coupons for a store that doesn't exist.
- The victims live in a spreadsheet. One of the servers held an Excel file β
0828.xlsxβ a fresh export of victim emails and balances, maintained by the operator. Over a hundred rows, topped by a fabricated balance of 96 million. The scam's bookkeeping is as crude as its frontend is polished. - There is a kill switch. The platform ships an admin feature for mass liquidation β batch-flagging victim accounts for forced liquidation. Deployed in a routine update, like a normal feature. It sits there for the day a victim wins too much or asks too many questions.
And the cherry on top: an administrator tool to set a victim's withdrawal amount β the mirror image of the deposit-injection tool. Fake deposits in the morning, fake withdrawals in the evening. Both sides of the ledger are props.
3. The one real pipe
Strip away the theater and exactly one part of the machine touches real money: the OTC desk.
The flow, mechanically:
- The victim is groomed in chat β the "analyst," a friendly professional who responds quickly, understands their goals, and never pressures them (at first).
- The victim creates an "OTC order" β buying platform credits (USDT) with fiat, at a fixed exchange rate set by the platform.
- The platform displays wire instructions: a bank name, an account number, and a payee β plus a QR code to scan. The victim then opens their own banking app and sends real money, bank-to-bank.
- The victim uploads a screenshot of their transfer receipt through the app.
- An operator reviews the receipt and clicks "approve." Fake USDT appears in the victim's balance.
Everything real happens in steps 3 and 4 -inside the victim's bank and the victim's phone. The platform never touches the money. It only displays the instructions and records the claim. That's the design: no payment processor, no custody, no liability β just a bank account number that rotates.
The bank accounts belong to a succession of freshly-incorporated shell companies, each used for a few weeks of collection and then retired. The platform's own records tie every order to its destination account β and because the platform is the operator's own bookkeeping, we can name exactly which companies collected the victims' money:
Shell company (Singapore) Bank Masked account Collected (platform ledger) KIYUU TECHNOLOGY PTE. LTD. DBS 8854xxx575 ~219,000 SGD / 29 orders BRASS FASHION PTE. LTD. OCBC 9880xxx370 ~142,000 SGD / 4 orders PULSE BEATS EVENTS MARI 2482xxx160 ~88,700 SGD / 12 orders EVERFIELDGROUP MARI 2306xxx660 ~46,800 SGD / 5 orders EASTONED TRADING PTE LTD MARI 2202xxx733 ~26,000 SGD / 8 orders HIVEGRID PTE LTD DBS 8854xxx786 ~21,900 SGD / 14 orders YUNQI TECHNOLOGY PTE. LTD. ANEXT 1129xxx226 earlier rotation RASHIDAH IDS MARI 2516xxx952 stood up on a Monday evening, collecting by the same night
Plus, on the international brands: JOB JOHNSON BUSINESS SOLUTIONS SPC at an Omani bank, Expo Union Group Limited at ICBC (Asia), and a US mule account at Bank of America under a personal name. Every one of these is a registered company with officers on file β in Singapore, a few dollars at the company registry reveals who signed the papers. That registry lookup is the shortest path from "anonymous scammer" to "named defendant," and it's sitting in the evidence package waiting for law enforcement.
The completed-order ledger totals over 630,000 SGD (~$490K USD) on the flagship alone β and that's with several obviously-fake puppet orders subtracted.
Where the loot goes
The platform's records also answer the question victims never get to ask: where does my money go after the wire lands? The answer is a money-laundering ladder with the operator's fingerprints on every rung:
- The shells collect. One account at a time, a few weeks each, then retired β the rotation exists precisely because real wires hit them and banks start asking questions.
- The crypto side exists for the exit. The operator's own records show a string of withdrawals to KYC'd exchanges β 132,900 USDT to one major exchange, 150,000 USDT to a self-custody wallet, a trail of smaller transfers across three more exchanges β with addresses and timestamps attached. Every one of those accounts was opened with someone's verified identity. That's the part of the machine law enforcement can actually grab.
- And some of the "victims" on the roster are the operators themselves β sockpuppet identities wearing American names, running on proxy exits, there to chat with real victims. One of them, a "Kristin Murphy" persona, maintains accounts on five different social platforms β all empty, all lurkers β the modern equivalent of a mannequin in a shop window. The registration IPs on those accounts are traceable by platform security teams.
The looted money, in other words, doesn't disappear into a void. It walks through shell banks and KYC'd exchange accounts, leaving a trail of timestamps and addresses β and the people on the other end of that trail had to show their real faces to open those accounts.
The victims' receipts make it undeniable. One victim β call him Ra K****** β a man with a stable job and a home address in a Singapore condominium, transferred 149,751.93 SGD (~$116,000 USD) across five orders in one month. Four of his five receipts are on the platform's servers, screenshots of his own bank confirmations. He photographed his own losses, step by step, and uploaded them.
He is not the biggest attempted. One victim placed orders worth 5.5 million SGD β and cancelled every one, leaving remarks in the system like "payment directed to an individual person's account when it should be to a trading account linked to the investor." He smelled it. The operator is still working him, pumping half a million USDT of fake balance into his account to make the next ask feel small.
4. The trust machine
The most sophisticated thing this operation ever built was its reputation.
An earlier brand β call it the trust brand β ran a different playbook. It paid people. Real, on-chain, verifiable payouts: 497 of them, totaling about 196,000 USDT, each a small win of a few hundred to a few thousand dollars. The logic is brutal and effective: pay a little, convince the victim withdrawals work, and the next deposit is ten times the bait.
The proof is in the chain. A victim in Detroit deposited 42,190 USDT and got back 725. A man in Florida got nine separate payouts totaling 3,000 β after depositing 4,100. A Calgary resident received a 107 USDT payout with a real transaction hash. Two Edmonton residents β real names, real Canadian phone numbers, logging in from residential Telus IPv6 connections β were being primed: one received 37 USDT before ever depositing a cent. The bait comes first when the profile is worth it.
Then the trust brand was burned, and its victim list was migrated to the new brands β the same victim IDs appear across platforms, carrying their "trust" with them like luggage.
5. The people behind the machine
The operation runs like a call center because it is one β in the worst sense of the term.
The shifts. Operators work ~12-hour days, 10:00 to 22:30, with the same morning ritual every single day: a wake-up sweep where dozens of persona accounts get logged in one by one, twenty seconds apart, from the same two workstations. Test accounts get cycled. The admin console gets opened. Then the money work begins β card assignments, order approvals, fake injections β peaking in the afternoon and evening.
The personas. Victim-facing "investors" with English names β the platform's social proof β all log in through VPN exits. The operator team itself doesn't bother hiding as much: the console work happens on raw ISP connections from at least four locations, including a Chinese province and multiple Southeast Asian border towns β regions famous for exactly this industry. The connections themselves are quiet: gateway devices with open-but-silent ports, VoIP phones, and no exposed cameras anywhere.
The geography, specifically. The operator's daily console IPs trace to a Laotian telecom block routed through Thailand β the kind of uplink used on the Thai-Myanmar-Lao border, where the "office" is more likely a compound. One of their connections last week came from Mongla, Myanmar β a town whose name appears in every serious report on scam-compound trafficking. The team's own metadata tells the story: 12-hour shifts, persona logins at all hours, staff accounts cycling on shared workstations. Whether the people clicking "approve" are there by choice is a question the human-trafficking angle exists to ask.
The cross-operation tie. The operator's home router β the one used to build the servers β runs a DNS server with a tell: it sinkholes a popular search engine's domain to a specific dead-end IP. That exact same sinkhole address appears in the infrastructure of a different operation from the same group β an Android malware/RAT campaign distributing a wedding-invitation lure. Same network hygiene, same dead-end, two fraud lines. These aren't isolated scammers; it's a portfolio of crime, run with shared tooling.
The automation. Login bots that fire the same account every few minutes from rotating proxies. Test accounts named 樑ζε·1 through 24. A universal two-factor-authentication bypass code configured in the platform's own settings table β different per brand, like a house key under each doormat.
The names. The admin console's own audit trail names the people at the top the way they name themselves: the super-admin account belongs to a burner mailbox on a Chinese provider, the config auditor signs their work with the handle C******, and the day-to-day crew operate under single-word aliases β one of them, tellingly, means "get rich." Small details, but they're the kind of details that connect a database row to a human being.
The developers. This is where it gets uncomfortable for them. The operation's frontends live in public code repositories, and the git history is a gift: seven developer identities with personal emails β a backend dev, an Android dev, an H5 dev, and several multi-repo contributors β committing steadily for months, along with a development fallback pointing at a home LAN address. One developer's handle matches a username that logged into the platform itself from a raw home internet connection in China. The people building the fraud used the fraud from the same networks they built it on.
6. The victims
The ledger is abstract until you attach it to people β and the platform is full of people, thousands of them, checking in every day.
The routine. The same names log in around the clock: a Singaporean man who checks his balance before work and after dinner, every single day. A woman who cancelled a 7,000 SGD order one morning with the words "I no longer need this transaction" β then came back that afternoon and completed a 3,000 SGD one. A retired-looking name on the roster who logs in at 4 a.m. The platform's login stream is a slow, sad metronome of people watching numbers that only the operator controls.
The ones who went deep. The flagship's top ten victims alone account for ~90% of the real-money ledger. The list, masked: Ra K****** (149,751 SGD, receipts uploaded), A L**** (70,816 across 8 orders), E* L**** (70,000 in one attempt β and possibly a puppet, the records suggest), H Y*** (51,000), M S** A***** (25,440 across 10 orders β the highest-frequency buyer on record), and more. Behind each: KYC photos, home addresses, employers, incomes.
The onboarding script. New victims arrive on a conveyor belt. The pattern is identical, and I watched it happen live more than once: a new account registers β submits KYC within hours β an operator approves it β within seconds, a small "credit" appears in the account (230 USDT for one, 55 for another β odd, believable amounts) β the "analyst" introduces themselves β the funnel begins. Three new victims onboarded in a single 24-hour window while I watched. Each one's first real wire is a matter of days away.
The near-miss. The 5.5-million-SGD man wasn't the only skeptic. A Canadian in Edmonton attempted a six-figure order the day after joining β and cancelled it. Another Edmonton resident has received 37 USDT from the platform without ever depositing β the bait, paid in advance, because his profile looked worth grooming. Both were spared, for now, by timing: the brand they were on went dormant before the trap closed.
The belief gap. The most haunting number in the whole case is the difference between what victims believe they lost and what actually moved. Across the brands, victims have lodged withdrawal requests worth over $12 million β money they are certain exists, sitting "in their accounts." The verified real losses are ~$620Kβ$870K. The other eleven million dollars never existed anywhere except a MySQL row. And that gap β between the life savings people believe are locked up and the near-nothing that's actually recoverable β is the cruelest part of the machine's design. It doesn't just take money. It takes the story the victim tells themselves about what they had.
7. What the victims gave up
The money is the headline, but the data is the collateral.
Every victim goes through KYC: passport or ID photos (front and back), proof of address, proof of income. The photos carry their EXIF metadata β device model, timestamps, sometimes GPS coordinates of where the victim photographed their documents. One passport photo in the store was taken on an iPhone 14 Plus with full GPS attached; an income screenshot came from a Samsung A55. Device fingerprints, on record, per victim.
All of it β thousands of documents β sits in a cloud object bucket where the files are publicly readable to anyone with the URL, and the URLs are sequential.
The scale, conservatively: over 3,300 registered accounts across the brands, realistically somewhere in the low thousands of unique humans, spanning Singapore, Malaysia, Hong Kong, the United States, and Canada. Their aggregate real losses sit in a verified range of roughly $620,000 to $870,000 USD β the fiat wires to the shell accounts, plus the fraction of the crypto ledger that chain verification confirmed as real. (The victims believe they lost far more β the trapped withdrawal requests alone total over $12 million across the brands. That gap between believed and real is itself the con.)
8. Technical fingerprints β the little things that gave them away
Beyond the business model, the platform leaks personality through its technology. A short tour of the fingerprints:
- The JWT secret is the RuoYi default. The backend signs session tokens with the string
abcdefghijklmnopqrstuvwxyzβ the stock value shipped in the framework's example config, never changed. Anyone who has read the framework's documentation can forge an admin token for this platform. The operator deployed a banking-scale fraud on a skeleton key left in the door by the tutorial. - The database monitor runs on default credentials. The production Druid monitor answers to
ruoyi / 123456β the framework's stock password, unchanged. Through it, the database credentials themselves were recoverable. Defaults, everywhere: a universal two-factor bypass code per brand (six-digit, configured in the settings table), liquidation ratios set to 1.0 and 0.85 (positions liquidate at 100% and 85% loss respectively), and a "blast ratio" knob the admins tune like a radio. - The jar files tell the brand's life story. Each clone runs a Java fat-jar, and the operators version them by stacking numbers:
1Gwkx.jar,2Gwkx.jar,3Gwkx.jar... And when they kill a brand, the last jar gets suffixed:jbouyangstop.jarβ "ouyang, stop." The file system is a graveyard of renamed ambitions. - The API is an open book. The main backend exposes its Swagger documentation publicly β 639 endpoints, including 341 admin paths (withdrawal examination, recharge management, balance manipulation). The roadmap to every button the admins press has been public the whole time.
- One table weighs 8.4 gigabytes. A scheduled-job log with 58 million rows β every automated market-sync and news-crawl the platform ever ran, logged and forgotten. It's 91% of the entire fleet's database mass, and it's worthless. Everything that matters β every victim record across nine brands β fits in the remaining ~0.9 GB.
- The "market data" is a relay with a cache. Real quotes flow from a legitimate vendor into a relay server, get cached for seven days, and are served to every clone. The relay is the injection point: cached quotes downstream, operator-controlled balances on top. The screen shows a real market; the account shows a fictional one.
- The fake news is automated. A Python crawler runs every 30 minutes, pulling financial headlines into the platform's news feed β deployment files, cron jobs, and a
.envwith the database password left on the server like a diary. - The victim documents are public files. Every KYC photo, every receipt, every QR code image sits in one cloud bucket with publicly-readable objects and sequential URLs.
img1785652775128,img1785652775129... no authentication, no access log anyone checks. A victim's passport is one integer away from the last one. - The bot logs in on schedule. An automated account fires paired logins every few minutes through rotating proxy exits β same account, same rhythm, for hours. Operational automation, visible in the login table like a heartbeat monitor.
None of these are sophisticated mistakes. They're the fingerprints of a team that optimized one thing β the con β and copy-pasted everything else from tutorials. That asymmetry is exactly why the evidence holds together so completely.
9. The lifecycle of a fake exchange
Put it all together and the business model emerges:
- Build β clone the template, register the brand (the current wave is "AI investment analytics" flavored, riding the hype), park the domains
- Launch β real market data on, fake news crawler on, personas warmed up
- Milk β the OTC pipe, one shell account at a time, one approval at a time
- Convince β small real payouts to the promising ones; fake whales to the uncertain ones
- Burn β retire the brand when the banks start flagging; delete the database; migrate the victims
- Repeat β the next name is already parked
It's a franchise of ghosts. Nine brands, dozens of domains, four countries of infrastructure, seven developers, a persona army β and behind all of it, exactly one real trick: a bank account number shown to a person who trusts you.
If you're inside this right now
If any of this sounds familiar β an app that tells you to wire money to a bank account instead of a trading platform's funding system, daily-return promises, an analyst who's always available, withdrawals that always find a new reason to fail:
- Stop sending money. Every "fee to unlock," every "margin call," every "tax payment" is the final phase.
- Call your bank today and report the transfers β recall and freeze requests are most effective while the receiving accounts still hold funds.
- File a police report. In Singapore, the Anti-Scam Centre. In the US, the FBI's IC3. In Canada, the CAFC.
- Don't be ashamed. The machine was built by professionals to beat your pattern recognition. The only mistake that matters now is the next wire.
The brands named in this article are real and still operating under rotating names. All victim identities are masked; all financial figures come from the platform's own records and on-chain verification. A complete evidence package has been prepared for law enforcement and the affected banks.