The investigation has uncovered a complex 15-layer money trail involving more than 20,000 bank accounts and transactions across multiple states. Police are now trying to identify the masterminds behind the fake USDT investment platform and the network operating the mule accounts.
By PC Bureau
Bhopal, August 8, 2026: What began as a sophisticated cryptocurrency investment scam has now expanded into a major cybercrime investigation spanning multiple states, thousands of bank accounts and a suspected network of money mules used to conceal more than ₹21 crore in fraud proceeds.
The investigation has also resulted in the arrest of Jagdish Kumar Malviya, a BJP leader and zila panchayat member from Shajapur, after investigators traced around ₹50 lakh of the allegedly defrauded money to an account linked to him.
Police allege that Malviya knowingly facilitated the movement of cyber-fraud proceeds through a bank account under his control and received a 2 per cent commission for allowing the account to be used as a conduit. Investigators believe the account was part of a much larger interstate network designed to rapidly move stolen money through multiple layers before it could be detected or frozen.
₹21 Crore Lost in Fake USDT Investment Scheme
The case began with the alleged targeting of 70-year-old Gwalior-based chartered accountant Ashok Vijayvargiya, who lost more than ₹21 crore after being drawn into a fake cryptocurrency investment operation.
According to investigators, Vijayvargiya was contacted through WhatsApp in December 2025 by fraudsters posing as investment advisers. A woman identifying herself as “Divya” allegedly established contact with him and persuaded him to invest in USDT, a cryptocurrency linked to the US dollar.
जब देश का हर आम नागरिक ऑनलाइन फ्रॉड और साइबर ठगी से परेशान हो, तब सत्ताधारी दल के नेता खुद करोड़ों की ठगी के सिंडिकेट चला रहे हैं!
मध्यप्रदेश के इतिहास की सबसे बड़ी साइबर ठगी का जो सनसनीखेज खुलासा हुआ है, उसने भारतीय जनता पार्टी के ‘शुचिता और ईमानदारी’ के दावों की सरेआम धज्जियां… pic.twitter.com/86ueQSjRAl
— ArinOmPawar (@ArinOmPawar2003) August 6, 2026
The fraudsters reportedly built credibility gradually rather than demanding a large payment immediately. Vijayvargiya was initially allowed to withdraw a small amount, reinforcing his belief that he was dealing with a genuine investment platform.
He was subsequently directed to a trading website that displayed what appeared to be spectacular returns. His supposed investment was shown growing to more than ₹33 crore, according to the investigation.
The apparent profits, however, existed only on a fabricated digital platform.
When Vijayvargiya attempted to withdraw his money, the fraudsters allegedly demanded additional payments under various pretexts, including income tax, risk margins and other charges. Each payment was followed by another demand, keeping him locked into the scheme.
By the time he realised he had been deceived, more than ₹21 crore had allegedly been transferred in 106 transactions involving 76 bank accounts.
Investigators Follow the Money
The breakthrough came when cyber investigators began reconstructing the money trail.
According to police, nearly ₹77 lakh from the initial layer of transactions was traced to accounts linked to Malviya. Of this amount, approximately ₹50 lakh has been directly connected to the Gwalior cyber-fraud case.
Investigators allege that Malviya had access to the bank account and internet-banking credentials of an organisation of which he was president. Police suspect that the account was subsequently used to receive and transfer funds generated through cybercrime.
During questioning, Malviya allegedly admitted allowing the account to be used for routing money in exchange for a 2 per cent commission.
Police have also detected suspicious transactions exceeding ₹2.5 crore in accounts associated with him, raising the possibility that the accounts were repeatedly used for moving funds originating from cyber frauds.
Money Routed Through 15 Layers
The scale of the operation has complicated the investigation.
Police say the ₹21.06 crore allegedly lost by Vijayvargiya was fragmented and routed through as many as 15 layers of transactions, involving thousands of accounts and digital transfers.
Investigators have so far identified more than 20,000 bank accounts and digital transactions connected to the broader money trail.
Nearly 35 per cent of the money was initially routed through accounts in southern India before being dispersed across several states, including Karnataka, Tamil Nadu, Andhra Pradesh, Kerala, Gujarat, Rajasthan, Uttar Pradesh, Haryana, Jharkhand, West Bengal, Chhattisgarh and Madhya Pradesh.
Investigators believe the strategy was designed to make the stolen money difficult to trace. Funds were repeatedly transferred, split into smaller amounts and moved between accounts, sometimes within a short period, reducing the possibility of a single bank account being flagged and frozen.
Only Part of the Money Recovered
Authorities have so far managed to freeze approximately ₹2 crore linked to the fraud.
A substantial portion of the remaining money had allegedly been withdrawn, converted into cryptocurrency or moved through digital payment channels before investigators could intercept it.
The complex layering of transactions has made recovery considerably more difficult. Investigators are now attempting to determine which account holders knowingly participated in the operation and which may have been unwittingly recruited as money mules.
Police Probe Wider Interstate Network
Malviya’s arrest has provided investigators with another potential entry point into the wider syndicate.
Police suspect that the accused was connected to an interstate network that recruits or controls “mule accounts” — bank accounts used to receive stolen money and quickly transfer it onward, often for a commission.
The account holders may receive a fixed percentage for each transaction while the masterminds remain several layers removed from the original fraud.
Investigators are now examining the identities of the people controlling the accounts, the communications between them and the methods used to coordinate the rapid movement of funds.
READ: Punjab Transfers Top Cop Days After Alleged Jantar Mantar Terror Module Claims
Digital Trail Leads Beyond India
Police are also examining the digital infrastructure behind the fake cryptocurrency platform.
According to investigators, the probe includes analysis of IP addresses, WhatsApp communications and phone numbers, including at least one number carrying a US country code.
Investigators are attempting to determine who created and operated the fraudulent trading platform, where its servers were located and whether the same infrastructure was used to target other victims.
The use of cryptocurrency has added another layer of complexity because funds can be converted and transferred across digital wallets, potentially obscuring the original source of the money.
Questions Over Malviya’s Activities
Investigators are also examining Malviya’s financial activities and alleged lifestyle changes.
Police sources have claimed that he maintained an expensive lifestyle that appeared disproportionate to his known sources of income. Investigators are also examining his recent foreign travel, including a trip to Bangkok in July, which reportedly took place while the cybercrime investigation was underway.
Malviya has been produced before a court and remanded in police custody for further questioning.
Police are expected to examine his financial records, digital devices, communication history and links with other suspected money mules to determine the extent of his involvement.
Investigation Expands
The arrest is being viewed by investigators as only one part of a much larger operation.
Police officer Sanjeev Nayan Sharma said the investigation is focused on identifying the masterminds behind the fake cryptocurrency platform, tracing the digital infrastructure used by the fraudsters and establishing the hierarchy of the interstate network.
Investigators are particularly interested in determining who recruited the mule-account holders, who issued instructions for transferring the money and who ultimately controlled the proceeds.
The case illustrates the increasingly sophisticated nature of cybercrime, in which victims are not necessarily confronted with obvious threats or fake links. Instead, fraudsters build trust over weeks or months, create convincing investment interfaces and use elaborate banking networks to make stolen funds difficult to trace.
For investigators, the seemingly simple WhatsApp greeting that began with “Hello, this is Divya speaking” has opened a sprawling trail stretching across multiple states, thousands of bank accounts and potentially several layers of an organised cybercrime syndicate. The challenge now is to move beyond the money mules and identify the operators who designed the fraud, controlled the fake investment platform and ultimately benefited from the ₹21-crore loss.











