Before a mining machine rebate scheme collapses, the phrase "illegal fundraising" rarely appears first in group chats.

What typically emerges first are explanations such as "on-chain congestion," "system maintenance," or "delays in yield settlement." A few days later, withdrawal limits are reduced, customer service begins issuing standardized responses, and group administrators warn members against spreading negative information. Some participants continue to wait for official announcements, while others have already reported the matter to the police. Only after law enforcement authorities become involved do the parties realize that, although they believed they were purchasing mining machines, the case file actually focuses on the absorption of funds, promises of returns, platform tokens, and the ultimate disposition of the funds.

This is precisely where virtual currency mining machine rebate cases are most prone to misjudgment. Unlike traditional fundraising cases, which involve only contracts, transfer records, and interest schedules, these schemes may indeed have records of mining machine purchases, on-chain addresses, platform tokens, application back-end systems, and community management operations; some projects even genuinely pay electricity bills and rent server rooms. Consequently, many principals and employees feel aggrieved: "We are not a pure Ponzi scheme; why are we characterized as illegally absorbing public deposits, or even treated as committing fundraising fraud?"

Criminal cases do not turn solely on the terminology employed by a project. Terms such as mining machines, cloud hashrate, nodes, and platform tokens do not, in themselves, determine the applicable charges. The analysis must return to the operational realities of the project: why users were willing to remit funds, the source of the promised yields, whether platform tokens could circulate freely in practice, why withdrawals were restricted, who controlled the back-end systems, and where the funds ultimately went.

Only by disaggregating these facts can one clarify the legal characterization: among mining machine rebate schemes, some cases may be primarily assessed as illegal absorption of public deposits, while others may face further scrutiny for fundraising fraud.

Why Mining Machine Rebate Schemes Escalate from Commercial Disputes into Criminal Case Files

A legitimate hashrate service must, at a minimum, provide clear answers to several questions: what exactly the user is purchasing; whether the purchase corresponds to real equipment or genuine hashrate; how yields are generated; who bears the risk of loss; and whether the platform has portrayed "potential yields" as "fixed returns."

If users purchase clearly defined mining machine custody services, with contracts specifying equipment models, custody data centers, electricity fee settlements, mining pool addresses, and yield distribution rules, and the platform makes no guarantees of principal protection or fixed returns, then subsequent losses cannot simply be equated with fraud. Market downturns, breaches by custody providers, equipment failures, and regulatory changes can all cause a business to fail. Business failure may give rise to civil liability, administrative risks, and even risks associated with illegal fundraising, but it is distinct from a scheme that was fraudulent from the outset.

The problem is that many so-called mining machine rebate projects do not operate in this manner.

The mining machines visible to users may be nothing more than icons on an application interface; the so-called nodes may merely reflect tier levels assigned to users in the back-end system; the platform tokens distributed daily cannot circulate freely outside the platform; and prices, output volumes, and withdrawal rules are all set unilaterally by the project operators. Users believe they are purchasing hashrate, but in reality, once funds are received, they are primarily used to redeem obligations to earlier participants, pay commissions to marketing teams, and sustain community engagement, with only a small proportion actually allocated to mining machines, electricity costs, and data center rentals.

Under such a structure, mining machines cease to be merely technical products and instead become a pretext for absorbing funds. Users do not enter the scheme because they understand the logic of mining, but because they observe signals such as "daily crediting," "accelerated returns on reinvestment," "referral rewards," and "future exchange listings." It is at this point that criminal risk begins to accumulate.

Therefore, handling such cases cannot stop at the assertion that "we have mining machines." The case file will pursue further inquiries: how many mining machines were acquired, when they were purchased, whether they can be mapped to user entitlements, into whose wallets the mining pool outputs were deposited, and whether user withdrawals were funded by genuine mining outputs or by subsequent inflows from new participants. Only if these questions can be satisfactorily answered is there a basis for discussing the existence of genuine business operations.

The Distinction Between Illegally Absorbing Public Deposits and Fundraising Fraud Does Not Hinge on Whether the Project Incurred Losses

Illegally absorbing public deposits and fundraising fraud are often discussed together, but in criminal defense, the gravity of these two charges differs significantly.

For the crime of illegally absorbing public deposits, the core considerations are whether funds were absorbed from unspecified members of the public, whether there was a promise to repay principal and interest or provide returns, and whether financial management order was disrupted. In the context of mining machine rebate projects, if a platform publicly promotes high yields, stable coin production, reinvestment rewards, and team commissions, inducing a large number of unspecified users to transfer funds or virtual assets into the platform, such conduct may be characterized as illegal fundraising, even if the project operators initially subjectively intended to operate the business legitimately.

Fundraising fraud goes a step further. It is not automatically established merely because a project collapses or investors suffer losses. The key question under Criminal Law is whether the project operators had the purpose of illegal possession.

While this statement may sound abstract, it becomes quite concrete when examined within case files.

For instance: whether there were sufficient real-world assets to support the promised returns at the project's inception; whether the platform tokens had any external circulation value; whether the so-called K-line charts and prices were manipulated via the backend system; whether incoming funds were transferred to personal accounts, affiliated companies, or wallets with unexplained origins; and whether, after knowing that redemption was no longer feasible, the operators continued to recruit new users, fabricate positive news, restrict withdrawals, and use new funds to cover old debts.

If a project did indeed purchase equipment, pay electricity bills, and connect to mining pools, but later lost control due to market downturns, custody disputes, or regulatory changes, the case certainly still carries risk. However, one cannot simply reclassify the person in charge as committing fundraising fraud solely because final redemption failed.

Another scenario is far harder to justify. If the platform lacked sufficient real mining machines from the outset, with platform tokens circulating only within the system and prices subject to arbitrary adjustment, and user repayments relied primarily on continuous recharge by new users; and if, after a funding gap emerged, the project operators continued to claim in group chats that “new mining machines will soon be connected,” “the exchange will list shortly,” or “withdrawals will resume after system upgrades,” while simultaneously dispersing assets into multiple wallets or personal accounts, then the discussion in the case shifts beyond mere illegal fundraising to why the operators continued to solicit funds despite knowing they could not fulfill their obligations.

The law does not punish failure itself. What the law truly cannot tolerate is using technical jargon to obscure an unfulfillable promise, and then using money from later participants to maintain the trust of earlier ones.

Platform Tokens, Backend Systems, and Wallet Flows Reveal the True Nature of the Project

In mining machine rebate cases, whitepapers, promotional posters, and community announcements are not entirely useless, but they primarily demonstrate how the project presented itself externally. What truly clarifies the nature of the project are often the platform tokens, backend systems, and wallet fund flows.

First, consider the platform tokens.

Can the tokens returned by the platform to users circulate outside the platform? Is there a contract address? Are there external transaction records? Is the price formed by the market, or is it set in the backend? If the daily balance growth, yield rates, and K-line increases seen by users are all adjusted by the project team in the backend, then the so-called "mining rewards" are not market outcomes, but signals manufactured by the project team.

Many investors are willing to reinvest not because they truly understand the output of mining machines, but because they see their account balances rising every day, witness others posting withdrawal proofs in group chats, and are told by customer service that the token will be listed on exchanges. In criminal cases, these screenshots, scripts, announcements, and backend access privileges are collectively used to determine whether the project team fabricated return expectations.

Next, examine the backend.

The most sensitive permissions on such platforms usually do not lie in ordinary page development, but in rules governing token generation, user balances, price displays, withdrawal reviews, wallet consolidation, and announcement publication. Who can modify prices, who can adjust balances, who can suspend withdrawals, and who knows that the real capital pool is insufficient to meet redemption obligations—these details are more important than job titles such as "technology," "operations," or "customer service."

Finally, examine wallets and fund flows.

After users' funds or USDT enter the system, do they go into the company's official accounts, accounts for purchasing mining machines, and electricity fee accounts, or are they quickly dispersed to the personal wallets of persons in charge, affiliated companies, and commission accounts for marketing teams? Does the output from mining pools flow back into the user reward pool? Do funds withdrawn by users actually come from mining machine output, or from subsequent deposits made by other users?

These questions may seem trivial, but they form the skeleton of the boundaries between criminal charges. Because what criminal cases assess is not how much a project's PowerPoint presentation resembles Web3, but how the system actually collects money and disburses it in reality.

Whether an employee is merely an "ordinary worker" depends on how close they are to the funds and control rights.

After a project is investigated, the most common statement made by employees is: "I was just an ordinary worker."

This statement may sometimes hold true, and sometimes it may not. There is no automatic "immunity for ordinary workers" in criminal cases, nor should anyone be directly equated with a core accomplice simply because they worked for the project company. What truly matters is how close they were to the entry points for funds, promises of returns, backend control, and restrictions on withdrawals.

The risk for community managers lies not in how many messages they sent, but in whether they participated in designing scripts about returns, whether they continued to placate users and recruit new members while knowing that withdrawals were difficult, and whether they received commissions based on deposit amounts and reinvestment amounts. The risk for customer service staff lies not in having responded to user inquiries, but in whether, after withdrawal limits were imposed, they concealed the true reasons using standardized scripts and continued to create expectations that services would "soon resume."

Technical roles cannot be generalized either. Performing ordinary page development, fixing bugs, and maintaining servers is fundamentally different from holding permissions to modify prices, adjust balances, suspend withdrawals, and conceal real data. The same applies to finance and administrative personnel. Processing payroll and reimbursements according to established procedures is not the same as participating in multi-wallet consolidation, routing funds through personal accounts, and fragmenting fund flows.

For employees and their family members, merely producing the employment contract and bank statements reflecting salary payments is far from sufficient. It is more effective to compile details such as the date of onboarding, job responsibilities, direct supervisor, backend system access privileges, work group chat records, meeting minutes, performance evaluation rules, sources of commissions, and whether the individual handled user complaints or withdrawal issues. In many cases, it is precisely these details that determine whether an individual can be disentangled from the core chain of liability.

For project leaders, it is not acceptable to simply shift responsibility to the technical or operations teams. Key questions—such as who established the revenue rules, who issued the platform tokens, who controlled the flow of funds, who approved withdrawal restrictions, and whether the marketing team continued to recruit participants after incidents occurred—ultimately trace back to the decision-making chain and the capital flow chain.

Notes for Family Members and the Parties Involved

In cases involving mining machine rebates, node dividends, and platform token mining, the greatest pitfall is to immediately assert, “We are not committing fraud.” While this emotional response is understandable, it offers limited assistance to the case.

A more effective approach is to first construct a timeline.

The first line should clarify how the project was marketed: when promotional activities began, what the promotional materials stated, whether users purchased mining machines, nodes, computing power, or platform token rights; whether there were promises of principal protection, fixed returns, accelerated returns upon reinvestment, or referral rewards; and whether public promotions were consistent with the actual backend rules.

The second line should clarify the flow of funds: into which accounts or wallets user assets were deposited; whether they were converted into RMB; and the respective proportions allocated to mining machines, electricity fees, data centers, research and development, promotion, salaries, commissions, and personal accounts. In crypto asset-related cases, on-chain records and wallet addresses are often more persuasive than oral explanations.

The third line should clarify the origin of the tokens: whether the platform tokens had a contract address, whether they could be traded externally, how their price was formed, when withdrawal rules changed, when announcements were issued, and when standardized customer service scripts began to be used.

The fourth line should clarify what each individual did: what each person was responsible for, the extent of their knowledge, and whether they participated in making return promises, recruiting new users, controlling the backend, pooling funds, or imposing withdrawal restrictions. Do not merely categorize individuals broadly as bosses, technical staff, operations personnel, or customer service representatives; instead, specify concrete actions and access privileges.

The fifth line should clarify how matters were handled after incidents occurred: whether user recruitment was halted, whether risks were publicly disclosed, whether a repayment plan was proposed, whether ledgers, wallets, servers, and backend records were surrendered, and whether data was deleted, assets were transferred, or users were further induced to recharge. In many cases, post-incident conduct inversely influences the handling authorities’ assessment of subjective intent.

Once the timeline is constructed, the case shifts from abstract debates over “whether the project constitutes fraud” to a factual level that can be meaningfully discussed. For the parties involved, this also forms the basis for seeking adjustments to charges, distinguishing between principal and accessory offenders, obtaining bail, and creating room for sentencing mitigation.

Ultimately, the greatest risk in mining machine rebate projects lies not in the use of virtual assets or blockchain terminology, but in using a seemingly technical facade to bear the pressure of absorbing funds from the public, promising returns, controlling prices via the backend, and maintaining continuous repayments.

What is truly useful is not to offer more polished explanations of terms such as “mining rigs,” “nodes,” or “platform tokens,” but to place every fund flow, each price adjustment, and every announcement restricting withdrawals back into the timeline in which they occurred.

Only when the timeline is clear can there be a meaningful re-examination of whether the project amounted to business failure, loss of managerial control, or the making of promises that were impossible to fulfill from the outset.

About Mankun

Mankun Law Firm was established in 2015. It is a boutique law firm dedicated to serving Web3, the next-generation internet, with deep expertise in blockchain, artificial intelligence, and tech finance within the new economy.

Headquartered in Shanghai, the Firm maintains branch offices in Hong Kong, Shenzhen, Silicon Valley, and other locations. Its core team members come from renowned law firms, judicial authorities, technology companies, and digital asset institutions. Leveraging a unique multi-dimensional perspective encompassing law, industry, and regulation, the Firm provides high-quality legal services that combine depth in China with global breadth.

Drawing on a profound understanding of the new economy, continuous attention to and research on regulatory policies, and extensive practical experience, the Mankun team is adept at providing comprehensive legal services from the perspectives of business models and legal practice. For clients in emerging sectors such as Web3 blockchain, artificial intelligence (AI), crypto payments (PayFi), decentralized finance (DeFi), tokenization of real-world assets (RWA), NFT digital collectibles, and crypto funds, the Firm offers services including business structure design, project financing and investment, operational compliance, commercial dispute resolution, establishment of anti-money laundering (AML) compliance systems, cooperation with global law enforcement investigations, digital asset tracing and recovery, criminal risk prevention and control, and criminal defense.