Every skeptic has heard the mantra: "On-chain data doesn't lie."
But here's a $22 million counterexample that wasn't even a smart contract. The SEC just hit Florida resident Zan Shaikh and his company Mining Automatic with a lawsuit for defrauding over 380 investors. The pitch was simple—pool money for crypto mining, get guaranteed monthly returns. The reality was even simpler: only 13% of the funds ever touched mining hardware. The rest went to marketing, personal expenses, and paying early investors in a textbook Ponzi structure.
No token launch. No DeFi integration. No NFT collection. Just a bank account and a promise.
Context: Who Was Mining Automatic?
The complaint (filed in the U.S. District Court for the Southern District of Florida) alleges that between 2023 and 2025, Shaikh marketed Mining Automatic as a professional mining operation. Investors were promised a fixed monthly return—terms vague enough to avoid spelling out an APR, but implied to be "guaranteed." In total, $22 million was raised.
Here's where the data gets cold: SEC filings show that only about $2.86 million (13%) actually went toward mining operations. The remaining $19.14 million was funneled into two buckets: (1) aggressive marketing to recruit new investors, and (2) personal luxury spending for Shaikh and unrelated business costs. The Ponzi mechanics are textbook—new money paid old money, and the gap between raised and returned was at least $20 million.
No on-chain evidence exists because there was no chain. The entire operation was a traditional financial fraud wrapped in crypto lingo.
Core: Where the Data Would Have Spoken
I've spent years staring at transaction logs—first as a junior auditor catching reentrancy bugs in 2017 ICO contracts, then analyzing DeFi farming loops in 2020, and most recently tracking AI-agent trade patterns on Solana in 2025. Every one of those cases had one thing in common: the code eventually told the truth.
But this case is different. There was no code. And that's precisely why it succeeded.
Let's reverse-engineer what a legitimate MaaS (Mining-as-a-Service) operation should look like on-chain:

- Hashrate Proof: A real mining pool publishes real-time hashrate and payout addresses. For example, Foundry USA maintains a public dashboard showing 30+ EH/s and daily miner payouts. Mining Automatic offered zero such transparency.
- Reserve Verification: Any fund that pools miner capital should hold the underlying hardware or at least provide a custody receipt. In this case, the 13% mining spend likely went to a cloud mining contract that wasn't even owned by Shaikh.
- Return Consistency: Guaranteed monthly returns are mathematically impossible in mining. Bitcoin's hashprice (revenue per TH/s) varies with difficulty and BTC price. A fixed monthly return implies either a Ponzi or a miracle. A quick historical check shows that no major mining fund ever promised fixed returns—because it's structurally unsustainable.
Imagine if Shaikh had actually deployed a smart contract for the investment pool. We could have traced the 13% flow to mining addresses, the 87% flow to personal wallets, and flagged the anomaly within hours. Any on-chain detective would have spotted the massive gap between "operational spend" and "investor payouts."
But Shaikh didn't need a contract. He just needed a bank account and a compelling story. And that's the uncomfortable truth: most retail investors check for a website, a pitch deck, maybe a company registration—they don't ask for a public address to verify mining activity.
Volume without intent is just digital noise. Here, the volume was all noise—the 87% had no productive intent at all.

From my 2020 Harvest Finance analysis, I learned that yield is often just gas fee redistribution when the underlying model breaks. Here, the yield was just new investor principal redistribution. The same principle applies: if you can't trace the revenue source, assume it doesn't exist.
Contrarian: The Blind Spot We All Miss
The easy takeaway is "don't trust guaranteed returns." Everyone knows that. But the deeper problem is that the crypto industry has fetishized code transparency while ignoring the simplest fraud vector: non-smart-contract promises.
We've built dashboards for every DeFi protocol, TVL trackers, and NFT wash-trading detectors. But none of that protects an investor who hands over bank wire money to a fake mining company. In fact, the obsession with on-chain metrics might give investors a false sense of security—they think "I'll only invest in projects I can audit," while ignoring the fact that the biggest scams operate outside the chain.
Here's the contrarian punch:
Smart contracts are not the barrier to fraud; they are a lightweight accountability tool. A real mining company that uses smart contracts to manage pool contributions is actually more trustworthy because those contracts can be audited. Mining Automatic avoided contracts not because they were unsophisticated, but because they knew that code would expose them.
Yet many legitimate MaaS projects still rely on traditional corporate structures and opaque financial statements. The crypto community applauds them for being "regulated" without demanding on-chain proof of operations. That's a blind spot—regulation doesn't prevent fraud; it punishes it after the fact. On-chain proof prevents it ex-ante.
Trust, but verify. On-chain verification is the only truth.
Takeaway: The Signal for the Next 6 Months
This SEC action is a warning, but not just to scammers. It's a warning to investors and analysts: if a project's value proposition can be executed without blockchain, it probably isn't blockchain.
The next wave of mining scams will likely wrap themselves in AI-agent narratives or RWA tokenization to distract from the same Ponzi structure. When you hear "guaranteed return" combined with "mining" or "staking," immediately ask for the on-chain address holding the productive assets. If they can't provide one that demonstrably earns revenue, assume it's a lie.
A guaranteed return is the first sign of fraud. The second sign is the absence of code.
The final word belongs to the data: Shaikh raised $22M, returned only $2M, and now faces permanent injunction. The real loss isn't just the money—it's the trust that could have been preserved with a simple public ledger. Next time someone offers you a deal that's "too good to be true," ask for the wallet. If there's no wallet, walk away.