A mid-sized technology company in Zurich received an email from what appeared to be their regular cryptocurrency payment processor. The email informed them of a change in the processor's wallet address and asked them to update their records. The finance team updated the address and proceeded to make a routine payment of 45 ETH (worth approximately $140,000) for vendor services. The payment went to a wallet controlled by scammers, not the payment processor. By the time the company realized the error, the ETH had been moved through a cross-chain bridge and was unrecoverable. This was a business email compromise (BEC) attack — one of the most common and costly forms of business crypto fraud.

As more businesses adopt cryptocurrency — for treasury management, vendor payments, employee compensation, and Web3 operations — business crypto fraud is increasing rapidly. The FBI reported that business email compromise involving cryptocurrency resulted in over $2.9 billion in losses in 2023, and the trend is accelerating. Businesses are attractive targets because they transact in larger amounts than individuals, and corporate payment processes can be manipulated through social engineering.

In this article, I explain the most common types of business crypto fraud, how to prevent them, and what to do if your company has been targeted. This article is written for business owners, CFOs, finance teams, and in-house counsel.

Types of business crypto fraud

1. Business Email Compromise (BEC) with crypto

Business email compromise is the most common form of business crypto fraud. The scammer compromises a legitimate email account (often through phishing or credential theft) and uses it to send fraudulent payment instructions. In the crypto context, BEC typically involves:

BEC attacks are particularly effective because they exploit trust in email communications. The email appears to come from a legitimate source (a vendor, an executive, a payment processor), and the request seems routine. The finance team may not realize that the wallet address has been changed until the vendor complains about not receiving payment — by which time the funds are gone.

2. Corporate treasury fraud

Companies that hold cryptocurrency in their corporate treasury are vulnerable to internal and external fraud:

3. Vendor impersonation

Scammers impersonate legitimate vendors or service providers and request crypto payments. This is similar to BEC but does not necessarily involve email compromise — the scammer may use a different email domain that looks similar (e.g., payment@vendor-llc.com instead of payment@vendor.com), or they may contact the company through a different channel (phone, messaging app).

Vendor impersonation is particularly effective against companies that have recently started using crypto for payments and may not have established verification procedures for crypto transactions.

4. Web3 and smart contract incidents

Companies operating in the Web3 space (DeFi protocols, NFT platforms, blockchain games) face additional risks:

5. Ransomware targeting businesses

Ransomware is a major threat to businesses, and virtually all ransom demands are in cryptocurrency. The ransomware encrypts the company's systems and demands payment in Bitcoin or another cryptocurrency. See our ransomware tracing article for the tracing and recovery aspects of ransomware.

How to prevent business crypto fraud

Prevention is the most effective strategy for business crypto fraud. Here are the key measures:

1. Multi-signature wallets

All corporate cryptocurrency should be held in multi-signature wallets. A multi-signature wallet requires multiple approvals (e.g., 2 of 3, or 3 of 5) for any transaction. This means that a single compromised key or a single rogue employee cannot drain the wallet — the transaction requires approval from multiple authorized individuals. Multi-signature solutions include:

2. Verification procedures for wallet address changes

Never change a wallet address based on an email alone. Always verify wallet address changes through a second channel — call the vendor's known phone number, verify through a video call, or meet in person. This is the single most effective measure against BEC attacks involving crypto.

Establish a written policy: wallet address changes must be verified by at least two employees, through at least two independent channels, and the verification must be documented. This policy should be enforced regardless of the urgency of the payment request.

3. Employee training

Train all employees who handle cryptocurrency payments on the common fraud schemes. The training should include:

4. Cold storage for long-term holdings

Cryptocurrency that is not needed for day-to-day operations should be held in cold storage — offline wallets that cannot be accessed through the internet. Cold storage eliminates the risk of remote hacking. The private keys are generated on an offline device, stored in a physical safe, and only accessed when a transaction is needed.

5. Cyber insurance

Consider purchasing cyber insurance that covers crypto theft. Not all cyber insurance policies cover cryptocurrency — check the policy carefully. The policy should cover theft of cryptocurrency from corporate wallets, theft through BEC, and losses from smart contract exploits (if applicable). See our ransomware article for more on cyber insurance.

What to do if your company has been scammed

If your company has been a victim of crypto fraud, act quickly:

Case study: recovering corporate crypto after a BEC attack

A Swiss technology company was defrauded of 120 ETH ($390,000) in a BEC attack. The scammer compromised the email account of the company's payment processor and sent a wallet address change request. The finance team updated the address and sent the payment. The scammer immediately moved the ETH through Thorchain to Solana, then to a Binance deposit address.

We were engaged within 2 hours of the fraud. Our forensic team traced the ETH through Thorchain and identified the Binance deposit address within 4 hours. We filed an urgent freeze request with Binance, including the forensic report and a preliminary police report. Binance froze the funds ($370,000 — the remaining balance after bridge fees) before the scammer could withdraw.

The company filed a formal police report with FedPol and obtained a Swiss court order compelling Binance to disclose the account holder's identity. The scammer was identified as a resident of a non-EU country. The frozen funds were returned to the company through the legal process, with a total recovery of 97% of the stolen amount. The remaining 3% was lost to bridge fees and exchange processing fees.

The key to the successful recovery was speed — the company engaged us within 2 hours, and we traced and froze the funds within 6 hours. If the company had waited until the next day, the funds would have been withdrawn from Binance and the recovery would not have been possible. This case illustrates the importance of having an incident response plan that includes immediate engagement of forensic and legal resources.

The legal framework for business crypto fraud

Business crypto fraud involves several legal considerations that individual crypto fraud does not:

Building a crypto incident response plan

Every company that holds or transacts in cryptocurrency should have a crypto incident response plan. The plan should include:

The cost of business crypto fraud beyond the immediate loss

The immediate financial loss is only part of the cost of business crypto fraud. Companies that have been defrauded also face:

The total cost of a business crypto fraud incident — including the stolen funds, the investigation costs, the legal costs, the regulatory fines, the reputational damage, and the operational disruption — can be 2-3 times the amount stolen. This is why prevention is so important: the cost of preventing crypto fraud is a fraction of the cost of recovering from it.

The regulatory landscape for business crypto holdings

The regulatory landscape for businesses that hold cryptocurrency is evolving. Key developments include:

The bottom line

Business crypto fraud is a growing threat as more companies adopt cryptocurrency. BEC attacks, treasury fraud, vendor impersonation, and Web3 incidents are the most common types. Each requires a different prevention strategy, and each leaves a different forensic trail. Understanding the specific type of fraud your company faces is the first step toward both prevention and recovery. If you are unsure whether your current security measures are adequate for the threats your company faces, contact us for a security review — we can identify vulnerabilities before scammers do. Prevention — through multi-signature wallets, verification procedures, employee training, cold storage, and cyber insurance — is the best strategy, and the investment in prevention is minimal compared to the cost of a single incident. A multi-signature wallet setup, employee training program, and incident response plan can be implemented for a few thousand dollars — while a single BEC attack can cost hundreds of thousands or millions. The return on investment for crypto security is among the highest of any corporate security measure your company can implement. If fraud does occur, speed is critical: engage forensic and legal resources immediately, trace the funds, and file freeze requests before the scammer can cash out. The first 24 hours determine whether recovery is possible. Companies that act within hours of the fraud have a much higher recovery rate than companies that take days or weeks to respond. In our experience, companies that engage forensic and legal resources within 2 hours of discovering the fraud recover 50-97% of the stolen funds. Companies that wait more than 24 hours typically recover less than 20%. The difference is stark and unforgiving, and it applies regardless of company size or industry.

If your company has been affected by crypto fraud, contact us immediately. We work with corporate victims of crypto fraud to trace stolen funds, file freeze requests, coordinate with law enforcement, and manage the legal and regulatory implications. Our experience with both the forensic and legal aspects of business crypto fraud allows us to provide comprehensive support — from the first hour of the incident to the final recovery, including regulatory notifications, board communications, and insurance claims. Do not wait — contact us the moment you discover the fraud, and let us help you protect your company's assets and reputation. If you have not yet experienced fraud, contact us for a preventive security review — the best time to prepare is before the incident occurs, not after.

N. Silinevics
Nils Silinevics Crypto Compliance Counsel · Former FIU Investigator · Valken Legal AG