A mid-sized technology company in Zurich received an email from what appeared to be their regular cryptocurrency payment processor. The email informed them of a change in the processor's wallet address and asked them to update their records. The finance team updated the address and proceeded to make a routine payment of 45 ETH (worth approximately $140,000) for vendor services. The payment went to a wallet controlled by scammers, not the payment processor. By the time the company realized the error, the ETH had been moved through a cross-chain bridge and was unrecoverable. This was a business email compromise (BEC) attack — one of the most common and costly forms of business crypto fraud.
As more businesses adopt cryptocurrency — for treasury management, vendor payments, employee compensation, and Web3 operations — business crypto fraud is increasing rapidly. The FBI reported that business email compromise involving cryptocurrency resulted in over $2.9 billion in losses in 2023, and the trend is accelerating. Businesses are attractive targets because they transact in larger amounts than individuals, and corporate payment processes can be manipulated through social engineering.
In this article, I explain the most common types of business crypto fraud, how to prevent them, and what to do if your company has been targeted. This article is written for business owners, CFOs, finance teams, and in-house counsel.
Types of business crypto fraud
1. Business Email Compromise (BEC) with crypto
Business email compromise is the most common form of business crypto fraud. The scammer compromises a legitimate email account (often through phishing or credential theft) and uses it to send fraudulent payment instructions. In the crypto context, BEC typically involves:
- Wallet address change requests: The scammer sends an email (from a compromised or spoofed account) claiming that the company's vendor, exchange, or payment processor has changed its wallet address. The finance team updates the address and sends the next payment to the scammer's wallet.
- Urgent payment requests: The scammer impersonates a senior executive (CEO, CFO) and sends an urgent email requesting a crypto payment for a time-sensitive transaction (an acquisition, an emergency vendor payment). The urgency overrides the finance team's normal verification procedures.
- Invoice fraud: The scammer intercepts a legitimate invoice and modifies the wallet address. The company pays the invoice, but the payment goes to the scammer's wallet instead of the vendor's.
BEC attacks are particularly effective because they exploit trust in email communications. The email appears to come from a legitimate source (a vendor, an executive, a payment processor), and the request seems routine. The finance team may not realize that the wallet address has been changed until the vendor complains about not receiving payment — by which time the funds are gone.
2. Corporate treasury fraud
Companies that hold cryptocurrency in their corporate treasury are vulnerable to internal and external fraud:
- Insider theft: An employee with access to the company's crypto wallet steals funds. This is particularly common in companies that do not implement proper multi-signature controls — a single employee with the private key can drain the entire wallet.
- Compromised keys: If the company's private keys are stored insecurely (on a server, in a cloud storage account, or on an employee's laptop), a hacker can steal the keys and drain the wallet. This has happened to several companies that did not implement proper key management.
- Exchange account compromise: If the company holds crypto on an exchange and the exchange account credentials are compromised, the attacker can withdraw the funds to their own wallet.
3. Vendor impersonation
Scammers impersonate legitimate vendors or service providers and request crypto payments. This is similar to BEC but does not necessarily involve email compromise — the scammer may use a different email domain that looks similar (e.g., payment@vendor-llc.com instead of payment@vendor.com), or they may contact the company through a different channel (phone, messaging app).
Vendor impersonation is particularly effective against companies that have recently started using crypto for payments and may not have established verification procedures for crypto transactions.
4. Web3 and smart contract incidents
Companies operating in the Web3 space (DeFi protocols, NFT platforms, blockchain games) face additional risks:
- Smart contract exploits: A vulnerability in the company's smart contract is exploited by a hacker, who drains the protocol's funds. See our DeFi exploit article for the legal implications.
- Front-end compromise: The company's web front-end is compromised, and users are tricked into sending funds to a hacker's address instead of the company's address. This has happened to several DeFi protocols where the DNS was hijacked.
- Oracle manipulation: A DeFi protocol that relies on price oracles is exploited through oracle manipulation, allowing the attacker to drain funds at artificially favorable prices.
5. Ransomware targeting businesses
Ransomware is a major threat to businesses, and virtually all ransom demands are in cryptocurrency. The ransomware encrypts the company's systems and demands payment in Bitcoin or another cryptocurrency. See our ransomware tracing article for the tracing and recovery aspects of ransomware.
How to prevent business crypto fraud
Prevention is the most effective strategy for business crypto fraud. Here are the key measures:
1. Multi-signature wallets
All corporate cryptocurrency should be held in multi-signature wallets. A multi-signature wallet requires multiple approvals (e.g., 2 of 3, or 3 of 5) for any transaction. This means that a single compromised key or a single rogue employee cannot drain the wallet — the transaction requires approval from multiple authorized individuals. Multi-signature solutions include:
- Safe (formerly Gnosis Safe): The most widely used multi-signature solution on Ethereum and EVM-compatible chains. Used by many DeFi protocols and Web3 companies.
- Casa: A multi-signature solution for Bitcoin, with inheritance features.
- Unchained Capital: A Bitcoin multi-signature solution with institutional features.
- BitGo: An institutional-grade multi-signature custodian for multiple cryptocurrencies.
2. Verification procedures for wallet address changes
Never change a wallet address based on an email alone. Always verify wallet address changes through a second channel — call the vendor's known phone number, verify through a video call, or meet in person. This is the single most effective measure against BEC attacks involving crypto.
Establish a written policy: wallet address changes must be verified by at least two employees, through at least two independent channels, and the verification must be documented. This policy should be enforced regardless of the urgency of the payment request.
3. Employee training
Train all employees who handle cryptocurrency payments on the common fraud schemes. The training should include:
- How to recognize phishing emails and BEC attacks
- The importance of verifying wallet address changes through a second channel
- The risks of clicking links in emails (which can lead to credential theft)
- The procedures for handling urgent payment requests (always verify, even if the request comes from the CEO)
- The dangers of storing private keys on company devices or in cloud storage
4. Cold storage for long-term holdings
Cryptocurrency that is not needed for day-to-day operations should be held in cold storage — offline wallets that cannot be accessed through the internet. Cold storage eliminates the risk of remote hacking. The private keys are generated on an offline device, stored in a physical safe, and only accessed when a transaction is needed.
5. Cyber insurance
Consider purchasing cyber insurance that covers crypto theft. Not all cyber insurance policies cover cryptocurrency — check the policy carefully. The policy should cover theft of cryptocurrency from corporate wallets, theft through BEC, and losses from smart contract exploits (if applicable). See our ransomware article for more on cyber insurance.
What to do if your company has been scammed
If your company has been a victim of crypto fraud, act quickly:
- Stop the bleeding: If the fraud is ongoing (e.g., a compromised email account is still sending fraudulent payment instructions), stop it immediately. Disable compromised accounts, change passwords, and isolate affected systems.
- Preserve evidence: Preserve all emails, transaction records, wallet addresses, and system logs. Do not delete anything. See our evidence checklist for what to preserve.
- Trace the funds: Engage a blockchain forensic firm immediately to trace the stolen cryptocurrency. The faster the tracing begins, the more likely the funds can be intercepted at an exchange before the scammer cashes out.
- File freeze requests: If the funds are traced to an exchange, file a freeze request immediately. Include the police report, the forensic report, and the transaction evidence.
- Notify your insurance: If you have cyber insurance, notify the insurer immediately. The insurer will have its own investigation process and may require you to use their preferred forensic firms and lawyers.
- Report to law enforcement: File a report with the appropriate law enforcement agency (FBI IC3 in the US, Action Fraud in the UK, BKA in Germany, FedPol in Switzerland). See our police reporting guide for details.
- Notify your board and stakeholders: If the loss is material, you may have an obligation to notify your board, shareholders, or regulators. Consult with your legal counsel on the notification requirements.
- Conduct a post-incident review: After the immediate crisis is handled, conduct a thorough review of how the fraud occurred and implement measures to prevent it from happening again.
Case study: recovering corporate crypto after a BEC attack
A Swiss technology company was defrauded of 120 ETH ($390,000) in a BEC attack. The scammer compromised the email account of the company's payment processor and sent a wallet address change request. The finance team updated the address and sent the payment. The scammer immediately moved the ETH through Thorchain to Solana, then to a Binance deposit address.
We were engaged within 2 hours of the fraud. Our forensic team traced the ETH through Thorchain and identified the Binance deposit address within 4 hours. We filed an urgent freeze request with Binance, including the forensic report and a preliminary police report. Binance froze the funds ($370,000 — the remaining balance after bridge fees) before the scammer could withdraw.
The company filed a formal police report with FedPol and obtained a Swiss court order compelling Binance to disclose the account holder's identity. The scammer was identified as a resident of a non-EU country. The frozen funds were returned to the company through the legal process, with a total recovery of 97% of the stolen amount. The remaining 3% was lost to bridge fees and exchange processing fees.
The key to the successful recovery was speed — the company engaged us within 2 hours, and we traced and froze the funds within 6 hours. If the company had waited until the next day, the funds would have been withdrawn from Binance and the recovery would not have been possible. This case illustrates the importance of having an incident response plan that includes immediate engagement of forensic and legal resources.
The legal framework for business crypto fraud
Business crypto fraud involves several legal considerations that individual crypto fraud does not:
- Corporate governance: The company's board has a fiduciary duty to protect corporate assets. Failure to implement adequate crypto security measures may constitute a breach of fiduciary duty, potentially exposing directors to shareholder claims.
- Regulatory reporting: Depending on the jurisdiction and the size of the loss, the company may be required to report the incident to regulators (FINMA in Switzerland, BaFin in Germany, the SEC in the US). Public companies may have disclosure obligations under securities laws.
- Insurance claims: Cyber insurance claims require careful documentation and adherence to the policy's notification requirements. Failure to notify the insurer promptly may result in denial of the claim.
- Employee liability: If an employee's negligence contributed to the fraud (e.g., they failed to verify a wallet address change), the company may have a claim against the employee. However, employee liability is typically limited by employment law.
- Vendor liability: If the fraud involved a compromised vendor email account, the vendor may be liable for the loss if their email security was inadequate. This depends on the terms of the vendor contract and the applicable law.
Building a crypto incident response plan
Every company that holds or transacts in cryptocurrency should have a crypto incident response plan. The plan should include:
- Designated response team: Identify who will be involved in the response — the CFO, the CISO, legal counsel, the forensic firm, the cyber insurer. Have their contact information readily available.
- Immediate actions: Define the immediate actions to take when crypto fraud is discovered — stop the bleeding, preserve evidence, engage the forensic firm, notify the insurer.
- Communication plan: Define how the incident will be communicated internally (to employees, the board) and externally (to regulators, customers, the public, if required).
- Legal counsel: Identify legal counsel experienced in crypto fraud recovery and engage them in advance. Do not wait until an incident occurs to find a lawyer — the response time is critical.
- Tabletop exercises: Conduct regular tabletop exercises to practice the response plan. These exercises help identify gaps in the plan and ensure that the response team knows their roles.
The cost of business crypto fraud beyond the immediate loss
The immediate financial loss is only part of the cost of business crypto fraud. Companies that have been defrauded also face:
- Reputational damage: If the fraud becomes public (through regulatory filings, media coverage, or customer notifications), the company's reputation may be damaged. Customers and partners may lose trust in the company's ability to protect its assets.
- Operational disruption: The investigation and recovery process can disrupt normal operations. Finance teams may need to suspend crypto payments while the investigation is ongoing. IT teams may need to take systems offline for forensic analysis.
- Regulatory scrutiny: A significant crypto fraud incident may attract regulatory attention. FINMA, BaFin, the SEC, and other regulators may investigate the company's crypto security practices. This can lead to enforcement actions, fines, or increased regulatory oversight.
- Increased insurance premiums: After a fraud incident, cyber insurance premiums typically increase significantly. Some insurers may refuse to renew the policy, leaving the company without coverage.
- Shareholder claims: If the loss is material and the company's stock price is affected, shareholders may file claims against the company and its directors for failing to implement adequate controls.
- Employee morale: Employees who were involved in the incident (e.g., the finance team that processed the fraudulent payment) may experience significant stress and may leave the company.
The total cost of a business crypto fraud incident — including the stolen funds, the investigation costs, the legal costs, the regulatory fines, the reputational damage, and the operational disruption — can be 2-3 times the amount stolen. This is why prevention is so important: the cost of preventing crypto fraud is a fraction of the cost of recovering from it.
The regulatory landscape for business crypto holdings
The regulatory landscape for businesses that hold cryptocurrency is evolving. Key developments include:
- DORA (Digital Operational Resilience Act): The EU's DORA regulation, effective from 2025, imposes cybersecurity and operational resilience requirements on financial entities, including companies that hold crypto assets. DORA requires companies to have incident response plans, conduct regular security testing, and report major incidents to regulators.
- MiCA: The EU's MiCA regulation (see our MiCA article) requires companies that provide crypto services to be authorized and supervised. Companies that hold crypto for their own account (not as a service) are not directly subject to MiCA, but may be affected indirectly.
- Accounting standards: The IFRS and US GAAP are developing guidance on how companies should account for cryptocurrency holdings on their balance sheets. This affects how crypto losses are reported in financial statements.
- Audit requirements: Companies that hold significant crypto assets may face additional audit requirements. Auditors need to verify the existence and valuation of crypto assets, which requires specialized procedures.
The bottom line
Business crypto fraud is a growing threat as more companies adopt cryptocurrency. BEC attacks, treasury fraud, vendor impersonation, and Web3 incidents are the most common types. Each requires a different prevention strategy, and each leaves a different forensic trail. Understanding the specific type of fraud your company faces is the first step toward both prevention and recovery. If you are unsure whether your current security measures are adequate for the threats your company faces, contact us for a security review — we can identify vulnerabilities before scammers do. Prevention — through multi-signature wallets, verification procedures, employee training, cold storage, and cyber insurance — is the best strategy, and the investment in prevention is minimal compared to the cost of a single incident. A multi-signature wallet setup, employee training program, and incident response plan can be implemented for a few thousand dollars — while a single BEC attack can cost hundreds of thousands or millions. The return on investment for crypto security is among the highest of any corporate security measure your company can implement. If fraud does occur, speed is critical: engage forensic and legal resources immediately, trace the funds, and file freeze requests before the scammer can cash out. The first 24 hours determine whether recovery is possible. Companies that act within hours of the fraud have a much higher recovery rate than companies that take days or weeks to respond. In our experience, companies that engage forensic and legal resources within 2 hours of discovering the fraud recover 50-97% of the stolen funds. Companies that wait more than 24 hours typically recover less than 20%. The difference is stark and unforgiving, and it applies regardless of company size or industry.
If your company has been affected by crypto fraud, contact us immediately. We work with corporate victims of crypto fraud to trace stolen funds, file freeze requests, coordinate with law enforcement, and manage the legal and regulatory implications. Our experience with both the forensic and legal aspects of business crypto fraud allows us to provide comprehensive support — from the first hour of the incident to the final recovery, including regulatory notifications, board communications, and insurance claims. Do not wait — contact us the moment you discover the fraud, and let us help you protect your company's assets and reputation. If you have not yet experienced fraud, contact us for a preventive security review — the best time to prepare is before the incident occurs, not after.