Fraud Recovery · Phishing · Bitfinex
Act fast

Phishing on Bitfinex?
We trace and freeze.

A fake Bitfinex login page captured your credentials. The attacker accessed your account and withdrew your crypto. Bitfinex is BVI-registered and operated by iFinex (the same parent company as Tether). Bitfinex has BSA (Bank Secrecy Act) compliance procedures and is subpoena-responsive — they have cooperated with US DOJ and SEC investigations. The $10,000 minimum deposit for verified accounts means Bitfinex scammers are typically higher-value operators.

◉ Swiss licensed lawyers◉ Blockchain forensics◉ Bitfinex compliance channel
How it works

How phishing works on Bitfinex

Bitfinex phishing attacks are less common than Binance or Coinbase phishing — Bitfinex has fewer users and a $10,000 minimum for verified accounts, which filters out many small-scale scammers. However, the phishing attacks that do target Bitfinex users tend to be more sophisticated and higher-value. The attacker creates a fake Bitfinex login page — bitfinex-secure-login.com, bitfinex-verify-account.net — and sends a phishing email mimicking Bitfinex's security notifications.

The Tether connection: Bitfinex and Tether are both operated by iFinex Inc. If your stolen funds were in USDT, there's a unique recovery path: we can pursue both a Bitfinex exchange freeze AND a Tether on-chain blacklist. Tether can freeze USDT at the smart contract level on Ethereum, Tron, and other chains. This dual approach — exchange freeze + on-chain blacklist — is only available when the stolen funds are in USDT and the scammer used Bitfinex. See our Tether blacklist page for the on-chain freeze mechanism.

The institutional account structure: Bitfinex's $10K minimum and institutional focus means the compliance process is more thorough than retail-focused exchanges. Higher-tier Bitfinex accounts may have submitted Source of Wealth documentation. Through legal process, we can obtain these SoW documents — and if they're fabricated (common for scammers), they serve as additional evidence of fraud. This is a unique advantage of Bitfinex cases.

The 2016 hack legacy: Bitfinex suffered a major hack in 2016 (120,000 BTC stolen). Since then, Bitfinex has improved its security infrastructure, including enhanced 2FA requirements and withdrawal whitelists. However, these security features protect the exchange — not individual users who are phished. If you gave the attacker your credentials, Bitfinex's security infrastructure cannot prevent the withdrawal.

Bitfinex response

How Bitfinex handles phishing cases

Compliance structure: Bitfinex's compliance team operates under BVI registration with BSA (Bank Secrecy Act) compliance obligations. Bitfinex is subpoena-responsive — they have cooperated with US DOJ investigations, SEC inquiries, and international law enforcement requests. Response times: 7-14 business days for freeze requests. Bitfinex is methodical in their compliance approach.

Freeze capability: Bitfinex can freeze accounts receiving stolen funds. Requires a court order, subpoena, or law enforcement request. Bitfinex is BVI-registered, so the legal process follows BVI procedures or MLAT for international requests. However, because Bitfinex has BSA obligations and has historically cooperated with US authorities, they are more responsive than purely offshore exchanges. Response: 7-14 business days.

KYC and SoW disclosure: Bitfinex KYC includes: government ID, proof of address, and for higher-tier accounts, source of wealth documentation. The $10K minimum means most Bitfinex accounts have higher-tier verification. Through legal process (subpoena or MLAT), we can obtain the KYC and any SoW documents. Fabricated SoW documents are additional evidence of fraud.

The dual USDT path: If your stolen funds were in USDT, we can pursue recovery through two channels simultaneously: (1) Bitfinex exchange freeze — freeze the attacker's Bitfinex account, and (2) Tether on-chain blacklist — freeze the USDT at the smart contract level on Ethereum/Tron/etc. This dual approach increases recovery chances. If the attacker withdraws USDT from Bitfinex before the exchange freeze, the on-chain blacklist still prevents them from transferring the USDT to another exchange.

Step by step

Our recovery process for Bitfinex phishing

  • 1. Immediate damage control (0-2h): If you still have access: change password, review withdrawal whitelist, check withdrawal history. If you lost access: contact Bitfinex support through the official website.
  • 2. Blockchain tracing (2-48h): We trace the stolen funds on-chain to identify the Bitfinex deposit address. If funds are in USDT, we also prepare the Tether blacklist request as a parallel recovery path.
  • 3. Legal freeze request (7-14 days): We file a legal request with Bitfinex's compliance team. If funds are in USDT, we simultaneously file a Tether blacklist request through legal channels. Bitfinex responds within 7-14 business days.
  • 4. KYC and SoW disclosure (2-6 weeks): Through subpoena or MLAT, we obtain the attacker's Bitfinex KYC and any Source of Wealth documentation. Fabricated SoW documents are additional fraud evidence.
  • 5. Recovery (4-16 weeks): With identity known and funds frozen (on Bitfinex and/or on-chain via Tether blacklist), we pursue civil recovery or coordinate criminal proceedings. Bitfinex cases see 65-80% recovery rates — higher when USDT dual-path is available.
Real case

Case: Bitfinex phishing with Tether dual-path

A client received a phishing email that mimicked Bitfinex: "Bitfinex Security: Withdrawal Request Confirmation. You have requested to withdraw 85,000 USDT." The email contained a link to bitfinex-cancel-withdrawal.com. The client clicked, entered credentials and 2FA code on the fake page.

The attack: The attacker logged into the real Bitfinex, added a new withdrawal address (an external Tron wallet), and withdrew 85,000 USDT (~€85,000). The external wallet then attempted to transfer the USDT to a second exchange for cash-out.

The dual-path recovery: We pursued two recovery channels simultaneously: (1) We filed a legal freeze request with Bitfinex's compliance team — they cooperated (subpoena-responsive) and shared the attacker's KYC within 10 business days. The KYC revealed a resident of Hong Kong. (2) We filed a Tether blacklist request through legal channels — Tether blacklisted the attacker's Tron wallet address at the smart contract level, preventing the USDT from being transferred to any other address. The attacker's USDT was frozen on-chain.

Outcome: 88% recovery (€75,000 of €85,000). The Tether on-chain blacklist was the key — it froze the USDT before the attacker could move them to a second exchange. The Bitfinex KYC identified the attacker. The €10,000 gap was due to the attacker having already converted some USDT to TRX before the blacklist. Civil recovery proceedings initiated in Hong Kong.

Details anonymized to protect client confidentiality. Swiss professional secrecy applies.

Were your stolen funds in USDT? We can pursue a Tether on-chain blacklist in parallel with the Bitfinex freeze — the dual-path approach significantly increases recovery chances.

Warning: After a phishing attack, fake "recovery services" will contact you. Read our recovery scam warning before engaging anyone.

FAQ

Phishing on Bitfinex — questions

Bitfinex is connected to Tether. Does this help phishing recovery?

Yes — significantly. Bitfinex and Tether are both operated by iFinex Inc. If your stolen funds are in USDT, we can pursue a dual-path recovery: (1) Bitfinex exchange freeze — freeze the attacker's Bitfinex account, and (2) Tether on-chain blacklist — freeze the USDT at the smart contract level on Ethereum, Tron, and other chains. Even if the attacker withdraws USDT from Bitfinex before the exchange freeze, the on-chain blacklist prevents them from transferring the USDT to another exchange. This dual approach is only available when the stolen funds are in USDT and the scammer used Bitfinex.

How long does Bitfinex take to respond to a freeze request?

7-14 business days. Bitfinex is BVI-registered but has BSA compliance obligations and is subpoena-responsive — they have cooperated with US DOJ and SEC investigations. For non-US jurisdictions, we use BVI legal procedures or MLAT. Bitfinex is methodical in their compliance approach — they don't rush but they follow procedures correctly.

Can I get the attacker's Source of Wealth documents from Bitfinex?

Bitfinex's $10K minimum for verified accounts means most accounts have higher-tier verification, which includes Source of Wealth documentation — bank statements, business records, tax filings. Through a subpoena or MLAT, we can obtain these. If the SoW documents are fabricated (common for scammers), they serve as additional evidence of fraud. This is a unique advantage of Bitfinex cases — the $10K minimum means scammers using Bitfinex are typically higher-value and have submitted more documentation.

Why do scammers use Bitfinex for phishing?

Bitfinex has a $10,000 minimum for verified accounts, which filters out small-scale scammers. The scammers who use Bitfinex tend to be higher-value operators running sophisticated phishing campaigns. The institutional account structure makes them harder to catch — but also means larger recoverable amounts. The Tether connection (iFinex parent company) is another reason — scammers who deal in USDT may route funds through Bitfinex.

Was Bitfinex hacked before? Is it safe?

Bitfinex suffered a major hack in 2016 (120,000 BTC stolen). Since then, Bitfinex has improved its security infrastructure significantly, including enhanced 2FA, withdrawal whitelists, and cold storage. However, these security features protect the exchange — not individual users who are phished. If you gave the attacker your credentials, Bitfinex's security infrastructure cannot prevent the withdrawal. Recovery relies on tracing and freezing, not on exchange security.

How is Bitfinex different from Binance for phishing recovery?

Bitfinex is slower (7-14 days vs Binance's 3-7 days), has fewer users (smaller compliance team), and is BVI-registered (less transparent than Binance's multi-jurisdictional approach). However, Bitfinex has unique advantages: the Tether dual-path (on-chain USDT blacklist + exchange freeze), the $10K minimum (higher-value scammers = more documentation), subpoena responsiveness (cooperates with US authorities), and SoW documentation collection. Bitfinex cases see 65-80% recovery rates — higher when the USDT dual-path is available.

Related

Other scams on Bitfinex

Investment Fraud
Rug Pull
Pig Butchering
SIM Swap

Phishing on other platforms

Binance
Bybit
Coinbase
Kraken
OKX
ALL PLATFORMS →
REPORT NOW

Phishing on Bitfinex?
Every hour counts.

Describe what happened. Include the phishing URL, withdrawal addresses, transaction hashes, and amount stolen. If funds are in USDT, mention this — we may pursue the Tether dual-path. We respond within 6 hours.

Swiss lawyersBlockchain forensicsBitfinex + Tether dual-path