Phishing attempts, transaction screening and wallet controls shape what happens when suspicious crypto activity reaches a service.
A crypto transfer often looks straightforward once it reaches the chain. The difficult part is everything that may have happened before it: a fake support message can compromise access, and a compliance review may be the first sign that the funds have drawn attention.
The August breach at crypto payment processor Coinsbuy shows what can follow when access is compromised. As we reported in our review of the Coinsbuy hack, wallets linked to the company lost more than $8 million across Ethereum and TRON. The attacker then began routing part of the stolen assets towards Monero through several exchange services. The available evidence pointed to compromised wallet keys or administrative access. Neither Ethereum nor TRON showed evidence of a protocol-level failure.
The incident does not reveal how access was obtained. In many cases, the first opening is far less technical: a convincing email, a copied support account or a request for a wallet approval.
Crypto Phishing Emails and Fake Support
Crypto phishing emails and fake support accounts aim to obtain a recovery phrase, secure a harmful approval or persuade a wallet holder to sign a transaction.
Our analysis of crypto phishing emails examined a September 2026 campaign targeting Trezor users. Attackers used compromised Brevo newsletter infrastructure to send a fake security notice to roughly 347,000 addresses. Trezor said that its devices and internal systems were unaffected. Around 2,500 recipients reached the malicious domain before it was removed.
Sender details offer only one clue. The pressure inside the message often reveals more: a deadline, a request to move funds or a demand to switch the conversation to a different channel.
The strongest red flags are usually urgency, fear, and unusual requests. If a message pressures you to act immediately, move funds, install software, connect a wallet, or unexpectedly switch to another communication channel, you should become cautious. AI has made phishing cheaper, easier to scale, and much more professional, so poor grammar or bad design are no longer reliable warning signs.
— Albert Quehenberger, CEO of AQ Forensics and ChangeNOW Ambassador
A suspicious link can lead to a cloned sign-in page, a malicious download or a wallet-connection request. The greatest risk arrives when a user enters a seed phrase, installs software, signs an unfamiliar message or approves a transaction. Our guide to phishing emails explains the practical steps to take after an attempted compromise.
Fake Crypto Migration Scams
Fake crypto migration messages use real regulatory deadlines and platform changes to make an attacker’s request look routine.
Our analysis of fake exchange migration requests uses the EU’s July 2026 MiCA licensing deadline as an example. The article cites more than 1,700 unlicensed platforms that could have to limit or stop EU service, potentially affecting up to 10 million users. That real deadline gave fraudulent “account migration” and “wallet re-verification” messages a plausible pretext.
A genuine migration is announced through a provider’s official channels. It never requires a seed phrase or private key. We receive reports of impersonation websites or channels one to three times each week, according to the same migration-scam analysis. A report from a user or a community member may provide the first lead, allowing our team to document the fraud and request action against a malicious domain.
What Happens After Crypto Is Stolen
Once an attacker has wallet access or an approved permission, stolen crypto can move across addresses, networks and services within minutes. A screened service may become the first place where the route of those assets is examined.
Our Coinsbuy incident report traced the first outflows to two Ethereum addresses and one TRON address. Coinsbuy paused deposits and withdrawals during its assessment, then restored service within hours.
Transfers can become visible when they enter a service that assesses address exposure, transaction routes and other risk indicators. Assets that remain in self-custodied wallets stay beyond the direct reach of an individual provider’s risk systems. The next point of contact may be a swap, an exchange deposit or another service interaction.
Why Crypto Transactions Get Flagged for AML Review
Crypto transactions enter AML review when transaction data indicates exposure to theft, fraud, sanctions or other elevated risks. The review establishes the context a provider needs before deciding how to handle a transfer.
Our guide to flagged crypto transactions lists exposure to addresses associated with theft, fraud, ransomware or sanctions, unusual transaction patterns and sanctions screening as possible grounds for review. Precise trigger thresholds remain confidential because publishing them would undermine the controls designed to detect risk.
An AML review doesn't mean you are trying to swap stolen money. Our review serves the main purpose — to make sure that we can either proceed with the swap or return the funds of a scam or a hack with the help of law enforcement.
— Pauline Shangett, Chief Strategy Officer at ChangeNOW
Reviews can involve automated signals, manual analysis and requests for identity, source-of-funds or transaction-history documents.
Every AML review is different. After a transaction is flagged, our compliance team reviews the case manually and determines the next steps based on the specific circumstances. There is no universal timeframe or identical review flow for every transaction. Providing the requested information promptly and following the compliance team’s instructions can help avoid unnecessary delays and move the review forward more efficiently.
— ChangeNOW Compliance Team
Can Stolen Crypto Be Recovered?
Sometimes. Recovery depends on prompt reporting, traceable fund flows and stolen assets reaching a service or institution able to act. Every case turns on its own facts.
In a case study of a $220,000 phishing loss, we described a user who submitted wallet information through a website impersonating a crypto platform. After receiving the report, we adjusted risk settings associated with the case. When the attacker later attempted a swap, our systems froze the assets. We then provided transaction information to the Singapore Police Force. The funds returned to the victim after the relevant legal process concluded.
Our safety report on two US cases details a further $295,000 in stolen digital assets returned to victims after attempted exchanges entered enhanced monitoring. One case involved about $185,000 from an investment scam. The other involved roughly $110,000 after a phishing link exposed a wallet. Early reports, targeted monitoring, manual confirmation and validation from the relevant law-enforcement agencies made those outcomes possible.
Those cases describe specific investigations, not an expected recovery rate. Over nine years, we have returned more than $50 million to victims of scams, hacks and thefts, as Pauline notes in our AML review explainer. Delayed reports, repeated transfers, cross-chain movement and assets held beyond a provider’s operational reach reduce the options available at each subsequent step.
Unfortunately we can't return the user's funds, because they never actually reached us, they went straight to the scammer's wallet. What we can do is explain to the user that they've been targeted by fraud and walk them through how to tell our official site apart from a scam site. On top of that, we report the fake site to the registrar ourselves and push to get it taken down.
— ChangeNOW Compliance Team
Crypto Wallet Security and Transaction Approvals
Crypto wallet security depends on who can access a device, what a user approves and how much value sits behind a single wallet or recovery method.
Our wallet-security article cites estimates of roughly $17 billion in crypto scam losses during 2025, alongside a year-over-year increase of more than 1,400% in impersonation scams. Hardware wallets keep private keys away from remote extraction. A malicious approval can still authorise the movement of assets, which is why the confirmation screen deserves the same scrutiny as the wallet itself.
Separating balances by purpose limits exposure. An everyday wallet can hold an operational amount for regular activity. Offline storage can hold funds with a longer time horizon.
Systems used for significant crypto holdings are often also used for everyday email, browsing, downloads and normal office activity. Every additional use increases the attack surface.
— Albert Quehenberger, CEO of AQ Forensics and ChangeNOW Ambassador
How to Store a Seed Phrase Securely
A seed phrase can restore control of an entire self-custodied wallet. Keeping it offline and separate from internet-connected devices reduces the chance that a single compromise exposes both funds and the recovery method.
Our seed-phrase storage guide refers to a January 2026 fake-Trezor-support scam in which a holder reportedly lost roughly $282 million after sharing a 12-word recovery phrase. The attacker received the information required to recreate access to the wallet.
Offline, durable backups held in separate locations reduce the number of systems that can expose a recovery phrase. Screenshots, cloud notes, email drafts and chat messages leave digital copies that may be reachable during the same compromise affecting a wallet.
From the cases I see in forensic work, the cryptography itself is rarely what fails. The recurring problem is the human and operational layer.
— Albert Quehenberger, CEO of AQ Forensics and ChangeNOW Ambassador
Large Bitcoin holdings require planning around cold storage, backups, recovery testing and transaction procedures. Our guide to storing large Bitcoin balances covers geographically separated backups and multisignature arrangements alongside cold storage. Each setup needs tested backups and a written recovery plan.
The first alert may arrive in an inbox. Another may surface when a service pauses a transfer. Both moments can determine how much control remains once crypto starts moving.
Thank you for reading this week’s digest. A security check may feel like an interruption, but it can also be the first moment suspicious activity becomes visible.