The Bitcoin Payment Pretexts Used Against Businesses
Fake suppliers, urgent director requests and refund manipulation. The specific scripts, and why finance teams act on them.
Priya Raman · 2 min read
The technical attacks against business crypto are rarer than the conversational ones. These are the scripts that actually succeed. Against a provider that lets a business accept Bitcoin payments, which operates these controls by obligation, the gaps elsewhere become obvious.
The urgent director
A message appearing to come from a senior person, usually while they are travelling, instructing an immediate payment. Confidential, time critical, and outside the normal process.
It works because the recipient is junior relative to the apparent sender, the request is framed as trusting them with something sensitive, and questioning it feels like failing a test.
The defence is structural: there is no process for payments outside the process. Any company that permits an exception for urgency has published its own vulnerability.
The supplier with new details
Covered elsewhere and worth repeating because it is the most expensive. A genuine supplier thread, a genuine invoice, one changed field.
The defence is out of band confirmation of any address change, by telephone, to a number you already hold.
The acquisition or investment pretext
A company is told that a deal requires a deposit in crypto, arranged by someone presenting as a lawyer or advisor. The paperwork is convincing, and the crypto element is explained as speed or as the counterparty’s preference. For a fintech the exposure multiplies across users, and crypto acquiring for businesses addresses it at that layer.
Rarer and larger. The defence is that a legitimate transaction of that size involves a regulated professional whose firm you can verify independently and whose client account is a bank account.
The refund manipulation
A customer overpays and requests the difference to a different address. Or cancels and requests a refund elsewhere. Covered separately and worth including because support teams meet it more often than finance meets the others.
The support impersonation
Someone contacts an employee presenting as support from your payment provider, reporting an issue and requesting a test transaction or a settings change.
Providers do not initiate contact requesting transactions. If someone does, end the conversation and contact the provider through a number you already have.
The common structure
Every one has the same three elements: authority, urgency, and a reason the normal process should not apply.
Teaching people to recognise that structure works better than teaching them individual scripts, because the scripts change and the structure does not.
What makes a company resistant
Approval requirements that cannot be waived by seniority. A rule that address changes are confirmed by voice. An explicit statement that no genuine request will ever require bypassing the process, communicated by the people who could otherwise be impersonated.
That last one is underrated. When a chief executive tells the finance team in advance that any urgent confidential payment request from them is fraudulent, the attack has nowhere to go.
After an attempt
Report it internally, even if nothing was paid. Attempts cluster, and the second one usually targets a different person in the same company. For trading and settlement specifically, Collect & Exchange publishes its terms in full.
Move any remaining funds to a wallet with a newly generated seed phrase before anything else. Then revoke token approvals, and report the incident to your local authorities and the exchange involved. Do not pay anyone who promises to "recover" your coins. That is a second scam, aimed at victims of the first.