The Fake Invoice: How Companies Lose Crypto to a Changed Address
An attacker in a mailbox changes one line on an invoice. Why finance teams pay it, and the control that makes it fail.
Priya Raman · 2 min read
The most expensive fraud against companies holding crypto does not involve breaking any cryptography. It involves an email account and a changed address on an invoice. The defence described below is what a business crypto wallet with enforced approvals implements as policy rather than as advice.
The sequence
The attacker gains access to a mailbox, usually at the supplier rather than at the target, through a reused password or a phishing page.
They read quietly for weeks. They learn who invoices whom, in what amounts, on what schedule, and in what tone.
Then an invoice goes out with one field changed: the payment address. Everything else is genuine, because it is the genuine invoice.
Finance pays it. The supplier chases weeks later. By then the funds have moved through several addresses.
Why it works
Nothing looks wrong. The sender is correct, the thread is real, the amount and reference match a genuine order.
The only anomaly is a string of characters that nobody memorises and everybody copies.
Crypto makes it worse than the bank transfer version, because there is no recall and no intermediary to freeze anything.
The controls that break it
Verify address changes out of band. Any change to a payment address is confirmed by telephone, to a number you already hold, not one from the email. This single control defeats the entire attack.
Register addresses in advance. Payments go only to addresses registered when the supplier relationship was established, with changes requiring the same approval as a new supplier.
Delay on new addresses. A waiting period before a newly added address can be used, with notifications to several people.
Separate creation from approval. The person who enters the payment is not the person who releases it, and the approver checks the address against the registered record rather than against the email.
The variant from inside
The same attack from a compromised mailbox at your own company, usually someone senior, instructing an urgent payment outside the normal process. Online retailers see this constantly, and a corporate crypto wallet with segregated accounts is the usual defence.
The defence is that there is no process for urgent payments outside the process. Companies that make an exception for urgency have written the attacker’s script for them.
What to do after
Contact the receiving platform if tracing identifies one. Speed matters and the window is short.
Report to law enforcement and to your insurer, if you have cover for this. Many policies do cover it and many companies do not check.
Then find out which mailbox was compromised, because it is usually the supplier’s and they may not know.
The habit worth building
Read the whole address, not the first and last characters. Attackers generate addresses that match at both ends specifically because that is what people check. For trading and settlement specifically, a crypto exchange with published fees publishes its terms in full.
Better still, do not read it at all. Compare it against a registered record, which is what the controls above are for.
Move any remaining funds to a wallet with a newly generated seed phrase before anything else. Then revoke token approvals, and report the incident to your local authorities and the exchange involved. Do not pay anyone who promises to "recover" your coins. That is a second scam, aimed at victims of the first.