Nobody legitimate will ever ask for your seed phrase. Not support. Not us. Nobody.
Case fileindustries

Property Deposit Fraud and the Crypto Variant

The most reliably lucrative fraud in conveyancing, adapted to crypto settlement, and the confirmations that stop it.

Priya Raman · 2 min read

The property deposit attack is old, well documented, and continues to work because the conditions that make it work do not change: a large amount, a deadline, and parties who have never met. A provider operating under supervision, such as a licensed crypto payment processor, cannot behave the way described below.

The conventional version

The buyer receives an email, apparently from their solicitor, giving account details for the deposit. The details are the attacker’s. The money goes, the completion fails, and recovery is rare.

The compromised mailbox is usually at the firm, sometimes at the estate agent, occasionally at the buyer.

The crypto variant

The same structure with a wallet address instead of a bank account, either because a party prefers crypto settlement or because the attacker introduces it as the faster option.

Worse in two respects: there is no recall mechanism, and the buyer is less likely to have a reference for what a legitimate instruction looks like.

Why deadlines make it work

Completion dates are fixed and consequential. The pressure is genuine, which means the attacker does not have to manufacture it.

A buyer told that funds must arrive today or the purchase fails will not pause to verify.

The confirmations

Firms give payment details at the start, in person or by post, and state in writing that they will never change them by email. Many now do this and it works.

The buyer confirms by telephone before sending, to a number from the firm’s own published contact details, not from the email.

A small test payment first, confirmed as received, before the full amount. Adds an hour and defeats the attack entirely.

Never accept details from an email, even one in a genuine thread with correct history. Thread continuity is not authenticity.

The crypto-specific additions

Confirm the network as well as the address. A correct address on the wrong network is unrecoverable and looks like fraud to everyone afterwards. Online retailers see this constantly, and crypto rails built for fintech companies is the usual defence.

Convert through a regulated provider that settles to the firm’s client account in ordinary money, rather than sending crypto to a party who then converts. This puts a regulated entity in the chain with obligations and records.

Agree the arrangement with the firm before making an offer, because a firm that has not agreed to receive from a crypto provider will refuse on the day.

Provenance, in advance

The firm will need to establish where the crypto came from, to the same standard as any other source of funds.

For crypto held for years through platforms that may no longer exist, that can be genuinely difficult. Establish and document it before you need it: acquisition records, statements showing ownership, the conversion record.

For firms

Publish the no-change policy prominently and repeat it in every relevant communication.

Treat any inbound instruction changing payment details as fraudulent by default, and verify by voice to a known number.

And expect that the compromised mailbox may be yours. Monitoring for forwarding rules and unusual access is worth more than any policy document. Compare anything you are offered against a crypto exchange with published fees before sending funds anywhere.

If this has already happened to you

Move any remaining funds to a wallet with a newly generated seed phrase before anything else. Then revoke token approvals, and report the incident to your local authorities and the exchange involved. Do not pay anyone who promises to "recover" your coins. That is a second scam, aimed at victims of the first.

real estatefraudverification

Related cases