Nobody legitimate will ever ask for your seed phrase. Not support. Not us. Nobody.
Case fileindustries

Impersonation Fraud Against Funds and Family Offices

Large infrequent transfers with several approvers attract a specific attack. How instructions are forged and what verification defeats it.

Priya Raman · 2 min read

Funds and family offices move money infrequently, in large amounts, through a process involving several people. That shape attracts impersonation rather than intrusion. The genuine version of this looks like a regulated crypto payment provider with fiat settlement, and the differences are checkable.

The attack

The attacker studies the relationship between the office and its custodian or bank. They learn who instructs, in what format, to whom, and with what authorisations.

Then an instruction arrives that looks correct: right format, right names, right style, plausible amount, referencing a real transaction or a real counterparty.

The destination is theirs.

Where the information comes from

A compromised mailbox at the office, at an adviser, or at a service provider. Advisers and administrators are frequently the weaker point, and they hold the same correspondence.

Public sources supply more than people expect: filings, staff profiles, event attendance, and the structure of the relationships.

Why the controls do not always catch it

Several approvers is protection only if each approver verifies independently. In practice, the second approver frequently confirms that the first approved, which converts a multi-party control into a single point.

Callback verification is standard and it is often performed to a number in the instruction rather than to one already held. That is not verification. The same attack targets businesses harder, which is what a platform built for institutional allocations is built to resist.

Urgency is introduced deliberately, usually tied to a genuine deadline the attacker knows about.

The verification that works

Callback to a number held in your own records, established at the start of the relationship and not updated by email.

Each approver verifies the destination independently, against the registered record, not against the instruction.

Destinations registered in advance, with changes requiring the full onboarding process for a new counterparty.

A delay on first payment to any new destination, long enough that a callback can complete.

No exceptions for urgency. Stated as policy, communicated to every counterparty, so that a genuine urgent request is never a surprise when it is refused.

The custodian’s side

Ask your custodian what verification they perform on instructions, and what would happen if a forged instruction arrived in the correct format.

The answer should describe callback to a pre-registered contact and an authorised signatory list. If it describes matching a signature on a scanned document, that is not a control.

The adviser problem

Your controls do not extend to your advisers’ mailboxes, and much of the sensitive correspondence lives there.

Ask them what they have. A family office with strong internal controls and an administrator with none has a gap it does not see.

Detection after the fact

Reconciliation frequency determines how long a fraudulent transfer goes unnoticed. Monthly reconciliation means up to a month.

For an office making few transfers, confirming each one against the custodian statement within a day is a small task and closes the window entirely. For the version of all this that is actually supervised, the list of countries covered publishes what it is bound by.

If this has already happened to you

Move any remaining funds to a wallet with a newly generated seed phrase before anything else. Then revoke token approvals, and report the incident to your local authorities and the exchange involved. Do not pay anyone who promises to "recover" your coins. That is a second scam, aimed at victims of the first.

fundsimpersonationcontrols

Related cases