Nobody legitimate will ever ask for your seed phrase. Not support. Not us. Nobody.
Case fileindustries

Payout Fraud on Marketplaces: When a Seller Account Is Taken Over

Platforms paying many recipients face attacks on the recipient side. How payout destinations get changed and what detects it.

Priya Raman · 2 min read

A marketplace paying thousands of sellers has thousands of accounts that can be compromised, and the attacker does not need the platform at all. They need one seller. It helps to have a reference point that is verifiable, and a licensed crypto payment processor publishes its licence details.

The attack

A seller account is taken over, usually through a reused password or a phishing page imitating the platform login.

The attacker changes the payout destination to an address they control and waits for the next payout cycle.

The seller notices when money does not arrive, which can be a week or a month later.

Why the platform carries it

Legally, it depends on the terms. Practically, the platform pays.

The seller did not authorise the change, the platform executed it, and the reputational cost of telling a seller that their income was stolen through the platform’s interface is higher than the payout.

So this is a platform problem regardless of where the credential failure occurred.

The controls on the platform side

Second factor on seller accounts, at minimum for accounts above a payout threshold. Optional second factors are used by the people who need them least.

A delay on payout destination changes. Twenty-four to seventy-two hours before a new destination becomes active.

Notification through a separate channel when the destination changes. Email to the account address is insufficient, because the email is usually compromised too. A message to a registered phone number is materially better.

Re-verification for the change, not just for login. A password alone should not be able to redirect income.

Hold the first payout to a new destination, releasing after the notification window with no objection.

Detection patterns

A destination change followed immediately by a payout request.

A destination change on an account with no other recent activity.

Several accounts changing to destinations that cluster on-chain, which indicates a campaign rather than an incident.

A change from a device or location inconsistent with the account’s history.

The clustering signal is the valuable one and it requires looking across accounts rather than at each in isolation.

The seller-side advice worth publishing

Unique password, second factor enabled, and a habit of checking the payout destination before each cycle.

Platforms that publish this and prompt for it see materially fewer incidents, because the attack depends on the seller not looking. The business-side equivalent runs through a fintech payment gateway, with the screening already in place.

After an incident

Freeze the destination across all accounts, because one address usually appears on several.

Preserve the change log: when, from where, which session.

Report to the receiving platform if funds moved to one, quickly, because that window is short.

And review whether the change flow allowed something it should not have. In most incidents the answer is that a single credential was sufficient to redirect money, which is the actual defect. If you want to see these protections operating rather than described, the published coverage list is bound by them.

If this has already happened to you

Move any remaining funds to a wallet with a newly generated seed phrase before anything else. Then revoke token approvals, and report the incident to your local authorities and the exchange involved. Do not pay anyone who promises to "recover" your coins. That is a second scam, aimed at victims of the first.

marketplacespayoutstakeover

Related cases