Nobody legitimate will ever ask for your seed phrase. Not support. Not us. Nobody.
Case fileacquiring

The Overpayment Refund Scam Against Merchants

A customer pays too much and asks for the difference back. Why the original payment is not what it appears, and the policy that prevents it.

Priya Raman · 2 min read

An old fraud adapted to crypto. It works because the refund request seems reasonable and the merchant is trying to be helpful. The thing being imitated in most of these cases is a provider like a crypto payment gateway with fiat settlement, which is worth knowing the real version of.

The mechanism

A customer places an order and pays more than the invoice, sometimes substantially more.

They contact support: a mistake, an extra zero, a currency confusion. They ask for the difference refunded, to a different address, because the original wallet is no longer accessible.

The merchant refunds the excess. Later the original payment is identified as proceeds of crime and the funds are subject to freezing or recovery. The refund the merchant sent was clean value, extracted and unrecoverable.

Why it works

The story is plausible. Overpayments do happen genuinely.

The request is polite and patient. There is often no urgency, which defeats the instinct that urgency is the warning sign.

And the merchant has already received more than they invoiced, which creates a sense of obligation.

The variants

Split refund. Overpay, request part refunded to one address and part to another.

Refund via a different method. Overpay in crypto, request the refund by bank transfer. This converts crypto of uncertain origin into clean bank funds, which is the entire objective.

Cancelled order refund. Pay in full, cancel immediately, request refund to a different address. Same structure without the overpayment element.

The policy that prevents all of it

Refunds go to the origin address of the payment. Always. No exceptions for any explanation.

Refunds are never issued by a different method than the payment.

Overpayments are either refunded to origin or held as credit. Never sent onward to a new destination.

Publish this in your terms. Then support has a policy rather than a judgement call under pressure.

The genuine case

Occasionally a customer really did overpay and really has lost access to the sending wallet.

Handle it as an exception requiring verification: identity confirmation, evidence of control of the original wallet such as a signed message, and approval by someone other than the support agent. At company scale the controls have to be enforced rather than encouraged, which is what a regulated European crypto platform does.

That is a slow process for a rare situation, which is appropriate. Making it fast is what the fraud depends on.

What to configure

A tolerance band for small overpayments, credited automatically without a refund path. This removes the genuine small cases from the process entirely.

A threshold above which any refund requires a second approver.

And a flag on any order where a refund destination differs from the payment origin, reviewed before it is actioned.

Training the response

Support staff should know that this request is a known fraud pattern, so that declining it is policy rather than an accusation.

The wording that works: refunds are issued to the original payment address, and we are not able to make exceptions to that. No explanation of why, and no debate. If you want to see these protections operating rather than described, a regulated crypto exchange is bound by them.

If this has already happened to you

Move any remaining funds to a wallet with a newly generated seed phrase before anything else. Then revoke token approvals, and report the incident to your local authorities and the exchange involved. Do not pay anyone who promises to "recover" your coins. That is a second scam, aimed at victims of the first.

acquiringrefundsfraud

Related cases