AI Fake Exchange CCO Listing Scam: Forged Executive Video Interviews Used to Extort Project Listing Deposits
Victims are predominantly founders and business development leads of small and medium-sized crypto project teams who are in a critical fundraising or exchange-listing phase and eager to land on tier-one exchanges like Binance for liquidity and endorsement. Their psychological vulnerability lies in anxiety over opaque listing processes coupled with a misplaced belief in "internal connections" and "direct executive access." When someone with a familiar executive face appears on video claiming private communication can unlock a "fast track," they easily drop their guard. Moderate amounts of USDT collected under the guise of "deposits" or "listing fees" are more easily rationalized, and victims often stay silent afterward out of concern for their reputation.
Key Fields
FIELD STAMPSWho Gets Targeted
Victims are predominantly founders and business development leads of small and medium-sized crypto project teams who are in a critical fundraising or exchange-listing phase and eager to land on tier-one exchanges like Binance for liquidity and endorsement. Their psychological vulnerability lies in anxiety over opaque listing processes coupled with a misplaced belief in "internal connections" and "direct executive access." When someone with a familiar executive face appears on video claiming private communication can unlock a "fast track," they easily drop their guard. Moderate amounts of USDT collected under the guise of "deposits" or "listing fees" are more easily rationalized, and victims often stay silent afterward out of concern for their reputation.
骗局怎么运作
- Step 1: Precisely target prey. Scammers scout out small and medium-sized project teams seeking listings on channels like LinkedIn and Telegram, research their funding dynamics and leadership backgrounds, and send direct messages posing as exchange listing team members or their assistants with hooks like, "Your project has caught the attention of our CCO, and we can arrange an internal evaluation call."
- Step 2: Forge executive video interviews. Using public speech and interview materials of the executive, scammers leverage real-time Deepfake face-swapping and voice cloning to appear in Zoom or spoofed meeting links as the "Exchange CCO," creating short real-time responses to project a false sense of authority and further lower the victim's guard.
- Step 3: Put forward listing conditions. Following the video conference, the "executive" hands over communication to the "compliance team," requiring the project team to pay a listing deposit, security audit deposit, or liquidity lock-up funds in advance under the pretext of "an internal anti-spam mechanism that is fully refunded after listing." Amounts are typically kept under several hundred thousand USDT to avoid triggering major suspicion.
- Step 4: Guide payment through counterfeit processes. The counterpart sends a spoofed exchange domain or "official cold wallet address," requesting a USDT transfer and a screenshot of the receipt. Some variants also induce project teams to connect wallets and sign authorizations, taking the opportunity to batch-drain assets from the project treasury.
- Step 5: Delay and disappear. Once the transfer is complete, the scammers stall for weeks under the guise of "internal scheduling" or "compliance review," responses gradually slow down, and finally the account is deleted, the domain is abandoned, and the video link expires, leaving the victimized team to realize that the executive, assistant, and compliance team were all accomplices playing different roles.
- Step 6: Multi-project serial harvesting. The same syndicate reuses the same Deepfake materials and meeting scripts to simultaneously approach different project teams, running upwards of ten "listing lines" at a time. While the amount per case is small, the total volume is substantial. A 2022 BlockTempo report already pointed out multiple projects falling victim to similar tactics impersonating the Binance CCO.
红旗信号(看到这些快跑)
- 🚩 Exchange executives proactively initiate cold contact with project teams via direct messages or LinkedIn promising listings; legitimate exchange listings are never initiated from personal executive accounts
- 🚩 During video conferences, the "executive" avoids deep technical questions, image edges occasionally distort, lip-sync and audio are slightly misaligned, or they refuse to enable two-way interactive verification
- 🚩 Any demand requiring advance USDT transfers under the name of "deposits," "security bonds," or "anti-spam deposits" before initiating the listing process
- 🚩 Payment addresses pointing to personal wallets or recently registered domain pages rather than official exchange contract addresses or corporate accounts
- 🚩 Using spoofed domains closely resembling official ones (adding a letter or changing the top-level domain) to send materials and contracts, with official seals easily forged via Photoshop
- 🚩 Heavy emphasis on confidentiality throughout: "Do not disclose this communication externally, or your qualification will be revoked," preventing project teams from verifying through official customer support channels
- 🚩 Instantly switching communicators and contact methods right after the call, with elaborate role divisions (executives, assistants, and compliance officers taking turns) to manufacture a sense of formal process
真实案例
- In August 2022, BlockTempo reported that hackers utilized Deepfake technology to impersonate the Binance CCO, conducting video calls with multiple crypto project teams for listing scams. The Binance CCO subsequently issued a statement on social media confirming the video was AI-forged and warning the industry, with several project teams already victimized. (Source: [https://www.blocktempo.com/hackers-use-deepfake-to-impersonate-binance-cco/](https://www.blocktempo.com/hackers-use-deepfake-to-impersonate-binance-cco/))
- In February 2026, Hong Kong police dismantled a cross-border syndicate committing fraud using AI deepfake technology. The group lured overseas victims online to invest in virtual currencies under false identities, involving up to 34 million Hong Kong dollars. Nine involved men and women were charged with conspiracy to defraud and money laundering and appeared at the Eastern Magistrates' Court (according to Sing Tao Daily). (Source: [https://www.singtaousa.com/2026/02/10/news/china/deepfake-crypto-scam-fraud-charges](https://www.singtaousa.com/2026/02/10/news/china/deepfake-crypto-scam-fraud-charges))
- In March 2026, a Zhihu column exposed a Google Coin counterfeit scam: a 28-year-old internet industry victim saw an AI face-swapped celebrity "endorsement" video on short video and social platforms, clicked into a high-fidelity campaign page, and was guided to connect their wallet, resulting in related assets being drained within approximately 24 hours.
- In June 2026, multiple Deepfake crypto-trading videos forging Elon Musk's image spread across overseas platforms to commit fraud, with cumulative scam amounts reportedly reaching the hundreds of millions of dollars. Dogecoin co-founder Billy Markus publicly mocked such fake videos and warned investors not to fall for them (according to public reports).
- In 2025, Hong Kong police received 11 reports of Binance-impersonation scams involving 3.5 million Hong Kong dollars. Fake mining pools piggybacking on Binance used "4% daily returns and referral commission rewards" as bait; after investors deposited stablecoins, the platform barred withdrawals, and funds vanished for good. Project Home warned that the platform lacked valid registration. (Source: [https://www.paiu.cn/article/7420.html](https://www.paiu.cn/article/7420.html))
Official Stance
- In August 2022, the Binance CCO publicly debunked rumors via official social media accounts, confirming that circulating footage of "themselves on a video call pitching listings" was Deepfake-forged, and warning project teams and investors to stay alert against impersonators.
- In May 2026, Ripple CTO David Schwartz publicly warned that AI-generated deepfakes and impersonation tactics are being deployed on a large scale for scams targeting crypto investors, urging the community to raise verification awareness.
- In May 2026, South Korean exchange Bithumb issued a risk notice warning users to stay vigilant against fake investment and airdrop scams leveraging AI deepfakes of celebrities.
- In February 2026, Hong Kong police issued a bulletin following the dismantling of a Deepfake cross-border scam syndicate, confirming the group involved 34 million Hong Kong dollars, charging 9 individuals with conspiracy to defraud and money laundering, and reminding the public not to trust online "executive" identities blindly.
How to Protect Yourself
- ✅ Trust only official channels: Listing applications must always be submitted through the official website listing portal, never accepting "direct executive access" initiated via direct messages, Telegram, or LinkedIn
- ✅ Two-way identity verification: Upon receiving video invitations claiming to be from executives, cross-verify through official exchange customer support or their verified social accounts, and ask the person to perform designated random actions during the video to check for real-time forgery
- ✅ Reject all upfront transfers: Legitimate exchanges never ask project teams for upfront USDT under the guise of deposits or bonds; any demand for advance payment must be treated as fraud
- ✅ Minimal wallet authorization: Project treasuries should be managed using multi-sig wallets, keeping daily operational wallets isolated from the treasury, and avoiding unfamiliar links, Approves, or Permit signatures on strange contracts
- ✅ Preserve evidence and report promptly: Save chat logs, meeting recordings, domains, and transaction hashes, report immediately to local cybersecurity law enforcement and exchange risk management, and notify the community to prevent chained victimization
- https://www.blocktempo.com/hackers-use-deepfake-to-impersonate-binance-cco/
- https://www.singtaousa.com/2026/02/10/news/china/deepfake-crypto-scam-fraud-charges
- https://cloud.tencent.com/developer/article/2667062
- https://www.studioglobal.ai/zh-cn/discover/answers/what-recent-warnings-have-bithumb-and-ripple-6a0738c977ab35ad68ba2673