Gunjo · Business Intelligence for the AI Era
← Sticker Wall SCAM · DETAIL

Deepfake Executive Video Conference Scam - AI Impersonating CEOs and CFOs in Meetings to Order Transfers and Drain Wallets

Victims are mostly finance personnel of crypto projects, BD partners of exchanges, cross-border corporate accountants, and operations staff hired to handle multi-signature wallets. Their common weakness is being embedded in a high-pressure hierarchical culture, where they dare not perform secondary verification when faced with a living boss's face and urgent instructions in a video. At the same time, crypto industry transfers are instantly credited and irreversible, teams work across time zones, and channels to verify with real people in person are limited. Fraudsters deliberately choose late nights or holidays to initiate meetings, exploiting victims' anxiety about missing critical milestones like token listings, airdrops, or financing. They compress the identity verification step to zero, and once transfer instructions are executed, the funds are rapidly split via coin mixers, making the probability of recovery extremely low.

SCAM

Key Fields

FIELD STAMPS
IndustryFintech
RegionGlobal(跨境(香港及东亚为主,波及全球加密项目团队))
ScaleGray Market
ChannelOther
⚠️ This entry compiles scam tactics and public reporting; it is not investment or legal advice. Content is organized from public reporting and third-party complaint platforms; this site does not make any finding of illegality against the parties involved, who may contact us for correction if they object. If you encounter fraud, report it to the police immediately (110 / anti-fraud hotline 96110 in mainland China; local police overseas).

Who Gets Targeted

Victims are mostly finance personnel of crypto projects, BD partners of exchanges, cross-border corporate accountants, and operations staff hired to handle multi-signature wallets. Their common weakness is being embedded in a high-pressure hierarchical culture, where they dare not perform secondary verification when faced with a living boss's face and urgent instructions in a video. At the same time, crypto industry transfers are instantly credited and irreversible, teams work across time zones, and channels to verify with real people in person are limited. Fraudsters deliberately choose late nights or holidays to initiate meetings, exploiting victims' anxiety about missing critical milestones like token listings, airdrops, or financing. They compress the identity verification step to zero, and once transfer instructions are executed, the funds are rapidly split via coin mixers, making the probability of recovery extremely low.

骗局怎么运作

  • Step 1 Reconnaissance: Attackers collect public speech videos and voice materials of executives through LinkedIn, Twitter, and project official websites. By training open-source face-swapping and voice-cloning models for several days, they can generate digital avatars that can be driven in real time, while mapping out the target company's organizational structure and payment approval workflow.
  • Step 2 Infiltration and Paving: Attackers send meeting invitations to finance staff through phishing emails or compromised instant messaging accounts, using the pitch: 'The CEO has urgently called an emergency financial meeting to discuss a confidential acquisition; please do not leak this.' This creates an atmosphere of confidentiality that cuts off the victim's channel to verify with colleagues.
  • Step 3 Forging Multi-Person Meetings: Once the meeting begins, the victim sees the CEO, CFO, or even external legal counsel online simultaneously. The visuals and audio are synthesized in real time or pre-recorded clips by AI, with only the victim being a real person. The illusion of a group backing the event completely crushes psychological defenses, making it feel like 'everyone is present.'
  • Step 4 Issuing Transfer Instructions: The 'CEO' demands that the victim transfer USDT on the spot or sign wallet authorization to specified addresses under the pretext of paying acquisition deposits, participating in exchange strategic allotments, or claiming cooperative airdrops, pressuring them with claims of 'being busy with due diligence and having no time to explain.'
  • Step 5 Fund Splitting and Laundering: After funds arrive, scripts automatically transfer them layer by layer through cross-chain bridges and coin mixers within dozens of seconds. Some variants share forged exchange backend screenshots during the meeting to display 'equivalent assets arrived' to pacify the victim, by which time the funds are untraceable once the anomaly is discovered.

红旗信号(看到这些快跑)

  • 🚩 So-called emergency meetings bypass official email systems, being temporarily initiated only through instant messaging private chats with refusals to reschedule
  • 🚩 Executives in the meeting refuse to answer personalized verification questions, or camera feeds show edge jitter and delay when turning heads or blocking faces
  • 🚩 Requests to transfer funds to unfamiliar addresses or connect wallets to sign authorizations, while refusing to go through the company's existing dual-review and cold wallet procedures
  • 🚩 Emphasizing absolute confidentiality and prohibiting disclosure of meeting contents to any colleagues, deliberately cutting off horizontal verification channels
  • 🚩 Meeting link domains have subtle spelling differences from official websites, or requests to install unknown meeting plugins and wallet verification tools

真实案例

  • In February 2024, the Hong Kong Police Force reported that an employee at a multinational company's Hong Kong branch was pulled into a forged multi-person video conference. The 'headquarters CFO' and multiple colleagues in the video were Deepfake composites. The employee followed instructions to transfer about 200 million Hong Kong dollars across 15 transactions, discovering the scam days later after verifying with headquarters, making it the world's largest case of its kind at the time.
  • Starting from May 2022, Deepfake videos circulating online forged Elon Musk, Binance founder Changpeng Zhao, and investor Cathie Wood promoting crypto platforms, inducing viewers to deposit funds into designated addresses. According to multiple media reports, cumulative global losses reached hundreds of millions of dollars.
  • In February 2026, the Hong Kong Police Force busted a cross-border syndicate using AI deepfake technology for fraud. The syndicate defrauded overseas victims of up to 34 million Hong Kong dollars by luring them online to invest in virtual currencies. Nine men and women were charged with conspiracy to defraud and money laundering, and the case was brought before the Eastern Magistrates' Court and adjourned to April of that year. (Source: [https://www.singtaousa.com/2026/02/10/news/china/deepfake-crypto-scam-fraud-charges](https://www.singtaousa.com/2026/02/10/news/china/deepfake-crypto-scam-fraud-charges))
  • In March 2026, blockchain security agencies disclosed that North Korean-backed attackers utilized AI-generated executive Deepfake avatars to impersonate CEOs in Zoom meetings, conducting social engineering attacks against crypto projects and draining project funds. Multiple development teams reported experiencing similar techniques. (Source: [https://blockeden.xyz/zh/blog/2026/03/08/north-korean-deepfake-zoom-campaigns-crypto](https://blockeden.xyz/zh/blog/2026/03/08/north-korean-deepfake-zoom-campaigns-crypto))
  • In February 2024, a finance employee at the Hong Kong branch of British engineering firm Arup was invited to an AI deepfake video conference impersonating company executives. Except for the employee, all other participants were AI-generated fake executive images and voices. The employee believed it was real and subsequently transferred a total of about 200 million Hong Kong dollars to local bank accounts in multiple batches following instructions. After the incident, Arup reported the case to the Hong Kong Police Force, and it was classified as obtaining property by deception. (Source: [https://www.theguardian.com/technology/article/2024/may/17/uk-engineering-arup-deepfake-scam-hong-kong-ai-video](https://www.theguardian.com/technology/article/2024/may/17/uk-engineering-arup-deepfake-scam-hong-kong-ai-video))

Official Stance

  • In February 2024, the Cyber Security and Technology Crime Bureau of the Hong Kong Police Force held a press conference to publicly report a Deepfake video conference scam involving about 200 million Hong Kong dollars, reminding enterprises to establish dual-verification mechanisms for fund transfers.
  • In February 2024, the Hong Kong Police Force reported busting a cross-border fraud syndicate using AI deepfake technology to lure victims into virtual currency investments, involving 34 million Hong Kong dollars, and reminded citizens to verify the identity of video call participants.
  • In May 2025, the Cyberspace Administration of China, in conjunction with financial regulatory authorities, cracked down on a batch of accounts and websites hyping virtual currency transactions and spreading false financial information, continuing to warn against illegal financial activities using celebrity traffic to induce investment.
  • The Chief Security Officer of Binance publicly warned in May 2023 that fraudsters were using AI Deepfake technology to attempt to bypass exchange KYC identity verification, urging the industry to upgrade liveness detection defenses.
  • In February 2026, South Korean exchange Bithumb and Ripple Chief Technology Officer David Schwartz successively issued public warnings to investors to be alert to the surge in AI deepfake impersonation scams targeting crypto users.

How to Protect Yourself

  • ✅ Establish an out-of-band verification ironclad rule: Any instructions involving fund transfers or wallet authorizations must be re-confirmed through pre-arranged independent channels such as directly calling the person's mobile phone, never using contact methods within the meeting to call back.
  • ✅ Enterprises should configure multi-signature wallets and whitelist address systems. Single transfers exceeding thresholds require two or more managers to separately approve on different devices, structurally preventing a single person from being bluffed into releasing funds.
  • ✅ Proactively set up dynamic verification actions during video conferences, such as asking the other party to cover their face with their hand and turn their head sideways or answer impromptu questions known only to real people, observing whether video feeds exhibit deepfake jitters and glitches.
  • ✅ Finance and operations personnel should only download meeting software from official app stores, and default to rejecting any plugin installations, wallet connections, and authorization signature requests popping up during meetings.
  • ✅ Regularly drill anti-deepfake emergency response procedures using real-world cases, and list transfer requests featuring 'emergency plus confidentiality' pitches as highest-risk events subject to a mandatory twenty-four-hour cool-down period.