Gunjo · Business Intelligence for the AI Era
← Sticker Wall SCAM · DETAIL

Impersonating Mt.Gox Rehabilitation Refunds: Phishing Scams Using 'Payment Received' as Bait to Steal Creditor Accounts and Private Keys

The primary targets are overseas crypto holders who stored funds on Mt.Gox around 2014. Most are men aged 35 to 60 who possess some technical knowledge but have not followed the case closely for over a decade. They hold claims ranging from thousands to millions of dollars. Their psychological vulnerability stems from the desperation of waiting twelve years; the mere mention of 'refund' triggers an emotional response. They are aware of the complex procedures and fear missing the deadline. Having not interacted with their crypto accounts for years, they lack the habit of verifying official-looking emails, making them highly susceptible to surrendering seed phrases or exchange credentials under pressure from 'final deadline' or 're-verification required' tactics.

SCAM

Key Fields

FIELD STAMPS
IndustryFintech
RegionJapan(日本/日本)
ScaleGray Market
ChannelOther
⚠️ This entry compiles scam tactics and public reporting; it is not investment or legal advice. Content is organized from public reporting and third-party complaint platforms; this site does not make any finding of illegality against the parties involved, who may contact us for correction if they object. If you encounter fraud, report it to the police immediately (110 / anti-fraud hotline 96110 in mainland China; local police overseas).

Who Gets Targeted

The primary targets are overseas crypto holders who stored funds on Mt.Gox around 2014. Most are men aged 35 to 60 who possess some technical knowledge but have not followed the case closely for over a decade. They hold claims ranging from thousands to millions of dollars. Their psychological vulnerability stems from the desperation of waiting twelve years; the mere mention of 'refund' triggers an emotional response. They are aware of the complex procedures and fear missing the deadline. Having not interacted with their crypto accounts for years, they lack the habit of verifying official-looking emails, making them highly susceptible to surrendering seed phrases or exchange credentials under pressure from 'final deadline' or 're-verification required' tactics.

骗局怎么运作

  • Step 1: Scammers use leaked email databases from the early Mt.Gox era or public creditor lists to conduct targeted phishing. They send emails disguised as the Rehabilitation Trustee or partner exchanges like Kraken and Bitstamp, with subject lines such as 'Your Rehabilitation Repayment Pending Confirmation.' The content mimics official formats and cites the October 31, 2026 deadline to establish credibility.
  • Step 2: The email contains a 'Login to View Payment Progress' button, redirecting to a fake domain that differs from the official site by only one or two characters. The page is a pixel-perfect replica of the login interface. Once the victim enters their credentials, they are captured in real-time, allowing scammers to immediately attempt to access the victim's linked email and exchange accounts.
  • Step 3: For versions claiming 'direct on-chain payment,' scammers induce victims to connect their wallets to a so-called 'payment claim contract.' In reality, this is a malicious signature authorization. Once confirmed, the assets in the wallet are authorized to be transferred out. The scammers claim this is 'required to verify ownership of the address before BTC can be released.'
  • Step 4: A 'thawing fee' variant targets those desperate for their long-awaited funds. Scammers falsely claim that the claim has been frozen and requires a deposit, tax, or processing fee to release the funds. Amounts range from hundreds to tens of thousands of dollars, requested in minor cryptocurrencies like USDT to personal addresses, with promises of a refund alongside the payment within 24 hours.
  • Step 5: In social engineering phases, scammers infiltrate creditor forums and Telegram groups, posing as 'creditors who have successfully received payment' to share fake internal process screenshots. They privately recommend 'intermediary lawyers who can accelerate approval,' collect high service fees, and then disappear. Some also steal identity documents for secondary identity theft.
  • Step 6: Once successful, they quickly move the funds. If they obtain exchange credentials, they withdraw the assets or cash out OTC; if they obtain private keys, they drain the wallets. Funds are dispersed through mixers and cross-chain bridges. The entire process occurs within the few days the victim expects the 'payment' to arrive. By the time the victim notices the anomaly, the fake site is closed, and the scammers move to a new domain.

红旗信号(看到这些快跑)

  • 🚩 Any 'payment claim link' sent proactively via email or private message: Rehabilitation payments are only distributed through the designated exchanges registered by the victim in advance. Officials will never ask you to click a link in an email to log in and verify your claim.
  • 🚩 Requests for private keys, seed phrases, or wallet signature authorizations: Standard civil rehabilitation procedures never require creditors to provide wallet private keys. Anyone asking for a seed phrase is undoubtedly a scammer.
  • 🚩 Requests for advance payments under the guise of 'deposits, thawing fees, taxes, or acceleration fees': There is no such thing as a pre-payment requirement for creditors in the Japanese civil rehabilitation process. 'Pay first, receive later' is a classic advance-fee scam structure.
  • 🚩 Creating a sense of urgency with 'deadline expired' or 'last 48 hours' countdowns: Real deadline extensions are announced months in advance via official trustee notices and are not enforced through short-notice emails.
  • 🚩 Domain names with subtle differences from the official site or requests to download 'creditor-specific apps' of unknown origin: Official procedures are conducted only through court-designated channels and trustee announcements; there are no independent apps.
  • 🚩 Strangers in communities bragging about 'having received payment' and enthusiastically sharing shortcuts: Using 'survivor' testimonials to lower defenses is a classic tactic. Real creditors rarely publicly boast about the details of their payouts.

真实案例

  • In February 2014, Mt.Gox suddenly suspended withdrawals and filed for bankruptcy protection. Approximately 850,000 BTC went missing (including about 740,000 belonging to customers and 100,000 belonging to the platform), then valued at about $450 million. The incident shattered trust in early crypto custody, and numerous scams posing as 'Mt.Gox official recovery services' began to emerge around victimized creditors. (Source: https://news.sina.cn/j_uc.d.html?docid=hrfqzkc4247280)
  • In March 2019, the Tokyo District Court ruled that the former CEO of Mt.Gox was not guilty of embezzlement but sentenced him to two years and six months in prison (suspended for four years) for falsifying electronic records. According to reports from Sina and other media, the verdict confirmed the incident as a 'hack' rather than an exit scam. Subsequently, scammers shifted to using the narrative that 'management is not liable and assets still exist' to package 'internal recovery channel' scams. (Source: https://news.sina.cn/j_uc.d.html?docid=hrfqzkc4247280)
  • Starting in July 2024, the Rehabilitation Trustee began distributing BTC and BCH to creditors in batches through designated exchanges like Kraken and Bitstamp. During this period, multiple security media outlets and communities reported a surge in phishing emails impersonating the trustee and partner exchanges. Numerous creditors reported on forums that their email and exchange accounts were compromised after clicking fake links, with losses ranging from thousands to hundreds of thousands of dollars (identities of those involved remain undisclosed). (Source: https://www.panewslab.com/zh/articles/2037866976f5)
  • Between 2025 and 2026, the Tokyo District Court and the Trustee announced several times that the final repayment deadline had been extended to October 31, 2026. Each announcement was followed by a new wave of 'deadline countdown' phishing emails. The trustee has repeatedly stated through official channels that they will never request passwords or payments via email, confirming that the scale of phishing scams has reached a level of official concern.

Official Stance

  • Between 2024 and 2026, the Mt.Gox Rehabilitation Trustee issued multiple announcements on the official repayment portal, reminding creditors that all payments are distributed only through pre-selected designated exchanges like Kraken and Bitbank. They will never ask for passwords, private keys, or additional payments via email. Beware of fake notifications.
  • On the eve of the physical repayment launch in July 2024, Japanese authorities and partner exchange Kraken issued notices stating they had received reports of numerous phishing websites impersonating the Mt.Gox repayment process. They reminded users to access the site only by manually typing the URL into their browser and to never click any email links.
  • Since the September 2021 notice from the People's Bank of China and other departments regarding the prevention and disposal of risks associated with virtual currency trading, Chinese regulatory authorities have consistently warned: virtual currency-related business is illegal financial activity. Services provided by overseas exchanges to domestic residents are also illegal. So-called 'paid services to assist in recovering overseas exchange assets' are not protected by law and are themselves high-frequency scams.
  • International anti-phishing organizations and several blockchain security firms issued continuous warnings from 2024 to 2026, noting that whenever there is a large Mt.Gox transfer or repayment milestone, on-chain monitoring detects a simultaneous surge in fake addresses and phishing domains targeting creditors. Users are advised to verify domain certificates and enable hardware wallets and two-factor authentication.

How to Protect Yourself

  • ✅ Stick to official channels only: All repayment operations must be performed only on the official address manually entered into your browser and within the previously registered designated exchange account. Never click any links in emails or private messages, even if the page looks identical.
  • ✅ Enable hardware-level protection: Bind your exchange account to a dedicated email address protected by a hardware key or authenticator for two-factor authentication. Disable SMS-only recovery methods to prevent password resets after a phishing success.
  • ✅ Never surrender private keys: Engrave in your mind that 'no claim, refund, or thawing process requires a seed phrase.' If you encounter a 'claim page' that asks for signature authorization or wallet import, close it immediately and report the domain.
  • ✅ Cross-verify extensions and announcements: When you see a 'deadline countdown,' first check the trustee's official announcements and mainstream media reports to confirm the actual date. Real extension information will appear simultaneously across multiple authoritative media outlets, not just in a single email.
  • ✅ Verify with official customer support: Reject any third party claiming to be creditor services, agents, or acceleration consultants. If in doubt, verify directly through the official customer support channels of the designated exchange. Keep all email and transfer records for reporting purposes.