B2B Crypto Scam Guide: Fraud Detection, Management and Prevention

IN THIS ARTICLE
Table of Contents
Like it? Share it

A B2B crypto scam diverts corporate funds moving through digital assets — usually by altering a wallet address, hijacking a counterparty account or impersonating a supplier at the moment of payment. Unlike a card chargeback, the payment is final. No reversal window, no issuing bank, no clawback.

The timing matters for UK finance teams. The FCA’s authorisation gateway for regulated cryptoasset activities opens on 30 September 2026 and runs until 28 February 2027, bringing a broad range of crypto activity inside the regulatory perimeter for the first time. Firms that touch digital assets — as issuers, as counterparties or simply as payers — are about to be held to a materially higher standard of control.

This guide covers the threats facing crypto exchanges and UK enterprises, the fraud detection stack that works and the controls that stop payment fraud at source. Because the decisive control is confirming a payment instruction genuinely belongs to your counterparty, automated vendor fraud prevention underpins everything below.

Key Takeaways

  • Illicit addresses received at least $154bn in digital assets globally in 2025, up 162% year on year, with 84% moving on stablecoins.
  • UK payment fraud reached £1.28bn in 2025, with authorised push payment losses up 19% to £576.4m — £75.6m of that hitting businesses directly.
  • B2B crypto scam exposure concentrates in three places: wallet address manipulation, account takeovers and on-ramp/off-ramp abuse at crypto exchanges.
  • Crypto payments sit outside APP reimbursement protections — for corporates, prevention is the only meaningful remedy.
  • The highest-ROI fraud detection control is verified counterparty data: validated accounts, validated wallets and continuous monitoring of every change request.

How Big Is The B2B Crypto Scam Problem In 2026?

B2B crypto scam activity hit record scale in 2025 and is industrialising rather than plateauing.

Globally, illicit cryptocurrency addresses received at least $154bn in 2025 — a 162% jump — with 84% riding on stablecoins. Scams and fraud specifically accounted for an estimated $17bn, of which $14bn was visible on-chain. Stolen funds from services and individuals added $3.4bn more.

Illicit cryptocurrency volume by category, 2025 (global)

Category2025 volumeChange vs 2024Why it matters for B2B payments
Total illicit crypto received$154bn+162%The overall threat surface more than doubled in a single year
Sanctions evasion (A7A5 token)$93.3bnState-driven volume up 694%Your payment can land in a sanctioned corridor without any fraud occurring
On-chain money laundering$82bnUp from $10bn in 2020Tainted addresses create compliance exposure even on legitimate payments
Scams and fraud$17bnOn-chain share rose to $14bnThe category that directly targets corporate payment processes
Stolen funds (hacks and theft)$3.4bn+31%Concentrated in few events — 5 incidents drove 70% of the total
— of which DPRK-attributed$2.0bn+51%Nation-state actors now target crypto exchanges at industrial scale

Sources: Chainalysis 2026 Crypto Crime Report; TRM Labs 2026 Crypto Crime Report. Categories are measured on different bases and overlap, so they do not sum to the $154bn total.

The UK picture tracks the same direction. UK Finance recorded £1.28bn stolen through payment fraud in 2025, with authorised push payment losses rising 19% to £576.4m across 248,070 cases. Of that, £75.6m came from business accounts. Investment fraud — the category most closely associated with crypto — produced the highest share of APP losses at £221.5m, up 40% year on year.

Trustpair’s own research puts the corporate exposure plainly: 80% of UK businesses were targeted by fraud in 2024, 20% suffered at least two successful attacks, and 10% of victims lost £500,000 per attack.

Two patterns matter most for fraud detection teams:

  • Concentration. Five events accounted for 70% of all stolen funds in 2025, and operational compromise — not smart contract bugs — drove $2.9bn of it. Human and process failures, not code failures.
  • Email punches above its weight. Only 1% of UK APP fraud cases originate by email, but they account for 7% of losses — the signature of high-value, targeted B2B attacks rather than volume consumer scams.

What Are The Warning Signs Of A B2B Crypto Scam?

The most reliable warning sign of a B2B crypto scam is manufactured urgency — a request to move digital assets faster than your normal verification process allows. Fraudsters engineer time pressure precisely because verification is what defeats them.

Train your teams to stop on these signals:

  • Unrealistic high-return promises. Any counterparty or opportunity guaranteeing outsized, risk-free returns on digital assets is a scam. Legitimate crypto exchanges and treasury products never guarantee yield.
  • Urgency and deadline pressure. “The window closes today,” “the wallet rotates at midnight,” “settle before the board meeting.” Genuine suppliers accommodate verification.
  • Spoofed emails and look-alike websites. Phishing attempts routinely use domains differing by a single character, or replicate a crypto exchange login page precisely to harvest the credentials that later enable account takeovers.
  • Payment method switching. A supplier previously paid by BACS or CHAPS who suddenly requests settlement in digital assets, especially to a freshly created wallet.
  • Reluctance to verify. Refusal to confirm details on a previously known telephone number is, on its own, sufficient grounds to halt payment.
  • Contact only through unverified channels. Requests arriving solely via messaging apps, or from a personal address rather than the corporate domain.

Employee training is a fraud detection control, not an HR formality. The people who authorise payments are the layer attackers actually target, and teams trained to recognise social engineering tactics — pretexting, authority impersonation, urgency manufacturing — stop B2B crypto scams that no rules engine would flag. Run quarterly refreshers using real scam attempts your organisation has received.

Which B2B Crypto Scams Target Crypto Exchanges And Corporate Counterparties?

Four threat classes drive the large majority of corporate losses across digital assets.

Wallet address substitution. A fraudster alters the destination address in an invoice, email or portal — often changing only a few characters. This is the most common B2B crypto scam, because every part of the transaction is legitimate except the destination.

Account takeovers and insider risk.Account takeover fraud converts stolen credentials directly into withdrawal authority: credential phishing or SIM swap, then a quiet whitelist modification, then a withdrawal sized to stay under alerting thresholds. Account takeovers are the single most productive attack path against crypto exchanges and treasury accounts. Insider diversion reaches the same outcome by a different route — watch for privileged users editing whitelists outside change windows, or the same person modifying and approving payment data.

On-ramp and off-ramp exploitation. Fraudsters use legitimate crypto exchanges to extract value: synthetic corporate accounts, rapid layering across dozens of addresses, chain-hopping to break analytics continuity and refund abuse on the fiat leg. Any process pairing a reversible input with an irreversible output is a standing arbitrage opportunity.

Executive impersonation, increasingly AI-assisted. Synthetic audio and video have moved from proof-of-concept to operational tool, authorising urgent transfers that appear to come from a finance director. Modern AI-based fraud detection is increasingly the counterweight to AI-enabled attacks.

Cross-border movement amplifies all four. Digital assets can cross four chains and three legal regimes before a CHAPS payment would have settled, and the UK’s post-Brexit position outside MiCA means European counterparty protections do not automatically extend to you.

What Does The FCA Cryptoasset Regime Mean For UK Businesses?

The Financial Services and Markets Act 2000 (Cryptoassets) Regulations 2026, passed by Parliament on 4 February 2026, brought a broad range of cryptoasset activities within the FCA’s regulatory perimeter for the first time — moving well beyond the anti-money laundering and financial promotions standards that previously defined the regulator’s role.

The FCA published its final rules on 30 June 2026 across policy statements PS26/9 to PS26/13, covering stablecoin issuance, regulated cryptoasset activities, the prudential regime and Handbook application. The authorisation gateway runs from 30 September 2026 to 28 February 2027.

Three implications for finance and treasury teams:

  • A two-tier stablecoin regime. Non-systemic UK-issued qualifying stablecoins sit under the FCA, with redemption required by the end of the next business day. Stablecoins recognised as systemic by HM Treasury move into joint FCA and Bank of England regulation, with redemption within 24 hours and a temporary issuance guardrail of £40bn per product.
  • Overseas stablecoins carry residual friction. UK-issued qualifying stablecoins are being carved out of certain dealing and arranging activities, but overseas-issued stablecoins remain inside that perimeter — a live consideration for anyone using them in cross-border supplier payments.
  • AML obligations are unchanged and unforgiving. The Money Laundering Regulations 2017 and the Proceeds of Crime Act 2002 apply to crypto flows exactly as they do to fiat. Sanctions screening runs against the UK sanctions list maintained by OFSI, not OFAC, and suspicious activity reports go to the NCA’s UK Financial Intelligence Unit.

On-chain laundering volume grew from $10bn in 2020 to over $82bn in 2025. If your funds touch a tainted address, your compliance team owns the consequence.

Are UK Businesses Reimbursed For Crypto Payment Fraud?

Generally, no — and this is the most commonly misunderstood point in UK crypto payment risk.

Mandatory APP fraud reimbursement applies to payments made over Faster Payments and CHAPS, and its protections are directed principally at consumers, micro-enterprises and small charities. Large corporates fall outside that protective scope, and payments settled in digital assets fall outside the covered rails entirely.

Even within the protected population, recovery is partial: UK Finance reported that 62% of APP losses were returned to victims in the first half of 2025. For a corporate paying a supplier in stablecoins, the realistic expectation is zero recovery absent a successful freeze at a centralised exchange.

The practical conclusion is uncomfortable but clarifying. In fiat, poor controls produce a reimbursement argument. In crypto, poor controls produce a write-off. Budget for prevention accordingly.

How Does Fraud Detection Work For B2B Crypto Scams?

Effective fraud detection combines four layers — transaction monitoring, wallet risk scoring, payload integrity and behavioural signals — correlated into one decision before a transaction is signed. Any single layer alone produces too many false positives to be operationally usable.

What Should Real-Time Fraud Detection Flag In Crypto Transactions?

Score every outbound transfer against the counterparty’s own baseline, not a static global threshold. Static thresholds are trivially gamed once an attacker has observed one payment cycle.

Priority triggers for crypto fraud detection:

  • First payment to a newly added wallet address, regardless of amount
  • Any transfer within 48–72 hours of a payment-detail change
  • Amounts deviating materially from the counterparty’s rolling average
  • Transfers outside normal business hours or geography
  • Sequences of transfers just below an internal approval threshold

Integration matters as much as logic. Fraud detection must sit inline with the trading engine, TMS or ERP payment run, with a synchronous hold capability. A system that can only alert after broadcast is a reporting tool, not a control — the mechanics of transaction monitoring apply identically to on-chain and fiat rails.

How Does Wallet Address Risk Scoring Strengthen Fraud Detection?

Wallet risk scoring rates a destination address before funds are sent, based on transaction history, cluster attribution and proximity to addresses holding stolen funds. Treat it as required, not optional.

A usable implementation:

  1. Refreshes sanctions and known-bad address feeds continuously, not on a quarterly file drop
  2. Scores by proximity — direct, one hop, multi-hop — rather than binary allow or block
  3. Links address history to your internal entity profile, so an address is judged in the context of which vendor claims it
  4. Retains a score snapshot at payment time for audit defensibility

Step 3 is the one most teams skip, and the one that catches substitution attacks. An address can be perfectly clean and still be the wrong address.

How Do You Stop QR Code And Wallet Address Manipulation?

Validate the destination server-side against a pre-approved record — never trust what is rendered on screen. Clipboard-hijacking malware and doctored QR codes both exploit the gap between what a human reads and what the payload contains.

  • Compare the displayed address against the actual transaction payload programmatically, before signing
  • Decode and validate QR contents server-side; never accept a client-side decode as authoritative
  • Enforce checksum validation on every manually entered address, rejecting malformed entries outright
  • Log every scan and address entry with user, timestamp, device and payload for forensic trails
  • Require out-of-band confirmation on a previously known channel for any new or modified address

Never verify an address using contact details supplied in the same thread that requested the change. The same discipline that makes bank account verification effective against invoice fraud applies directly to wallet addresses.

Which Behavioural Signals Improve Fraud Detection Accuracy?

Capture device fingerprints, session duration, navigation paths and approval timing, then baseline per user and per counterparty. The value is in correlation: a single anomaly is noise, but an unrecognised device → a whitelist change → a withdrawal to a one-hop-exposed address is a confirmed B2B crypto scam in progress and should auto-hold.

Which Operational Controls Prevent B2B Crypto Scams And Payment Fraud?

Six controls are non-negotiable for any organisation exposed to digital assets.

ControlWhat it preventsImplementation standard
Phishing-resistant MFA on custodial accessAccount takeoversHardware keys or FIDO2 — SMS OTP is insufficient
Strict counterparty onboardingFake vendor and shell entitiesVerified entity, beneficial ownership, validated account before first payment
Least-privilege accessInsider diversionNo identity can both modify payment data and approve payment
Server-side address validationAddress and QR manipulationChecksum plus match against pre-approved record
Human review on payment-detail changesVendor email compromiseOut-of-band callback on a known number
Withdrawal whitelisting with delayRapid exfiltration of stolen funds24–48 hour delay on newly added addresses

The separation-of-duties rule deserves emphasis: if one person can add a wallet address and release a payment to it, no fraud detection technology will reliably save you.

How Should You Respond To A B2B Crypto Scam Alert?

Automate the high-confidence decisions and reserve humans for ambiguity. Automate blocks on sanctioned addresses, holds on first payments to new wallets and declines on failed payload validation. Route high-value transfers with mixed signals, long-standing vendors with a first-time anomaly and suspected insider cases to manual review — always to a named owner, never a shared inbox.

Classify by combined monetary and reputational exposure, not amount alone: a £10,000 payment to a sanctioned address outranks a £2m payment to a five-year vendor. Maintain an audit trail for every case, including alerts dismissed as false positives — dismissals are where the FCA will look first.

How Do You Recover Stolen Funds After A B2B Crypto Scam?

Recovery of stolen funds depends almost entirely on speed, because the window closes in hours rather than weeks:

  • Hour 0–1: Trace the destination address. Freeze related internal accounts and suspend the payment run. Notify your bank immediately if a fiat leg exists.
  • Hour 1–4: Notify every crypto exchange in the fund path — exchanges can freeze balances still in custody, and this is the single highest-probability recovery route.
  • Hour 4–24: Engage blockchain forensics for cross-chain tracing. Report to Action Fraud (or Police Scotland if you are in Scotland), and submit a suspicious activity report to the NCA’s UKFIU where POCA obligations are triggered.
  • Day 1–3: Prepare cross-border legal notices, brief insurers and preserve all logs and device images.

One critical warning: be extremely cautious of cryptocurrency recovery services charging upfront fees. Advance-fee recovery scams specifically target organisations that have already lost stolen funds, and they are a recognised secondary victimisation pattern. Legitimate blockchain forensics firms work under a defined engagement contract; they do not cold-contact victims promising guaranteed recovery.

Identify your Action Fraud reference process and your exchange compliance contacts before you need them. Sourcing them mid-incident costs the hours that decide recoverability.

How Do You Choose A Fraud Detection Vendor For Digital Assets?

Choose on integration depth and data coverage first, detection sophistication second. A best-in-class model that cannot block a payment inline is worth less than a simpler model wired into your payment run. Our comparison of fraud prevention software sets out how the main categories differ.

Must-have API capability: synchronous pre-transaction validation (target under 500ms), bulk counterparty screening, webhook alerts, case management read and write access, full audit log export.

Commercial requirements: 99.9%+ uptime SLA with defined degraded-mode behaviour, volume-tiered pricing (reject per-alert models — they penalise you for tuning sensitivity upward), named data sources with stated refresh frequency, and native ERP and TMS connectors rather than a custom build.

Roll out in phases: inventory your data sources and fix master data quality first, name a technical and business owner per endpoint, pilot in monitor-only mode on one corridor for 30–60 days, then assign permanent ownership for quarterly tuning. Untuned fraud detection rules degrade within two quarters.

Which Fraud Detection Metrics Prove Your Programme Works?

Track five metrics and review them weekly — payment fraud patterns shift faster than a monthly cycle can capture.

Fraud detection maturity targets, months 1–12

MetricPilot (months 1–2, monitor-only)Rollout (months 3–6)Steady state (months 7–12)
Mean time to detect (MTTD)Establish baselineUnder 5 minutesUnder 60 seconds
Mean time to respond (MTTR), P1Not yet enforcedUnder 1 hourUnder 15 minutes
False positive rateExpect 25–40%Under 20%Under 10%
False negative rateEstablish baselineRule review per incidentZero tolerance
% of payment value covered by validated counterparty dataUnder 25%50–75%Above 95%

Recommended targets, not measured results — set your own baseline during the pilot and tune against it. False positive rates for pre-payment validation run far lower than AML screening baselines, so do not benchmark the two against each other.

The last row is the one to watch. Coverage of validated counterparty data is your true prevention rate, and it is the leading indicator for every other metric in the table.

How Does Trustpair Prevent B2B Crypto Scams And Payment Fraud?

Trustpair stops the payment diversion at the centre of most B2B crypto scams by validating counterparty data before money moves. Where blockchain analytics tells you whether an address is risky, Trustpair answers the prior question: does this payment instruction genuinely belong to your counterparty?

  • Automated counterparty validation — verify vendor identity and bank account ownership across 200 countries, at onboarding and continuously, so a fictitious or hijacked counterparty never reaches a payment run
  • Continuous monitoring of payment data changes — every modification triggers real-time fraud detection, catching vendor email compromise at the exact moment it surfaces
  • Account reconciliation — match executed payments against validated records to surface diverted payments in hours, not at month-end close
  • Native integration with SAP, Oracle, ION and Ivalua, so payment fraud controls run inside the workflow your teams already use

UK customers consistently report the same outcomes: manual bank-detail verification eliminated, faster vendor onboarding and zero successful payment fraud across a validated vendor base.

Your Next Steps

  • This week: Enforce phishing-resistant MFA on all custodial access to shut down account takeovers, and enable a time delay on newly whitelisted addresses.
  • This month: Audit counterparty master data and calculate what share of payment volume runs against validated records. That percentage is your real prevention coverage.
  • This quarter: Confirm whether your activities fall inside the FCA perimeter ahead of the February 2027 gateway close, and pilot inline pre-payment fraud detection in monitor-only mode.

Digital assets are not going away, and neither is the payment fraud that follows them. With APP reimbursement offering corporates little protection and crypto payments offering none, the organisations adopting these rails safely are the ones treating verified counterparty data as infrastructure — not as a compliance checkbox.

Speak to a Trustpair fraud expert to assess where your current controls leave you exposed.

FAQ
Frequently asked questions
Browse through our different sections and find the answer to your question.
The most common cryptocurrency scams targeting businesses are phishing attacks, Ponzi schemes, fake vendor fraud and wallet address substitution. Phishing uses spoofed emails or look-alike websites to harvest the credentials that enable account takeovers, while Ponzi schemes lure corporate treasuries with returns paid from new deposits rather than genuine yield. Investment fraud produced £221.5m of UK APP losses in 2025, up 40% year on year, making it the single largest loss category.
Yes — attempted scams should be reported to Action Fraud even where no money left the business. Phishing emails, suspicious wallet solicitations and near-miss incidents all contribute intelligence that helps investigators map criminal infrastructure and warn other organisations. Preserve the wallet addresses, sender domains and message content, since near-miss reports frequently supply the indicators that make later cases prosecutable.
Most cryptocurrency recovery services that charge upfront fees are themselves scams, targeting organisations that have already lost funds. Genuine blockchain forensics firms operate under a defined engagement contract, work alongside law enforcement and never guarantee recovery outcomes. Treat any unsolicited approach promising to retrieve your digital assets for an advance payment as a second attack rather than a solution.
Most standard cyber policies exclude or heavily sub-limit cryptocurrency losses, and social engineering cover is typically a separate endorsement with its own cap. Review your policy for three specifics: whether digital assets are named as covered property, whether authorised transfers induced by deception are included, and which verification procedures you must evidence to keep a claim valid.
Simply paying a supplier in cryptocurrency does not itself require authorisation, but the FCA regime captures firms carrying on regulated cryptoasset activities such as issuance, custody, dealing, arranging or operating a trading platform. The authorisation gateway is open from 30 September 2026 to 28 February 2027. Any business with crypto exposure should take specific advice on whether its activities fall inside the perimeter, and must in all cases meet Money Laundering Regulations 2017 obligations and screen against the UK sanctions list.

You’d like these articles

Ready to beat the fraudsters? Try our 2-minute game

Trustpair rejoint Basware pour accélérer la lutte contre la fraude

Ready to beat the fraudsters? Try our 2-minute game