Deepfake Voice Scams Targeting Crypto Executives Surge, Exchanges Warn
AI-cloned voices impersonating founders and finance chiefs are being used to push through fraudulent withdrawals and rushed OTC deals, and exchanges say the calls are now good enough to fool people who know better.
Every major exchange has spent the past year telling customers to hang up on unsolicited calls asking for withdrawal codes. The advice is now colliding with a harder problem: the call sounds exactly like your CFO, your co-founder, or your compliance lead, because in a growing number of documented cases, it is their voice — cloned from a handful of public interview clips and run through commodity AI tooling that costs less than a monthly streaming subscription.
How the calls actually work
Security teams at several exchanges say the pattern is consistent enough to describe as a playbook. Attackers scrape public audio of a target executive — a podcast appearance, a conference panel, an earnings call — feed it into a voice-cloning model, and use the output either in a live, AI-mediated phone call or in a pre-recorded voicemail designed to sound urgent. The ask is almost always the same: authorise a withdrawal, approve a wire, or fast-track an OTC settlement outside normal sign-off, framed as time-critical and best handled quietly. Some incidents have paired the cloned voice with a spoofed caller ID matching the real executive's known number, closing the last gap that used to let a suspicious employee catch the fraud.
What makes this generation of scam different from the crude "grandparent scam" clips that circulated a couple of years ago is latency and interactivity. Real-time voice cloning has improved to the point that the model can respond conversationally, including answering follow-up questions in the target's cadence, rather than playing a static script. A finance team member testing the caller with an off-script question used to be a reliable defence. Exchanges now say that test alone is no longer sufficient.
Who's actually being hit
The targets skew toward people with authority to move money without a second signature: treasury staff at exchanges and funds, OTC desk operators, and smaller project teams where the founder is also the person who can approve a transaction. A handful of publicised incidents this year involved attackers impersonating a company's own CEO on an internal call to instruct a transfer, and separately, impersonating a counterparty's negotiator to rush through an OTC block trade at an off-market price before the fraud was caught. Exchanges have been more forthcoming about attempted incidents than successful ones, for obvious reasons, but the volume of reported attempts has risen sharply enough that several platforms have issued fresh advisories in the past few weeks specifically calling out voice-based social engineering, distinct from the phishing-link warnings that have dominated prior guidance.
What's actually working as a defence
The mitigations exchanges are pushing aren't exotic, which is part of the frustration — they're the same controls good treasury operations should have had regardless of deepfakes. Out-of-band verification is the big one: any request to move funds, however it arrives, gets confirmed through a separate channel the caller didn't control, ideally a pre-agreed code word that changes regularly rather than a callback to a number the attacker could also have spoofed. Multi-party approval for withdrawals above a threshold removes the single point of failure that voice-cloning attacks are specifically designed to exploit. And a hard rule against approving anything under time pressure, however senior the voice on the line claims to be, closes off the urgency lever that almost every one of these incidents relies on.
The uncomfortable reality is that voice authentication was never a particularly strong control to begin with; it just felt strong because faking it used to require effort most criminals couldn't be bothered with. That barrier is gone. Exchanges that treated "I recognised the voice" as sufficient authorisation for anything involving money are the ones now rewriting their internal procedures at speed, and the ones that already required cryptographic or multi-party sign-off for large transfers are finding that boring, unglamorous process is exactly what's holding up under an attack built to exploit trust in a human voice.



