Official Wallsec emails only ever come from an @wallsec.co.uk address.

Monthly notes

UK cryptocurrency fraud updates

A short, factual note each month on what we are actually seeing at intake — which fraud patterns are recurring, how the funds tend to move, and which reporting routes are producing results. No statistics we cannot evidence.

Written and reviewed by the Wallsec investigations team · Last updated

September 2026 — impersonation of recovery help, and faster off-ramps

The pattern that grew most this month was second-stage contact: people who had already reported a loss being approached by someone claiming to be able to retrieve it. Alongside that, first-hop movement to an exchange deposit address kept getting quicker.

  • Second-stage approaches usually arrive by direct message or a search advert, reference details the victim posted publicly, and ask for an upfront payment. Wallsec never asks for private keys, a seed phrase, remote access to a device, or payment in cryptocurrency.
  • In several enquiries the stolen balance reached a centralised exchange deposit address on the same day, which shortens the window in which a compliance team can act.
  • Stablecoins on Tron and Ethereum remained the dominant loss denomination in enquiries reaching our intake desk.
  • Reporting to Action Fraud and to the receiving exchange in parallel, rather than one after the other, continued to produce the most usable case files.
  • Where a victim still had access to the wallet, revoking outstanding token approvals before moving any remaining balance avoided a repeat drain in the cases we reviewed.

August 2026 — what we saw at intake

Approvals-based wallet drains and long-form investment fraud continued to make up most of the enquiries we received, with a rise in cases where the first hop moved through a cross-chain bridge within minutes.

  • Most losses reported to us were denominated in stablecoins, with Tron and Ethereum the dominant networks.
  • In approval-based drains, the malicious permission was frequently signed weeks before the balance was taken, so the date of the loss and the date of the mistake were far apart.
  • Bridging at the first or second hop was common. It does not end a trace, but it adds a step and usually a day of work.
  • Several enquiries arrived after an unsolicited message offering to retrieve funds. No legitimate firm asks for a payment in cryptocurrency, private keys or a seed phrase.

July 2026 — reporting routes and timing

The cases that produced the most usable outcomes were the ones reported to the receiving exchange within days, not weeks. Timing continues to matter more than the size of the loss.

  • Exchange compliance teams can only act while the funds are still sitting in an account they control.
  • An Action Fraud reference number was requested by nearly every bank and exchange we saw clients deal with.
  • Screenshots taken before a fake platform went offline were, in several cases, the only surviving record of the account balance shown to the victim.
  • Fake versions of legitimate-looking trading sites were the most common single vector reported to us this month.

Background reading: UK cryptocurrency fraud hub and investigation guides.

These notes describe patterns observed in enquiries made to Wallsec. They are general information, not legal or financial advice, and no outcome is implied or guaranteed.

Seeing something similar?

We scope at intake and tell you honestly whether the onchain data supports a traceable case.

Request a case review