Crypto Invoice Fraud: One Swapped Address

A supplier you have paid nine times sends invoice number ten. Same template, same signature block, same person you spoke to on Tuesday. One line is different: the wallet address. You pay it. Ninety seconds later the funds have been swapped, split and moved, and there is no bank on either end to call.
The FBI's Internet Crime Complaint Center logged 24,768 business email compromise reports in 2025, with $3.05 billion in reported losses — up from 21,442 reports and $2.77 billion the year before. Most of that money still moves by bank wire. But this fraud follows whatever rail the victim actually uses, and a growing share of invoices now settle in USDT and USDC.
Nobody attacks the blockchain
The chain is not the weak part. The email thread is.
There are two common shapes. In the first, someone is sitting inside a mailbox — yours or your supplier's — reading real correspondence. They wait for a genuine invoice to go out, then send a short follow-up: we've changed banking providers, please use the updated address below. It arrives in the same thread, under the same display name, often quoting the message above it. IC3 describes the classic version in one line: a vendor you regularly deal with sends an invoice with an updated payment address.
In the second, nothing is rewritten except the string itself. The attacker substitutes an address whose first four and last four characters match the real one. Anyone who checks a payment destination the way most people do — glance at the start, glance at the end, approve — will wave it through. That is the same weakness address poisoning exploits, applied to a document instead of a transaction history.
Both work for the same reason. The victim is not being asked to do anything unusual. They are being asked to pay an invoice they were already expecting.
Crypto removes the second chance
A misdirected bank wire is bad. It is also, sometimes, recoverable. There is a correspondent bank, a recall procedure, a compliance desk at the receiving institution, and a window measured in hours or days.
A misdirected on-chain payment settles in seconds and belongs to whoever holds the key. There is no recall. The only lever left is the token issuer, and issuers are not a support desk.
Tether has blacklisted close to 10,000 addresses and frozen more than $5 billion in USDT. Circle's list is far shorter — roughly 370 addresses and about $109 million. Those freezes are real and they have returned real money to real victims. But Circle's Jeremy Allaire said in April 2026 that USDC will not be frozen without a court order, and treats the capability as non-discretionary. Getting a court order means lawyers, a jurisdiction, a named defendant and weeks you do not have. Treat a freeze as a lottery ticket, not a recovery plan.
"But the address came back clean"
Here is the uncomfortable part, and anyone selling you screening should say it out loud: a fraudster's fresh wallet will often pass a sanctions check. It was created an hour ago. It has no history and appears on no list. Clean is not the same as safe.
Screening still earns its place, for three reasons.
First, a lot of this money does not sit in a fresh wallet for long. It lands in reused collection addresses that already have a reputation. Chainalysis put illicit inflows at a minimum of $154 billion in 2025, a 162% jump year over year, with value received by sanctioned entities up 694%. That is an enormous volume of already-known destinations, and a payment routed toward one is a payment you want to stop before it leaves.
Second, screening tells you about age and behaviour, not just list membership. An address that has existed for two hours and never received anything is not the treasury account of a company that has invoiced you nine times. That mismatch is the signal. The list hit is a bonus.
Third, if you do get paid into a wallet that later turns out to have received proceeds of crime, your own address inherits that history. Exchanges screen deposits on the way in. You find out about the problem when your withdrawal is held for review, not when the transfer lands.
There is also the reverse trick, on the receiving side. Since the GENIUS Act became law in July 2025, security firm Blockaid has counted more than 54,000 fake stablecoins among the 17 million-plus tokens minted in that period. A payment can "arrive" in something that looks like USDC in a wallet interface and is worth nothing. Check the contract, not the ticker.
What actually stops it
None of this requires new technology. It requires the payment address to stop being an editable line of text in a message.
- Confirm any new or changed address on a different channel from the one the request arrived on. Call the number you already had, not the one in the signature.
- Compare the whole string. Not the first four characters and the last four.
- Send a small test payment to any new destination, and have the recipient confirm the amount before the real transfer goes out.
- Screen the address before you pay, not after the payment is disputed.
- Take the address out of email entirely — issue the invoice so the payment address is fixed when the invoice is created, and the payer sees a link rather than a string someone can retype.
If you are the one getting paid, the mirror image applies. When a client insists they paid and nothing arrived, the tampered document may well have been yours. Sending payment details as plain text in a message body means every forwarded copy of that message is an opportunity for someone else. It also means you have no way to prove what you originally sent.
Set an internal rule and write it down: any change to payment details, from anyone, at any amount, is verified by voice before a transfer goes out. Make it boring and unnegotiable, so nobody has to make a judgement call at 6pm on a Friday when the supplier sounds annoyed.
Nobody in this story is careless. The finance person paid an invoice they were expecting, from a company they knew, in a thread they had been reading for months. That is exactly the point — the attack is designed to look like routine work. The habit that costs nothing is to treat a changed payment address as an incident rather than an update, and to check where the money is actually going before it goes there.
Sources
- 1.2025 Internet Crime Report — FBI Internet Crime Complaint Center (IC3)
- 2.Business Email Compromise: The $55 Billion Scam — FBI Internet Crime Complaint Center (IC3)
- 3.The 2026 Crypto Crime Report — Chainalysis
- 4.Circle CEO Allaire defends decision not to freeze USDC in Drift exploit — The Block
- 5.Stablecoin Impersonation Threats Expanding Across Malicious Tokens and dApps — Blockaid
- 6.USDT Freeze 2026: Who's Frozen, How to Check, Live Data — BlockSec
This article is general information, not legal, tax, financial, or investment advice. Crypto carries risk — do your own research and consult a qualified professional before acting. Constatum makes no warranty as to accuracy or completeness and accepts no liability for decisions made based on it.


