📊 Crypto Clarity Weekly

Wednesday, August 5, 2026  ·  Security Alert  ·  Free Edition

Threat Level HIGH AI Impersonation Attack Class Deepfake Face + Voice Clone Arup Loss $25M One Video Call Best Defense Verify Out-of-Band

🚫 Impersonation Attacks: Fake Founders, Fake Announcements, AI Voices

Week 32 · Security Alert · Deep Dive + 5-Step Verification Sprint

🌞 Free all summer: Wednesday Security Alerts are normally premium. They're free for every subscriber through Labor Day. Know someone who should be reading this? Forward it their way.

The market found its footing after last week's deleveraging. BTC is back to $64,139, roughly flat against last Wednesday's $63,993 but up from Monday's dip to $62,767, and Fear & Greed has recovered to 38 from 33 at the start of the week. ETH sits at $1,867, and HYPE bounced to about $54.51, up nearly 4% from Monday's low. Two headlines stand out. First, a constructive one: BlackRock bought roughly $111 million of BTC through its ETF, a quiet sign that institutions are accumulating the dip. Second, fitting for a security edition: attackers exploited a firmware flaw in Coldcard hardware wallets to drain roughly 1,128 BTC (about $72 million) from more than 1,100 self-custody users, a stark reminder that even the careful, cold-storage crowd is a target. More in David's Desk, including a HYPE watch that is suddenly climbing back toward its line.

🔅 Where This Fits in the Series

Back in June we covered phishing: the art of tricking you into acting on a fake message. Today's topic is phishing's far more dangerous cousin, supercharged by AI. The scammer no longer just sends you a suspicious email. They show up as a familiar face on a video call, a trusted voice on the phone, or a founder livestreaming an announcement. The old advice, "don't trust strangers online," quietly assumed you could still recognize the people you do trust. Artificial intelligence has broken that assumption, and this edition is about what to do now that it has.

⚠ Threat Brief

An impersonation attack is social engineering with a new weapon. Deepfake video and voice-cloning tools are now cheap, fast, and good enough to fool people who are paying close attention. An attacker can build a convincing fake of a CEO, a support agent, or a family member using nothing but public footage, then use it to demand a transfer or a password. The hard truth is that you can no longer reliably spot the fake with your own eyes and ears. The only defense that still works is to stop trusting the channel the request came in on, and to verify the person through a separate, trusted one before you act.

🚫 Impersonation Attacks

When the Face on the Screen and the Voice on the Phone Are Both Fake

For years, our security instincts have leaned on a simple shortcut: we trust people we recognize. We relax when we see a familiar face or hear a familiar voice. Impersonation attacks weaponize exactly that instinct, and AI has made them frighteningly good. They come in three main flavors.

Flavor 1: Fake Founders

You've likely seen these: a slick "livestream" of a famous founder, a well-known CEO, or a celebrity, announcing that to celebrate some milestone they're giving back. Send 1 BTC to this address and they'll send you 2 back. The video looks real because it is real footage, with an AI-generated voice layered on top, or a full deepfake built from public clips. It preys on authority (this person is credible), urgency (the offer ends soon), and greed (free money). No legitimate founder has ever run a "send crypto to get double back" event. Treat every single one as a scam, full stop.

Flavor 2: Fake Announcements

Here the attacker takes over, or convincingly spoofs, an official channel: a project's X account, a Discord server, a Telegram group. Then they post a fake airdrop, a fake "token migration, move your funds now," or a malicious link dressed up as an urgent official notice. The archetype is the 2020 Twitter hack, when attackers seized the verified accounts of major figures and companies and posted a Bitcoin doubling scam, netting roughly $118,000 in hours from people who trusted the blue check. Today the same play runs on hacked project accounts and AI-polished announcements that are far harder to distinguish from the real thing.

Flavor 3: Voice Clones

This is the one that will reach your family. Modern tools can clone a convincing voice from just a few seconds of audio, easily harvested from a social media video or a voicemail. The calls that follow are brutal in their simplicity: a "grandchild" in tears saying they're in trouble and need crypto fast; an "exchange support agent" warning your account is compromised and walking you through "securing" it; a "boss" authorizing an urgent transfer. The voice is right, the panic is real, and the clock is ticking. That combination is what defeats otherwise careful people.

📋 Case Study

The $25M Video Call Where Everyone Was Fake

In January 2024, an employee at the engineering firm Arup, in its Hong Kong office, received a message from the company's UK-based CFO about a confidential transaction. The employee was suspicious, and rightly so. It had the hallmarks of a scam.

So the attackers escalated. They invited the employee to a video call. On that call were the CFO and several other senior colleagues, all familiar faces, all discussing the transaction as routine. Every one of them was an AI-generated deepfake, built entirely from public video and audio of the real executives. Reassured by the faces and voices he knew, the employee made 15 transfers totaling roughly $25 million to five different accounts.

Note the sequence, because it's the whole lesson: the employee's skepticism was correct. What broke it was not a cleverer email. It was a video call full of people he trusted. The attack didn't overpower his judgment. It gave his judgment fake evidence to rely on.

How it unraveled: The fraud came to light only when the employee later contacted the real corporate headquarters about the "secret transaction." Actual leadership confirmed there had been no such request, no such meeting, and no such call. A single out-of-band check, made before the transfers instead of after, would have stopped all $25 million.

Why You Can't Just "Spot the Fake" Anymore

The old advice was to look for glitches: weird blinking, robotic audio, mangled hands. That advice is expiring fast. The tools improve every month, and the source material they need, your face and voice, is already public on LinkedIn, YouTube, podcasts, and company calls. More importantly, these attacks don't target your technology. They target your trust. For your whole life, seeing someone's face and hearing their voice was proof of who they were. That equation no longer holds, and no amount of squinting at the screen fixes it. Which is why the defense has to change.

📚 From the Blog

We wrote a full companion guide to this exact threat: how to spot an AI-generated crypto scam, with the three verification steps that stop deepfake video and voice attacks cold. If today's edition rattled you a little (it should), this is the practical playbook.

Read: How to Spot a Deepfake Crypto Scam →

⏱ Your 5-Step Verification Sprint: 15 Minutes

You can't out-detect the fakes anymore. You can build habits that make them fail.

1 Make "verify before you act" a hard rule. For any request involving money, keys, or access, confirm it through a second channel before doing anything. The more urgent and secretive the request, the more that rule applies, not less. Urgency is the scammer's favorite tool.
2 Set a family code word this week. A private phrase only your real family knows. If a panicked "relative" calls needing money or crypto and can't say it, you hang up. This single habit defeats the voice-clone emergency call, which is the attack most likely to reach the people you love.
3 Call back on a number you already trust. Never use the number, link, or button the request gives you. Look up the real contact independently and reach out through it. For "exchange support," go to the official app or site yourself; real support almost never calls you first.
4 Treat any "send crypto, get more back" event as a scam. Founders, exchanges, and celebrities do not double your money. A deepfake livestream saying otherwise is not an opportunity you're lucky to catch. It is the entire scam, and it is always fake.
5 Reply with an impersonation attempt you've seen. A fake livestream, a "support" call, a spoofed project account. Send it my way and I'll break down the tells and share the patterns, so the whole list learns to recognize what's circulating right now.

📋 From David's Desk

This is the topic that worries me most for the people I care about, because it doesn't prey on the careless. It preys on the careful. Read the Arup story again: the employee was suspicious, which is exactly what we tell everyone to be. And he still lost $25 million, because the scam handed his good instincts a familiar face to trust. That's the part I need you to sit with. "Be more skeptical" is no longer enough on its own. The new rule is to verify the people you already trust through a second channel, every single time money is involved.

If you do one thing after reading this, set a code word with your family this week. It's free, it takes five minutes, and it is the single best defense against the voice-clone call that is, statistically, coming for someone you love. I set one with mine after I first researched this attack, and I've never regretted it.

On the market: the floor from last week's flush is holding, BTC back near $64K and BlackRock quietly buying the dip. And a quick flag for those following the HYPE watch: Fear & Greed has climbed back to 38, just two points from my entry line, and HYPE has bounced to about $54.51. After four weeks of patient "monitoring only," the watch is genuinely back in play. The rule hasn't changed. I need to see 40 and hold, not just a touch. But I'll be watching it closely into Friday's premium edition.

📅 What's Coming Friday

Friday (Premium, DeFi Deep Dive): Morpho: Optimized Lending That Aims to Outperform Aave and Compound. A newer lending protocol with serious TVL and a genuinely clever design that squeezes better rates out of the same markets. Includes the Scanner Watch and the real-money portfolio update, plus where the HYPE watch stands. Friday is where Premium lives.

💬 Seen an Impersonation Attempt?

Hit reply with one impersonation scam you've run into: a fake founder livestream, a "support" call, a spoofed project account, a voice-clone attempt. I'll break down the tells and share the patterns with the list, so we all learn what's circulating right now. I read every reply.

Reply: Here's One I Saw →

📗 Safe DeFi: Your First 90 Days  ·  Website  ·  Blog  ·  📺 YouTube  ·  📷 Instagram  ·  [email protected]

Crypto Clarity Weekly is educational content only and does not constitute financial or investment advice. Always do your own research before investing.

You're receiving this as a subscriber to Crypto Clarity Weekly. Want the Friday premium editions too? Upgrade here.  ·  Unsubscribe

Reply

Avatar

or to participate

Recommended for you