Threat Intelligence Directory
Fraud

Cryptocurrency Investment Scam

Attack Trigger

Promises of guaranteed high returns on cryptocurrency investments

What Attackers Want

$500–$500,000 in initial investment plus escalating "withdrawal fees"

How This Attack Works

Scammers promote fake cryptocurrency exchanges, trading bots, or investment platforms via email claiming guaranteed returns of 10–50% per week. Victims are shown fabricated dashboards displaying growing balances. When they attempt to withdraw, they are told to pay taxes, fees, or insurance before funds can be released — payments that are never returned.

Red Flags to Watch For

  • Guaranteed returns on crypto — no legitimate investment offers this
  • Unsolicited email or social media message about a trading opportunity
  • Platform is not listed on any recognized exchange registry
  • You are shown profits on a dashboard but cannot withdraw without paying fees first
  • Operator claims to be an AI trading bot with a proprietary algorithm
  • Someone claims to have made life-changing returns and wants to share the secret

Known Malicious Domains

These domains have been associated with this attack. Never click links going to these addresses.

  • crypto-profit-now.comMALICIOUS
  • bitcoin-investment-returns.netMALICIOUS
  • altcoin-trading-platform.comMALICIOUS
  • defi-yield-guaranteed.comMALICIOUS

Glance automatically blocks emails from domains on this list. Domain list is not exhaustive — attackers register new domains continuously.

How Glance Stops This

  • Domain similarity analysis catches lookalike sender addresses at millisecond speed
  • SPF / DKIM / DMARC validation flags authentication failures before you ever see the email
  • VirusTotal + Google Safe Browsing checks every link in real time
  • Urgency language detection scores the email higher for manual review
  • Known malicious domain blocklist updated continuously from live scan data

Don't wait to get hit.

Glance scans every incoming email against 12 detection layers — including the exact tactics described above — before it reaches your inbox.

Protect My Inbox — Free