The FBI warned that criminals behind cryptocurrency investment scams are increasingly sending in-person couriers to collect cash from victims when banks or financial institutions block suspicious transfers. In these schemes, fraudsters typically contact targets through social media, dating platforms, or messaging apps, build trust through so-called pig butchering or romance baiting, and then direct them to fake investment platforms where money is stolen instead of invested.
According to the FBI, scammers may claim a victim’s account has been flagged and arrange a cash handoff authenticated with a pre-arranged password or a specific U.S. dollar bill serial number. After the pickup, victims are shown fabricated gains in virtual wallets and pressured to send more money for bogus taxes or penalties. The bureau urged people to research crypto platforms, avoid sharing home addresses or meeting unknown individuals, watch for love bombing behavior, and report incidents with detailed evidence; the FBI’s 2025 Internet Crime Report said U.S. victims lost nearly $21 billion to cyber-enabled crime in 2025, including $8.6 billion tied to investment scams.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
The FBI warned that criminals behind cryptocurrency investment scams are increasingly arranging in-person couriers to pick up cash from victims when financial institutions block suspicious transfers. The agency also advised the public to research platforms, avoid sharing personal information or home addresses, and report incidents with supporting evidence.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
4 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcescworld.com
Open sourceic3.gov
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.