The Theft Often Begins Before the Theft
The damage rarely begins with a hack. Whether the bitcoin sits in a hardware wallet, an exchange or a retirement account, the entry point is the same: a person under pressure, trusting the wrong message.
First published on Substack on 19 April 2026. Revised for this blog on 2 October 2026. The FBI figure now reflects the full 2025 IC3 report, which found investment fraud, not phishing, was the largest source of losses.
The damage rarely begins with a hack.
It usually starts with something smaller. A text that looks routine. A phone call that sounds official. A support reply that feels helpful. A verification code request that seems urgent but harmless. A small moment where trust is redirected.
It often looks like this. A message arrives that appears to be from an exchange or a mobile carrier. There is a problem. It sounds serious but fixable. A code is sent. The person shares it, believing they are securing the account. In reality, they have just handed over the final piece needed to unlock it.
The theft does not begin at the wallet. It begins at the moment of belief.
Real cases keep following this structure. In Justice Department prosecutions of SIM-swap rings, attackers bribed phone-company employees to take over victims' numbers, then reset their accounts and drained funds worth millions. In reported incidents involving exchange users, attackers impersonated support staff and walked victims through fake recovery steps. Other times the message arrives by email or through the browser itself, asking the user to log in, confirm, fix or recover something that was never broken.
The setup is not always a message or a call. Sometimes it is planted in wallet history. In address-poisoning scams, attackers send a tiny amount from an address that looks familiar enough to trust later. The small transfer is bait. The real attack comes later, when someone copies an address from history instead of verifying it.
I mostly avoid the word crypto, and here it earns its place. This is where many people just starting out blur the lines between Bitcoin, crypto, platforms, funds, support, recovery and investing. Once the categories get fuzzy, one human error stops being an isolated mistake and starts feeding a much wider story.
The FBI's Internet Crime Complaint Center recorded more than $11 billion in crypto-related losses in 2025, a record. Most of it came from investment fraud, which runs on persuasion rather than on broken code.
That should change how people picture the threat. The lesson is wider than "be careful with self-custody." Whether someone holds keys directly, uses an exchange, or only has exposure through funds or retirement accounts, the structure changes but the human layer does not. That is where attacks concentrate.
A SIM swap matters if a phone number is tied to recovery. A fake support message matters if someone trusts the wrong contact path. A verification-code scam works if urgency feels legitimate. A browser prompt works if the user starts in the wrong place. Email often becomes the master key: once it is controlled, resets and access flows follow.
The account type changes, but the person remains the entry point.
These attacks do not succeed because people are careless. They succeed because they arrive inside workflows people already trust: support tickets, recovery flows, security alerts.
The environment is shifting in the attackers' favor. Social engineering keeps winning because it scales. Voice phishing works better than many people expect, and AI is making impersonation faster, cheaper and more convincing. Messages sound right. Calls feel informed. Pressure feels real. AI does not need to break Bitcoin to do damage. It only needs to make deception cheaper.
Even the systems themselves are not always the boundary. Insider access, through coercion or bribery, has already been used to bypass safeguards in telecom and support environments. So the risk does not stay inside one wallet, platform or account type. A brokerage login can be reset. An exchange account can be taken over. A retirement platform can be accessed. A custodial service can be socially engineered.
The defenses are simple, but they have to exist before pressure shows up:
- Put a PIN or password on your mobile phone account.
- Reduce reliance on SMS wherever stronger authentication exists.
- Never share a verification code, seed phrase or recovery detail with anyone who contacted you first.
- Never resolve an account issue through a contact that reached out to you.
- Decide in advance how you will verify support and recovery paths.
Because in the moment, it will feel legitimate.
So here is the question I would ask of your own setup: what part of your Bitcoin life still depends on you trusting the right message, screen or recovery prompt under pressure?
Whatever the container, the entry point is the person holding it.
Sources
- FBI Internet Crime Complaint Center, 2025 IC3 Annual Report (April 2026); summary in The Block, 12 April 2026.
- U.S. Attorney's Office, Eastern District of Michigan, International hacking group members sentenced in SIM hijacking conspiracy, 30 November 2021.
- U.S. Attorney's Office, Eastern District of Louisiana, Former phone company employee pleads guilty to role in SIM swap scam conspiracy.