Deepfake scams: when the face on the call is not real
AI voice clones and video fakes now run the old cons. The 25 million dollar Arup call, fake Elon Musk crypto ads, voice-clone family emergencies, and the code word that beats them.
A deepfake scam uses AI-generated video or cloned voices to impersonate someone you trust: your boss, your bank, a celebrity, or your own family. The technology crossed a line in the last few years. A few seconds of audio from a social media clip is enough to clone a voice, and live video fakes are good enough to survive a work call. The scripts are the same old cons. The faces and voices are new, and they defeat the instinct people relied on: I know who I am talking to.
This is no longer rare crime news. It is an industrial technique, and the crypto world, with its irreversible transfers, is where it pays best.
What did the big deepfake scams actually look like?
The defining case hit the engineering firm Arup in 2024. A finance employee in Hong Kong joined a video call with what looked and sounded like the company's CFO and several colleagues. Every other person on the call was a deepfake. The employee approved transfers totaling about 25 million dollars. There was no hacking involved. The security hole was a meeting where everyone familiar was fake.
The retail version floods social media: deepfaked Elon Musk videos promoting crypto doubling sites and fake investment platforms, often running as paid ads or hijacked live streams. Older clips of real interviews get re-lipped to pitch giveaway scams that collect coins and vanish. The celebrity never said it, and thousands of people paid anyway.
How do voice-clone scams work on ordinary families?
The grandparent scam with a software upgrade. The phone rings, and a voice that sounds exactly like your son or granddaughter says there was an accident or an arrest and money is needed quietly and now. The audio source is anything public: a TikTok clip, a voicemail greeting, a school event video. Ten seconds is plenty for the cloning tools.
The defense is unglamorous and works: a family code word agreed offline, and a rule that any urgent money request gets verified by hanging up and calling the person's real number. Scammers manufacture time pressure because verification kills them. Any story that forbids you from checking is confessing.
Can I spot a deepfake by looking?
Sometimes, and you should not bet on it. Older fakes had tells: odd blinking, waxy skin, hands that melt, lighting that does not match. The current generation fixes most of that, and a compressed phone video hides the rest. Researchers report that people barely beat coin flips against good fakes.
So verify identity by channel, not by face. In a company, that means transfers over a threshold require a callback to a known number or a second approver, no matter who asks on video, and it worked at Ferrari in 2024, where an executive challenged a convincing voice clone of the CEO with a personal question and the caller hung up. At home, it means the code word. Treat the face and the voice as unverified until the channel says otherwise.
What does this have to do with crypto?
Crypto is the getaway vehicle. A wire transfer can sometimes be recalled, and a card payment disputed. A crypto transfer is final in minutes, which is why deepfake investment ads, fake exchange support calls, and cloned-CEO transfer requests so often end at a wallet address. The blockchain then does what it does: records the theft publicly, permanently, and without an undo button.
The rules that protect you are the same ones this whole subject keeps arriving at. Nobody legitimate needs your seed phrase, your remote screen, or a payment that cannot wait an hour. Money moves on verification, not on a familiar face. And the more urgent the voice, the slower your hands should get.