Bitcoin ATM Payment Demand? It’s a Scam Script

We Live Security · Medium sophistication
Last updated September 25, 2026

The article describes a common fraud pattern where scammers impersonate police, government officials, or other trusted authorities over the phone to pressure victims into paying via a Bitcoin/crypto ATM. The victim is told their money is at risk, instructed to withdraw cash, and then directed to scan a QR code at a crypto ATM that sends funds to the criminal’s wallet. It also warns that these transactions are typically irreversible and recovery scams may follow.

Key findings

  • Scammers use phone-based impersonation to frighten victims and keep them on the line until payment is made via a crypto ATM.
  • Victims are directed to withdraw cash, go to a specific Bitcoin/crypto ATM, and scan a QR code that sends funds to the criminal’s wallet.
  • The article cites FBI reporting that these scams generated $389M in losses in 2025, with older victims (50+) disproportionately affected.
  • Crypto ATM payments are difficult to reverse, and recovery scams may target victims afterward.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance/Accounting, Customer-facing staff, Non-technical staff, Older or otherwise at-risk staff.
  • Affected industries: Financial services (banks and payments), Retail locations hosting ATMs (gas stations, transport hubs, stores), Consumers/households.
  • Attack channels: vishing, smishing, physical, website.
  • Impersonated: Police officer / government employee / trusted official, Technical support / security support (implied via popup and call center).

Awareness takeaways

  • Treat any request to pay via a Bitcoin/crypto ATM as a scam and end the call.
  • Verify any alarming claim using official contact details (not numbers/emails provided by the caller or a popup).
  • Watch for coercion tactics: urgency, fear, and pressure to stay on the phone and not seek help.
  • Assume crypto ATM payments are difficult to reverse and report quickly while preserving evidence.

Red flags to watch for

  • Unsolicited call creating fear and urgency about criminal activity or compromised funds
  • Caller insists you stay on the phone and discourages you from contacting others
  • Instruction to pay via a Bitcoin/crypto ATM using a QR code sent by text
  • Unexpected computer popup demanding you call a number
  • Payment instruction that involves withdrawing cash and using a crypto ATM
  • High-pressure language that discourages verification through official channels
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

If anyone on the phone ever tells you to pay at a Bitcoin ATM, that’s not urgent security, that’s a scam. The call sounds official: 'Your identity is being used for crime, your funds are at risk.' They keep you on the line, tell you to withdraw cash, go to a specific Bitcoin ATM, then scan a QR code they text you. Here’s the trick: that QR code tells the ATM to send your cash straight into their crypto wallet. Once it’s gone, it’s almost impossible to reverse, and they may even call back later with a fake 'recovery' offer. Remember this one rule: if anyone ever tells you to pay or move money using a Bitcoin or crypto ATM, hang up immediately and call the real organization using their official number.

Similar attacks

Fake Google Play Pages Push Spyware at Logistics

Fake Google Play Pages Push Spyware at Logistics

A real campaign is targeting logistics firms with fake Google Play pages impersonating well-known logistics brands to trick employees into installing an Android spyware app. Once installed, the spyware can steal newly received SMS messages (including one-time passcodes) and enable call forwarding,…

September 24, 2026
AI Search Results Turn Into Phishing Traps

AI Search Results Turn Into Phishing Traps

This bulletin describes multiple real-world scams where attackers make fake pages and messages look like routine, trusted experiences (search answers, Google login pop-ups, “giveaways,” and official-sounding calls). Examples include a fake Claude Max giveaway using a convincing fake Google sign-in…

September 24, 2026
Revolut Smishing Uses Fake Identity Check

Revolut Smishing Uses Fake Identity Check

Following a Revolut data breach, scammers sent text messages that appeared to come from the same message thread as legitimate Revolut texts. The texts pushed victims to click a link for a fake identity “liveness check,” request camera access, and then capture passwords, information that could be…

September 21, 2026
Revolut Users Hit With SMS Phish After Breach

Revolut Users Hit With SMS Phish After Breach

Days after Revolut disclosed that customer records were shared with an unauthorized party, some customers reported receiving phishing texts that appeared in the same SMS thread as real Revolut messages. The link led to a fake site that asked for camera access to mimic Revolut’s identity “liveness”…

September 17, 2026
Fraudulent Gov Email and Passkey Lures Hit Orgs

Fraudulent Gov Email and Passkey Lures Hit Orgs

The bulletin describes real-world social engineering where staff were tricked into disclosing sensitive data or access. In one case, Revolut employees responded to fraudulent information requests sent from a real government-domain email account, exposing extensive customer records. Separately,…

September 14, 2026
Deepfake ‘Kidnapping’ Calls and the Safe Word Fix

Deepfake ‘Kidnapping’ Calls and the Safe Word Fix

The article describes how scammers use AI voice cloning to impersonate a loved one during a phone call and pressure relatives into paying money (often framed as a kidnapping emergency). It recommends a practical defense: a pre-agreed family “safe word” and a simple verification process (hang up and…

September 10, 2026