Fake Detective Tried to Steal Crypto Seed Phrase

Graham Cluley · Medium sophistication
Last updated August 6, 2026

A scammer called Graham Cluley while spoofing the real Crime Stoppers phone number and posed as a police detective investigating cybercrime. The caller tried to build trust, claimed to have evidence tied to Cluley (including a passport scan), and steered the conversation toward his Trezor hardware wallet and whether criminals had his 24‑word recovery phrase. A follow-up email claiming to be from the Metropolitan Police attempted to pressure him into cooperating.

Key findings

  • Attacker spoofed the caller ID to appear as the Crime Stoppers number (0800 555 111).
  • Caller posed as a detective and used a believable investigative story to build trust and reduce suspicion.
  • Scammer demonstrated knowledge of the target’s personal data (phone number, personal email) to increase credibility.
  • The interaction appeared aimed at obtaining the victim’s 24-word cryptocurrency recovery seed phrase.
  • A follow-up email impersonating the Metropolitan Police attempted to intimidate the target into compliance.

Who’s being targeted

  • Commonly targeted roles: Executives, Finance, General staff, Anyone who uses cryptocurrency wallets.
  • Affected industries: Consumers / individuals, Cryptocurrency users, Financial services (crypto wallets and exchanges).
  • Attack channels: vishing, email.
  • Impersonated: Crime Stoppers detective (law enforcement), Metropolitan Police.

Awareness takeaways

  • Treat unexpected ‘law enforcement’ calls as untrusted, hang up and verify via official channels you look up yourself.
  • Never share wallet recovery phrases (seed words) with anyone, any request for them is almost certainly theft.
  • Be suspicious when a caller pivots to money/assets questions; that’s often the true motive of the scam.
  • Validate alarming emails by checking technical indicators (like headers) and by confirming with the supposed sender through trusted contact methods.

Red flags to watch for

  • Unexpected call using authority (“detective”) to create urgency and compliance
  • Probing questions about assets (“how much cryptocurrency”) unrelated to a legitimate investigation
  • Requesting or steering toward disclosure of a secret recovery phrase (equivalent to the keys to the wallet)
  • Threatening language implying punishment for non-compliance
  • Mismatch between caller identity (Crime Stoppers) and email sender (Metropolitan Police)
  • Signs of email spoofing visible in headers
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Your phone rings. Caller ID says Crime Stoppers, 0800 555 111. A calm voice: “Hello, this is Detective David Pullen.” He sounds legit, knows your phone and email, says he’s on a cybercrime case. Then he pivots: do you have a Trezor wallet, how much crypto, do criminals have your 24-word seed key? Later, an email shows up, claiming to be the Metropolitan Police, hinting you could face action if you don’t cooperate. The headers tell the truth: it’s forged, from somewhere else. Here’s the rule: if anyone on a call or email asks for your 24-word recovery phrase, hang up, ignore the email, and contact the organisation using a number or website you look up yourself.

Similar attacks

Fake IRS Letters Push Crypto “Compliance Portal”

Fake IRS Letters Push Crypto “Compliance Portal”

Scammers are mailing official-looking “IRS” letters to cryptocurrency holders, urging them to scan a QR code and enroll in a fake “Digital Asset Compliance Portal.” The QR code leads to a fraudulent IRS-lookalike site that gathers wallet/exchange details and then prompts victims to provide a phone…

August 4, 2026
BEC ‘Are you at your desk?’ Lures Surge in Q2

BEC ‘Are you at your desk?’ Lures Surge in Q2

Microsoft reports billions of phishing attempts in Q2 2026, with attackers increasingly using attachments (PDF/DOC/HTML) and new formats like calendar invites to trick employees into entering credentials. The report also highlights continued growth in Teams-based social engineering and notes that…

July 23, 2026
Finance Phishing Lures Feed Telegram Data Leaks

Finance Phishing Lures Feed Telegram Data Leaks

A June 2026 financial-sector threat report describes real phishing emails that used business-looking themes (e.g., money transfers, receipts, voicemail) to push victims to malicious links or HTML attachments that mimic login pages. The report also highlights cases where stolen account information…

July 22, 2026
Govt-Themed Phishing Spreads Cruciferra Malware

Govt-Themed Phishing Spreads Cruciferra Malware

Proofpoint observed real phishing campaigns using government-themed lures to trick people into downloading ZIP files that install malware. The campaigns used a “crypter” service called Cruciferra to help common remote-access and data-stealing malware evade detection. Financial services, healthcare,…

July 21, 2026
Fake IT Helpdesk Calls Hit Wall Street Firms

Fake IT Helpdesk Calls Hit Wall Street Firms

A ransom-focused hacking group targeted major U.S. financial and other firms by calling employees on their personal phones while impersonating the company help desk. Victims were pushed to “update passkeys or multifactor authentication” and sent to look‑alike websites designed to steal passwords…

August 6, 2026
UNC6671 Vishing: Fake IT Passkey ‘Migration’ Scam

UNC6671 Vishing: Fake IT Passkey ‘Migration’ Scam

Google reports UNC6671 is still actively compromising organizations by calling employees and pretending to be IT helpdesk staff running an urgent security migration. Victims are pushed to visit lookalike login pages that steal passwords and MFA codes, which then enables data theft and extortion…

August 6, 2026