Fake Detective Tried to Steal Crypto Seed Phrase

Graham Cluley · Medium sophistication
Last updated August 6, 2026

A scammer called Graham Cluley while spoofing the real Crime Stoppers phone number and posed as a police detective investigating cybercrime. The caller tried to build trust, claimed to have evidence tied to Cluley (including a passport scan), and steered the conversation toward his Trezor hardware wallet and whether criminals had his 24‑word recovery phrase. A follow-up email claiming to be from the Metropolitan Police attempted to pressure him into cooperating.

Key findings

  • Attacker spoofed the caller ID to appear as the Crime Stoppers number (0800 555 111).
  • Caller posed as a detective and used a believable investigative story to build trust and reduce suspicion.
  • Scammer demonstrated knowledge of the target’s personal data (phone number, personal email) to increase credibility.
  • The interaction appeared aimed at obtaining the victim’s 24-word cryptocurrency recovery seed phrase.
  • A follow-up email impersonating the Metropolitan Police attempted to intimidate the target into compliance.

Who’s being targeted

  • Commonly targeted roles: Executives, Finance, General staff, Anyone who uses cryptocurrency wallets.
  • Affected industries: Consumers / individuals, Cryptocurrency users, Financial services (crypto wallets and exchanges).
  • Attack channels: vishing, email.
  • Impersonated: Crime Stoppers detective (law enforcement), Metropolitan Police.

Awareness takeaways

  • Treat unexpected ‘law enforcement’ calls as untrusted, hang up and verify via official channels you look up yourself.
  • Never share wallet recovery phrases (seed words) with anyone, any request for them is almost certainly theft.
  • Be suspicious when a caller pivots to money/assets questions; that’s often the true motive of the scam.
  • Validate alarming emails by checking technical indicators (like headers) and by confirming with the supposed sender through trusted contact methods.

Red flags to watch for

  • Unexpected call using authority (“detective”) to create urgency and compliance
  • Probing questions about assets (“how much cryptocurrency”) unrelated to a legitimate investigation
  • Requesting or steering toward disclosure of a secret recovery phrase (equivalent to the keys to the wallet)
  • Threatening language implying punishment for non-compliance
  • Mismatch between caller identity (Crime Stoppers) and email sender (Metropolitan Police)
  • Signs of email spoofing visible in headers
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Your phone rings. Caller ID says Crime Stoppers, 0800 555 111. A calm voice: “Hello, this is Detective David Pullen.” He sounds legit, knows your phone and email, says he’s on a cybercrime case. Then he pivots: do you have a Trezor wallet, how much crypto, do criminals have your 24-word seed key? Later, an email shows up, claiming to be the Metropolitan Police, hinting you could face action if you don’t cooperate. The headers tell the truth: it’s forged, from somewhere else. Here’s the rule: if anyone on a call or email asks for your 24-word recovery phrase, hang up, ignore the email, and contact the organisation using a number or website you look up yourself.

Similar attacks

Fake IT Calls Push AnyDesk in Brazil Heists

Fake IT Calls Push AnyDesk in Brazil Heists

Mandiant and Google report that the financially motivated group BREEZE COMET compromised Brazilian organizations to enable fraudulent bank transfers. The actor used human manipulation (including fake IT support calls) and believable “tax/receipt” downloads hosted on trusted-looking government…

September 1, 2026
Recruiter, RMM, and Vishing Scams Hit Hard

Recruiter, RMM, and Vishing Scams Hit Hard

This weekly roundup includes multiple real-world social-engineering and phishing-style operations, including fake recruiter outreach pushing malicious Android apps, phishing emails that trick users into installing remote management tools, and vishing that reportedly led to compromised Okta…

September 4, 2026
AI-Aided Crypto Scam Used Phishing + Vishing Combo

AI-Aided Crypto Scam Used Phishing + Vishing Combo

Researchers found a crypto fraud operation that used AI-assisted tooling to sift and verify over 100,000 phone numbers, then target confirmed crypto users. The campaign used a one-two approach: phishing messages that included a case/verification code, followed by phone calls that referenced those…

August 19, 2026
Fraud Ring Targets Crypto Users via Phone + Phish

Fraud Ring Targets Crypto Users via Phone + Phish

Researchers described a real fraud operation that first verified which phone numbers were tied to cryptocurrency exchange accounts, then targeted confirmed owners. The attackers used phishing emails, vishing calls, and fake wallet apps while impersonating popular hardware/software wallet brands,…

August 18, 2026
Crypto Scam Used Email + Vishing + Fake Wallet Apps

Crypto Scam Used Email + Vishing + Fake Wallet Apps

Rapid7 uncovered an active cryptocurrency fraud operation that combined phishing emails, follow-up phone calls, and counterfeit wallet apps to trick victims into handing over wallet recovery (seed) phrases. The attackers validated and enriched phone-number leads first, then used matching “support…

August 17, 2026
Fake IRS Letters Push Crypto “Compliance Portal”

Fake IRS Letters Push Crypto “Compliance Portal”

Scammers are mailing official-looking “IRS” letters to cryptocurrency holders, urging them to scan a QR code and enroll in a fake “Digital Asset Compliance Portal.” The QR code leads to a fraudulent IRS-lookalike site that gathers wallet/exchange details and then prompts victims to provide a phone…

August 4, 2026