
Fake VC Scam: How Web3 Founders Lose ETH
The pitch was perfect. That's how you know it's fake.
The trouble with a good scam: it doesn't look like one. It looks like a Tuesday. A warm intro from a name you half-recognise, a 3pm Meet, a face that nods on cue, a term sheet before the coffee's cold. Standard fundraising choreography — except the same LLM stack founders bolted onto Claude this quarter got repointed at them by lads who aren't building anything except a shopping list. One founder lost 4.2 ETH before dinner. Another handed over SAFE cap-table access without lifting an eyebrow. A third signed one polite little signature that emptied the treasury multisig in the time it takes to boil a kettle. Terribly civilised. Right up until the wallet's empty.
Summer 2026. The pitch lands like a proper gentleman — pressed suit, warm intro, a term sheet that smells of old money and new PDF. Only the gentleman is an LLM in a bespoke domain, the partner is a deepfake, and the "formation deposit" is the polite way of walking your treasury into a stranger's boot. Founders hand the company over in ninety seconds because the email cadence was, quote-unquote, "honestly, kind of flattering".
Related reading: deepfake job interviews for founders · how malicious signTypedData / approve() drains work · free Scam Detector · glossary (Revoke.cash, approvals).
The Scheme: AI Agents Impersonating VCs
Founders automated investor outreach. The lads across the road automated investor impersonation — same tools, same prompts, same posture, opposite direction. Scrape LinkedIn, Crunchbase, Messari. Feed the lot into a model that writes like a Paradigm associate one glass of wine in — humble, specific, quietly clever. Register a lookalike domain via Njalla, dust off a warmed Twitter persona, and land in the inbox at 8:47am local, because that's when the real ones send. Every artefact convinces because the legitimate artefact was built with the exact same stack last quarter. It's not counterfeiting. It's karaoke — and the crowd, God bless them, is singing along.
Automation doesn't pick sides. It just goes faster for whoever pointed it first — and the wrong lads pointed it Monday morning.
Fake VC Emails: What They Actually Do To Founders
Step one: an "associate" from a real fund emails from `[email protected]` (note the extra `s`). The email is warm, specific, cites two portfolio companies you actually respect, and asks for a 20-minute call. Attachment: a "portfolio thesis" PDF that opens fine. The PDF is not the payload. The email chain is.
Step two: after the call — held on a real Google Meet with a real face (deepfake, warmed for two weeks on Twitter) — you get a follow-up: "partner is interested, we'd like to allocate $500k at the terms discussed." The next email contains a wallet address for "a token round formation deposit" or a "SAFE co-signing gas fee" of 0.2 ETH. A real VC has never once asked a founder to send them ETH.
Step three: variants replace the ETH request with a signature request. `signTypedData` against a contract that looks like a KYC gate or an escrow. It's an `approve()` for your USDC/USDT treasury with an unlimited allowance. Signed. Drained. The scammer's LLM even sends a follow-up 24 hours later apologising that the KYC gateway had a bug, so the founder doesn't flag anything until the wallet is empty.
The scam isn't the email. The scam is the *sequence*.
Anatomy Of A Fake VC Email: 3 Real Templates (Anonymised)
Names, funds, and wallets swapped for placeholders. The prose, the cadence, the red flags — all lifted verbatim from campaigns founders have forwarded to us since March 2026.
Legit VC Email vs Fake VC Email — Side-By-Side
Same greeting. Same word count. Wildly different intent. Nine signals that separate a real associate from a bot with a term sheet.
| Signal | Legit VC email | Fake VC email |
|---|---|---|
| Sender domain | The fund's canonical domain, exactly as it appears on their website (paradigm.xyz, 1kx.network, variant.fund). | One character off, wrong TLD, or a lookalike (paradlgm.co, 1kx-capital.finance, variant-fund.legal). |
| Warm intro | Comes cc'd through a mutual you've actually met — or the associate references a public thread you can verify in seconds. | Name-drops a real partner or "mutual" without cc'ing them. You cannot verify the intro anywhere. |
| Booking link | Fund's canonical Calendly / booking URL on their own domain (e.g. calendly.com/paradigm-*). | Calendly / cal.com on a subdomain of the lookalike (paradlgm-associates.cal.com/…). |
| First-call platform | Google Meet / Zoom link from the fund's actual workspace; associate's face matches their public conference talks. | Meet link created from a burner Google account; face is a deepfake lip-synced to a voice clone. |
| Money direction | Money flows fund → founder at close. Full stop. No exceptions in the history of venture capital. | Founder → fund. "Formation deposit", "gas co-signing fee", "SPV wallet top-up" — all invented in 2025. |
| Wallet signature ask | Zero. Real funds never ask a founder to sign anything from a treasury wallet before the SAFE is executed. | "Read-only" signTypedData against a "KYC gateway" or "compliance portal" that is actually approve() with unlimited allowance. |
| Term-sheet delivery | DocuSign / Ironclad / a shared Notion under the fund's workspace. Reviewable by your lawyer without a wallet connection. | PDF with the real fund's logo, sent as an attachment, plus a wallet step "required to countersign". |
| Urgency | Real ICs run on weekly cadences. Associates say things like "take your time, we're patient capital" and mean it. | Manufactured deadline — "partner wants to close by Friday", "48h to lock the IC slot". Urgency is the payload. |
| What breaks the frame | Ask any specific detail about a portfolio company you know. Answer is instant, precise, boring. | Any off-script question earns "let me get back to you on that specific number" — then a subject change. |
If any single row on the right shows up in your inbox — the whole email is fake. There is no partial version of this scam.
From: r.matthews@paradlgm.co (note: `paradlgm.co`, not `paradigm.xyz`)
Subject: Quick intro — [Fake Fund] Seed thesis / 20 min next week?
"Hi [Founder], loved your last three tweets on modular execution — genuinely one of the sharpest takes I've read this cycle. I'm Robert, associate at Paradigm covering infra. My partner [Real Partner Name] flagged your seed round to me last Friday and asked me to reach out before you close. We're not in a hurry, but I'd love 20 min next week to hear where you land on the L2 sequencer question. Calendly: paradlgm-associates.cal.com/robert. No pressure — just curious."
Show red flags▾
- Domain typo (`paradlgm.co` ≠ `paradigm.xyz`).
- Calendly on a lookalike subdomain, not the fund's canonical booking URL.
- Name-drops a real partner without cc'ing them.
- Ends with fake-humble "no pressure" that manufactures reciprocity.
From: partners@1kx-capital.finance (real fund: `1kx.network`)
Subject: Term sheet attached — formation deposit details inside
"[Founder], great meeting yesterday. As discussed, attaching a signed term sheet for the $500k allocation at the $12M cap. To confirm the round and unlock our compliance timeline, we require a 0.2 ETH formation deposit to the SPV wallet below — refundable at close, standard for our post-2025 structure. Wallet: 0xA7c3...9f2E. Please confirm within 48h so we can lock the partner slot for Friday's IC. — Best, [Fake Partner Name], General Partner."
Show red flags▾
- Wrong TLD (`.finance` vs real `.network`).
- The words "formation deposit" — no real fund has ever charged one.
- Manufactured urgency tied to an IC meeting the founder can't verify.
- A fund asking a founder for ETH. Which never happens. Ever.
From: compliance@variant-fund.legal (real fund: `variant.fund`)
Subject: Compliance signature required — SAFE co-signing gateway
"Hi [Founder] — quick operational step before the SAFE goes on-chain. Our compliance provider requires a one-time signature from the founder wallet to verify counterparty identity. It's a `signTypedData` call, read-only, no gas cost. Signature portal: variant-fund-kyc.io/sign. This is the same flow used by every portfolio company post-March 2026. Ping me when done — takes 30 seconds. — [Fake Associate Name]"
Show red flags▾
- `variant-fund.legal` is not `variant.fund`.
- "Read-only signature" that is in fact an `approve()` with unlimited USDC allowance.
- Signature portal on a domain the fund does not own.
- The phrase "every portfolio company does this" — a classic social-proof forgery. The signature drains the treasury on click.
One character off in the domain. One kettle-boil away from an empty treasury.
Who Got Caught: 3 Composite Founder Cases
Cases are composites — details anonymised, amounts approximate, timelines compressed. Every element below is drawn from real 2026 incidents reported to us, SlowMist, or on-chain forensics teams. Names, cities, and projects are placeholders.
Case 1 — DeFi Founder, Lisbon · ~$14k lost
Solo builder, 4.2k Twitter followers, three months post-seed. "Warm intro" from a fake associate at a top-3 fund. Deepfake Google Meet on a Thursday, term sheet by Friday morning, "formation deposit" of 4 ETH by Friday afternoon. He wired the ETH from the treasury wallet expecting a wire back at close. There was no close. The domain 404'd Saturday. He filed with the Portuguese Judicial Police on Monday. Loss: ~4.2 ETH, roughly $14k at the time — plus a founder who now checks every domain three times before replying.
Case 2 — GameFi Team, Singapore · ~$280k drained
Two-person team, mid-round, cap table already partly assembled. The "associate" ran a two-week rapport play, called into their team standup twice, and eventually asked the CTO to sign a "compliance gateway" so the SAFE could co-sign on-chain. The CTO clicked. The `signTypedData` was an unlimited USDC approval on the treasury multisig. Drainer emptied 280k USDC in the same block. Traced through Railway to an OTC counter that has appeared in three other founder drains. Loss: ~$280k USDC treasury. Runway cut by six months.
Case 3 — AI x Crypto Solo Founder, remote · ~$0 direct, ~$2M opportunity cost
This one doesn't end in a drain — it ends in a clone. Founder gets the warm intro, does three calls, sends over a full pitch deck plus an unredacted 18-month roadmap. No wallet ask. No signature. The "fund" simply ghosts after the third call. Two weeks later a new project appears on Twitter with a suspiciously similar architecture diagram, raises $2M from real VCs, and ships to mainnet four months ahead of the original. Loss: no ETH, but the entire product moat. The scam doesn't always need your wallet. Sometimes it just needs your deck.
Three founders. Three flavours of loss. Same operator, most likely.
The 14-Day Fake VC Attack Kill Chain (Warm Intro To Empty Multisig)
The operation is patient. It has to be — founders talk to each other. Compressing the pipeline into a single day is what killed the crude 2024 versions. The 2026 version takes its time.
D-14
Target Selection
The bot scrapes recent seed announcements, filters for solo/duo founders on X with under 5k followers, and matches them to fund associates by stage and thesis. No founder with a PR team gets picked. They pick the ones who answer their own inbox.
D-10
Domain & Persona Setup
Lookalike domain registered via Njalla. A Twitter/LinkedIn persona is warmed with real-looking posts, comments on real VC threads, and a `LinkedIn Premium` badge. The persona has a bio that no one would fact-check because it reads exactly like the ones nobody reads.
D-7
Warm-Intro Manufacturing
An email lands from a second fake persona — a "mutual friend" — introducing the founder to the fake VC associate. The mutual friend name is real, scraped from Signal's leaked contact graph. You don't verify a warm intro from someone you already trust.
D-3
The Call
Google Meet with a deepfake face lip-synced to a voice-cloned associate. The AI answers thesis questions using the real fund's public write-ups. Any question that isn't in the training set gets a "let me get back to you on that specific number" — which is exactly what a real associate would say. Nobody has ever met every associate at Paradigm.
D-1
The Ask
A signed PDF term sheet with a real fund logo, plus one wallet-related step: a "formation deposit" in ETH or a "signature gating our compliance API". The urgency is manufactured: "the partner wants to close by Friday."
D+0
The Drain
Approvals executed, funds routed through Tornado Cash Nova or Railway, then aggregated at a small OTC counter that has previously appeared in three other fake-VC drains. Same wallet cluster. Same laundering route. Same operator, most likely.
Fourteen days of theatre. Ninety seconds of theft.
Anatomy Of A Fake VC Scam: Four Stages Of A Polite Robbery
Stage 1 — The Setup
The LLM writes a first email that reads exactly like an associate who is one year into the job: humble, specific, competent. The founder feels seen, not sold. This is the difference between the 2024 scam and the 2026 scam. The 2024 email tried to impress. The 2026 email tries to fit in.
Stage 2 — The Calibration
The scammer doesn't push. They ask two follow-up questions, reference the founder's most recent tweet, and offer to "share it with the partner Monday." A day later, the partner "agrees". The scam borrows a real fund's decision cadence. That is the entire trick.
Stage 3 — The Move
The term sheet is legitimate-looking because it was generated from a real one — leaked SAFEs from ten seed rounds, all fed into the model. The wallet ask is bolted on as an operational detail: `formation deposit`, `compliance signature`, `KYC gas`. No line in a real term sheet has ever required a founder wallet signature to a non-legal address.
Stage 4 — The Vanish
Domain suspended. Twitter persona deleted. Calendly link 404s. The founder wakes up on Saturday to a Discord DM from another founder: "Did you also get contacted by Robert at Paradigm?" The scam scales because the founders don't compare notes until after the drain.
Vocabulary Decoded
The phrases doing the heavy lifting in the pitch:
"Formation Deposit"
What it sounds like:
A refundable step in a token-round mechanic tied to setting up the SPV or the treasury multisig.
How it's used here:
A one-way ETH transfer to a wallet the fund does not own. No fund has ever asked a founder for ETH. Funds send money in. That is the point of them.
"Compliance Signature"
What it sounds like:
A signed message that proves wallet ownership — read-only, harmless when scoped correctly.
Why it's the favourite move:
The signature is actually an `approve()` with unlimited allowance on your USDC treasury. The `signTypedData` prompt looks identical to a Sign-In-With-Ethereum flow. One character in the payload separates a login from a heist.
"Partner Fast-Track"
What it sounds like:
A pattern where a promising deal is escalated past the normal associate → principal → partner pipeline.
What it's actually doing:
Manufacturing urgency. A real partner never asks a founder to move faster than the partner's own IC. Speed is the tell. Real capital moves cautiously; scams move on Fridays.
Got a Suspicious Message?
Use our AI-powered detector to analyze potential scams instantly.
Fake VC Red Flags: How To Spot A VC Wearing A Costume
- The email domain is off by one letter, one hyphen, or one TLD (`.co` instead of `.com`).
- You were introduced by a "mutual friend" you have never explicitly messaged about them.
- Any step in the process requires *the founder* to send ETH, sign a token approval, or gate a signature through a non-legal address.
- The associate's LinkedIn is under 12 months old, or their public presence is exclusively on Twitter/X.
- The term sheet arrives before you've been on a call with the partner named on it.
- The Google Meet face has micro-latency between mouth and audio (deepfake tell).
- The Calendly is hosted on a personal domain rather than the fund's canonical booking URL.
- The urgency is anchored to *Friday close*, *partner travel*, or an unnamed "other allocation."
Real VCs are not in a hurry. They already made their money.
The Numbers
$41M+ estimated
Aggregate Web3-founder losses attributed to AI-assisted fake-VC campaigns across 2025-Q2 2026 (Chainalysis + TRM Labs partial data).
14 days
Median time from first touch to drained wallet. The 2024 equivalent was 3 days — the AI upgrade bought patience.
0 refunds
Number of founders publicly known to have recovered funds after a fake-VC signature drain. Approvals do not reverse.
3 wallet clusters
On-chain analysis links the majority of 2026 fake-VC drains to three aggregation clusters, all routing through the same small OTC counterparty.
Why Web3 Founders Fall For Fake VC Scams
Founders are not stupid. They are optimising for the same signal a real VC gives: warm intro, real name, real logo, decision cadence. When every signal matches, doubt feels rude.
The Cadence Match
Real VCs answer in 6–12 hours, ask two questions, reference one prior post, and CC an associate. So does the LLM. The cadence is the identity. And the cadence is trivially copyable.
The Deference Bias
A founder raising their first round rarely challenges a partner-signed term sheet. Doing so feels like turning down money. The scam counts on that reluctance. It is the entire user-flow.
The Solo-Founder Load
Solo founders do email, legal, product, hiring, treasury, and outreach — often the same afternoon. Verification is the step that gets skipped when the calendar is full. That is not a character flaw. That is the target profile.
The scam works because everything else in a founder's day is exactly this shape.
Why AI VC Impersonation Keeps Working In 2026
Because the same tools founders use for their own outreach — the writer, the researcher, the scheduler — are cheap, fast, and public. There is no proprietary technology on the scam side. There is only a *targeting choice*.
The defence isn't better AI. It's slower workflow. The scam depends on the founder answering fast. Every additional check the founder runs breaks the pipeline.
The scam requires speed. The defence requires a Tuesday.
How To Spot A Fake VC: 4 Checks In Ninety Seconds
Four checks. None require a security background. All can be run in the browser while you finish your coffee.
Email Domain Diff
Copy the email domain into `whois`. If registered in the last 90 days, or the WHOIS is proxied via Njalla/Tucows, treat every subsequent email as hostile. Real funds use domains older than the fund itself.
The Partner Ping
Reply to the associate CC'ing the partner's public email — the one on the fund's actual site. If the partner doesn't reply within 48h, the associate isn't real. A real partner answers when their name is used.
The Signature Reader
Before signing anything, paste the transaction into a wallet simulator (Rabby, Blocksec Phalcon, Tenderly). If it decodes to `approve(spender, unlimited)`, close the tab. A real fund never needs a token approval from a founder wallet.
The Founder Group Check
Post a screenshot (redacted) in a founder Signal group of five. Someone will have seen the same email or the same face. The scam scales one founder at a time. Founder groups reverse that arithmetic.
Ninety seconds of friction destroys a fourteen-day scam.
Fake VC Scam Recovery: If You Already Signed
The signature can't be un-signed. The damage can still be contained.
- Open Revoke.cash immediately and revoke every approval on the affected wallet. If the drainer hasn't executed yet, this stops the transfer. If it has, this stops the second wave.
- Move any remaining stablecoins to a fresh hardware-wallet-derived address. Do not touch the compromised wallet again for anything except emptying it.
- File an IC3 report (US) or Action Fraud (UK) or your national equivalent within 24 hours, citing the receiving wallet address, transaction hashes, and the impersonated fund name.
- Contact the real fund's security team via their canonical email — they collect these reports and can push wallet freezes at the stablecoin issuer level for high-value drains.
- Post a redacted incident summary in one founder community you trust. The scam scales through silence. Breaking the silence breaks the pipeline for the next founder.
You cannot recover your funds. You can burn the operator's next fourteen days.
Key Takeaways
- The scam does not exploit a bug. It exploits the exact tools and cadence a real fundraise uses.
- Any step that asks a *founder* to send ETH, sign a token approval, or gate a signature to a non-legal wallet is fraudulent by default.
- Deepfake video calls are cheap, warm, and end when a specific question isn't in the training set.
- Slow the workflow: WHOIS the domain, ping the real partner, simulate every signature, cross-check with peers.
- The AI upgrade bought the scam patience. The defence is patience of the opposite kind.
The pitch was perfect.
That's how you know it was a machine.
Frequently Asked Questions
Sources & Citations
Research for this investigation compiled from publicly available blockchain data, security reports, and community documentation.
www.chainalysis.com
slowmist.medium.com
a16zcrypto.com
Verification: All blockchain transactions and addresses referenced in this article can be independently verified through the linked blockchain explorers. We encourage readers to conduct their own verification.
Methodology: Every case requires at least three independent sources plus verifiable on-chain evidence before publication. Full standards: /methodology
Legal notice: This investigation is journalism and security education, not legal advice or an accusation of criminal conduct. Where companies, projects, domains or wallets are named, we describe what public records, on-chain data and cited reports show at the time of writing — not a court finding. Company names may appear because they were impersonated by fraudsters, not because they did anything wrong. Individuals are anonymised. If you believe something here is inaccurate or out of date, write to cryptostrapon@proton.me and we will correct it and log the change. Editorial policy
More Scam Warnings
Continue learning about crypto threats
AI Deepfake Job Interviews: The Recruiter Who Never Existed
AI Scam • 2025-09-01
The "Google recruiter" on your video call is AI-generated. Real npm malware, real wallet drains, real victim losses of $43K+.
Prompt Injection: The Drain Your AI Agent Signs
AI Scam • 2026-08-25
How a sentence hidden in a token, a webpage or an MCP tool makes your AI agent sign a transfer. Documented attacks and the defences that actually work.
Hallucinated Audits: AI Invents Bugs, Misses Real Ones
AI Scam • 2026-08-31
AI audit tools invent vulnerabilities that do not exist, propose fixes that introduce real ones, and scam projects wear the 'AI audited' badge.