The scenario we now see with some regularity looks nothing like a typo-laden phishing email. A finance team member joins a video call already in progress. The CFO is on screen, speaking in a familiar voice, referencing a real ongoing deal, and asking for an urgent treasury transfer to close it before a deadline that cannot slip. Everything about the call looks and sounds correct. It is not the CFO.
This is distinct from the static deepfake images and cloned-voice phone calls that get most of the public attention, and it is distinct from ordinary business email compromise. Real time video deepfake fraud uses live face and voice synthesis during an actual video call, reacting to questions, holding a conversation, and adjusting tone in the moment. It is more convincing than a pre-recorded clip because it responds like a real conversation, and it is specifically being aimed at the one context, a live executive request, that many organizations still treat as sufficient authorization on its own.
Why crypto treasury transfers are a preferred target
A cryptocurrency transfer is final the moment it confirms on chain. There is no intervening business day, no correspondent bank to flag an unusual pattern, and no simple recall request once the transaction has settled. For an attacker impersonating an executive, that makes a company crypto wallet a considerably more attractive target than a bank account, where a fraudulent wire at least has a narrow window in which it might still be stopped or clawed back before it clears.
The call itself is usually the culmination of reconnaissance, not the first step. Attackers frequently draw on publicly available footage, earnings calls, conference talks, internal town halls posted online, to train the model used to impersonate a specific executive, and they typically already know internal terminology, deal names, and reporting relationships well enough to sound credible without those details giving anything away.
Why a video call alone is no longer a reliable check
Many organizations built their internal fraud awareness around the idea that a phone call or video call was the safe way to confirm a suspicious email request, since a voice or face on a live call felt harder to fake convincingly than text. That assumption is now outdated. A live call adds a layer of apparent legitimacy that can make staff less likely to question an unusual request, not more, precisely because it feels more personal and harder to fabricate than it actually is.
The defense that actually works is not learning to spot a deepfake in the moment. Detection on a live call is genuinely difficult even for people who know what to look for. The defense that works is refusing to treat any single communication channel, including a live video call, as sufficient authorization for an irreversible transfer.
Verification protocols worth putting in place
- Out-of-band confirmation for any transfer above a set threshold, meaning the request must be independently confirmed through a second channel the requester did not initiate, such as a call placed to a number already on file rather than one provided during the original call.
- A rotating verbal code word or phrase, known only to a small internal group and changed periodically, that must be provided before any high value transfer instruction is actioned, regardless of how the request arrives.
- A strict callback policy: if a request arrives urgently on a live call, the recipient hangs up and calls the requester back on a known, previously stored number rather than continuing on the original line or trusting a number given during the call.
- A dual-approval requirement for treasury movements above a set size, structured so the second approver is not reachable through the same communication thread as the first request.
- A default posture that urgency itself is a warning sign. Genuine time pressure on an irreversible crypto transfer is rare enough that it should trigger more scrutiny, not less.
If a transfer has already gone out
The transaction identifier, the destination wallet address, and a full record of the call itself, including any recording, meeting metadata, and the exact request made, are the starting point for any investigation. Preserve them before internal discussion about what happened has a chance to blur the timeline. From there, the case is treated much like any other business wallet compromise: the traceable path the funds took matters more than reconstructing exactly how convincing the impersonation was.