Bitcoin and mining fraud response
Stop the next loss, identify what was actually compromised, preserve evidence, and hand the incident to the right provider or Canadian authority. A transaction identifier, a wallet warning, a missing miner, and a fake investment dashboard are different incidents and require different responses.
Stop now if the request is still active
- Do not send another payment, withdrawal fee, tax, deposit, bond, shipping charge, or recovery fee.
- Do not share a recovery phrase, private key, wallet backup, password, one-time code, remote-access session, or screen share.
- Do not sign another transaction or message that you do not fully understand.
- End the unexpected call or chat. Find the organization’s contact information independently; do not use the number or link in the message.
- If anyone is in immediate danger, call 911. If money or personal information was lost, contact local police and the Canadian Anti-Fraud Centre.
The first ten minutes: contain without destroying evidence
- Stop interaction. Do not argue with the sender or disclose what you know. Stop payments, signing, remote access, shipments, and account changes requested by the suspected fraudster.
- Use a known-clean channel. From a different trusted device where practical, independently contact the relevant wallet provider, custodian, bank, card issuer, payment service, marketplace, carrier, or merchant. A provider may be able to secure an account or payment rail; that does not mean it can reverse an on-chain Bitcoin transfer.
- Separate the secret from the device. If a seed phrase or private key may have been exposed, stop using the suspect device for wallet activity. Do not type the secret into a website, chat, form, or “verification” tool.
- Preserve before cleaning. Save original messages, emails, invoices, transaction identifiers, addresses, URLs, phone numbers, account names, order records, shipping records, and a timeline. Do not wipe or reset a possibly compromised device before qualified incident-response or law-enforcement guidance.
- Open official reports. Contact the financial or service provider, local police, and the Canadian Anti-Fraud Centre as the incident requires. Record every report number, contact, date, and instruction.
Broadcast, mempool, and confirmation are different states
Bitcoin does not provide a bank-style administrative chargeback. That does not make every transaction “instantly irreversible.” First determine what your wallet and a trusted node actually report. A screenshot, payment notification, or transaction identifier supplied by another person is not proof that you were paid.
| Observed state | What it can mean | What it does not prove | Safe operational response |
|---|---|---|---|
| Created or signed | A wallet constructed or signed transaction data. | It does not prove that a node accepted or relayed it, or that a recipient was paid. | Do not broadcast if the destination, amount, fee, or signing request is wrong. Follow the exact wallet’s official instructions. |
| Broadcast or submitted | A wallet or node attempted to submit the transaction to its local node and peers. | It does not guarantee propagation, mempool acceptance by other nodes, or inclusion in a block. | Verify the transaction through your own wallet or node. Do not fulfill an order from a sender’s screenshot. |
| Seen in a mempool | A particular node accepted an unconfirmed transaction under that node’s current policy. | There is no single global mempool. The transaction may be absent elsewhere, evicted, replaced, conflicted, or remain unconfirmed. | Treat it as unconfirmed. Apply a written, risk-based merchant acceptance policy rather than a universal shortcut. |
| One or more confirmations | The transaction is included in the best chain recognized by the node, with depth shown by the confirmation count. | A confirmation is not a finding that the payment was legitimate, and “one confirmation” is not absolute finality. Chain reorganizations can change recent status. | Set confirmation requirements by value, delivery risk, fraud signals, and the service’s documented policy. Greater depth generally reduces replacement risk. |
| Conflicted, replaced, or no longer seen | A different spend may have confirmed, node policy may have changed, or the transaction may have been evicted or abandoned locally. | It does not by itself identify fraud or prove that a wallet can recover the payment. | Pause fulfillment. Preserve both transaction identifiers and obtain wallet/provider guidance; do not attempt an improvised “recovery” transaction. |
Bitcoin Core exposes confirmation, conflict, and mempool fields precisely because transaction state is not a single yes/no flag. Its documentation also describes transaction relay as an asynchronous system without a globally consistent “first” sighting. For a deeper mining context, see D-Central’s Bitcoin mining guide and mining-pool reference.
Classify the incident before taking action
| Incident class | Typical signal | Primary asset at risk | First trusted handoff |
|---|---|---|---|
| Wallet or signing-key compromise | A seed/private key was disclosed, an unknown transaction was signed, or wallet malware is suspected. | Every spend controlled by the exposed signing material, plus device and identity data. | The wallet’s official recovery documentation, a qualified incident responder, and police where theft or attempted theft occurred. |
| Custodial account compromise | Unknown login, password reset, API key, withdrawal, or authentication-factor change. | Provider-held assets, linked fiat rails, identity records, and reused credentials. | The provider’s independently located security channel and linked financial institution. |
| Merchant or payment fraud | Fake payment proof, changed invoice address, disputed fulfillment, or an unconfirmed/conflicted payment. | Goods, services, payment credentials, and business records. | Your payment processor or node operator, marketplace, financial institution, and police where loss occurred. |
| Hardware, seller, shipping, or repair fraud | Non-delivery, substituted/stripped hardware, fake tracking, false support, or repeated new fees. | Purchase funds, equipment, serial-number identity, warranty and shipment. | Payment provider, marketplace, carrier, consumer-protection route, police, and CAFC. |
| Cloud, investment, or mining-return fraud | Fixed or certain return claims, fake dashboard balances, recruitment rewards, or a payment demanded to unlock a withdrawal. | Deposits, identity documents, account credentials, and subsequent “tax” or recovery payments. | Financial institution, provincial/territorial securities regulator, police, and CAFC. |
| Impersonation or recovery fraud | An unexpected “support,” police, government, investigator, or recovery contact demands money, secrets, codes, or remote access. | Remaining funds, accounts, identity, devices, and the victim’s earlier case information. | The real organization using a contact route you found independently, police, and CAFC. |
Response branches
A. Wallet, seed, or private-key exposure
- Treat a disclosed seed phrase, private key, or signing backup as compromised. A legitimate support agent does not need it.
- Stop signing on the suspect device. Preserve it if malware or unauthorized access may need investigation.
- On a separate known-clean device, use only the wallet project’s official documentation to create and verify a new wallet. If it is safe and you retain control, moving remaining funds to new signing material may limit further loss, but an attacker may act first and success is not guaranteed.
- Verify the new receiving address on a trusted display and with a second person for organizational funds. Never send the old seed to a helper.
- Rotate passwords and authentication factors for associated email, custodian, cloud backup, password manager, and mobile account from a known-clean device.
B. Custodian, email, or service account
- Independently open the provider’s real site or app; do not follow the alert’s link.
- Use the provider’s documented security process to lock the account, revoke active sessions and API keys, review withdrawal addresses, and replace compromised credentials.
- Contact the linked bank, card issuer, or payment provider immediately when fiat or card information is involved.
- Preserve login alerts, IP/device notices, support tickets, withdrawal records, and the exact time you contacted the provider.
- A provider may control an internal account or an off-chain withdrawal queue. It cannot administratively reverse a confirmed Bitcoin transaction on the network.
C. Merchant or payment incident
- Verify the expected address, amount, asset/network, transaction identifier, confirmation state, and any conflicts using your own checkout records and trusted wallet/node.
- Do not accept a screenshot, email receipt, wallet animation, or block-explorer link supplied by the buyer as sole proof.
- Pause physical shipment, digital delivery, refund, and reshipment while the payment state or identity is disputed.
- Keep the original invoice, address-generation record, checkout logs, correspondence, fulfillment decision, carrier scans, and refund communications.
- Set a written confirmation policy proportionate to value and delivery risk; Bitcoin has no universal confirmation count that fits every merchant situation.
D. Mining hardware, seller, repair, or shipping dispute
- Do not pay a new customs, insurance, release, diagnostic, or reshipping fee until independently verified with the carrier, payment provider, or written contract.
- Preserve the product listing, domain, refund policy, invoice, payment record, promised configuration, serial numbers, nameplate photos, packaging, carrier record, and unedited opening/condition photos.
- Distinguish a defect or contract dispute from deliberate fraud. Give accurate facts to the marketplace, provider, police, and consumer-protection body; do not make public accusations that exceed the evidence.
- Before installing miner firmware or a “diagnostic” file received in chat, verify its origin and integrity. Use the firmware authenticity guide.
- For a D-Central repair or order only, use the published repair intake or contact page. D-Central does not provide fund recovery.
E. Cloud, investment, or mining-return scheme
- Stop if a dashboard demands another deposit, “tax,” liquidity proof, wallet synchronization payment, or fee to release a withdrawal.
- A displayed balance, hashrate animation, payment table, or early small withdrawal does not prove that mining, trading, or custody exists.
- Guaranteed or low-risk returns, urgency, secrecy, recruitment rewards, remote-access requests, and payment to a so-called safe wallet are stop signals.
- Check securities registration where applicable. A FINTRAC money-services-business registration is not a licence, endorsement, solvency test, or investment approval.
- Preserve the full account ledger and every deposit address/transaction identifier before the site or account disappears.
F. Impersonation and “recovery” contact
- End the contact. Call the purported organization using a number you independently found on its official site or on the back of a card.
- Do not move money to a “safe” wallet or account on an unexpected caller’s instructions.
- Do not provide remote access, one-time codes, identity documents, seed phrases, or a payment to “validate” wallet ownership.
- Assume details from the first incident can be used to make a second approach sound credible.
- Never pay an unsolicited recovery service or anyone demanding money before “releasing” recovered funds. Report the new approach as part of the same case.
Build an evidence pack without exposing new secrets
Keep originals unchanged where practical and work from copies. Record who collected each item, when, and from which device or account. Do not post the evidence publicly. A seed phrase, private key, wallet backup, password, authentication code, or unnecessary identity document must never be included in a general fraud report or sent to a self-described investigator.
| Evidence group | Record | Preservation note |
|---|---|---|
| Timeline | First contact, promises, instructions, payments, account changes, discovery, containment steps, and reports, with time zone. | Keep a chronological log. Add corrections as new entries rather than silently rewriting the original account. |
| Bitcoin/payment | Transaction identifiers, addresses, amount and unit, wallet/node status, invoice, payment rail, exchange rate source/time if relevant, and conflicting transactions. | Copy exact text. Do not include signing secrets. Note which node, wallet, or provider supplied each status. |
| Communications | Emails with headers, texts, chat exports, voicemail, caller number, social profile, usernames, advertisements, and support tickets. | Retain originals and metadata. Screenshots are useful context but should not replace original files or exports. |
| Website/account | Exact URL, page copy, terms, withdrawal/error screens, account ledger, login alerts, API/session changes, and provider case number. | Record the date and time. Do not log back in from a suspect link merely to collect more evidence. |
| Hardware/order | Listing, invoice, quoted model/configuration, serial and nameplate, payment, shipment, packaging, item condition, and repair authorization. | Photograph without opening energized equipment or disturbing a condition that may be relevant to a carrier, insurer, police, or safety investigation. |
| Reports and handoffs | Institution, contact route, agent/officer name where provided, date, instructions, file number, and follow-up deadline. | Verify unexpected follow-up independently and refer to the existing file number. Recovery fraud often follows an earlier report. |
Canadian reporting and provider handoff
Reporting does not guarantee investigation, freezing, reimbursement, or recovery. It creates an official record, lets providers act within their authority, and helps law enforcement connect related incidents.
| Route | Use it when | Provide | Boundary |
|---|---|---|---|
| 911 / local police | Call 911 for immediate danger. Contact local police when money, property, identity, extortion, unauthorized access, or threats are involved. | Evidence pack, loss amount/unit, transaction and account identifiers, safety concerns, and related report numbers. | Ask for a file number. Police cannot promise that on-chain funds will be returned. |
| Canadian Anti-Fraud Centre | Report attempted or completed fraud and cybercrime online, or call 1-888-495-8501. | Fraud pattern, communications, payment details, identifiers, involved platforms, and local police file number. | CAFC collects and connects reports; a report is not a recovery guarantee. |
| Financial institution or payment provider | A bank, card, wire, e-transfer, money service, or provider account funded or transferred the payment. | Account/payment identifiers, time, recipient, fraud report, and requested protective action. | Available holds, disputes, recalls, or reimbursements depend on the rail, timing, contract, investigation, and law. |
| Wallet, custodian, marketplace, carrier, or website | Their account, service, shipment, advertisement, or infrastructure was involved. | Only the information needed for the official abuse/security process, plus police/CAFC references where appropriate. | Use an independently verified contact route. Never disclose a seed phrase or private key. |
| Securities regulator | An investment, trading, advisory, pooled-return, or securities/derivatives offer may be involved. | Offer materials, salesperson/firm identity, registration search result, account ledger, deposits, and withdrawal demands. | Registration can add oversight but is not proof that an offer is safe or risk-free. |
| Canadian Centre for Cyber Security | An organization faces malware, network compromise, ransomware, account takeover, or a material cyber incident. | Technical indicators, affected systems, timeline, mitigations, impact, and law-enforcement contact. | The Cyber Centre is a technical cyber-security authority, not a substitute for police, CAFC, privacy, legal, insurance, or financial reporting. |
Controls that reduce the next incident
Wallet and account controls
- Keep seed phrases and private keys offline and out of photos, cloud notes, email, chat, forms, and remote-support sessions.
- Use a separate known-clean signing environment appropriate to the value and threat model.
- Verify destination, amount, fee, and change on a trusted display before signing.
- Use unique credentials and phishing-resistant multi-factor authentication where the provider supports it.
- Maintain tested backups and a written incident/recovery plan; a backup is not useful until its restore process is understood.
Mining and merchant controls
- Use a second-person check for new payout addresses, high-value payments, refunds, and vendor bank/address changes.
- Verify firmware at its official source and retain the version, checksum/signature evidence, and hardware identity.
- Document pool account, payout threshold, fee, template/payout arrangement, and address-change controls; a share dashboard is an off-chain service record.
- Verify sellers, repair facilities, terms, payment protections, exact equipment identity, and shipment before paying. A registry entry alone is not an endorsement.
- Train staff to stop on urgency, secrecy, remote-access requests, changed payment instructions, and recovery approaches.
Pinned primary sources
- Canadian Anti-Fraud Centre: What to do if you are a victim of fraud — evidence collection, financial-institution and police contact, online/telephone reporting, and the warning about repeat recovery fraud.
- Canadian Anti-Fraud Centre: Fraud trends, first six months of 2026 — current impersonation, investment, spear-phishing, bank-investigator, and recovery-fraud patterns.
- Competition Bureau Canada: How to report fraud and scams in Canada — gather evidence, contact police/CAFC, and notify the institution that transferred money.
- Competition Bureau Canada: Purchase of merchandise scams — seller, payment-protection, delivery, refund-policy, and online-store checks.
- Canadian Centre for Cyber Security: What to do when your organization has been compromised — containment, keeping a compromised device powered on, and preserving volatile and non-volatile evidence.
- Canadian Centre for Cyber Security: Have you been a victim of cybercrime? — preserve evidence, isolate affected networks, report to law enforcement, and retain report numbers.
- FINTRAC Money Services Business Registry — registry status and FINTRAC’s express warning that registration is not endorsement or licensing.
- Ontario Securities Commission: Investor warnings and alerts — official warnings, registration-check guidance, and a contact path for suspected unregistered activity.
- Bitcoin whitepaper — primary description of transaction chains, proof of work, and the probability model for replacing transaction history.
- Bitcoin Core: transaction replacement FAQ — why unconfirmed transactions in an asynchronous network do not have a globally agreed first-seen order.
- Bitcoin Core RPC: gettransaction — confirmation counts, negative conflict depth, block identity, wallet conflicts, and mempool conflicts.
- Bitcoin Core RPC: getmempoolentry — node-local mempool data, dependencies, spenders, fees, and replaceability state.
- Bitcoin developer guide: Payment processing — broadcast is not proof of payment; confirmation depth changes double-spend risk.
- Bitcoin.org: Securing your wallet — backups, offline signing, software updates, multisignature, and the risks of online custody.
Reviewed 2026-08-30. Reporting systems, contact hours, provider procedures, wallet behaviour, and applicable laws can change. Re-open the official source before acting. This page deliberately contains no live network metric, recovery probability, or universal confirmation count.
Frequently asked questions
I sent bitcoin to a scammer. Can I cancel the transaction?
There is no central Bitcoin operator that can cancel or charge back a transfer. First verify the actual state in your own wallet or trusted node: created, broadcast, present in that node’s mempool, confirmed, or conflicted are different states. Contact the wallet/custodial provider, involved payment service, local police, and CAFC promptly, but do not assume they can reverse an on-chain transfer and do not pay anyone who promises cancellation or recovery.
Does seeing a transaction in a mempool mean the payment is final?
No. A mempool is a node’s local set of accepted, unconfirmed transactions. Nodes can have different mempool views, and a transaction can be evicted, replaced, conflicted, or remain unconfirmed. A merchant should verify through its own trusted infrastructure and apply a written policy based on value and delivery risk.
Does one confirmation make a Bitcoin transaction absolutely irreversible?
No confirmation count creates simplistic instant or absolute finality. A confirmation means the transaction is in the best chain recognized by the observing node; additional blocks increase its depth and generally reduce replacement risk. Recent chain reorganizations are possible. The appropriate acceptance depth depends on value, fraud risk, delivery reversibility, and the provider’s documented policy.
I exposed my seed phrase or private key. What should I do?
Treat the signing material as compromised and stop using the suspect device for wallet activity. Do not send the seed to support or enter it in a recovery website. Using a separate known-clean device and only the wallet project’s official procedure, create and verify new signing material and, if it is safe and you retain control, transfer remaining funds. An attacker may act first, so this can limit loss but cannot guarantee it. Preserve the suspect device when malware or unauthorized access may require investigation.
Can support ask for remote access, a one-time code, or my recovery phrase?
Treat an unexpected request for remote access, authentication codes, passwords, a seed phrase, or a private key as a stop signal. End the contact and reach the organization through contact information you independently locate. Even a real support process should not require your Bitcoin signing secret.
A mining-hardware order did not arrive. Is that automatically fraud?
No. Non-delivery can be a carrier, inventory, contract, or seller problem, and deliberate fraud requires evidence. Preserve the listing, invoice, payment, promised configuration, communications, tracking, serial information, and policies. Contact the seller, marketplace, carrier, and payment provider through verified routes. If money or property was taken through deception, report it to local police and CAFC. Do not send repeated new fees without independent verification.
A mining or investment dashboard says I must pay tax or a fee before withdrawing. Should I pay?
Stop. A demand for another deposit, tax, liquidity proof, wallet synchronization payment, or release fee is a common escalation pattern. Do not send more money. Preserve the account ledger, deposit transactions, messages, URL, and withdrawal demand; contact the financial institution, applicable securities regulator, local police, and CAFC. A balance displayed on a website does not prove that assets or mining activity exist.
Can a tracing or recovery service guarantee that stolen bitcoin will be returned?
No. Reporting and tracing may help an investigation, especially when funds reach an identifiable regulated provider, but neither proves that funds can be frozen or returned. CAFC warns that fraud victims are often targeted again with recovery promises. Do not pay an unsolicited service or anyone demanding an advance payment to unlock, validate, insure, tax, or release recovered funds.

