Skip to content
News Crypto News

Crypto: €36 Million Missing After WhatsApp and AI Scam

Nearly €95 million was moved out of Fideuram accounts in a scam involving a fake WhatsApp message, forged emails and an AI-cloned voice. Much of the money was recovered. At least €36 million remains unaccounted for and was allegedly converted into crypto assets, with bitcoin cited in the reconstruction of the case. Italian investigators are now tracing the funds across several countries.

A deceptive phone call symbolically accompanies the movement of bank funds into digital wallets
The scam combines executive impersonation, an AI-cloned voice and international wire transfers.

Crypto: €95 million moved within hours

The case began in February 2026. Paolo Molesini, then chairman of Fideuram, received a WhatsApp message he believed came from Carlo Messina, chief executive of Intesa Sanpaolo, the bank’s parent company. The fake executive referred to an urgent financial transaction requiring several international transfers.

The method resembles the social engineering used in other crypto scams involving several hundred million dollars. There is no need to hack a banking system directly when an attacker can convince someone who already has the necessary authorizations.

The fraudsters then added a second layer. Molesini received a call that appeared to come from Paolo Nastasi, managing partner of law firm A&O Shearman in Italy, who was entirely uninvolved in the matter. According to the investigation, his voice may have been replicated using artificial intelligence tools.

Emails imitating those sent by the law firm then provided the bank details. Most of the transfers went to China and Hong Kong.

Everything appeared consistent: the executive, the lawyer, the financial context and the urgency. That is precisely what made the attack so effective.

AI is reshaping executive impersonation scams

Fideuram quickly detected the anomaly and activated international banking cooperation mechanisms. In China, more than €40 million was frozen. An investigation conducted with Portuguese authorities subsequently led to an additional €13 million being frozen at a bank in Portugal.

The rest became much harder to recover. According to Corriere della Sera, at least €36 million passed through several accounts before being converted into digital assets. Investigators are still trying to trace the funds through international mutual legal assistance requests. Paolo Molesini, who stepped down as Fideuram chairman in March, is not implicated in the investigation.

The scenario is no longer particularly unusual. In its 2026 global report, INTERPOL estimates that scams using AI are 4.5 times more profitable than traditional methods. Just a few seconds of audio can be enough to produce a convincing voice imitation.

BrefCrypto has already reported that AI now operates on both sides of crypto fraud: criminals automate identity impersonation while financial platforms strengthen their detection systems.

A familiar voice is therefore no longer proof of identity.

Bitcoin does not erase the trail

Moving through crypto might appear to be the ideal final step for fraudsters. That conclusion would be premature. Once funds are converted into bitcoin, their movements become visible on a public blockchain. The identity behind an address is not directly disclosed, but the transactions, amounts and addresses remain recorded.

The difficulties begin when criminals use multiple wallets, move funds through several exchanges, switch blockchains or seek to convert the assets into fiat currency. This is exactly the kind of route investigators and on-chain analysis specialists are trying to reconstruct.

BrefCrypto has previously documented a case involving nearly $100 million and a combination of bank accounts and cryptocurrencies. The pattern is repeating: the scam can begin in traditional finance before crypto becomes a tool for moving or laundering the funds.

The Fideuram case primarily illustrates the growing power of social engineering. The criminals apparently did not need to break a blockchain or compromise a wallet. They replicated a chain of trust: a known executive, a credible lawyer, professional emails and an urgent request.

Crypto came afterward.

And that is probably the most important aspect of the case. The initial vulnerability was not cryptographic. It was human.

Sources cited1
BrefCrypto Crypto news from Africa and around the world
Follow us on Google News →
Lydie Musekwa
Author

Lydie Musekwa