It doesn’t start with a fake email or a hacked wire instruction. It starts with a conversation.
A new cryptocurrency scam is making its way through the real estate industry. And it’s catching agents off guard.
The U.S. Secret Service recently informed the National Association of Realtors® (NAR) about this threat, and it’s now listed under the “Cybercrime & Wire Fraud” section of NAR’s Hot Topics legal page for a reason: real estate professionals are losing life savings to a scam that feels less like a con and more like a relationship.
If you’re picturing a simple phishing email (or a dating app), think again. This is a slower burn. And that’s what makes it so dangerous.
The “Pig Butchering” Scam That’s Targeting Agents
The scam works like this: someone posing as a wealthy all-cash buyer contacts an agent to build a working relationship. Over time, the buyer shares how they made their fortune in cryptocurrency and invites the agent to check out an investment platform. The site looks professional. The crypto appears legit.
Side note: If you’ve been on Instagram long enough, you’ve probably seen countless comments from random people bragging about how they’ve made a killing on crypto.
It’s become a near-instant red flag in many IG users’ brains.
That said, being immune to scammy IG comments is no guarantee you won’t fall for a scam like this if the perpetrator knows exactly what to say (in an email, text or DM) to deactivate your internal alarm.
Once the “wealthy, all-cash buyer” gains the agent’s trust, here’s how the scam goes down:
At first, the agent “tests” the crypto investment platform, makes a small investment, and sees a big return. They’re even able to withdraw some of their profits.
Then comes the real trap: the agent invests more money. And now, we’re talking tens or hundreds of thousands of dollars, including retirement savings. But this time, they lose it all.
This variation of a “pig butchering” scam grooms the victim over time. The fraudster builds trust, offers rewards, and then takes everything.
FBI: Real Estate Cybercrime Losses Surged in 2024
This isn’t an isolated case. According to the FBI’s Internet Crime Complaint Center (IC3), reported cybercrime losses exceeded $16.6 billion in 2024, a 33% increase over 2023.
The most common types of cybercrime affecting the real estate industry include:
- Phishing, Vishing, Smishing, and Pharming: These scams use unsolicited emails, texts, or phone calls to impersonate trusted sources and trick people into revealing personal, financial, or login information.
- Wire Fraud: Criminals gain access to email accounts and send fraudulent wire instructions, often during closing.
- Personal Data Breaches: Cybercriminals view, copy, or steal sensitive information, which can be used for identity theft or other fraud.
And despite rising awareness, these attacks are only becoming more sophisticated.
Real-Life Example: $956K Nearly Lost, Then Recovered
The good news? If you act fast, you may still be able to recover stolen funds.
In one case last year, IC3’s Recovery Asset Team helped a homebuyer recover nearly $956,342 in closing funds after a spoofed email, appearing to come from their real estate agent, led them to send the money to a fraudulent account.
But time is critical. Suspected fraud should be reported to IC3.gov within 72 hours for the best chance of recovery.
How to Protect Yourself and Your Clients
This is a good time to revisit your office’s cybersecurity protocols. Here’s what every real estate professional should be doing today.
For Cryptocurrency Scams:
#1: Ignore unsolicited investment offers. If it comes through a text, DM, or email from someone you don’t know (or barely know), walk away.
#2: Limit what you share online. Scammers collect personal details to build a profile and gain your trust.
#3: Watch for common red flags. These include:
- Fast-tracked relationships
- Boasts of crypto wealth
- Promises of big returns
- Urgency to act
- Avoidance of in-person meetings
#4: Research any platform thoroughly. Look for SEC registration and check corporate records.
#5: Report any suspicious activity. Contact IC3 and your local law enforcement.
For General Cybersecurity:
- Train your team to pause before clicking unknown links or opening unexpected attachments.
- Keep all software and systems updated with the latest security patches.
- Remind clients, repeatedly, about the risk of wire fraud and the importance of verifying payment instructions by phone.
- Use unique, strong passwords and never reuse them across accounts.
- Enable multifactor authentication (MFA) on all business accounts.
- Back up your files regularly using the 3-2-1 strategy: three copies, two formats, one stored off-site.
- Make sure all vendors follow sound cybersecurity practices, and include those expectations in contracts.
- Report any cyber incident immediately to IC3.gov, your local FBI field office, and law enforcement.
A Final Word for Agents
Whether it’s a spoofed email, a fake crypto platform, or a phishing text, the goal is the same: gain your trust, steal your money, and move on.
Take this seriously. Protect yourself, your team, and your clients by creating a culture of skepticism and digital hygiene.
And if something feels off, speak up early—before it costs you everything.






