Celebrity Crypto Giveaway Deepfake: How It Works
The livestream is real, the channel is stolen and the face was never filmed. Scammers hijack a large YouTube channel, rebrand it as a company, and loop an AI-generated celebrity offering to double any crypto you send. Nothing comes back, and crypto transfers cannot be reversed.
Key facts
- 22,364 complaints, adjusted losses over $893,346,472
- Complaints to the FBI in 2025 that referenced AI-related information
- FBI Internet Crime Complaint Center, 2025 Annual Report
- over $632 million
- Investment-fraud losses in 2025 with a declared AI nexus, inside a category totalling over $8 billion
- FBI Internet Crime Complaint Center, 2025 Annual Report
- over $8 billion across 72,984 complaints
- Total investment-fraud losses reported to the FBI in 2025, the largest loss category of the year
- FBI Internet Crime Complaint Center, 2025 Annual Report
- $3.5 billion
- Reported losses to imposter scams in 2025, against a record total of about $16 billion in reported fraud
- Federal Trade Commission, June 2026
- more than $118,000
- Bitcoin taken in hours in the July 2020 takeover of verified accounts, before deepfakes were involved
- New York State Department of Financial Services, Twitter Investigation Report
- four employees
- Staff who handed over credentials to callers posing as the company's own IT department in that 2020 takeover
- New York State Department of Financial Services, Twitter Investigation Report
- about 12.5 million
- Subscribers on the largest hijacked YouTube channel tracked in a stream-jacking study, with the top ten totalling about 62.9 million
- Bitdefender Labs, Stream-Jacking 2.0
- 10+ ETH and 12+ BTC, roughly $528,200 to $600,500
- Received by wallets monitored during a single stream-jacking campaign
- Bitdefender Labs, Stream-Jacking 2.0
- more than $690,000
- Transferred by an 82-year-old retiree who opened an account with $248 after watching a deepfake endorsement
- The New York Times, 14 August 2024
- $9.96
- Shipping fee charged by ads using a cloned voice and image to offer 3,000 free cookware sets, which harvested cards and enrolled hidden monthly charges
- The New York Times, 9 January 2024
- more than 700,000
- Advertiser accounts Google permanently suspended for AI impersonation scams, with reports of that ad type down 90%
- Google, 2024 Ads Safety Report
- nearly 500,000
- Public figures covered by Meta's facial-recognition protection against celeb-bait ads
- Meta Newsroom, October 2024
- $40 billion
- Projected annual cost of generative-AI-enabled fraud in the United States by 2027, from $12.3 billion in 2023
- Deloitte Center for Financial Services, projection, May 2024
The livestream is real, the channel is stolen and the face was never filmed. Scammers hijack a large YouTube channel, rebrand it as a company, and loop an AI-generated celebrity offering to double any crypto you send. Nothing comes back, and crypto transfers cannot be reversed.
Every public figure named on this page is named only as a documented victim of impersonation, in cases reported by named sources. None of them ran a giveaway.
The strangest thing about the manufactured face is that the trick is older than the face. What follows is one composite case through both doors this scam uses, the money path behind each, and the twenty-second check that ends it.
The case
Call him Frank. He is not one person. He is a composite, built from the investment-fraud complaints in the FBI’s files and from cases reporters have documented in detail. Every step below happens, in this order, to somebody, every day.
Frank is seventy-four, a retired engineer, careful with money his whole life. One evening, between a grandchild’s photo and a weather post, his feed serves him a video: a billionaire he has watched on the news for a decade, sitting in a familiar studio, talking about his newest project — an investment platform powered by artificial intelligence. Guaranteed weekly returns. Limited places. The interview looks completely real. The studio is real. The gestures are real. The voice is the voice.
Most of it is real. The New York Times investigated these advertisements in August 2024 and documented how they are assembled: a genuine interview is taken, the audio is stripped out and replaced with an AI replica of the voice reading a script the celebrity never saw, and the mouth movements are then re-animated to match the new words. Real studio, real face, rented voice. The Times reported thousands of these videos in circulation. Which makes the celebrity in the advertisement a victim here too — his face was borrowed to rob the viewer.
Door one: the platform. Frank clicks. The site looks like a private bank. He starts small, a couple of hundred dollars, just to see. The dashboard rewards him immediately, and the chart climbs. He adds more. It climbs faster. The Times documented the same spiral with a real person: an 82-year-old retiree who opened his account with $248 and, over the following weeks, moved in more than $690,000 of his retirement. It vanished.
When Frank tries to take a little out, there is a verification fee. Then a tax. Then silence. That machine — the typed balance, the fee ladder — is the subject of a separate case on this site. This one is about the face that walked him through the door, because the face is not finished with him.
Door two: the stream. Weeks later a rocket launch is trending, and a channel that looks entirely official — millions of subscribers, verified badge — is streaming it live. And there he is again. The same face, live this time, announcing a giveaway to celebrate the launch: scan the QR code, send any amount of cryptocurrency, and the company sends back double.
This one does not even feel like investing to Frank. It feels like a promotion, from a company, on a channel with a checkmark. He scans. He sends. And this door does not bother with a fake dashboard, because it does not need one. The money is simply gone. Crypto moves on rails no bank can reverse, and there is nothing to log back into.
Two doors. A slow one, dressed as an investment. A fast one, dressed as a gift. The same borrowed face opens both. To see who is holding it, stop looking at the face and look at the stage it is standing on.
How it works, step by step
Seven moves. The technology only touches one of them.
- The stage is stolen, not built. Bitdefender documented the supply chain: malware steals the session tokens and cookies of a real channel owner, and the channel is then renamed, re-avatared and re-bannered as a company, with every original video hidden. The largest channel it tracked held about 12.5 million subscribers, and the top ten together held about 62.9 million. It works because credibility on a platform is stored in numbers — subscriber count, account age, badge — and all three survive a change of owner. Nobody built a trustworthy-looking channel. They took a trustworthy one.
- The badge and the history stay. So does everything you would check. It works because the checks available to you were designed to answer is this account established, not is this account still controlled by the person who established it. You are not being shown a new channel that looks legitimate. You are being shown a legitimate channel that changed hands this week.
- The room is arranged so nobody can speak. Live chat is disabled. A QR code sits on screen. A countdown implies expiry. It works because chat is the only peer review a livestream has. One viewer typing the word scam would end the broadcast’s usefulness, so the feature is removed — and on a live event, removed chat reads as crowd control rather than as a missing safeguard.
- The broadcast is timed to real news. Bitdefender tracked waves of these streams pinned to hot events, including a wave starting in July 2024 in which the three largest hijacked channels held more than 31 million subscribers between them. It works because an unscheduled corporate livestream is implausible on an ordinary Tuesday and completely plausible during a launch, an election night or a market shock. The news supplies the reason you are not suspicious.
- The face is assembled from footage that really exists. Genuine interview, AI voice replica, re-animated mouth. It works because your brain is not verifying pixels, it is matching a memory — and the memory it matches was built over ten years of real appearances. The forgery only has to be good enough to trigger recognition you already carry.
- The offer does your arithmetic for you. Send one, receive two. Guaranteed weekly returns. It works because a fixed multiple removes the only thinking that would save you. You are handed a conclusion instead of a proposition, and the countdown ensures you do not have time to notice that no market pays for showing up.
- The rail is chosen for what happens afterwards. A QR code pointing at a crypto wallet, or a card field on a delivery page. It works because both are one-way. The FBI’s rule is unconditional: “Do not send money, gift cards, cryptocurrency, or other assets to people you do not know or have met only online or over the phone.”
The trick is older than the technology
July 2020. Years before this technology was cheap, the real, verified accounts of some of the most famous people alive — Barack Obama, Elon Musk, Jeff Bezos, Kim Kardashian West among them — all posted the same strange message: send bitcoin, and it comes back doubled. No deepfake. No artificial intelligence at all. Attackers had phoned the company’s own staff pretending to be its IT department and talked four employees out of their credentials.
New York’s financial regulator, which investigated the attack, counted more than $118,000 in bitcoin taken in a matter of hours, from plain text, with no forgery in it.
That is the proof of concept, and it settles what the AI actually changed. When a trusted face makes the promise, send one, get two works. The problem for the criminals was that hijacking real celebrity accounts is loud and only works once. What they needed was a way to manufacture the trust rather than steal it, on demand, at zero marginal cost. That is the part AI industrialised. Not the scam. The face.
Why a famous face, specifically?
Because a famous face is trust you installed yourself. Ten years of interviews, launches and headlines, stored in your own memory, at no cost to the scammer. The operation does not have to build credibility or buy it. It rents yours, and you never see the invoice.
The FBI’s own 2025 report describes the mechanic in the plainest possible terms: “Investment clubs employ AI-generated videos and voices of celebrities, CEOs, or trusted figures to create fraudulent, high-stakes opportunities.”
Where the money goes
Three doors, three rails, one property in common.
Door one, the giveaway stream: straight to a wallet. The QR code resolves to a cryptocurrency address the operation controls. There is no account, no platform and no login, because there is nothing to sustain — the transaction is the entire product. Bitdefender monitored the wallets during a single campaign and recorded 10 or more ETH and 12 or more BTC, roughly $528,200 to $600,500. Crypto settles in minutes, crosses borders without permission and cannot be recalled. A QR code also removes the moment where you would have read the destination before approving it.
Door two, the endorsement funnel: the long extraction. Here the deepfake is only the advertisement. It leads to an investment platform, a small deposit that performs beautifully, a dashboard that climbs, and then a withdrawal that requires a release fee, a verification deposit or a tax on a balance you can see but cannot move. This is where the largest single losses live, and it is why the FBI’s investment-fraud category ran to over $8 billion across 72,984 complaints in 2025, with more than $632 million of it flagged by victims as AI-related. The Times case moved $248 in and more than $690,000 after it.
Door three, retail: the card is the product. In January 2024 the Times reported advertisements using a cloned voice and image to offer 3,000 free cookware sets because of a packaging error, funnelled to pages imitating a television network, with a $9.96 shipping fee that harvested card details and enrolled victims in hidden monthly charges. The brand told the paper there was no partnership. The fee was never the revenue; the card number and the recurring debit were.
The common property. Crypto cannot be reversed. A card charge on a page you reached from an advertisement can be disputed, which is exactly why that path also takes your identity data — a chargeback does not un-sell a card number. Every rail in this scam moves your money from an institution that owes you a process to a stranger who owes you nothing.
How to spot it
Four questions, in this order. The second one is the strongest and takes about twenty seconds.
- Does the promise do your arithmetic for you? Test: say the offer out loud as a business. A company with real shareholders is giving money to strangers on the internet as a marketing exercise. No market pays a fixed multiple for showing up, and no real celebrity doubles strangers’ money on a livestream. Not once, not ever.
- Check the stage, not the face. Test: leave the stream. Open a new tab and search for the company’s or the person’s official channel or website yourself — typing the name, not using any link, QR code, handle or button from the page you were on. A real announcement exists in both places. This one exists only where you found it. Look for the giveaway on the official channel, with its history intact and its comments open.
- Look for the tells the FBI publishes. Test: distorted hands or feet, unrealistic teeth or eyes, inaccurate shadows, watermarks, lag time, voice matching and unrealistic movements (FBI PSA, December 2024). Treat this as the weakest of the four checks, because it is the only one that gets worse for you every month. Your ears alone are no longer enough.
- Look at the rail before you look at the offer. Test: ask what recourse the payment leaves you. The FBI’s line is unconditional: do not send money, gift cards, cryptocurrency or other assets to people you do not know or have met only online or over the phone. If the only accepted method is the only irreversible one, the method has already told you the answer.
The two structural signs that outlive the forgery
Improvements in the fake face do not touch either of these.
Live chat disabled on a channel that has always allowed it. The forgery can be perfected; the need to silence the audience cannot be removed, because a single comment ruins the broadcast.
A QR code as the only way to act. Real companies publish announcements you can reach from their own front page. A destination that exists only as a scannable image, on a screen you cannot copy from, is a destination that does not want to be read.
What to do if it already happened
In this order.
- Send nothing more. Including any release fee, verification deposit or tax on a balance you can see but cannot move. There is no payment that unlocks it.
- Collect the evidence before it disappears. Wallet addresses, transaction hashes, the channel URL and handle, the platform’s URL, screenshots of the dashboard, the stream and every message. Channels are recovered or terminated and pages vanish, often within hours.
- Report to the FBI at ic3.gov with the addresses and hashes. IC3 is the Bureau’s intake for internet crime, and addresses plus hashes are the raw material of blockchain tracing — the forfeiture cases that do return money to victims are built out of exactly these reports.
- Report to the FTC at reportfraud.ftc.gov. The consumer-protection intake. It does not chase your individual transaction; it feeds enforcement and the loss statistics that fund the response.
- If a card was involved, dispute the charge with your issuer today, then watch for small recurring debits rather than a single large one, and consider replacing the card outright.
- If you handed over identity documents, work through identitytheft.gov, which produces a recovery plan and the affidavit banks accept.
- Report the channel, the stream or the advertisement to the platform. Individually slow, collectively fast, and it is the only input you control. Google says it permanently suspended more than 700,000 advertiser accounts over AI impersonation and saw reports of that ad type fall 90%; Meta says its facial-recognition defence now covers nearly 500,000 public figures, with user reports of celeb-bait down 22% in half a year. Those systems are trained by reports.
- Ignore anyone who offers to recover it for a fee. People who have lost crypto once are a marketing list, and recovery fraud is the follow-up business.
Nobody can promise recovery, least of all on crypto rails. Speed decides what remains possible.
How to not be next
- Make the stage test a reflex. Never act on an announcement from inside the thing announcing it. Leave, search the official source yourself, and let the absence be your answer.
- Treat a doubling offer as a closed question. There is no context in which it is real. This removes the need to judge the video at all.
- Never scan a payment QR code from a video. You cannot read what it points at, and that is a feature of the design, not an accident.
- Keep your money where you opened the account. Nothing that follows a celebrity advertisement needs to happen today, and no legitimate opportunity requires a new platform introduced by a stream.
- Stop grading faces. The forgeries improve monthly and your eyes do not. Grade the stage, the offer and the rail — all three get worse for the scammer as they get better at the face.
- Have the conversation with anyone in the family who invests. One sentence: a real announcement is always on the official channel too. Twenty seconds, once.
The numbers, and what they mean
- The FBI logged 22,364 complaints referencing AI-related information in 2025, with adjusted losses over $893,346,472. Investment fraud with a declared AI nexus exceeded $632 million, inside an investment category of over $8 billion across 72,984 complaints — and the report notes that many victims never realise AI was involved at all (IC3 2025 Annual Report).
- The FTC reported $3.5 billion lost to imposter scams in 2025, against a record of about $16 billion in total reported fraud (FTC, June 2026).
- Bitdefender tracked hijacked channels holding about 12.5 million subscribers at the top and about 62.9 million across the top ten, and wallets in one campaign receiving 10 or more ETH and 12 or more BTC, roughly $528,200 to $600,500 (Bitdefender Labs).
- In July 2020, before any of this needed AI, attackers talked four employees out of their credentials and New York’s financial regulator counted more than $118,000 in bitcoin taken in a few hours from real verified accounts (NYDFS Twitter Investigation Report).
- The New York Times documented the method — real interview, AI voice replica, re-animated mouth — thousands of such videos in circulation, and an 82-year-old retiree who opened an account with $248 and transferred more than $690,000 (NYT, August 2024); and the retail variant with a cloned voice, 3,000 cookware sets and a $9.96 shipping fee that harvested cards and enrolled hidden monthly charges (NYT, January 2024).
- Google says it built a team of over 100 experts against deepfake ads and permanently suspended more than 700,000 advertiser accounts for AI impersonation, with reports of that ad type falling 90% (Google 2024 Ads Safety Report). Meta says its facial-recognition defence against celeb-bait now protects nearly 500,000 public figures, and that user reports fell 22% in the first half of 2025 (Meta Newsroom).
- The FTC’s Impersonation Rule came into force in April 2024, and when the agency moved to extend it to the impersonation of individuals it warned that “Emerging technology – including AI-generated deepfakes – threatens to turbocharge this scourge” (FTC, February 2024).
- Deloitte projects that generative-AI-enabled fraud in the United States could reach $40 billion a year by 2027, up from $12.3 billion in 2023 (Deloitte).
The defences got better. The forgeries got cheaper. Cheap wins on volume, which is why every number above went up in the same year the enforcement numbers did.
Watch the full documentary
The stolen channel, the endorsement funnel and the four questions are in the documentary: Don’t Fall for the AI Celebrity Giveaway.
Related
The investment platform behind door two is the same machine described in the pig butchering scam, reached through a famous face instead of a months-long friendship. The retail version, minus the celebrity, is the free prize that charges shipping. And when the borrowed identity is a software company rather than a person, it becomes the fake Microsoft security alert. And when the manufactured image is of someone you love rather than someone you admire, it becomes the virtual kidnapping call, where an altered photograph is sold as proof of life. And when the cloned identity belongs to a grandchild instead of a billionaire, the same synthetic media runs the AI voice clone family emergency call.
Questions people ask
Is the Elon Musk bitcoin giveaway livestream real?
No. He is named here only as a documented victim of impersonation. The New York Times reported in August 2024 that scammers edited real interview footage, replaced the voice with an AI replica and adjusted the mouth movements, and that thousands of such videos were circulating.
The channel had a verified badge and millions of subscribers. How can it be fake?
The badge and the subscribers belong to whoever owned the channel before it was stolen. Bitdefender documented session-token theft used to take channels over, rename them after a company and hide all the original videos. The largest one it tracked had about 12.5 million subscribers.
Why is live chat disabled on the stream?
Because chat is where a viewer types the word scam and everyone else reads it. Bitdefender recorded disabled chat as a standard feature of these broadcasts, alongside the QR code and the countdown. On a channel that has always allowed chat, switching it off for the biggest announcement of the year is the tell.
The channel is named after a company but all its videos are gone. What happened?
That is the re-skin. Bitdefender documented the sequence: the account is taken over, the name, handle, avatar and banner are changed to a car or space company, and every original video is hidden. Only the subscriber count and the account age survive, because those are the assets being rented.
Was the Taylor Swift Le Creuset giveaway real?
No. The New York Times reported in January 2024 that ads used a cloned voice and her image to offer 3,000 cookware sets for a $9.96 shipping fee, which collected card details and enrolled victims in hidden monthly charges. Le Creuset said there was no partnership.
Why do these streams always appear during big news events?
Because an unscheduled corporate livestream is only plausible when something is happening. Bitdefender tracked waves of hijacked channels timed to hot news, including one that began in July 2024 in which the three largest stolen channels held more than 31 million subscribers between them.
How do I tell an AI video from a real one?
The FBI publishes tells: distorted hands or feet, unrealistic teeth or eyes, inaccurate shadows, watermarks, lag time, voice matching and unrealistic movements. But forgeries improve monthly, so check the stage instead of the face: leave the stream and find the company’s real channel or site independently.
Can I get crypto back after sending it to a giveaway address?
Usually not. Crypto transfers are not reversible, which is why they are the requested rail, and nobody can promise recovery. Report it anyway to ic3.gov with the wallet addresses and transaction hashes, and to reportfraud.ftc.gov, because those reports feed the seizure cases that do recover funds.
Read next
Case The AI Voice Clone Family Emergency Scam: The Voice Was the Last Thing They Had to Fake
The FTC documented this call in 2018, before voice cloning. A federal indictment describes the scripts, the couriers and the gag order — and never mentions AI.
Case The Sob Story Scam: The Sadness Is the Advertisement
A stranger's tragedy attached to a checkout button. The face belongs to an 84-year-old tailor who never agreed to be in it, and his wife is not sick.
Investment or crypto trading fraud Pig Butchering Scam: How the Wrong-Number Text Works
How the pig butchering scam turns a wrong-number text into a crypto account you can never withdraw from, with FBI, DOJ, Chainalysis and UN figures.
Case Sixty-One Million Dollars, From One Phone Call
One report to a federal tip line ended with $61 million in Tether frozen. Who holds the switch that stops stolen crypto, and what freezing does not do.