MoonPay co-founder and CFO lose $250,300 to email impersonation scam
MoonPay’s co-founder and CFO lost $250,300 in a typosquatting email fraud targeting senior executives at a time when the company has just won its hardest US regulatory credential. The case exposes a blind spot in institutional crypto security: social engineering defeats even teams with advanced blockchain tools at their disposal.
- Ivan Soto-Wright, MoonPay co-founder and CEO, and Mouna Ammari Siala, CFO, lost $250,300 via email impersonation of real estate developer Steve Witkoff
- Scammers used typosquatting, substituting capital I for lowercase l in domain names, to impersonate Witkoff and company executives in emails originating from Nigeria
- 40,350 USDT was transferred to a wallet tied to Nigerian citizen Ehiremen Aigbokhan; the incident raises questions about MoonPay’s internal controls after its recent BitLicense approval
- $250,300 Amount lost by MoonPay executives in single fraud incident
- 40,350 USDT frozen in Tether accounts pending DOJ recovery effort
- 50 US states MoonPay can now legally operate in after NYDFS BitLicense grant
Two senior executives of MoonPay, a major cryptocurrency payment processor, fell victim to an elaborate email impersonation fraud that extracted $250,300, according to reporting first revealed by crypto outlet Cryptopolitan. The targets, identified in a US Department of Justice filing as Ivan Soto-Wright, MoonPay’s co-founder and chief executive, and Mouna Ammari Siala, the company’s chief financial officer, were deceived into transferring funds to an account they believed was controlled by Steve Witkoff, a prominent real estate developer and co-chair of President Donald Trump’s 2017 inaugural committee. Blockchain analysis traced 40,350 USDT to a wallet controlled by Ehiremen Aigbokhan, a Nigerian citizen based in Lagos. The timing compounds institutional concerns: MoonPay received its NYDFS BitLicense last month, clearing it to operate in all 50 US states, one of the most stringent crypto regulatory approvals in America.
Typosquatting defeats advanced security at major crypto firm
The fraud relied on a technique as old as phishing itself but rarely publicized at the executive level: typosquatting. Scammers created email addresses nearly identical to legitimate ones by substituting a capital I for a lowercase l in domain names, crafting addresses like steve_witkoff@t47lnaugural.com and financersvp@t47lnaugural.com.
The DOJ filing notes that IP geolocation data showed these emails consistently originated from Nigeria, not the United States, yet the deception succeeded in convincing two executives who operate within an industry built on cryptographic verification and threat awareness.
The attack exploited a vulnerability inherent to email and human perception, not blockchain or wallet systems. Despite MoonPay’s position as cryptocurrency payment infrastructure, where users and founders typically possess sophisticated knowledge of digital asset security, social engineering proved as effective here as it is against ordinary users.
Institutional investors now face an uncomfortable question: if senior leadership at a regulated payments firm can be compromised through basic email spoofing, what confidence should large deployers place in internal controls across the broader fintech and crypto ecosystem?
The answer matters because MoonPay operates at a critical junction between traditional banking and blockchain, a position that now appears vulnerable to insider-level fraud.
Internal controls and regulatory scrutiny come into focus
The incident raises sharper questions about MoonPay’s vetting processes and oversight architecture. The DOJ filing references wallets marked as MoonPay accounts on Etherscan, suggesting the executives may have used official company infrastructure to conduct what appeared to be personal or inadequately verified transactions.
If confirmed, this points to a breakdown in separation between corporate and personal fund flows, as well as authorization checks that should prevent large outflows without secondary verification.
The timing creates regulatory pressure. NYDFS approval of MoonPay’s BitLicense came last month; regulators now have explicit jurisdiction over the company’s compliance practices and must assess whether this fraud indicates systemic gaps in governance or control infrastructure.
MoonPay has not publicly responded to requests for comment from multiple outlets as of publication. The company’s silence during a period of heightened scrutiny, immediately following BitLicense approval and amid a high-profile fraud involving its top two executives, may itself become a compliance issue if regulators view it as evasive.
The CCS read. We see a gap between technical sophistication and operational security culture. MoonPay’s executives have access to hardware wallets, multi-signature protocols, and blockchain verification tools that the broader crypto industry relies on, yet none of those tools protected against an attack that never touched the blockchain. The real lesson for institutional deployers is that onboarding crypto payment infrastructure requires assessing not just technical architecture but human-centered security practices, particularly at the board level where approval authority sits.
Watch for NYDFS regulatory response and whether it issues guidance on executive-level fraud prevention for licensed crypto firms. MoonPay’s public statement on the incident and any changes to internal authorization procedures will signal whether the company treats this as an isolated social engineering attack or as evidence of deeper control deficiencies. The outcome may set expectations for how other recently licensed payment processors are scrutinized.