What Is a Pig Butchering Scam?
A pig butchering scam is a long-duration investment scam in which the operator builds a personal or professional relationship with a target over weeks or months, then steers them onto a fraudulent cryptocurrency trading platform that displays fabricated returns until operators block withdrawals.
The name translates the Chinese phrase shā zhū pán, "killing pig plate": the victim is fattened with trust and simulated profits before the slaughter. Other names include "romance baiting" (opens in new tab) and "digital asset investment scam (opens in new tab)," FinCEN's September 2026 term for it.
How a pig butchering scam works
Operators reach targets through "wrong number" texts, dating apps such as Tinder, Bumble, and Hinge, and social platforms including Facebook, Instagram, and LinkedIn. Operators then move the conversation to WhatsApp scam activity, Telegram, WeChat, or Signal, where platform moderation and law enforcement visibility drop off.
Investigators recovered a manual (opens in new tab) in a Philippines compound raid that scripts the persona, instructs the operator to pose as a woman, drop a slow-responding target by day three, and probe for vulnerabilities such as divorce.
After weeks of daily messages, the persona claims insider knowledge of cryptocurrency, precious metals, or foreign exchange trading, then directs the target to a professional-looking website or app the criminals control.
The platform pulls live market data from legitimate exchanges through APIs, shows rapidly growing balances, and permits a small withdrawal (opens in new tab) to prove the money is real, and deposits escalate from there. When the victim requests a large withdrawal, the platform demands a "tax" or "fee" first, and once deposits stop, contact ends.
Authorities seized domains (opens in new tab) that spoofed the Singapore International Monetary Exchange after operators used them to convince U.S. victims they were investing legitimately, taking more than $10 million from five victims. Deposited funds moved immediately through private wallets and swapping services to conceal their origin.
Why pig butchering scams are hard to stop
U.S. financial institutions reported $12.7 billion (opens in new tab) in suspicious activity tied to digital asset investment scams between September 2023 and December 2025. Because customers authorize the transfers, reimbursement and enforcement both stall, and victims coached to deny third-party involvement rarely tip off a bank before the money is gone.
Even when fraud teams identify a scam, operators rebuild fast enough that new domains and marketplaces reappear as soon as reports take old ones down.
Behind those domains sits a franchise economy of Telegram-based marketplaces selling stolen data, fake identity documents, deepfake tooling, and laundering rails; when enforcement shuts one down, as when the U.S. Treasury severed Huione Group from the financial system in 2025, inflows shift (opens in new tab) to the next marketplace rather than stopping.
AI reinforces personas and makes video chat less reliable as a verification step: trainers teach compound workers to video chat with victims (opens in new tab) using an AI-generated face, and commercial LLM safeguards fail to flag (opens in new tab) the grooming phase because "emotionally supportive behavior is not inherently malicious."
These detection and enforcement limits have prompted different policy responses across jurisdictions.
UK payment providers have carried mandatory reimbursement (opens in new tab) obligations for authorized push payment scams since October 7, 2024, and in Singapore, financial institutions and telecommunications companies carry duties to mitigate phishing scams under the Shared Responsibility Framework (opens in new tab), effective December 16, 2024.
In the United States, a proposed class action (opens in new tab) alleges inadequate scam prevention against a major cryptocurrency exchange.
Types of pig butchering scams
Only the entry vector changes:
- Romance-led grooming. The persona meets the target on a dating app and pushes toward off-platform messaging (opens in new tab) early, where scammers can "communicate without the app's monitoring or safeguards."
- Professional or investment-group lure. A recruiter or trader persona on LinkedIn or Facebook adds the target to a WhatsApp or Telegram group where a "seemingly large group of witting participants" (opens in new tab) trades tips.
- "Wrong number" text. A short message such as "Hello, is this X?" tests whether the number is live, then pivots to friendship and an investment tip. AARP's 2026 scam list (opens in new tab) flags the wrong-number opener as a romance-scam warning sign.
- Task or job scam hybrid. Operators hire the target for paid online tasks and show real early payouts against a running commission balance, then demand cryptocurrency deposits to release earnings, a pattern (opens in new tab) the FBI also documents.
- Malvertising hybrid. Some operators skip the one-on-one grooming phase and buy automated paid ads (opens in new tab) as the hook, feeding victims straight into the fake platform.
- Recovery scam follow-on. After the slaughter, impostors posing as FBI or IC3 personnel offer to recover the victim's funds using AI-generated videos of fake officials and a spoofed IC3 website, a scheme the FBI detailed in a July 2026 PSA (opens in new tab).
How to defend against pig butchering scams
Effective controls target the impersonation infrastructure and the payment path, since the conversation itself happens on channels the institution cannot see.
- Monitor and pursue takedowns of lookalike domains and counterfeit apps. Firms should monitor for and address imposter websites (opens in new tab) impersonating their representatives, and for apps, watch for a developer name that does not match (opens in new tab) the firm, a name that repeatedly changes, or a handful of suspiciously perfect reviews.
- Report scam ads and spoofed profiles. Teams can use the standalone business impersonation option in Meta's Brand Rights Protection tool (opens in new tab).
- Add friction to high-risk crypto transfers. Screen destination wallets against known scam addresses, impose cooling-off periods on new-to-crypto customers, and show scam warnings at the point of payment. UK providers delay suspect payments (opens in new tab) when they have grounds to suspect fraud.
- File structured reports. U.S. financial institutions use FIN-2023-PIGBUTCHERING (opens in new tab) as the SAR key term, or under 2026 guidance (opens in new tab), field 34(z) with "Scam Centers," and send wallet addresses and scammer identifiers to IC3.
- Warn customers and train staff. When they detect impersonation, firms should post a website warning (opens in new tab) or email customers, and run testing programs (opens in new tab) on social engineering scenarios for employees and board members.
How Doppel helps
Doppel is the Frontier AI Social Engineering Defense (SED) platform that unifies Digital Risk Protection (DRP) and Human Risk Management (HRM) to detect the lookalike domains, counterfeit trading apps, and spoofed support accounts that pig butchering operators build in a brand's name, and dismantle them before customers can deposit.
Brand Protection links the fake domain, the counterfeit app, the scam ad, and the impostor support profile into a single campaign view through the Doppel Threat Graph, tying a trading site that resurfaces under a new domain back to the operation that spawned it.
Doppel's agentic AI correlates, prioritizes, and executes takedowns across registrars, hosts, app stores, social platforms, and ad networks at machine speed, while your analysts handle disputes, appeals, and ambiguous cases that need human judgment.
Simulation converts a detected investment-lure campaign into an employee exercise across WhatsApp, Telegram, SMS, and voice with one click, so frontline staff recognize the coaching pattern. Coordinated enforcement across every channel makes the campaign too costly to rebuild.
Request a demo to get started.
Frequently asked questions about pig butchering scams
What is a pig butchering scam?
A pig butchering scam is an investment scam in which a criminal builds trust with a target over weeks or months, usually through a romantic or professional relationship started on a dating app or social platform. Some contacts begin with a "wrong number" text. The criminal then persuades the target to deposit money into a fake cryptocurrency trading platform. The platform shows fabricated gains and allows a small withdrawal to build confidence before the operator pushes the victim to deposit larger sums. When the victim tries to cash out, the platform demands fees or taxes and then cuts off contact.
What is a pig butchering scam in cybersecurity?
In cybersecurity terms, a pig butchering scam is a multi-channel social engineering attack that combines brand impersonation with prolonged relationship grooming. Operators register lookalike domains and publish counterfeit apps that impersonate exchanges and financial institutions, then use messaging apps, AI-generated personas, and real-time deepfake video to steer victims onto that infrastructure. Brand-protection teams see fake platforms, impostor accounts, and scam ads carrying their company's name; fraud teams see customer-authorized transfers that trigger SAR filing obligations (opens in new tab).
Pig butchering scam vs. romance scam: what is the difference?
A classic romance scam asks the victim for money directly, citing a medical bill or travel cost. A pig butchering scam persuades the victim to fund a fraudulent trading platform because the victim believes the platform invests the deposited money. The fake platform with simulated returns is a structural requirement of pig butchering and is absent from most romance scams. Romance is also optional: the relationship driving a pig butchering scheme can be professional or investment-focused rather than romantic.
What is an example of a pig butchering scam?
Counterfeit trading apps named "Ace Pro" and "MBM_BitScan" (opens in new tab) reached the Apple App Store and Google Play; developers submitted each as a QR scanner or data tracker, then loaded a fake trading interface at runtime from a remote server. In a separate case, operators spoofing the Singapore International Monetary Exchange took more than $10 million (opens in new tab) from five U.S. victims before authorities seized the domains.


