Why this niche attracts fraud
Fraud follows irreversibility. A bank transfer can sometimes be recalled; a card payment can be charged back. A gift-card code cannot, because the code is the value — whoever reads the characters can spend them, and there is no mechanism to establish who read them first. A confirmed crypto transaction cannot either.
Put those two instruments in the same market and you get a category where the scammer's operational problem is solved for them. They do not need a bank account, a merchant relationship, or a way to move money across borders. They need somebody to read sixteen characters aloud.
The eleven patterns
Read these once. Recognition is the entire defence, and every one of them relies on you not having seen it before.
-
1. The agency impersonation
A caller claims to be from a tax authority, utility, court or police force and demands immediate payment in gift-card codes to avoid arrest or disconnection. No government body anywhere accepts gift cards. This remains the highest-volume pattern in the category.
-
2. The tech-support callback
A pop-up or call warns your device is infected. The "technician" gains remote access, shows you a fake refund overpayment, and asks you to return the difference in gift cards or crypto. The overpayment never existed; the screen was edited.
-
3. Romance, slow-played
Weeks or months of genuine-feeling conversation, then a crisis that needs gift cards because "the bank is blocked". The pacing is the tell — legitimate relationships do not have a payment mechanism attached to them.
-
4. The employer onboarding task
A new remote job asks you to buy gift cards for "client gifts" and forward the codes, with reimbursement promised on the next payroll run. Sometimes the entire company is fabricated; sometimes the recruiter is impersonating a real one.
-
5. The already-redeemed code
You buy a discounted code from a marketplace or forum. It fails, or it works for an hour before the balance is drained. The seller had the code too — nothing about a code being sold to you removes it from the seller's screen.
-
6. The chargeback timebomb
A code bought with a stolen card works fine for days or weeks, then the brand voids the balance when the chargeback processes. You lose the crypto you paid and the credit. This is the specific reason legitimate P2P platforms hold long escrow windows on card-funded trades.
-
7. The phishing redemption page
A convincing clone of a brand's redeem screen, reached from an email or a search advert. You enter the code, it "fails", and it is harvested and spent within seconds. Always type the brand domain yourself.
-
8. The fake voucher generator
"Free Bitcoin voucher codes, no deposit." The site asks for a wallet address, an email, sometimes an identity document, and delivers nothing. The product being sold is your data and your attention. See free crypto vouchers.
-
9. The off-platform P2P pull
A counterparty on a legitimate escrowed marketplace asks to complete the trade over a messaging app "to save fees". The escrow was the entire protection. Any request to move off-platform ends the conversation.
-
10. The overpayment reversal
You sell a card for crypto. The buyer sends "too much" and asks you to refund the difference. The original payment is later reversed or was never final, and your refund is gone. Structurally identical to the classic cheque-overpayment fraud.
-
11. The recovery scam
After you have been defrauded, a second actor contacts you offering to recover the funds for an upfront fee. This targets a list of known victims, often assembled from the first scam. Nobody legitimate charges upfront to recover crypto.
Universal tells
Every pattern above shares at least three of these. If you can spot them, you do not need to memorise the taxonomy.
Stop if any of these appear
- The payment method is specified for you. "Pay with Apple gift cards" or "send USDT" from someone who contacted you first. Legitimate creditors do not care which brand of card you own.
- Urgency with a countdown. Arrest today, disconnection this afternoon, the offer expires in ten minutes. Urgency exists to prevent you consulting anyone.
- Secrecy. "Do not tell the bank", "do not mention this to your family", "the investigation is confidential". Isolation is a required ingredient.
- You must read the code aloud, photograph it, or type it into a chat. There is no legitimate process in the world that works this way.
- An overpayment you are asked to return. Every variant of this is fraud. Every one.
- A price too far below market. A 40% discount on a liquid brand is a warning, not a bargain.
- Pressure to leave an escrowed platform. The escrow was the protection. Removing it is the goal.
Staying safe as a buyer
- Buy from platforms with a nameable legal entity. Bitrefill (Sweden), Coinsbee (Germany), CoinGate (Lithuania), CoinCards (since 2014). If you cannot find out who you are contracting with, that is the finding.
- Type domains yourself. Search adverts for gift-card platforms are a known phishing vector. Bookmark the platforms you use.
- Redeem promptly. A code sitting in an inbox is exposed to every future compromise of that inbox. Redeem, then delete.
- Use a dedicated email address. This is not paranoia — the Bitrefill breach in March 2026 exposed roughly 18,500 purchase records including email and crypto addresses. Compartmentalising limits what a future leak reveals.
- Never enter a code on a page you did not navigate to. Log in to the brand, find the redeem screen, apply it there.
Staying safe as a seller
Selling a gift card for crypto is structurally riskier than buying, because you release an irreversible asset against a reversible one. The rules are non-negotiable.
- Escrow or nothing. Use a platform that holds the crypto until the code is confirmed. Never release first, whatever the reputation score says.
- Assume card-funded cards can be voided. A code bought with a stolen card may work today and be void in three weeks. Price that risk in, or decline it.
- Never refund an overpayment. Return the whole transaction through the platform instead.
- Expect 55–85% of face value. Anyone offering 95% is either mistaken or setting you up. See selling gift cards for crypto.
If it already happened
Act in this order. The first hour matters far more than the first week.
- Call the card issuer, not the platform. Some brands can freeze an unspent balance. Have the code, the purchase receipt and the time of purchase ready.
- Report it. In the US, reportfraud.ftc.gov and IC3. In the UK, Action Fraud. Elsewhere, your national fraud reporting body. This rarely recovers money and does feed enforcement.
- Secure the accounts involved. Change the email password, enable an authenticator app rather than SMS, and check for forwarding rules you did not create.
- Expect the second wave. Recovery scams target known victims. Nobody legitimate charges an upfront fee to get your money back.
- Tell someone. The shame around this fraud is what keeps it working. The people who report it quickly are the ones who occasionally get something back.
Related: region locks for the non-fraud way to lose money, voucher codes explained for why a code behaves like cash, and our platform reviews for who has a nameable entity behind them.
Gift card scams: FAQ
Can I get my money back after a gift card scam?
Rarely, and speed is everything. Contact the card issuer immediately — some brands can freeze an unspent balance if you reach them before the scammer redeems it. If you paid with crypto, that leg is irreversible. Report to the FTC in the US and to your national fraud reporting body elsewhere; it will not usually recover funds but it does feed enforcement.
Why do scammers ask for gift cards specifically?
Because the code is the money. It moves instantly, over the phone, with no account and no reversal. It requires no banking infrastructure on the scammer's side, and once read aloud it can be resold in minutes. Crypto has similar irreversibility, which is why fraud in this niche often chains both.
Is Bitrefill or Coinsbee a scam?
No. Both are established platforms with real corporate entities — Bitrefill in Sweden since 2015, Coinsbee registered in Germany since 2019. Bitrefill did suffer a serious breach in March 2026, which is a security failure rather than fraud, and it disclosed it. The scams in this market cluster around unknown storefronts, marketplace listings and P2P counterparties, not the established platforms.
How do I know if a code I was given is legitimate?
You largely cannot, before redeeming. That is the structural problem with accepting codes from strangers. What you can do: redeem immediately rather than later, only accept codes through an escrowed platform, and never release crypto to a counterparty before a code is confirmed applied to your own account.
Are "discounted" gift cards ever legitimate?
Sometimes — genuine secondary marketplaces exist, and platforms do run real promotions, especially around Black Friday. But a 40% discount on a liquid brand is not a bargain, it is a signal. Cards that steep are usually bought with stolen payment methods and will be voided when the chargeback lands, often weeks later.
Sources and further reading
Figures on this page were checked in August 2026. Fees, country lists and promotions change without notice — always confirm on the operator's own site before you pay.
- FTC Consumer Advice — Gift card scams — patterns, reporting and what to do first
- FTC Data Spotlight — gift card fraud losses — reported loss figures from Consumer Sentinel
- FTC — Report fraud — US reporting portal
- FBI Internet Crime Complaint Center — US cybercrime reporting
- Action Fraud (UK) — UK reporting body