Why this matters
P2P trading has a structural property: users transfer fiat to each other directly, bypassing the platform. The platform only guarantees the crypto escrow. So virtually every scam targets the same thing — make you release crypto (or fiat) without getting anything back, and leave you with no evidence to dispute it.
The good news: scams are repetitive. If you recognise them by name, you'll recognise them in the wild. This article is a reference of 9 schemes plus the rules that block almost all of them.
Core principles (memorise these)
- Money goes only to your own account, using the payment details from the trade. If fiat ends up somewhere else, that's your problem — there's nothing to prove in a dispute.
- Release crypto only when fiat has actually arrived. Not "promised", not "screenshot attached", not "bank is processing" — visible on your balance.
- Conversation and evidence — only in the trade chat. Telegram, WhatsApp, phone don't count. If the counterparty drags you off-platform, the goal is almost always bad.
- No links, files, or QR codes from the counterparty. Especially "special payment forms", "bank apps", or "profile updates".
- Support never messages first. If "support" starts a conversation, it's a scammer. Real support replies only to your tickets and only from
@BitMomentSupportBot.
Now the specific schemes.
Scheme 1. Fake payment screenshot
What it looks like. The buyer sends a chat screenshot — "bank confirmed transfer", a push notification, a statement. Asks you to release crypto because "money is on the way".
Why it works. The seller sees a familiar bank logo, the right amount, the right time — believes it, clicks "Confirm receipt".
Defence.
- Never trust screenshots. Open your own bank app or web banking and check the balance and the transaction list. With your own eyes.
- For SBP transfers, you should see exactly the amount from the trade, from exactly the name listed in the counterparty's profile.
- If the bank says "credited" but it's been less than a minute, give it 1–5 minutes — some banks have small delays even for internal transfers.
- If money hasn't arrived within an hour of "payment", open a dispute. Don't release.
Scheme 2. "Sent by a third party"
What it looks like. Buyer sends a screenshot showing a transfer to your card — but from a different name (not theirs). Or says: "I don't have a card, my friend with the same last name paid for me".
Why it works. This is money from a stolen card. When the real owner notices, they file with the bank, the bank chargebacks the transfer, money is pulled back from your account. You've already given away crypto.
Defence.
- Accept payment only from the name registered in the counterparty's profile.
- If the sender's name differs, refuse and open a dispute. This isn't nitpicking — it's a hard rule.
- Don't accept "my spouse / friend / brother paid" stories. The platform only counts profile data.
Scheme 3. Payment reversal / chargeback
What it looks like. The trade went perfectly: money arrived, you released crypto. An hour, a day, a week later, the bank notifies you: transaction reversed.
Why it works. A stolen card was used, or the scammer reported an "unauthorised transfer" to bank security. Money is returned to the payer; your account goes negative.
Defence.
- This is the most dangerous scheme because everything looks clean at trade time. Main defence: accept payment via SBP by phone number only, and only from the name in the counterparty profile.
- Be especially careful with large first trades with a new counterparty (no reviews, low success rate, young account).
- If a reversal request lands, gather all evidence from the trade chat and contact
legal@bitmoment.pro.
Scheme 4. "Release first, I'll pay right after"
What it looks like. Buyer writes: "I'll pay, but the bank is slow right now — release the crypto, I trust you, you have a good rating". Variants: "I have a work deal closing", "I'm late for a flight", "the bank requires confirmation that I received the crypto before processing the transfer".
Why it works. Social engineering. Pressure, urgency, flattery.
Defence.
- This is always a scam. Banks don't require "confirmation of crypto receipt". The platform doesn't require it. Nothing should be released ahead of time.
- Don't respond to emotional arguments. The "Confirm receipt" button is pressed only after money has actually arrived in your account.
Scheme 5. Dragging you to Telegram (off-platform)
What it looks like. First message in the trade: "let's switch to Telegram, the chat here is slow" / "I have a question about the details, let's discuss in DMs".
Why it works. Off-platform there's no evidence. If you get scammed, the dispute moderator sees an empty trade chat and can't rule for you.
Defence.
- All communication — in the trade chat. Period.
- If the counterparty insists, refuse and open a dispute citing "off-platform communication attempt".
- This rule isn't bureaucracy — it's literally your protection in a dispute.
Scheme 6. Account takeover (phishing + 2FA bypass)
What it looks like.
- You get an email or message "from support" / "from security" / "about suspicious activity" with a link to "verify your account".
- The link leads to a fake site that looks like bitmoment. You enter email, password, 2FA code.
- The scammer immediately logs in to the real site with your credentials and withdraws the whole balance to their wallet.
Defence.
- Never click links in emails or messages. Open the site manually, from a bookmark you saved yourself.
- BitMoment never DMs you first and never sends "urgent verification links".
- Use 2FA via authenticator app (not SMS — SMS can be intercepted via SIM swap).
- Periodically review active sessions under Security → Sessions. If you see an unknown device, click Revoke and change your password.
Scheme 7. Address swap in the address book
What it looks like. A virus on your device swaps the crypto address you're copying for the scammer's address. You add this "your" address to the address book, withdraw to it 24 hours later — funds go to the attacker.
Defence.
- The 24-hour activation window exists for exactly this. Use that time to verify the address through a second channel (was the same address emailed to you?).
- Compare not only first/last characters, but at least 8 characters in the middle.
- On a device with crypto wallets: keep antivirus running, no pirated software, no shady browser extensions.
Scheme 8. "Buyer" = "seller" (triangle scam)
What it looks like. The scammer opens two parallel trades: one with you as a buyer, one with a third user as a seller. The victim's fiat is sent to you, you release crypto to the scammer, the scammer disappears. A day later the victim disputes "I paid but never got crypto", and their bank reverses your transfer.
Defence.
- This is a variant of scheme 3 (chargeback). Same defence: accept fiat only from the name in the counterparty profile.
- If the payment memo contains something odd (a third person's name, "payment for ad on exchange X"), that's a strong red flag.
- Don't hesitate to cancel suspicious trades. Losing one trade is cheaper than losing your balance.
Scheme 9. "Support" in Telegram
What it looks like. You complain about an issue in a public chat — a minute later "BitMoment moderator" DMs you, asks for login, code, balance screenshot, or "temporarily move crypto to a safe wallet".
Why it works. Scammers monitor public chats and pounce on victims.
Defence.
- Real support lives at two addresses only:
@BitMomentSupportBotandsupport@bitmoment.pro. - Support never asks for passwords, 2FA codes, seed phrases, or "temporary transfers".
- If someone DMs claiming to be support — take a screenshot, send the profile to
@BitMomentSupportBot. We ban these accounts platform-wide.
Per-trade checklist
Before clicking "Confirm receipt" (seller):
- Money is in my account (verified in the bank, not in a screenshot).
- Amount matches the trade.
- Sender name matches the counterparty profile.
- Payment memo contains nothing odd (no third names, no "payment for service X", etc.).
- Counterparty didn't propose anything off-platform.
Before clicking "I have paid" (buyer):
- I sent fiat to the trade's stated details, nowhere else.
- Amount matches the trade.
- I have a transfer confirmation (receipt, bank screenshot).
Before withdrawing crypto:
- Address double-checked (at least 8 middle characters).
- Address was activated more than 24 hours ago, or I'm independently sure.
- I entered the 2FA code myself and shared it with nobody.
If something goes wrong
- Don't close the trade. Open a dispute — that gives a moderator access to chat and details.
- Save all evidence: trade chat screenshots, bank statements, correspondence. If the counterparty dragged you to Telegram, save those screenshots too.
- Write to
legal@bitmoment.prowith a description and the trade number. - If you lost money outside the platform (sent to a scammer's external wallet, gave away card data), file with your local police. The platform can help with documents for the investigation, but money is returned by the bank, not by us.
