Skip to content
Buyer guide · 16 min

Crypto Gift Card Scams: Fake Stores, Drained Codes, Urgent Strangers

Three different frauds share one name. How to vet a store before you send coins, why a heavily discounted code is usually a stolen one, and the one rule that ends every "pay me in gift cards" call.

Published Aug 31, 2026
← All entries
Contents · 22

Three different frauds share one name. There is the store that takes your coins and ships nothing. There is the code that arrives exactly as promised and turns out to have been spent an hour before you bought it. And there is the stranger — on the phone, in the inbox, in a chat window — who is not selling anything at all and simply wants you to read sixteen digits out loud. These are not variations on a theme. They have different victims, different tells and different defences, and only two of them involve buying anything.

What links them is a property that cryptocurrency and gift-card codes happen to share: both settle in one direction only. A confirmed transaction cannot be recalled, and a redeemed code cannot be un-redeemed. Stack those two irreversibilities on top of each other and you have built, almost by accident, an ideal instrument for taking money from strangers. Everything below is about recognising the stack before you are standing on it.

Three scams, side by side

Before the detail, the shape. Nearly every incident in this corner of the internet is one of these three, and knowing which one you are looking at tells you what to do next.

ScamWhat happensWhere it finds youThe one tell
The fake storeYou pay and nothing is delivered — or a second "release" payment is demanded.Search ads, messaging groups, forum replies, lookalike domains.The discount is impossible.
The drained codeA real, correctly formatted code arrives with a zero balance.Peer-to-peer marketplaces, classifieds, "cheap codes" resellers.A person is selling it, not an issuer.
The urgent strangerYou buy real cards at a real shop and hand over the numbers.Phone calls, texts, romance and job chats, fake support desks.Somebody else chose the payment method.

The third is the largest by a wide margin, and the only one in which every commercial party behaves correctly. The FTC's consumer guidance on gift-card scams exists because of it, and it is worth reading even if you never buy a card with crypto in your life.

Scam one: the store that never delivers

This is the one people mean when they ask whether a crypto gift-card site is a scam. It is also the easiest of the three to defend against, because the fraud has to be constructed before you arrive, and constructing it leaves marks.

The mechanics are dull. A site is stood up with a catalogue scraped from a real store, a checkout that produces a wallet address, and a support channel that lives on a messaging app. You pay. Either nothing happens, or — the more profitable variant — the site reports a problem and asks for a second payment to fix it: a network fee, a verification deposit, an unlock charge on a large order. That second ask is the entire business model. The first payment establishes that you will send money; the second is where the profit is.

The discount is the tell

Start with the number on the front page, because it settles the question faster than anything else.

Gift cards are not a high-margin product. A retailer sells its own cards at face value, and a distributor buys them at a small single-digit discount off face — and that thin slice is the entire margin the whole chain divides between itself. Every reseller, aggregator and crypto storefront in the world is working inside it. It is why a genuine discount on a major brand is a few percent, and why ours is capped at 5%, which is roughly the ceiling honest inventory allows.

So when a store advertises 30%, 40% or 60% off an Amazon or Apple card, it is not offering a better deal on the same product. There is no supply chain in which that card was acquired at 40% off. Either it was never acquired at all, or it was bought with someone else's stolen payment details — which makes it the second scam in this article rather than the first, and leaves you holding a code the brand will void the moment the chargeback lands.

A discount much beyond 10% on a major brand is not a bargain. It is a description of where the inventory came from.

A shared address is the technical tell

The second check is specific to crypto, and almost nobody thinks to make it. A real checkout generates a fresh deposit address for your order and nothing else. That is not a courtesy. It is the only way a system with no accounts can tell your payment from everyone else's, and it is what makes an arriving deposit identify itself.

Fake stores rarely bother. They publish one address — the same one pinned in their channel, the same one in a screenshot from last week, the same one you are given on a second order. Then they ask you to send the transaction hash to "confirm" your payment, because with a shared address they genuinely cannot match a deposit to a buyer.

If you are asked to send a transaction hash, the store cannot identify your payment on its own. Occasionally that means an under-built store rather than a fraudulent one. It is never a good sign. A properly wired checkout starts watching the second your wallet broadcasts, which is what the walkthrough in crypto payment problems describes from the inside.

Ten checks that take a minute

None of these needs an account, a purchase or any technical skill. Run them in order — the first three eliminate most of what is out there.

CheckWhat you want to seeWhat a bad answer looks like
1. The headline discountA few percent off face value.25% or more off any major brand.
2. The deposit addressA new address per order, with its network printed beside it.One address reused across orders, or pasted into a chat.
3. Second paymentsThe total is the total.A fee to release, verify or unlock the order after you paid.
4. Order lookupA way to reopen your order later without an account.The only record of your purchase is a chat thread.
5. Support surfaceA contact route on the site itself, with a stated response window.A messaging-app handle and nothing else.
6. Written termsRefund window, delivery window, what happens on underpayment.No terms page — or terms copied verbatim from another store.
7. Payment statesPending, confirming and confirmed, updating live on the page.A static "send here and wait".
8. Catalogue honestyRegion locks and currency locks disclosed per card.Every card described as working worldwide.
9. Age and trailDated pages and an archive that predates the offer.No history at all, on a domain registered weeks ago.
10. Independent mentionsDiscussion somewhere the store does not control.Testimonials that exist only on its own pages.

The last one deserves a caveat. Testimonials on a store's own site are worth nothing by themselves — including ours. Look for the store being discussed somewhere it has no editorial control, and weigh that instead. The same logic applies to comparison pages written by sellers, which is why our own comparison links out to each competitor's help documentation rather than asking you to take our word for their policies.

Scam two: the code that was already spent

This one is subtler, because you do receive something. A real code, correctly formatted, for the right brand. You enter it and the balance is zero, or the brand refuses it outright.

A gift-card code is a bearer instrument: whoever types it first owns the balance, and the brand has no way to distinguish the buyer from the finder from the thief. That is the whole reason the format is convenient, and the whole reason resale is dangerous. There is no name on it, so there is nobody to restore it to.

Codes reach the discount marketplaces by three routes, and only one of them is safe:

  • Genuinely unwanted cards. Somebody was given a card for a shop they never use and sells it below face value. Legitimate in principle, and the reason resale marketplaces exist at all.
  • Cards bought with stolen payment details. The code is real and funded, right up until the chargeback lands weeks later and the brand voids the balance. You are the one holding it when that happens.
  • Codes that have been photographed. A code seen by anyone — a warehouse worker, a previous buyer, a screenshot in a group chat — remains a working code for whoever redeems it first. The seller can be entirely honest and still sell you nothing.

You cannot tell the three apart by looking, and neither can the marketplace. The defence is structural rather than forensic: buy from whoever issued the code, not from whoever is holding it. A card that travels from the brand's own distribution into your inbox has had no opportunity to be photographed and no reversible payment behind it.

Then redeem it promptly. Not because codes decay, but because your claim on the balance is only as good as being first. If it refuses, our redemption troubleshooting guide separates the boring causes — a region mismatch is by far the most common — from the ones that mean the code was never really yours.

Scam three: the stranger who wants to be paid in codes

This is the largest of the three and the only one in which every shop in the chain behaves properly. You buy a real card from a real retailer. You then read the numbers to somebody who should not have them.

The scripts change constantly; the structure never does. Somebody contacts you, manufactures urgency, and specifies gift cards as the payment method. It arrives as a tax office threatening arrest, a utility about to cut the power, a technician who has "found" a problem on your computer, a manager who needs cards for staff and is stuck in a meeting, a partner you have never met in person who needs help just this once, an employer who overpaid you and wants the difference back, a prize that needs a fee released before it can be sent.

Gift cards are chosen deliberately. They are on sale in every supermarket, they clear the instant the numbers are spoken, they resell for crypto within minutes, and — unlike a card payment or a bank transfer — there is no institution anywhere in the chain with the power to reverse them. A wire can occasionally be recalled. A code that has been read out is gone.

The rule that ends the call

No government, court, tax authority, police force, utility, bank, airline, hospital or employer has ever accepted payment in gift-card codes. Not once, in any country, for any reason. There is no exception to look for, no legitimate edge case, no department that does it differently. If the payment method being requested is a gift card, the request is fraudulent, and nothing else about the conversation needs to be evaluated at all.

That single rule resolves the entire category, including the versions nobody has heard yet. The stories evolve every season; the payment method is the part that has to stay fixed, because it is the part that makes the fraud work.

Two crypto-era variants

Two newer versions are worth naming, because both are designed to survive the rule above.

The card-to-coin conversion. You are told to buy a gift card and then use it to buy cryptocurrency, "because the transfer is faster" or "because the payment portal is down". This launders the request through a step that feels technical and voluntary. It is the same scam. The card is simply being moved one hop before it is spent.

The recovery service. After a loss, someone appears offering to trace or claw back the funds for an up-front fee — payable, of all things, in gift cards or crypto. Blockchain analytics firms are real, and they work for law enforcement and exchanges, not for individuals who message them first. Nobody who contacts you unprompted about money you have already lost is going to return it. The FTC's page on what to do after a scam sets out the real routes, none of which charge a fee.

What a real crypto checkout shows you

It is easier to recognise a legitimate checkout than to catalogue every fake one, because the legitimate version has to expose certain machinery in order to function. Seven things should be visible without asking anybody:

  • A deposit address that belongs to your order. Generated when you pick a coin, used once. This is what removes the need for an account, a login or a proof of payment.
  • The network printed beside the address. Tron, Ethereum, Solana — spelled out, not implied by the ticker. A wrong-chain send is the one failure in crypto payments nobody can undo, and a store that hides the network is setting you up for it.
  • A quote with a visible expiry and a written policy for when it lapses. Ours holds the price for the countdown and picks up late deposits with a 48-hour recovery sweep, settled at the sweep-time rate. What matters is less the specific policy than that one is stated in advance.
  • Live order states. The page should move from pending to confirming the moment your wallet broadcasts, with nothing to refresh and nothing to report.
  • One total, and no second ask. There is never a release fee, a verification deposit or an unlock charge. When a payment falls short it falls into a stated procedure — send the difference to the same address, or take the balance back.
  • An order you can reopen. Order lookup takes an order number and the email used at checkout, and stays live for 14 days. No account means no password to lose; it must not mean no record.
  • Terms that name the windows. Ours are in the terms and summarised in the FAQ: before a code is issued, an order can be returned in the coin it arrived in; after delivery, an unredeemed code can be refunded within 14 days. Once a code has been redeemed at the brand, nobody can reverse it.

That last clause has a corollary our terms state plainly, and it belongs in this article rather than buried in a policy page: a code you were talked into reading aloud is not refundable. Not here and not anywhere. The refund window protects you against a code that failed; nothing protects you against a code that worked perfectly for somebody else.

What we can prove, and what we cannot

A safety guide published by a shop is only worth reading if the shop is honest about the limits of its own case. So here is ours.

Checkable right now, without trusting us: the deposit address is new on every order; the network is printed next to it; the states move by themselves; there is no second payment anywhere in the flow; the refund and delivery windows are written down before you pay; an order can be reopened without an account; the guides in this journal carry dates and have been revised in public; and the catalogue says when a card is locked to a region instead of pretending everything works everywhere.

Not checkable: that we will still be here in five years. No no-KYC business can prove that, and any that claims to is telling you something it does not know. We take an email address and nothing else — which is the point of the model, and the reason there is very little here to leak — but the same design means no regulator is holding a deposit on your behalf.

The right posture toward any store in this category, this one included, is therefore narrower than trust: treat it as a counterparty for one transaction, not as a place to keep value. Buy the amount you are about to spend. Redeem the code when it arrives. Do not accumulate balances anywhere — not with us, not with a competitor. That advice costs us money, and it is still the correct advice.

If it has already happened

Speed is the only variable still under your control. A code reported to the brand within minutes of being read out is occasionally frozen before it is drained. The same call an hour later almost never is.

What happenedDo this firstThen
You read a code to a strangerCall the brand's gift-card fraud line, using the number on the brand's own site — never one you were given.Keep the card and the receipt. They are the proof of purchase the brand will ask for.
You paid a store that sent nothingSave the deposit address, the amount, the transaction hash and every message.Report it. The address is the durable identifier that links your case to other people's.
You bought a drained codeContact the marketplace and the brand the same day.The brand can usually say when and where the balance went, which is what makes a report actionable.
You sent crypto to the wrong placeAccept that nothing recovers it.Ignore anyone who says otherwise. Recovery offers that arrive after a public loss are a second scam.

Report it even when recovery is hopeless. In the United States that is reportfraud.ftc.gov, and for anything involving cryptocurrency the FBI's IC3; elsewhere, your national fraud reporting body. Reports are how one wallet address collected from a hundred victims turns into a case instead of a hundred separate disappointments.

Frequently asked questions

Is buying gift cards with crypto a scam?

No — it is an ordinary retail purchase with an unusual payment method. The risk is not in the model, it is in the counterparty, exactly as with any online purchase. What differs is that the payment cannot be charged back, which raises the cost of picking the wrong store and is why the checks above are worth the minute they take.

How can I tell whether a crypto gift-card site is legitimate?

Run the ten checks. The three that eliminate most fakes are the size of the discount, whether the deposit address is unique to your order, and whether any second payment is requested after you have paid. A store that fails any of those three is not worth investigating further.

Why is a 40% discount a bad sign rather than a good deal?

Because the margin does not exist. Distributors buy major-brand cards at a small single-digit discount off face value, and that slice is shared across the entire chain. A 40% discount cannot be funded by a legitimate purchase, which leaves inventory that was never bought at all or was bought with stolen payment details.

Can a gift-card code be stolen after I receive it?

The balance can be, if the code was ever visible to anyone else. Codes are bearer instruments: the first redemption wins, and the brand cannot tell a buyer from a thief. Buy from an issuer rather than a person, redeem promptly, and never post, photograph or paste a code anywhere.

Someone is asking me to pay a bill in gift cards. Could it ever be real?

No. No tax authority, court, police force, utility, bank or employer accepts gift-card codes, in any country, under any circumstances. The payment method settles it on its own — you do not need to evaluate the story or verify the caller.

A store wants my transaction hash. Is that normal?

It means the store cannot match your deposit by itself, which usually means the address is shared between buyers. A checkout that issues one address per order sees your payment the moment your wallet broadcasts it, and never needs a hash, a screenshot or a receipt.

I paid, and now the order needs a release fee. What should I do?

Stop. No legitimate checkout requires a second payment to deliver the first. A genuine shortfall is completed by sending the difference to the same address and nothing else — the real failure modes are set out in crypto payment problems. A release, verification or unlock fee is the scam itself, not a step inside one.

Do you hold my money if something goes wrong?

No, and that is deliberate. An unfunded or partly funded order is returned in the coin it arrived in, an unredeemed code can be refunded within 14 days, and there is no balance or wallet to leave funds sitting in. Buy what you are about to spend — it is the only posture that does not depend on trusting anybody's longevity.

Where do I report a gift-card scam?

Call the brand first; only the brand can freeze a balance, and Amazon, Apple, Steam and Google all run gift-card fraud lines. Then report it — reportfraud.ftc.gov in the US, IC3 for anything involving crypto, or your national fraud body elsewhere. Keep the card, the receipt and the addresses; a report without them is much harder to act on. If an order placed with us is the one that went wrong, start there instead.

End of entry

Found a region quirk we missed? Tell the desk — /contact.

Stop reading. Start spending.

81 live brands waiting.

Browse the catalog