
Fraud can begin with an SMS, persuade a victim to authorise an instant bank transfer, reach an exchange or mule account, be converted into crypto assets and eventually re-enter the fiat system. The problem is not a lack of traces, but the disconnect between those monitoring Web2 and those monitoring Web3.
The pattern is becoming increasingly common: a customer is targeted through phishing, smishing or social engineering and initiates a bank transfer to an apparently legitimate beneficiary. Within a very short period of time, the funds can be converted into crypto assets through an exchange, transferred across wallets, bridges or mixers, and eventually converted back into fiat currency. For the fraudster this is a single process, otherwise, for many organisations it remains a fragmented sequence involving different systems, responsibilities and areas of expertise.
This asymmetry creates an operational blind spot. Traditional fraud prevention systems effectively monitor banking channels, but often lose visibility once the money enters the on-chain ecosystem. Conversely, blockchain analytics tools can track movements across blockchains but are not always connected to banking flows, virtual IBANs or the decision-making processes already embedded within banks and fintech companies.
As a result, the fraud prevention and subsequent investigation chain tends to break down precisely at its most critical point: the conversion between fiat currency and digital assets.
The first factor is time. With instant payments, the window available to identify an anomaly, intervene and attempt to recover funds is drastically reduced. The second is human vulnerability. Social engineering and impersonation shift the attack from technology to the individual, inducing victims to authorise transactions that appear legitimate.
The third factor is Artificial Intelligence, which increases both the scale and speed of fraud attempts. The fourth is widespread exposure. Fraud is no longer a concern only for major financial institutions, as lower attack costs make smaller organisations attractive targets as well. The fifth force is the emergence of a new integrated Web2 + Web3 domain, in which digital banking, payments and DeFi become parts of the same criminal journey.
The presentation underlying this analysis reports a 340% increase in hybrid Web2 + Web3 attacks between 2022 and 2024 and identifies stablecoins as the predominant asset in the illicit transactions examined. The point is not to demonise technology, but to recognise that the phenomenon has reached a scale that requires appropriate monitoring and tools.
A hybrid fraud flow can be divided into four stages. The first is targeting within Web2, where phishing, smishing or malware lead either to the theft of credentials or to victims being induced to initiate a bank transfer. The second is conversion, when fiat currency is converted into Bitcoin or stablecoins through an exchange. The third is obfuscation, involving intermediary wallets, mixers, bridges or decentralised exchanges (DEXs). The fourth is cash-out, when the funds are converted back into fiat currency through exchanges and brokers with varying levels of regulatory compliance.
Within this chain, the money mule does not disappear. Instead, its role changes: it can become the operational bridge between the bank account and the crypto ecosystem, particularly at entry and exit points. For this reason, analysis cannot stop at an individual bank transfer or wallet. It must reconstruct relationships, destinations and behaviours throughout the entire flow.
The solution does not necessarily require replacing existing infrastructure. The approach proposed by Alfa Group and Crypfy is to integrate a blockchain intelligence layer into the existing fraud prevention stack, while leaving the final decision to the bank’s fraud prevention engine.
The first control concerns Wallet Risk Intelligence. Each wallet can be assessed through an explainable risk score, supported by reason codes, transaction history and continuous on-chain monitoring.
The second concerns the crypto exposure of bank transfers: how much of the outgoing SEPA flow reaches exchanges, crypto brokers or virtual IBANs, and which entity ultimately operates behind the banking rail.
The third control is Web3 Brand Protection. A Web3 domain is not merely a web address: it can be directly connected to a wallet and become a point through which funds are collected. Monitoring registrations, brand variations and links between domains and wallets can help anticipate impersonation attempts.
The fourth control takes place after the event, following fraud-related flows until they are converted back into fiat currency.
These measures can be complemented by transaction simulation, which makes it possible to determine what a transaction will actually execute before it is signed and translate a technical instruction into an understandable operational outcome: allow, review or block.
An analysis conducted by Crypfy on 30 Italian banks and banking service providers, using public sources and on-chain data, highlights that exposure is already tangible.
Nineteen of the thirty organisations were found to have their brands registered as Web3 domains by third parties; all thirty showed flows towards crypto exchanges and brokers within the scope examined; and seventeen had already launched initiatives involving crypto or digital assets.
These figures do not automatically indicate the presence of fraud. They do, however, demonstrate that exposure exists even when an institution does not directly provide crypto services.
Customers purchase digital assets, use exchanges and transfer funds to operators that may rely on third-party banks or virtual IBANs. The organisational boundary therefore no longer coincides with the boundary of risk.
When fraud reaches the blockchain, the traces do not disappear. Transactions are recorded on public ledgers and can be tracked, although attributing them to specific identities requires additional data and cooperation at the relevant points of intersection.
The critical variable is time. In the case of centralised stablecoins that include a freeze function, the intervention chain may involve the bank and the victim, blockchain intelligence providers, public authorities, exchanges and the stablecoin issuer.
The process begins with the response within Web2, continues through on-chain tracing and may ultimately result in the address being frozen and the funds being secured.
The timeframe indicated in the presentation is approximately 48 hours, although this window may close earlier if the assets are converted into instruments that cannot be frozen.
For this reason, the key point to monitor is not the stablecoin itself, but the conversion process. The ability to rapidly connect the bank transfer, exchange, wallet and subsequent on-chain journey can increase the chances of intervention and help build useful evidence even where recovery is no longer feasible.
The convergence of Web2 and Web3 requires a shift from separate controls towards a unified view of risk. As a starting point, every organisation should ask itself three practical questions:
The challenge is not to create a separate control framework dedicated exclusively to crypto assets. Rather, it is to extend existing fraud prevention capabilities so that they can monitor what has become a single, interconnected flow: from identity to payment, from the on-chain destination to the potential re-entry of funds into the fiat system. Web2 and Web3 are already interconnected for those carrying out attacks. They must become interconnected for those defending against them as well.
Alfa Group S.p.A.
Founded in 1996, Alfa Group is an Italian innovative SME operating in the cybersecurity sector and a leader in fraud and cyber risk management and mitigation for the banking sector, large corporations and Public Administrations. Alfa Group uses proprietary Artificial Intelligence algorithms to detect and combat fraud, protecting more than 120 financial institutions and monitoring approximately 23 million digital users through its Fraud Management solutions. It also provides coverage for more than 450,000 IT assets through its Cyber Exposure Management services.
Crypfy
Crypfy is an innovative startup specialising in Web3 and blockchain risk intelligence, developing technological solutions and advisory services for monitoring, fraud prevention and compliance in the cryptocurrency and digital asset ecosystem.

Article by:
Andrea Castellaneta, CEO and Co-Founder of Crypfy.ai