Escalate when the issuer relies on exaggerated business claims, undisclosed exemptions, fabricated partnerships, or testimonials that cannot be validated. A fundraising effort becomes a fraud risk when marketing is used to create false credibility or urgency, especially if investors are being asked to commit funds before the project, governance, or legal status is clear.
Why This Matters for Security Teams
Regulators and compliance teams should stop treating every ICO as ordinary fundraising once the pitch depends on claims that cannot be independently verified. Fraud risk rises when the issuer uses fabricated partnerships, selective disclosures, inflated timelines, or promises of regulatory approval that do not exist. That shifts the issue from disclosure quality to potential deception, which is a different control problem than a failed launch or weak market demand.
The practical distinction matters because controls for fundraising governance are not the same as controls for fraud detection. A legitimate project may still be risky, but a fraud risk requires closer scrutiny of intent, evidence, and traceability. Current guidance suggests aligning review with the same skepticism used in Ultimate Guide to NHIs — Regulatory and Audit Perspectives when assertions drive access to capital without supporting records. For baseline governance expectations, the NIST Cybersecurity Framework 2.0 remains a useful reference for evidence, accountability, and response discipline.
In practice, many compliance teams encounter ICO fraud indicators only after investors have already been solicited aggressively and documentation has begun to disappear.
How It Works in Practice
A normal fundraising effort usually has a defensible paper trail: corporate registration, named principals, a coherent use-of-funds statement, and claims that can be checked against public records. When that structure is missing, regulators should look for a pattern rather than a single red flag. One exaggerated claim can be a marketing mistake; repeated, material misstatements can indicate a scheme designed to induce reliance.
Operationally, the review should test whether the issuer can substantiate who it is, what it has built, and what investors are actually buying. The strongest warning signs are usually found in the mismatch between promotional language and verifiable evidence. That means checking domain ownership, legal entity status, token economics, jurisdictional permissions, escrow arrangements, and whether the team can validate any supposed partnerships or endorsements. The Top 10 NHI Issues is useful here because it reinforces a broader governance lesson: hidden dependencies and weak ownership often surface as control failures after the fact.
- Escalate when testimonials, influencer claims, or “advisor” quotes cannot be independently verified.
- Escalate when funds are requested before the business model, token rights, or legal status are clear.
- Escalate when the issuer claims exemptions, licenses, or partnerships without documentary proof.
- Escalate when messaging relies on urgency, scarcity, or guaranteed returns instead of risk disclosure.
For evidence handling, the NIST SP 800-53 Rev 5 Security and Privacy Controls supports disciplined record retention, monitoring, and incident response, while FATF-style identity and transaction checks help distinguish legitimate capital formation from concealment. These controls tend to break down when the issuer is offshore, uses layered shells, or routes promotion through anonymous channels because attribution and corroboration become too weak to support timely enforcement.
Common Variations and Edge Cases
Tighter fraud screening often increases review time and legal overhead, requiring organisations to balance investor protection against the risk of slowing a legitimate raise. That tradeoff is real, especially in cross-border offerings where disclosure norms differ and some marketing language is legally permissible but still misleading in context.
Guidance versus consensus is not uniform here. There is no universal standard for when promotional exaggeration becomes fraud, so compliance teams should focus on objective indicators: falsified identities, unprovable claims, concealed compensation, and selective omission of material facts. A weak project can be overhyped without being fraudulent, but once claims are knowingly false or designed to manufacture false credibility, the case moves into fraud-risk territory.
Edge cases also include meme-driven ICOs, experimental token launches, and private sales that look informal but still solicit capital from a broad audience. In those situations, the practical question is not whether the issuer is innovative, but whether the claims are auditable. The Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs is a useful reminder that lifecycle discipline matters: if governance, ownership, and evidence are not established early, later remediation is usually too late. For broader AML and KYC expectations, the FATF Recommendations — AML and KYC Framework remains relevant where fundraising, identity, and source-of-funds checks overlap.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM-01 | Fraud screening depends on clear governance and risk ownership. |
| NIST SP 800-53 Rev 5 | AU-2 | Auditable records are essential when claims or approvals are disputed. |
| NIST AI RMF | AI RMF helps structure trustworthy evidence and accountability checks. | |
| OWASP Non-Human Identity Top 10 | NHI-01 | Misleading claims often hide weak ownership and identity provenance. |
Assign a named owner for ICO fraud triage and require documented risk acceptance before public solicitation.
Related resources from NHI Mgmt Group
- How should security teams reduce fraud risk when digital identities are reused across multiple apps and services?
- How should security teams govern non-human identities for compliance?
- How should security teams govern non-human identities for SOC 2 compliance?
- Why do non-human identities create compliance risk even when policies exist?