Join our Newsletter — 33% off our NHI Course

Merge Scam

A Merge scam is a fraud scheme that impersonates an Ethereum network upgrade event to trick users into sending cryptocurrency to an attacker. The scam usually promises an inflated return or a required conversion step. Its effectiveness comes from confusion, urgency, and the appearance of technical legitimacy.

What a Merge Scam Actually Is

A merge scam is a confidence fraud built around a real or imagined blockchain upgrade event. The attacker borrows the language of protocol change, conversion, or migration to make a payment request or wallet action feel urgent and legitimate.

What makes the scheme effective is not technical sophistication on its own, but social engineering layered onto a believable story. The scam depends on the victim accepting that a network event requires immediate action, often with a promise of rewards, preserved access, or a required conversion.

How the Impersonation Works

Merge scams usually copy the visual and rhetorical cues of an official announcement. That can include branded pages, countdown timers, warnings about “upgrading,” and instructions that push the user toward a transaction or signature that benefits the attacker.

The scam is strongest when it imitates a concept users already associate with legitimate ecosystem change. By presenting the request as a necessary response to an upgrade, the attacker reduces scrutiny and turns a normal caution step into a perceived risk of missing out.

Why the Scam Persuades Users

This type of fraud succeeds because it combines confusion with urgency. Many users do not know the operational details of a network upgrade, so they rely on surface cues such as familiar terminology, official-looking language, and the pressure to act quickly.

The core deception is that a technical event is reframed as a user-level obligation. In reality, legitimate protocol upgrades do not require random users to “send funds to verify,” “convert holdings through a special portal,” or follow instructions from an unsolicited message.

Signals That Distinguish It From a Real Upgrade Notice

Real network upgrades are usually communicated through established project channels and do not depend on pressure tactics. A merge scam often stands out because it asks for private keys, demands an immediate transfer, or creates a one-time deadline that cannot be independently verified.

Users should treat any request that changes wallet control, redirects assets, or asks for approval to an unknown contract as high risk. The presence of technical jargon does not make the request credible; legitimacy depends on provenance, channel trust, and whether the action matches the actual mechanics of the claimed event.

Risk and Threat Considerations

Merge scams turn a recognizable infrastructure event into an asset theft path. The main risk is not the upgrade itself, but the attacker’s ability to exploit uncertainty, urgency, and the victim’s assumption that a blockchain event may require immediate wallet action.

Failure mechanism: The scam succeeds when the victim treats the fraudulent request as an operational requirement and authorizes a transfer, signing action, or secret disclosure that hands control or value to the attacker.

Impact: The result is usually direct financial loss, and in some cases continued exposure if the victim also reveals credentials, seed phrases, or wallet permissions that enable follow-on abuse.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK and OWASP API Security Top 10 address the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
MITRE ATT&CK T1566 — Phishing Merge scams use deceptive messages to induce fraudulent wallet actions.
T1656 — Impersonation The scam relies on pretending to be an official network event or authority.
Recommendation — Map merge-themed lures to T1566 and block unsolicited upgrade claims at the communication layer. Correlate upgrade notices with verified sources before approving any transaction or signature.
NIST SP 800-53 Rev 5 SI-10 — Information Input Validation Users must validate the provenance and legitimacy of inputs that request financial action.
IA-5 — Authenticator Management The scam may seek secrets or credential-like wallet material to gain control.
AU-6 — Audit Record Review, Analysis, and Reporting Suspicious transfer prompts and approvals need reviewable evidence for investigation.
Recommendation — Validate event provenance before allowing any wallet action prompted by external messaging. Protect and rotate wallet secrets and revoke any exposed credentials immediately. Review transaction logs and message trails for fraudulent approval patterns quickly.
OWASP API Security Top 10 API2 — Broken Authentication Fraudulent upgrade portals often mimic authentication or signing flows to capture control.
Recommendation — Verify the authenticity of every signing or login flow before user approval.

Practitioner Guidance

What to watch for: Treat upgrade-themed payment prompts as suspicious unless they are confirmed through the project’s own published channels and match the known mechanics of the event. A real protocol change should be explainable without requiring a victim to rush, guess, or trust an unsolicited link.

Common misunderstanding: Users often assume that technical language implies authenticity. In practice, the scam works precisely because it wraps a simple fraud in a plausible technical narrative, so verification of the source matters more than the sophistication of the wording.