A Merge scam is a fraud scheme that impersonates an Ethereum network upgrade event to trick users into sending cryptocurrency to an attacker. The scam usually promises an inflated return or a required conversion step. Its effectiveness comes from confusion, urgency, and the appearance of technical legitimacy.
What a Merge Scam Actually Is
A merge scam is a confidence fraud built around a real or imagined blockchain upgrade event. The attacker borrows the language of protocol change, conversion, or migration to make a payment request or wallet action feel urgent and legitimate.
What makes the scheme effective is not technical sophistication on its own, but social engineering layered onto a believable story. The scam depends on the victim accepting that a network event requires immediate action, often with a promise of rewards, preserved access, or a required conversion.
How the Impersonation Works
Merge scams usually copy the visual and rhetorical cues of an official announcement. That can include branded pages, countdown timers, warnings about “upgrading,” and instructions that push the user toward a transaction or signature that benefits the attacker.
The scam is strongest when it imitates a concept users already associate with legitimate ecosystem change. By presenting the request as a necessary response to an upgrade, the attacker reduces scrutiny and turns a normal caution step into a perceived risk of missing out.
Why the Scam Persuades Users
This type of fraud succeeds because it combines confusion with urgency. Many users do not know the operational details of a network upgrade, so they rely on surface cues such as familiar terminology, official-looking language, and the pressure to act quickly.
The core deception is that a technical event is reframed as a user-level obligation. In reality, legitimate protocol upgrades do not require random users to “send funds to verify,” “convert holdings through a special portal,” or follow instructions from an unsolicited message.
Signals That Distinguish It From a Real Upgrade Notice
Real network upgrades are usually communicated through established project channels and do not depend on pressure tactics. A merge scam often stands out because it asks for private keys, demands an immediate transfer, or creates a one-time deadline that cannot be independently verified.
Users should treat any request that changes wallet control, redirects assets, or asks for approval to an unknown contract as high risk. The presence of technical jargon does not make the request credible; legitimacy depends on provenance, channel trust, and whether the action matches the actual mechanics of the claimed event.
Risk and Threat Considerations
Merge scams turn a recognizable infrastructure event into an asset theft path. The main risk is not the upgrade itself, but the attacker’s ability to exploit uncertainty, urgency, and the victim’s assumption that a blockchain event may require immediate wallet action.
Failure mechanism: The scam succeeds when the victim treats the fraudulent request as an operational requirement and authorizes a transfer, signing action, or secret disclosure that hands control or value to the attacker.
Impact: The result is usually direct financial loss, and in some cases continued exposure if the victim also reveals credentials, seed phrases, or wallet permissions that enable follow-on abuse.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK and OWASP API Security Top 10 address the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1566 — Phishing | Merge scams use deceptive messages to induce fraudulent wallet actions. |
| T1656 — Impersonation | The scam relies on pretending to be an official network event or authority. | |
| Recommendation — Map merge-themed lures to T1566 and block unsolicited upgrade claims at the communication layer. Correlate upgrade notices with verified sources before approving any transaction or signature. | ||
| NIST SP 800-53 Rev 5 | SI-10 — Information Input Validation | Users must validate the provenance and legitimacy of inputs that request financial action. |
| IA-5 — Authenticator Management | The scam may seek secrets or credential-like wallet material to gain control. | |
| AU-6 — Audit Record Review, Analysis, and Reporting | Suspicious transfer prompts and approvals need reviewable evidence for investigation. | |
| Recommendation — Validate event provenance before allowing any wallet action prompted by external messaging. Protect and rotate wallet secrets and revoke any exposed credentials immediately. Review transaction logs and message trails for fraudulent approval patterns quickly. | ||
| OWASP API Security Top 10 | API2 — Broken Authentication | Fraudulent upgrade portals often mimic authentication or signing flows to capture control. |
| Recommendation — Verify the authenticity of every signing or login flow before user approval. | ||
Practitioner Guidance
What to watch for: Treat upgrade-themed payment prompts as suspicious unless they are confirmed through the project’s own published channels and match the known mechanics of the event. A real protocol change should be explainable without requiring a victim to rush, guess, or trust an unsolicited link.
Common misunderstanding: Users often assume that technical language implies authenticity. In practice, the scam works precisely because it wraps a simple fraud in a plausible technical narrative, so verification of the source matters more than the sophistication of the wording.
Related resources from NHI Mgmt Group
- What breaks when agents can trigger their own next tasks after a merge?
- How should crypto platforms reduce scam losses without slowing legitimate users?
- Who is accountable when a help desk scam leads to account takeover?
- How should security teams reduce phishing risk when AI makes scam messages more convincing?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org