Binance CCO Patrick Hillmann claimed scammers built an AI deepfake "hologram" of him from his TV interview footage and used it in live Zoom calls to convince crypto project teams they'd had real Binance token-listing meetings, a claim corroborated only by Hillmann's own account and unnamed secondhand reports, with no independent technical verification or publicly released video/audio evidence of the alleged deepfake.
Reviewed by the Social Engineering Examples team.
In mid-2022, Patrick Hillmann, then Binance's Chief Communications Officer, publicly claimed that an unidentified scam operation had built an AI deepfake "hologram" of him using footage from his prior television and news-media interview appearances, and deployed this synthetic video likeness in live Zoom calls with representatives of various crypto and blockchain projects, posing as Hillmann to discuss supposed opportunities to get the target's token listed on Binance, a process Hillmann said he has no personal authority over. Hillmann said he became aware of the scheme only indirectly, when people he had never met began thanking him for "meetings" that had never occurred, and that at least four separate groups told him they'd had such calls. He first disclosed the incident via a Binance company blog post titled "Scammers Created an AI Hologram of Me to Scam Unsuspecting Projects," published on Binance's blog on August 17, 2022 (per the page's own dateline and Wayback Machine archival captures beginning August 18, 2022). The claim reached wide public and press attention six days later, on August 23, 2022, when Hillmann posted about it on his own LinkedIn and tech outlets including The Verge, The Register, PCMag, Malwarebytes, and Gizmodo picked up the story the same day, warning the crypto community and stating Binance's cyber forensics team was investigating. However, the technical claim at the center of the story, that a real deepfake video was used, rests entirely on Hillmann's own account: the only evidence he has ever made public is a screenshot of a text chat with an anonymous individual, and he told The Verge he had personally seen only a "still capture," which Binance chose not to release. Contemporaneous reporting flagged this gap explicitly: The Verge's subhead read "There's no hard evidence that deepfakes were used, though," and Malwarebytes wrote that "no footage of these fakes currently exists," questioning whether a real-time deepfake video call was technically plausible in 2022 versus a simpler, less sophisticated fake. No independent forensic analysis, law-enforcement confirmation, or third-party technical validation of the deepfake claim has ever surfaced. No verified financial loss total, arrest, or named perpetrator has been publicly confirmed; a separate, unverified LinkedIn commenter's claim of a $250,000 token-fraud outcome tied to one project was likewise never corroborated by any primary source.
According to Hillmann's own account, which is the sole source for the technical claim and has never been independently corroborated, an unidentified group ("a sophisticated hacking team," in his words) scraped his public television and news-interview appearances to train an AI deepfake model that could reproduce his face and likeness in live or near-live video. He says this synthetic "hologram" was used in live Zoom video calls and online meetings with representatives of various crypto/blockchain projects, presenting itself as Binance's actual chief communications officer discussing token listing opportunities on the exchange, a topic Hillmann said he has no operational role in. The scam allegedly operated entirely outside Binance's own platforms, with initial contact and coordination happening on Telegram and LinkedIn. Hillmann says he discovered the operation only indirectly, after receiving unsolicited thank-you messages from people referencing "meetings" with him that never took place; at least four separate groups reportedly told him they'd had video calls with someone using his likeness. Critically, the only evidence Hillmann has ever made public is a screenshot of a text chat with an anonymous individual who claimed to have had a Zoom call with him. He told The Verge he had personally "only seen a still capture of the supposed deep fake" shared by one team, and declined to release it, citing advice from Binance's investigations team about preventing copycats. No video, audio, or forensic sample of the alleged deepfake has ever been published. The Verge's own headline framing noted "there's no hard evidence that deepfakes were used, though," and Malwarebytes' contemporaneous writeup stated "no footage of these fakes currently exists" and explicitly questioned whether a real-time deepfake video call was even technically plausible with 2022-era technology, versus simpler explanations (e.g., a low-quality pre-recorded loop, or a scammer describing an ordinary video call using the word "hologram" loosely). In short: a real, well-documented disclosure event occurred (Hillmann/Binance publicly claimed a deepfake was used against multiple crypto projects), but the underlying AI/deepfake mechanism itself rests entirely on that single interested party's uncorroborated account and unnamed secondhand reports, with no independent technical, forensic, or third-party validation.
Lure: a Zoom call with what appeared to be Binance's actual Chief Communications Officer, discussing the prospect of getting the target's token listed on Binance, an extremely high-value, credibility-conferring opportunity for any crypto project, delivered by a real, recognizable, named executive rather than an anonymous contact. Tell (in hindsight): the "meetings" existed only in the scam targets' experience. Hillmann himself had no record of or memory of ever taking those calls, and he began surfacing the fraud only because targets started thanking him unprompted for sessions he never attended. Other red flags: outreach and coordination occurred off Binance's official channels (Telegram/LinkedIn rather than verified corporate contacts), and the "opportunity" centered on listing decisions Hillmann said he has no authority over. Evidentiary caveat: the only artifact ever produced to substantiate the deepfake claim itself is a text-chat screenshot with an anonymous party. No video/audio sample exists publicly, so the specific "deepfake" mechanism is a claim to be treated with appropriate skepticism even as the broader disclosure/warning is well documented.
Binance and Hillmann publicly disclosed the alleged scheme via a Binance company blog post ("Scammers Created an AI Hologram of Me to Scam Unsuspecting Projects"), first published August 17, 2022, followed by Hillmann's own LinkedIn post and broad tech-press pickup on August 23, 2022, warning the crypto community. Binance said its cyber forensics/investigations team was looking into the activity and urged anyone contacted about "listing opportunities" purportedly from Binance staff to verify through official channels (e.g., Binance Verify) and report suspicious contacts. No arrests, indictment, or named suspect have been publicly confirmed. No verified aggregate financial loss figure was ever published; the incident's documented "outcome" is limited to public awareness/warning rather than a confirmed recovery, prosecution, or quantified victim loss. Confirmation-status note: the public disclosure event itself (Hillmann/Binance made this claim, it was widely reported, multiple outlets corroborate the timeline and quotes) is solidly documented. However, the underlying technical claim that this bulletin is filed under, that a real-time AI deepfake video was actually used, has never been independently verified. It rests solely on Hillmann's first-person account and unnamed secondhand "target" reports; no forensic report, released video/audio sample, law-enforcement confirmation, or third-party technical analysis has ever surfaced. The "confirmed" field on this record is set to false to reflect that the AI/deepfake mechanism specifically, as opposed to the fact that a disclosure and warning occurred, remains an unverified, single-source claim as of this check.
This case is one of the earliest and most frequently cited examples in deepfake-fraud literature of a claimed real-time deepfake video used to impersonate a specific, named, senior corporate executive in live video calls for financial fraud, but it is equally instructive as a case study in the evidentiary limits of self-reported AI-incident claims. The disclosure (a real executive publicly warning that he was impersonated) is well documented across many outlets; the underlying mechanism (an actual AI deepfake, as opposed to some lower-tech impersonation, a mislabeled ordinary video call, or exaggeration) was never independently verified by forensic examination, released media, or law enforcement, and contemporaneous tech press (The Verge, Malwarebytes) said so explicitly at the time. That gap matters for anyone using this case as evidence of "deepfake video fraud in the wild" circa 2022: it is best cited as "a senior executive's public, uncorroborated claim of being deepfaked" rather than as a technically confirmed deepfake attack. It nonetheless usefully foreshadowed the pattern of deepfake-video-call business fraud that became unambiguously documented later (e.g., the 2024 Arup/Hong Kong ~$25M deepfake-CFO video-conference fraud, which did involve verified financial loss), and it pushed Binance and the crypto industry to publicly promote out-of-band identity verification (e.g., Binance Verify) as a countermeasure regardless of whether the specific deepfake claim is ever substantiated.
Binance's own recommendation (and general best practice derived from the case): verify any executive's identity through official corporate channels (e.g., Binance Verify) rather than trusting a video call alone, treat "surprise" listing/business-opportunity outreach from a senior exec as a red flag worthy of independent confirmation, be skeptical of urgency/opportunity framing tied to a well-known brand name, and report suspicious contact to the company's official security/cyber-forensics team. Binance itself noted that its verification tooling is not foolproof and can be spoofed, underscoring that live video presence is no longer assumed sufficient proof of identity, especially for high-value financial asks like advance listing fees. Note: because the deepfake mechanism itself is unverified in this case, the more universally applicable lesson is procedural (independent out-of-band verification of any "surprise" executive contact) rather than a lesson about deepfake-detection specifically.
Two New Jersey men ran US "laptop farms" and shell companies that let North Korean IT workers pose as American…
A Brighton-area kitchen fitter lost roughly £76,000, including four loans he was pressured into taking out, after a Facebook ad…
An attacker impersonated LastPass CEO Karim Toubba with an AI voice clone over WhatsApp, but the targeted employee spotted the…