Case Library / Deepfake & Synthetic Media / Binance CCO Patrick Hillmann's Alleged Deepfake 'Hologram' Listing Scam Claim (2022)

Binance CCO Patrick Hillmann's Alleged Deepfake 'Hologram' Listing Scam Claim (2022)

Binance CCO Patrick Hillmann claimed scammers built an AI deepfake "hologram" of him from his TV interview footage and used it in live Zoom calls to convince crypto project teams they'd had real Binance token-listing meetings, a claim corroborated only by Hillmann's own account and unnamed secondhand reports, with no independent technical verification or publicly released video/audio evidence of the alleged deepfake.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

In mid-2022, Patrick Hillmann, then Binance's Chief Communications Officer, publicly claimed that an unidentified scam operation had built an AI deepfake "hologram" of him using footage from his prior television and news-media interview appearances, and deployed this synthetic video likeness in live Zoom calls with representatives of various crypto and blockchain projects, posing as Hillmann to discuss supposed opportunities to get the target's token listed on Binance, a process Hillmann said he has no personal authority over. Hillmann said he became aware of the scheme only indirectly, when people he had never met began thanking him for "meetings" that had never occurred, and that at least four separate groups told him they'd had such calls. He first disclosed the incident via a Binance company blog post titled "Scammers Created an AI Hologram of Me to Scam Unsuspecting Projects," published on Binance's blog on August 17, 2022 (per the page's own dateline and Wayback Machine archival captures beginning August 18, 2022). The claim reached wide public and press attention six days later, on August 23, 2022, when Hillmann posted about it on his own LinkedIn and tech outlets including The Verge, The Register, PCMag, Malwarebytes, and Gizmodo picked up the story the same day, warning the crypto community and stating Binance's cyber forensics team was investigating. However, the technical claim at the center of the story, that a real deepfake video was used, rests entirely on Hillmann's own account: the only evidence he has ever made public is a screenshot of a text chat with an anonymous individual, and he told The Verge he had personally seen only a "still capture," which Binance chose not to release. Contemporaneous reporting flagged this gap explicitly: The Verge's subhead read "There's no hard evidence that deepfakes were used, though," and Malwarebytes wrote that "no footage of these fakes currently exists," questioning whether a real-time deepfake video call was technically plausible in 2022 versus a simpler, less sophisticated fake. No independent forensic analysis, law-enforcement confirmation, or third-party technical validation of the deepfake claim has ever surfaced. No verified financial loss total, arrest, or named perpetrator has been publicly confirmed; a separate, unverified LinkedIn commenter's claim of a $250,000 token-fraud outcome tied to one project was likewise never corroborated by any primary source.

How the Attack Worked

According to Hillmann's own account, which is the sole source for the technical claim and has never been independently corroborated, an unidentified group ("a sophisticated hacking team," in his words) scraped his public television and news-interview appearances to train an AI deepfake model that could reproduce his face and likeness in live or near-live video. He says this synthetic "hologram" was used in live Zoom video calls and online meetings with representatives of various crypto/blockchain projects, presenting itself as Binance's actual chief communications officer discussing token listing opportunities on the exchange, a topic Hillmann said he has no operational role in. The scam allegedly operated entirely outside Binance's own platforms, with initial contact and coordination happening on Telegram and LinkedIn. Hillmann says he discovered the operation only indirectly, after receiving unsolicited thank-you messages from people referencing "meetings" with him that never took place; at least four separate groups reportedly told him they'd had video calls with someone using his likeness. Critically, the only evidence Hillmann has ever made public is a screenshot of a text chat with an anonymous individual who claimed to have had a Zoom call with him. He told The Verge he had personally "only seen a still capture of the supposed deep fake" shared by one team, and declined to release it, citing advice from Binance's investigations team about preventing copycats. No video, audio, or forensic sample of the alleged deepfake has ever been published. The Verge's own headline framing noted "there's no hard evidence that deepfakes were used, though," and Malwarebytes' contemporaneous writeup stated "no footage of these fakes currently exists" and explicitly questioned whether a real-time deepfake video call was even technically plausible with 2022-era technology, versus simpler explanations (e.g., a low-quality pre-recorded loop, or a scammer describing an ordinary video call using the word "hologram" loosely). In short: a real, well-documented disclosure event occurred (Hillmann/Binance publicly claimed a deepfake was used against multiple crypto projects), but the underlying AI/deepfake mechanism itself rests entirely on that single interested party's uncorroborated account and unnamed secondhand reports, with no independent technical, forensic, or third-party validation.

The Lure & the Tell

Lure: a Zoom call with what appeared to be Binance's actual Chief Communications Officer, discussing the prospect of getting the target's token listed on Binance, an extremely high-value, credibility-conferring opportunity for any crypto project, delivered by a real, recognizable, named executive rather than an anonymous contact. Tell (in hindsight): the "meetings" existed only in the scam targets' experience. Hillmann himself had no record of or memory of ever taking those calls, and he began surfacing the fraud only because targets started thanking him unprompted for sessions he never attended. Other red flags: outreach and coordination occurred off Binance's official channels (Telegram/LinkedIn rather than verified corporate contacts), and the "opportunity" centered on listing decisions Hillmann said he has no authority over. Evidentiary caveat: the only artifact ever produced to substantiate the deepfake claim itself is a text-chat screenshot with an anonymous party. No video/audio sample exists publicly, so the specific "deepfake" mechanism is a claim to be treated with appropriate skepticism even as the broader disclosure/warning is well documented.

Outcome

Binance and Hillmann publicly disclosed the alleged scheme via a Binance company blog post ("Scammers Created an AI Hologram of Me to Scam Unsuspecting Projects"), first published August 17, 2022, followed by Hillmann's own LinkedIn post and broad tech-press pickup on August 23, 2022, warning the crypto community. Binance said its cyber forensics/investigations team was looking into the activity and urged anyone contacted about "listing opportunities" purportedly from Binance staff to verify through official channels (e.g., Binance Verify) and report suspicious contacts. No arrests, indictment, or named suspect have been publicly confirmed. No verified aggregate financial loss figure was ever published; the incident's documented "outcome" is limited to public awareness/warning rather than a confirmed recovery, prosecution, or quantified victim loss. Confirmation-status note: the public disclosure event itself (Hillmann/Binance made this claim, it was widely reported, multiple outlets corroborate the timeline and quotes) is solidly documented. However, the underlying technical claim that this bulletin is filed under, that a real-time AI deepfake video was actually used, has never been independently verified. It rests solely on Hillmann's first-person account and unnamed secondhand "target" reports; no forensic report, released video/audio sample, law-enforcement confirmation, or third-party technical analysis has ever surfaced. The "confirmed" field on this record is set to false to reflect that the AI/deepfake mechanism specifically, as opposed to the fact that a disclosure and warning occurred, remains an unverified, single-source claim as of this check.

Why It Matters

This case is one of the earliest and most frequently cited examples in deepfake-fraud literature of a claimed real-time deepfake video used to impersonate a specific, named, senior corporate executive in live video calls for financial fraud, but it is equally instructive as a case study in the evidentiary limits of self-reported AI-incident claims. The disclosure (a real executive publicly warning that he was impersonated) is well documented across many outlets; the underlying mechanism (an actual AI deepfake, as opposed to some lower-tech impersonation, a mislabeled ordinary video call, or exaggeration) was never independently verified by forensic examination, released media, or law enforcement, and contemporaneous tech press (The Verge, Malwarebytes) said so explicitly at the time. That gap matters for anyone using this case as evidence of "deepfake video fraud in the wild" circa 2022: it is best cited as "a senior executive's public, uncorroborated claim of being deepfaked" rather than as a technically confirmed deepfake attack. It nonetheless usefully foreshadowed the pattern of deepfake-video-call business fraud that became unambiguously documented later (e.g., the 2024 Arup/Hong Kong ~$25M deepfake-CFO video-conference fraud, which did involve verified financial loss), and it pushed Binance and the crypto industry to publicly promote out-of-band identity verification (e.g., Binance Verify) as a countermeasure regardless of whether the specific deepfake claim is ever substantiated.

Defenses

Binance's own recommendation (and general best practice derived from the case): verify any executive's identity through official corporate channels (e.g., Binance Verify) rather than trusting a video call alone, treat "surprise" listing/business-opportunity outreach from a senior exec as a red flag worthy of independent confirmation, be skeptical of urgency/opportunity framing tied to a well-known brand name, and report suspicious contact to the company's official security/cyber-forensics team. Binance itself noted that its verification tooling is not foolproof and can be spoofed, underscoring that live video presence is no longer assumed sufficient proof of identity, especially for high-value financial asks like advance listing fees. Note: because the deepfake mechanism itself is unverified in this case, the more universally applicable lesson is procedural (independent out-of-band verification of any "surprise" executive contact) rather than a lesson about deepfake-detection specifically.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and synthetic-asset preparation: per Hillmann's account, an unidentified group sourced his publicly available television and news-interview footage, material readily available given his role as a named, media-facing executive, as likely training data for a synthetic video likeness, while separately identifying crypto/blockchain project teams as plausible targets for a Binance-listing pitch.
Countering Stage 1: A media-facing executive's public television and interview footage cannot realistically be suppressed, so the practical control sits downstream, at hardening how 'meetings' referencing that executive get verified, rather than trying to eliminate the source footage attackers could draw on.
2
Persona and channel setup: consistent with Hillmann's broader warning of 'a recent spike in hackers pretending to be Binance employees and executives on platforms such as Twitter, LinkedIn, Telegram,' the operation likely relied on impersonation-friendly social/messaging accounts on those platforms rather than any compromise of Binance's own systems.
Countering Stage 2: Proactive brand and executive-impersonation monitoring across LinkedIn, Twitter, and Telegram, paired with rapid takedown requests, shrinks the window a fake persona can operate in before being reported and removed.
3
Initial contact and lure: targets were approached, per The Verge, on Telegram and LinkedIn with the prospect of getting their token listed on Binance, an opportunity valuable enough to a crypto project that it would justify taking an unscheduled meeting with a senior Binance communications executive.
Countering Stage 3: Treat unsolicited 'listing opportunity' outreach that invokes a named executive over Telegram or LinkedIn, channels outside a company's official ecosystem, as inherently suspect, and confirm through a verified corporate channel (Binance itself pointed to its Binance Verify tool) before engaging further.
4
Credibility-building live video meeting (mechanism unverified): targets reported being placed on Zoom calls with what they believed was Hillmann himself; Hillmann's own claim is that this was an AI deepfake/'hologram' built from the sourced footage, though The Verge and Malwarebytes both note no video/audio sample was ever released and questioned whether real-time deepfake video was technically plausible in 2022, so a lower-tech impersonation cannot be ruled out.
Countering Stage 4: Live video presence should not, by itself, be treated as proof of identity for a high-value business decision; independently calling back through a separately confirmed corporate contact defeats a synthetic-video impersonation even when the video is convincing, which is why Binance's own guidance stressed out-of-band verification over trusting the call.
5
Advance-fee request: having established apparent legitimacy through the video meeting, the scheme's structure (per Hillmann's own comparison to 'the old Nigerian prince scam') would have moved targets toward paying an upfront fee to secure the promised token listing.
Countering Stage 5: Standard procurement and legal review of any upfront payment tied to a business opportunity, especially one as unusual as paying a fee to a named individual executive rather than a corporate billing channel, would flag the advance-fee structure regardless of how credible the preceding pitch appeared.
6
Payout and fund conversion (objective completion, unverified): the only concrete loss figure tied to this pattern is an uncorroborated LinkedIn comment from a project representative (Sahr Johnny) describing roughly $250,000 in AFR tokens obtained through the scheme and then dumped on the Stellar decentralized exchange, crashing its price roughly 98%, which if accurate would represent the scheme's cash-out step.
Countering Stage 6: Once funds or tokens are paid out and converted on a public decentralized exchange, recovery is largely infeasible; the realistic control point is upstream at Stage 5, blocking the fee payment itself, since after-the-fact blockchain tracing rarely enables recovery of already-dumped assets.
Quick Facts
Victim
Binance (Patrick Hillmann, then Chief Communications Officer), impersonated as the vector, per his own unverified account; the alleged defrauded parties were unnamed crypto/blockchain project teams who said they believed they were meeting with the real Hillmann about a Binance token listing
Location
Global / remote. Victims contacted via Zoom, Telegram, and LinkedIn; no single physical location, disclosed by Binance (headquartered/operating globally as a crypto exchange)
Date
2022-08-23
Impact
No verified public dollar-loss total was disclosed by Binance or Hillmann. One unverified LinkedIn commenter (Sahr Johnny) alleged a crypto project lost roughly $250,000 worth of "AFR" tokens that were then dumped on the Stellar DEX (a ~98% price crash), but this claim was not corroborated by Binance, Hillmann, or any primary/secondary source found. It is flagged here as an unverified allegation, not a confirmed figure.
Status
Alleged
Case Type
Real-World Incident
Sector
Cryptocurrency & Digital Assets
Related

Related Cases

DPRK RevGen Massachusetts Scheme: Wang Brothers' Laptop Farms and Shell Companies for North Korean IT Workers

Two New Jersey men ran US "laptop farms" and shell companies that let North Korean IT workers pose as American…

Incident 2021Read →

Deepfake Martin Lewis/Elon Musk Investment Scam Costs Brighton Man £76,000 via Fake Revolut Account "Carl"

A Brighton-area kitchen fitter lost roughly £76,000, including four loans he was pressured into taking out, after a Facebook ad…

Incident 2023Read →

LastPass Employee Foils AI Voice Deepfake of CEO Karim Toubba (2024)

An attacker impersonated LastPass CEO Karim Toubba with an AI voice clone over WhatsApp, but the targeted employee spotted the…

Incident 2024Read →