By Sam Rogers, Associate Director of Product, Scam Alert, Crystal Intelligence
Why Crypto Criminals Strike on Thursdays and Fridays
### Understanding the Weekly Patterns That Put Users at Risk in 2026 ### Crime has a rhythm, and consumers need to know it It is tempting to think of crypto crime as random. A phishing message arrives unexpectedly, a wallet is compromised without warning, or a fraudulent transaction appears to happen at an arbitrary moment. From the perspective of an individual victim, that can certainly be how the incident feels. Aggregated data can reveal a different picture. Crystal Intelligence's analysis has identified a noticeable day-of-week pattern in crypto theft activity. Within the data analysed, the largest amounts of stolen cryptocurrency were concentrated on Thursdays and Fridays, immediately before the weekend. Tuesdays and Wednesdays showed greater levels of attempted malicious activity, while the higher-value successful incidents were more heavily concentrated towards the end of the working week. This does not mean that Thursday and Friday are automatically dangerous, or that criminals stop operating on other days. Crypto scams, phishing campaigns, malware infections and account compromises occur every day. The significance of the pattern is that criminal activity is not always as unstructured as it appears. Attackers can choose when to initiate contact, when to send phishing material, when to test compromised credentials and when to attempt a high-value transfer. Organised groups can also learn from previous campaigns and adapt their timing according to the behaviour of victims, exchanges, financial institutions and security teams. For consumers, the lesson should not be to panic every Thursday afternoon. It should be to recognise that timing can form part of an attacker's strategy. ### Why criminals target late in the week The observed concentration of higher-value incidents later in the week is unlikely to have a single explanation. Human behaviour is one possible factor. By Thursday and Friday, people may be dealing with deadlines, completing administrative tasks or trying to finish work before the weekend. Transactions that would receive careful attention earlier in the week may be completed more quickly when someone is tired, distracted or under pressure. That matters because many forms of crypto theft depend on a very small decision being made incorrectly. A phishing page may require someone to enter credentials. A fraudulent wallet connection may depend on the user approving a transaction they have not properly reviewed. An address-poisoning or impersonation attempt may succeed because a recipient checks only the first and last few characters of an address. A fake customer-support conversation may work because the victim is more concerned with resolving an urgent problem than verifying who is providing the assistance. The Scam Alert typology reflects this wider environment. Account takeover, for example, can begin with phishing, malware, stolen credentials or intercepted authentication information before progressing to unauthorised transfers. Relevant indicators include unusual login activity, unexpected password resets, unfamiliar devices and unrequested authentication prompts. Crypto-specific fraud can create a different route towards the same outcome. The typology identifies cloned websites, wallet-connect prompts delivered through direct messages, fraudulent exchanges and smart-contract drainers among the tools associated with cryptocurrency scams. In all of these situations, the attack does not need the victim to behave recklessly. It may only require them to overlook one abnormal detail during an otherwise routine task. Institutional timing may also matter. Exchanges, financial institutions, technology companies and other service providers operate continuously, but staffing patterns and escalation processes can change around weekends and public holidays. An attacker who succeeds shortly before a lower-staffed period may gain additional time before suspicious activity is identified, escalated and investigated. It is important not to turn this into a universal rule. Crystal's day-of-week data shows an observed pattern. It does not by itself prove that fatigue or weekend staffing causes the pattern. What it does show is that consumers should not assume that the timing of criminal activity is irrelevant. ### Behind the scenes of a developing attack Not every crypto theft begins at the moment the assets are transferred. The visible transaction can be the final stage of activity that began hours or days earlier. Credentials may already have been compromised. A malicious application may already have been installed. A scammer may already have established contact with the victim. A wallet address may already have been introduced into the victim's transaction history. This distinction between preparation and execution is important. A phishing campaign, for example, can begin with large numbers of messages being distributed. Some recipients ignore them. Others click a link. A smaller number submit credentials. The attacker can then decide which compromised accounts are worth exploiting and when to act. Account takeover can follow a similar progression. The Scam Alert typology describes attackers using phishing, malware or social engineering to obtain control of financial accounts or online wallets. Once access has been achieved, unusual logins, password-reset activity or authentication prompts may appear before the eventual attempt to transfer assets. Crypto scams can involve additional technical preparation. A victim may be directed towards a cloned website or fake application, encouraged to connect a wallet or persuaded to approve a transaction that grants permissions they do not fully understand. The final movement of cryptocurrency may therefore occur some time after the first interaction with the malicious infrastructure. This is why increased malicious activity earlier in the week and larger amounts being stolen later in the week should not necessarily be viewed as two unrelated observations. In some cases, early activity may create opportunities that criminals exploit later. However, it would be misleading to suggest that every criminal group follows a fixed Tuesday-to-Friday schedule. Some attacks happen within minutes. Others take months. The Scam Alert typology identifies pig butchering, for example, as an initial-contact and grooming scam characterised by long conversations, movement into private messaging, fraudulent investment platforms, fabricated profits, repeated requests for larger deposits and eventual withdrawal restrictions. That type of operation does not fit neatly into a single working week. The weekly pattern is therefore most useful as a way of understanding aggregate activity and short-cycle attacks, rather than as a timetable that every scammer follows. ### Different threats operate on different timelines Consumers also need to distinguish between the moment a scam begins and the moment cryptocurrency is actually stolen. A phishing attack can develop quickly. Someone may receive an email or message, follow a malicious link and expose their credentials within minutes. If an attacker gains access to an exchange or wallet account, the subsequent attempt to transfer assets may follow almost immediately. Malware can have a longer period of preparation. Banking trojans, information stealers and keyloggers can collect credentials or monitor activity before criminals decide how to use the information they have obtained. The typology identifies unexpected authentication prompts, unfamiliar processes, suspicious account activity and transactions that the user did not initiate as potential warning signals across these forms of compromise. Fraudulent crypto investment schemes operate differently again. A fake trading platform may spend considerable time establishing trust before attempting to extract significant amounts from a victim. The platform can display artificial profits, offer apparently successful early transactions and gradually encourage increasingly large deposits. Romance and pig-butchering scams can extend that process even further. The relationship itself is part of the infrastructure of the crime. The typology describes long-term grooming, movement into WhatsApp or Telegram, fake brokerages or exchanges, apparent investment profits and demands for additional payments when the victim eventually tries to withdraw. These distinctions matter because a weekly statistical pattern should never make someone think they are safe simply because it is Monday. A fake investment platform that contacts someone on a Monday may still be grooming them for a payment weeks later. A malicious application installed on a Wednesday may not be exploited immediately. A compromised password can remain useful to a criminal long after the original phishing message was received. The calendar can tell us something about aggregate criminal behaviour. It cannot replace vigilance against the individual techniques criminals use. ### What this means for everyday crypto users The practical response to the late-week pattern is not complicated: when handling cryptocurrency, create deliberate friction around important decisions. Thursday and Friday are good days to be particularly conscious of this. If you are making a substantial transfer, slow the process down. Verify the destination address independently rather than relying exclusively on a recently copied address or an entry appearing in transaction history. Check the network being used and confirm the transaction details before approving it. The same principle applies to wallet connections. Connecting a wallet to a new application should not become a routine click-through process simply because the interface looks familiar. Fraudulent cryptocurrency services can use cloned websites, fake applications and wallet-connect prompts to imitate legitimate products. Before authorising a transaction or signing a message, understand what permission is actually being requested. Unexpected authentication activity also deserves attention. An unrequested one-time password, password-reset notification, login from a new location or authentication request can indicate that someone else is trying to access an account. These signals should not simply be dismissed because the account still appears to function normally. Consumers should also be careful about allowing urgency to determine how they handle a transaction. Friday-afternoon investment opportunities, unexpected customer-support messages and requests that supposedly must be completed before the weekend should be treated in exactly the same way as they would be on any other day: independently verified before any cryptocurrency is transferred. If anything, urgency should increase scrutiny rather than reduce it. ### Why transaction history can create false confidence One of the reasons crypto transactions require careful checking is that familiar-looking information can itself be manipulated. Users who regularly send cryptocurrency may begin relying on shortcuts. Instead of checking an entire destination address, they may compare only the beginning and end. They may copy an address from a previous transaction. They may assume that an address appearing in their wallet history must belong to someone they have interacted with before. Criminal techniques are designed to exploit these habits. Similarly, a familiar-looking website should not automatically be trusted. The Scam Alert typology identifies cloned sites and fraudulent exchanges among the infrastructure used in cryptocurrency scams. Small differences in a domain name, an advertisement leading to an imitation login page or a direct message containing a wallet-connect link can be enough to redirect a user into infrastructure controlled by a criminal. The safest habit is therefore verification based on an independent source. For an important transfer, confirm the address with the intended recipient through an established channel. For an exchange or wallet service, navigate through a known official website or application rather than an unsolicited message. For an investment platform, investigate the company and regulatory claims separately from the material presented by the person promoting it. These checks can feel repetitive. That is precisely why criminals look for moments when people are likely to skip them. ### The value of recognising preparation signals One advantage consumers have is that the final theft is not always the first visible sign that something is wrong. Phishing attempts, unusual login activity, unexpected authentication prompts, new devices and password-reset requests can all provide warning before an account is fully compromised. A sudden customer-support message following a public complaint can be another signal. So can an unexpected direct message containing a wallet-connect link, an invitation to an unfamiliar investment group or a request to download a new application. These incidents may appear insignificant when viewed individually. They become much more important when considered as possible stages in a wider sequence of activity. If an unexpected authentication request appears on Tuesday and nothing is stolen, that does not necessarily mean there was no threat. It may mean an attempted compromise failed. Changing credentials, reviewing active sessions and enabling stronger authentication at that point can prevent a later attempt from succeeding. The same applies to suspicious cryptocurrency transactions or wallet interactions. A small unexplained transaction, unfamiliar token approval or unexpected interaction with a smart contract should be investigated rather than ignored simply because the immediate financial impact appears limited. Recognising preparation gives users an opportunity to intervene before criminals reach the stage where they can transfer assets. ### How Scam Alert responds during high-risk periods The usefulness of Scam Alert does not depend on every report describing a completed scam. Reports of attempted phishing, suspicious wallet activity, impersonation accounts, fraudulent domains and other indicators can be valuable because they help build a broader picture of criminal infrastructure. A single report may contain a wallet address, transaction hash, domain, social media account or other identifier that appears unrelated to anything else. When similar information emerges from additional victims, relationships between incidents can become clearer. This is particularly important when criminal activity occurs in bursts. Several apparently unrelated reports received over a short period may contain overlapping addresses, websites, communication channels or transaction patterns. Identifying those relationships can help distinguish an isolated incident from a wider campaign. Scam Alert's development is increasingly focused on this intelligence layer. Structured reports create the foundation for clustering related scam activity, developing scam profiles and providing investigator-focused views that help law-enforcement and other authorised partners examine relationships between cases. Blockchain information adds another dimension. Cryptocurrency addresses and transaction hashes can be analysed alongside existing blockchain intelligence to establish whether assets have moved through known services or whether several reports appear connected to the same on-chain infrastructure. This does not mean that every report automatically results in an exchange freezing assets or law enforcement opening an investigation. Those decisions depend on the evidence available, the organisations involved and the applicable legal processes. The important point is that reporting quickly preserves information while it is still operationally useful. ### The danger of waiting until after the weekend Crypto transactions can move quickly. Once stolen cryptocurrency has been transferred from an initial address, criminals may move it again through additional wallets, exchanges, bridges, swap services or other infrastructure. Each additional movement can make the investigation more complicated. That is why waiting until Monday simply because an incident occurred on Friday evening can reduce the usefulness of the information available. The same principle applies to evidence outside the blockchain. Fraudulent websites can disappear. Social media accounts can be deleted. Telegram usernames can change. Messages can be removed and online advertisements can vanish. Capturing this information early helps preserve the context surrounding the transaction. Speed matters, but expectations also need to be realistic. Rapid reporting does not guarantee that stolen cryptocurrency can be intercepted or recovered. Blockchain transfers may be irreversible, assets may already have moved onwards and exchanges or law-enforcement agencies need sufficient information and legal authority before taking action. What rapid reporting can do is increase the amount of useful information available while the incident is still recent. A report made immediately can contain active domains, live social media accounts, current wallet addresses and transaction information that may become harder to reconstruct days later. For victims, the priority should therefore be to document and report what happened as soon as reasonably possible rather than waiting to see whether the situation resolves itself. ### What consumers should change in 2026 Understanding the rhythm visible in crypto crime data should change behaviour without creating a false sense that risk exists only on particular days. Thursday and Friday can be treated as useful reminders to slow down. Before making a large transfer, verify the destination. Before connecting to a new application, check the domain. Before approving a wallet interaction, examine what is actually being authorised. Before responding to an urgent support message, confirm that the account genuinely belongs to the organisation it claims to represent. But those habits should eventually become normal practice throughout the week. The deeper lesson from the data is not simply that criminals appear to achieve larger thefts on Thursdays and Fridays. It is that attackers can adapt their activity around human behaviour. They exploit urgency. They exploit familiarity. They exploit routine. They exploit the assumption that because something has worked safely many times before, it does not need to be checked again. And different forms of scam operate on different clocks. A phishing campaign may move from first contact to attempted theft within hours. An account takeover may involve several stages of credential collection and testing. A fake investment platform may develop over weeks. A pig-butchering operation may groom a victim for months before the largest transfers occur. There is no single criminal schedule. There are, however, patterns. Recognising those patterns gives consumers another source of information when deciding whether something feels normal, whether a transaction needs additional verification and whether suspicious activity should be reported immediately. Criminals study behaviour because predictability creates opportunity. Consumers can use exactly the same principle in reverse: understand where predictable habits create risk, introduce deliberate checks and make successful deception more difficult. Have you had cryptocurrency stolen through a scam, or have you spotted suspicious activity? Report it to Scam Alert here: [https://scam-alert.io/](https://scam-alert.io/)
Categories
Here are some common questions about crypto scams and resources available for victims.

