In a P2P triangle fraud, the person sending bank money may not be the person buying the crypto. A fraudster places themselves between a payer and a seller, gives the payer the seller’s bank details, and receives the seller’s crypto. Both visible participants may have lost value while the beneficiary disappears.
This is why a bank receipt, a completed order and a withdrawal hash can all be authentic without proving a lawful transaction between the people now disputing it. The investigation must reconstruct the instructions that connect them.
One transaction, three different understandings
Consider this hypothetical example. Elena sees an advertisement for equipment and agrees to pay TRY 96,000. A fraudster, using another identity, opens a P2P order to buy USDT from Cem for the same amount. The fraudster tells Elena to pay Cem’s IBAN, presenting it as the equipment supplier’s account. Cem receives the exact lira amount and releases USDT to the platform buyer. Elena receives no equipment.
Elena, deceived payer → Cem, crypto seller: TRY 96,000 bank transfer, intended by Elena as payment for equipment.
Cem → platform buyer controlled by the fraudster: USDT release, intended by Cem as performance of the P2P sale.
Fraudster → Elena and Cem: different instructions that make the two transfers appear connected.
The example establishes neither Cem’s innocence nor his guilt. Was the payer-name mismatch visible? Did Cem ask about it? Was this an isolated event or part of a repeated arrangement? Did he communicate with the fraudster about disguising the payment? Did Elena see any representation actually made by Cem? Each question requires evidence.
Why a third-party payment matters
Many platform trading rules require the payment account name to match the verified buyer. The OKX P2P transaction rules, for example, address payment-account identity and counterparty safeguards. The applicable entity, product, transaction date and rule version must still be checked. A global platform’s help page is not a Turkish statute or proof of local authorisation.
The mismatch is a warning because it breaks the simple inference that the contracting buyer paid the seller. A reference containing the order number does not repair this: the fraudster can instruct the victim to copy that reference. Nor does a screenshot of an identity document establish that its holder authorised the order or payment.
There can be non-fraud explanations for differences in displayed names, including transliteration, corporate accounts or truncated banking fields. Preserve the original display and seek verifiable clarification through the platform. Do not turn an unexplained discrepancy into a private exception to the platform’s rules. The foreign-user guide deals with name and document reconciliation.
Before release: verify the event, not the reassurance
The seller should verify an actual credit in their own bank channel, not rely on the buyer’s “paid” status or forwarded receipt. Compare amount, sender, reference and timing with the order. Check whether the funds are credited, pending, returned or merely represented in an image. Keep messages inside the supported transaction channel and preserve any request to move to an external chat.
If the payer differs from the verified buyer, pause release and use the platform’s dispute process. A statement that “my assistant always pays” is a claim to be tested. A private promise of indemnity may be unenforceable or practically worthless and does not bind the payer, bank or prosecutor. Platform safeguards should be followed even when the trade is urgent.
The escrow and appeals guide explains the limits of holding crypto in reserve. Escrow reduces some delivery risks; it does not authenticate the origin of bank funds. Once release occurs, a platform’s ability to recover the balance may depend on whether the buyer has withdrawn or moved it.
After release: two evidence files, one joined chronology
| The payer should preserve | The seller should preserve | The connecting question |
|---|---|---|
| Advertisement, false promise, website and communications | P2P advertisement, order and full chat | Who issued the bank instruction and who knew its purpose? |
| Original transfer receipt and bank statement | Credited transfer record with payer details | Is this the same payment, and was it reversed? |
| The account or wallet details supplied by the fraudster | Platform UID, release record and withdrawal information | Which account benefited from the crypto? |
| Contacts, timestamps and complaint records | Name-mismatch warnings, dispute tickets and login records | What was known before release, as distinct from learned later? |
Do not assume the later blockchain destination belongs to the registered platform buyer. It may be a custodial deposit address, an intermediary contract or another victim’s wallet. The platform’s internal ledger connects the P2P order to a user balance; withdrawal and account-control records connect that balance to the next event. A service label on an explorer is a lead, not proof of a person’s identity.
Use a single chronology with both participants’ records. Preserve original time zones. If a bank payment predates the P2P order, do not silently adjust the time to fit the narrative. Check whether the display uses a different zone, the wrong order was matched or the alleged sale was reconstructed afterwards. The evidence-file guide gives a practical reconciliation method.
Does receiving the victim’s money establish criminal liability?
It establishes an evidential connection that may justify further investigation. It does not, by itself, establish the recipient’s role in deception or knowing assistance. A careful file asks whether the seller controlled the fraudulent communications, shared devices or accounts, received compensation inconsistent with an ordinary trade, or continued a pattern after being alerted to victim-linked payments.
The inquiry must also test favourable evidence. Contemporaneous orders, independently documented crypto acquisition, ordinary pricing, warnings raised before release and lack of links to the false advertisement may matter. No single item should be promoted into an automatic defence. A fabricated order can look orderly; a genuine order can be knowingly used to convert criminal proceeds.
In Yargıtay 11th Criminal Chamber, E.2024/3673, K.2024/10848, 30 September 2024, arguments that the funds were believed to relate to crypto and that the commission was only 3% did not prevent affirmance of fraud convictions. The reasons are concise, so the decision should not be expanded into a universal rule about all P2P sellers. It is an adverse example showing that a crypto explanation must withstand the complete evidence.
Later law must also be considered. Law No. 7589 introduced a reduced-sentence provision for a defined form of participation limited to supplying specified account-access means for unjust benefit. It does not erase the need to establish participation and intent; it does not immunise the person who orchestrates the deception. See the P2P criminal-investigation guide for the wider analysis.
Can the payer recover from a seller who delivered crypto?
The criminal and civil questions are different. A payer may seek restitution or damages without proving that every recipient personally committed the fraud. A seller may argue that they provided value under a genuine agreement. The court must examine who contracted with whom, who authorised payment, to whom delivery was due and whether the claimed legal basis for retaining the money exists.
In Istanbul 16th Commercial Court, E.2022/852, K.2024/767, 21 November 2024, a company relied on a crypto-conversion explanation for funds transferred after a fraudulent investment approach. The court found the claimed mandate and delivery to the claimant unproved and ordered restitution. This is a first-instance decision with an appeal route recorded in the text; finality is not established here. Its lesson is evidential: saying “we sent Tether” is not equivalent to proving authorised performance for that claimant.
The civil-disputes guide explains how a contractual claim differs from unjust enrichment and interim attachment. It also addresses the risk of double recovery when a platform reimbursement, bank return, voluntary settlement and court claim overlap.
Why an improvised refund can produce a second loss
After the complaint, someone may demand a refund to an account different from the original payer’s, claiming the first account is closed or blocked. That request may come from the fraudster. Verify the claimant through reliable channels, check whether a reversal or seizure already exists, and establish the recipient and legal basis before making any payment.
A properly documented resolution should identify the original transfer, order, amount and currency; address any crypto already delivered; specify what is being repaid and to whom; and account for existing institutional or official measures. It should not require anyone to falsify records or promise that a prosecutor will close a case. Private parties cannot guarantee a public authority’s decision.
What to ask a platform to preserve
Use the order ID and a defined time range. Identify the two platform UIDs, advertisement, payment instructions, full chat, release authorisation, internal debit and credit entries, appeal history, relevant login and security events, and the subsequent withdrawal request. A user may not be entitled to receive the other person’s confidential KYC or device data directly; preservation and formal production are separate requests.
If the funds reach an identifiable custodian, provide the network, token contract, transaction hash, destination and timing to the competent authority and the custodian’s proper reporting channel. A private notice is not a court order and does not guarantee a freeze. The existing asset-recovery guide explains the broader preservation strategy.
Mistakes that weaken both parties’ positions
Do not contact the other participant to coordinate stories, remove contradictory messages, publish private identity documents, or accuse a wallet owner solely from a label. Do not describe every third-party payment as money laundering or every seller as innocent. The relevant conclusion depends on conduct, knowledge, authority and the actual flow of value.
A useful report leaves the reader able to follow the bank payment into the seller’s account and the crypto into the buyer’s balance, while identifying the missing evidence between those systems. That is the point at which competing explanations can be tested. Return to the Turkish P2P law guide for the connected regulatory and account-freeze questions.
