Fideuram, one of Italy's largest private banking groups, was hit by an AI voice scam that converted at least 36 million euros into cryptocurrency, according to a report from WuBlockchain published on October 2, 2026. The case puts a specific, large number on a threat that security teams have been warning about for two years: synthetic voices used to authorize high-value transfers that end up on a blockchain.
The attack moved private-bank money on-chain
The core facts from the source are narrow and worth stating plainly. An AI-generated voice was used in a scam against Fideuram, and at least 36 million euros was converted into crypto as a result. WuBlockchain is the reporting source for the figure and the method. Additional details on exactly how the voice was deployed, which accounts were drained, and where the funds ultimately landed were not confirmed at the time of writing.
Fideuram sits inside the Intesa Sanpaolo group and manages money for wealthy Italian clients. That profile matters. Private-banking relationships run on trust, phone calls, and personal relationship managers, which is precisely the surface that a cloned voice is built to exploit. A fraudster who can imitate a known client or a senior banker does not need to break any cryptography. They need one person on the other end of a call to believe the voice and act on it.
Cloned voices exploit the human approval step before money moves
Voice cloning has gotten cheap and fast. A short clip of someone speaking, pulled from a podcast, an earnings call, or a voicemail greeting, can be enough to generate convincing speech on demand. The attack does not target a wallet or a smart contract. It targets the human approval step that still sits in front of most large money movements.
The crypto angle here is the exit, not the entry. Funds that start as euros inside a regulated bank get converted and pushed on-chain because that is where settlement is fast and reversal is hard. Once value lands in a self-hosted wallet and gets bridged or swapped, clawing it back depends on exchanges freezing it quickly or law enforcement tracing it. That is a very different recovery process from a disputed card charge or a reversed wire.
It is worth separating two layers of risk for readers who hold crypto themselves. The Fideuram case is a social-engineering failure at a bank, not a flaw in any blockchain. The lesson transfers anyway: the weakest link in moving money is almost always a person being convinced to approve something, and AI has made that person far easier to fool.
Recovery depends on speed and stablecoin controls
Stolen funds that travel through centralized rails can sometimes be frozen. Issuers of major stablecoins have shown they will freeze balances tied to illicit activity, as Tether's freezes of hundreds of millions in flagged USDT this year demonstrate. Exchanges can also lock deposits if alerted fast enough. The window is short. The more hops the funds make across chains and mixers, the lower the odds of recovery.
Regulators and courts have been building the machinery to return money to victims, though it moves slowly. In the UK, the FCA has won confiscation orders to repay crypto fraud victims, a sign that recovery is possible but rarely quick or complete. Cases that route stolen funds into crypto, such as the Georgia banker charged over a 932,000 dollar scheme funneled through Coinbase, show the same pattern: fiat fraud, crypto exit, a trace-and-freeze race afterward.
Practical takeaways for anyone moving large sums
For individuals, the defense is procedural, not technical. Treat any urgent voice request to move money as suspect, even when the voice is familiar. Verify through a separate channel you initiated, not a number or link the caller provides. Agree on a verbal code word with family members or business partners for high-stakes requests. For crypto specifically, slow down before signing: use a hardware wallet, read the transaction, and never approve a transfer because someone on a call said to.
For institutions, the Fideuram case is a prompt to assume voice is no longer proof of identity. Callback verification, dual authorization on large transfers, and out-of-band confirmation are the controls that catch this, because they do not depend on recognizing a voice that can now be faked.
The 36 million euro figure is the headline, but the mechanism is the story. A convincing fake voice plus a fast on-chain exit is a repeatable template, and this will not be the last bank to report a version of it.
Overview
An AI voice scam targeting the Italian private bank Fideuram moved at least 36 million euros into cryptocurrency, per WuBlockchain's October 2, 2026 report. The attack exploited human approval rather than any blockchain weakness, and crypto served as the fast, hard-to-reverse exit. Recovery now hinges on how quickly exchanges and stablecoin issuers can freeze the funds. The broader signal: synthetic voices have made social engineering cheap and scalable, and callback verification plus dual authorization are the defenses that still work.



