Researched and last reviewed September 2026 · Written by the GiftMeCrypto research desk
Six patterns, and four rules that stop all of them. No government or company is ever paid in gift cards. Never enter a code anywhere but the brand's own site. A deep discount is priced fraud risk. And nobody legitimate asks you to pay to receive money.
- Most costly pattern
- The impostor-payment call
- Most invisible
- Retail rack card draining
- Most tempting
- The discount resale
- Most technical
- The fake redemption page
- Cruellest
- The recovery scam, second time round
The six patterns
1. The impostor-payment call
This pattern does more financial damage than everything else on this page combined. The script varies — an unpaid tax bill, a warrant, a compromised account, a utility disconnection, a relative in trouble — and the mechanism is always the same: urgency, isolation, and a payment method that cannot be reversed.
Crypto holders are disproportionately targeted, because someone comfortable with irreversible on-chain payments finds reading out a code feels routine. Both are equally unrecoverable. Our Apple gift card page covers this in more detail, because Apple cards are the most demanded instrument.
2. Retail rack card draining
Criminals lift cards from a store display, record the numbers and PINs or replace the packaging with tampered cards, and put them back. Automated systems poll the numbers. The moment a customer activates one at the till, the balance is spent — frequently within minutes.
- Buy prepaid products digitally. A card issued directly to you cannot have been handled.
- If buying physical, take a card from the back of the rack
- Check for reseals, mismatched barcodes and scratched PIN panels
- Register and check the balance immediately after activation, and keep the receipt
- Report a drained card to the retailer and issuer the same day — recovery is time-sensitive
3. The discount resale
A card offered well below face value on a peer-to-peer or key marketplace. The discount exists because the card was frequently bought with a stolen payment method — and when the original transaction is charged back, the retailer invalidates the code, sometimes weeks later and sometimes after part of the balance has been spent.
4. The fake redemption page
A cloned version of a brand's or voucher issuer's redemption page, ranking in search results or promoted in messages and video descriptions. It looks correct, it accepts your code, and it redeems the code itself. Because a code is a bearer instrument, whoever enters it first keeps the value.
The same family includes "balance checker" and "code verifier" sites, which are the same mechanism with a more innocent framing. Type the brand's domain by hand, every time. Our redemption guide lists the legitimate path for each brand.
5. The seller-side chargeback trap
Aimed at people selling cards for crypto. A buyer receives the code, redeems it, then claims it was invalid to force a refund — or asks to move the trade off-platform first, removing escrow and every protection with it.
- Never leave the platform's escrow. An off-platform request is the opening move of essentially every theft in this market.
- Never release a code on anything except the platform's own confirmation — not an email, not a screenshot, not the buyer's word.
- Keep the purchase receipt. It is your evidence in a dispute.
- Check completed-trade history before rate. Reputation is the only substitute for the balance verification nobody can do.
Detail on our selling guide and Paxful review.
6. The recovery scam
Four rules that stop all six
- No organisation is ever paid in gift cards This single rule eliminates the most expensive pattern entirely, and it has no exceptions worth remembering.
- Enter a code only on the brand's own site, typed by hand Stops fake redemption pages, code checkers and harvesting links.
- Treat a deep discount as a warning, not a bargain Below about 20% off, from an anonymous counterparty, the discount is the fraud rate.
- Money never has to move toward you for you to receive money Real fees are deducted from payouts. Any inbound payment requested before a payout ends the conversation.
If it already happened
- Stop. Whatever the explanation for the next payment, it is the same mechanism.
- If you have unused cards, take them back to the retailer with the receipt, immediately.
- If codes were sent, contact the brand's fraud line and the retailer the same day — some balances can be frozen if reported fast.
- Report it to your national fraud reporting service, using contact details you look up yourself.
- Preserve evidence — screenshots, phone numbers, domains, transaction hashes, order IDs.
- Refuse every recovery offer. See pattern six.
We cannot recover funds and neither can anybody who claims they can — see what we cannot help with.
What to teach a family member
Three sentences, in plain language, that cover most of the risk for someone who does not follow this subject.
For a child specifically, our Roblox page has the equivalent three sentences for game currency scams, which are the version they will actually encounter.
In terms of money lost, the impostor-payment call does more damage in this category than every markup, network fee and voucher charge on this website combined. It is not a crypto problem and it is not a sophisticated one — it is a phone call and a supermarket rack.
Which is why the one rule worth memorising is the one about organisations never being paid in gift cards. It requires no technical knowledge, it has no exceptions, and it protects the people most likely to be targeted — who are frequently not the people reading pages like this one. Tell somebody.