Rabat – CoinGecko CEO Bobby Ong took to X to warn the cryptocurrency community about a phishing campaign that uses Booking.com branding to promote a pseudonymous Dubai cryptocurrency summit featuring top tech names.
The scam emails, which have been circulating since last October, claimed to be making an “Exclusive Crypto Travel Summit” announcement by Booking.com and Coinbase.
Ong shared screenshots of the phishing attempt yesterday, detailing how the scammers mixed travel and cryptocurrency themes in order to entice recipients into clicking on malicious links.
The email provided private invitations to an event allegedly planned for November 2025 in Dubai and had Vitalik Buterin, co-founder of Ethereum, and Brian Armstrong, CEO of Coinbase, as key speakers.
The email even came with an RSVP deadline of September 30—a date that had already passed—suggesting rushed execution, but it also plays on recipients’ fear of missing out, pushing them toward rash decisions. “Best to just delete such emails,” Ong urged on X, asking Booking.com to investigate.
Booking.com responded to Ong’s X post by acknowledging reports of fake emails and requesting him to share booking information in private so that its team could investigate the incident.
The company did not directly confirm the scam, but offered assistance via official customer support channels. They emphasized that customers should respond only to legitimate Booking.com contacts.
In its own security section, Booking.com advises that people could be phished through email to a webpage that looks closely similar to the Booking.com Extranet log-in page, cautioning people to always closely look at the URL before entering any information.
“Report security issues within 24 hours of a suspected or actual phishing attack,” the report urges.
In 2024, the company also revealed that phishing attacks against its users have risen by 900%, with fraudsters increasingly using its highly trusted brand.
Read Also: Unity Patches Android Game Vulnerability that Threatened Crypto Users
The attacks are typically copies of real booking confirmations or special event promotions, leading victims to fraudulent sites made to capture credentials or digital tokens.
The example illustrates a growing sphere of intersection between the travel and crypto sectors—both ripe to exploit since both involve online transactions and international clients.
In this case, scammers counted on Booking.com’s reputation and the popular, star-studded fame of crypto to imbue their bait with legitimacy.
Security researchers notice that these cons are becoming more advanced in technique but remain rooted in little psychological baits—urgency, exclusivity, and prestige.
The fake summit’s offer of A-list speakers and “exclusive crypto travel partnerships” was just enough enticement to get hasty clicks from unsuspecting recipients.
Scam activities have grown increasingly “industrialized” in leveraging social engineering and advanced digital marketing techniques to exploit users’ trust and fear of missing out, blockchain analytics firm Elliptic says.
The impersonation case is one of a larger movement across the cryptocurrency sector. In September, Binance revealed it had foiled fraudsters posing as listing agents and customer care officers.
Binance CEO Richard Teng warned against phone scammers who pose as customer support personnel and encourage users to change their API keys—a step, in some cases, that led to stolen funds.
Ong reaffirmed that the adversarial nature of cryptocurrency demands perpetual vigilance, reminding users to scrutinize sender addresses and avoid clicking links from unconfirmed sources.
Security researchers echoed this warning as well, stating that strict verification and direct contact with authentic platforms are still the best remedies against phishing scams.








