Why USDT Trades Above Market Rate on P2P (And Who Is Actually Paying for It)
This is an update to an earlier piece I wrote on how people get scammed on Binance P2P. Let’s start with the question I get asked constantly: if the real market rate between the Turkish lira and the US dollar is, say, 47, why does USDT trade at 49, 50, even 51 on P2P? Why would anyone pay three or four lira over the actual rate for the same dollar? Most people answer this with the standard line: capital controls, banking friction, demand for dollar exposure. All true, all incomplete. There is a second, uglier layer sitting underneath that premium, and once you see it, you can’t unsee it.

The Recruitment
Let’s say you’re in Turkey, in the middle of the inflation years, scrolling TikTok or Instagram looking for extra income. Up pops a message, often from an attractive profile: “We’re looking for representatives in Turkey.” You move to WhatsApp. The pitch is simple. “We sell on Facebook Marketplace and a few other places. We just need to route funds through your bank account for a while. You keep 15 to 20 percent.” And they pay. On time, every time. $1,000 arrives, then another. You’re clearing $50 to $90 a day for almost no effort. At the real rate that’s roughly 470 lira a day. Keep it up for a month at $1,000 a day and you’ve cleared 30,000 lira. Push it to $2,000 a day and you’re at 60,000 lira, sitting at home. It runs exactly as promised, for weeks. The scam pays out first, on purpose. That’s the whole design.
The Squeeze
Then the holiday lands. Nine days of Bayram, the country closed. Your contact explains their funds are tied up elsewhere and won’t clear in time. No problem, you think, you’ve got savings, you’ll front it for nine days and take your usual cut, this time on $9,000, because you’ve been doing this for months and the relationship has earned trust. You send the $9,000. That is the moment they were waiting for. Their money was never routed through your account to begin with. It was always yours, and it’s gone the second it lands.
Where Your Money Actually Goes
Here’s the part that explains the premium. Your $9,000 doesn’t disappear into nothing. It moves to another account, run by someone in your exact position, who pushes it again to someone selling USDT on P2P. That seller now has a ready buyer for $9,000 worth of coin. The buyer is the person who scammed you, likely sitting in Georgia, Russia, Ukraine, Poland, Cyprus, or Malta, using a Turkish bank account they never had to open themselves. That buyer will happily pay 49 lira per dollar for the USDT. Why? Because it isn’t their money. Overpaying for coin bought with stolen funds costs them nothing real. It’s a wash, funded entirely by you. The premium the market pays for USDT on P2P is, in part, the going rate for buying distance from a crime. When the police report gets filed, and it does, the trail runs straight to you and to the stranger who received your transfer. The person who bought the USDT with your money shows a clean bank statement and a clean explanation: I sold $9,000 worth of USDT, payment came in, I accepted it. Nothing a prosecutor can attach to them. They keep the coin and start the cycle again with someone new.
The Economics of the Racket
One operator doesn’t run this once. A single operation cycles 20 to 30 people through this at any given time, each one good for $1,000 to $20,000 depending on how long they’ve been groomed. Do the maths and one operation clears $50,000 to $100,000 a week. Some of that gets recycled straight back into funding two or three new targets who are still in the trust-building phase, still getting paid on time, still telling friends about the great side income they found. This is not a one-off con. It’s a production line with a payroll, a recruitment funnel, and a settlement layer, and P2P is the settlement layer.
What This Means If You Trade P2P
A premium in any market exists because someone is compensating for a risk they don’t want to hold. In FX and crypto, that’s usually settlement time, liquidity depth, or counterparty exposure. In markets running hot with mule activity, part of that premium is somebody buying distance from a crime, and you are, unknowingly, one of the counterparties funding it. A few practical flags worth carrying with you:
A “job” that only requires your bank account, not your labor, is not a job. It’s an application to become an account.
Fast, reliable payouts for weeks are not proof of legitimacy. They’re the recruitment cost. The scam always pays first.
Any request to front your own money to unlock someone else’s is the tell, every single time, regardless of the story wrapped around it.
A P2P rate meaningfully above the interbank or aggregator rate deserves a “why,” not just a “great.” Sometimes it’s legitimate liquidity premium. Sometimes it’s laundering demand bidding the price up.
The Compliance Angle From where I sit, this is a textbook case of layering, the middle stage of money laundering where illicit funds get moved through multiple parties and instruments to obscure the original source. The mule’s account is the placement layer. The second and third transfers are the layering. The P2P USDT purchase is the integration point, where dirty money becomes a clean-looking crypto position with a plausible paper trail. Banks and exchanges built their KYC and transaction-monitoring programs precisely because this pattern, one account receiving irregular inbound transfers followed by rapid outbound movement, is one of the oldest tells in the book. It still works because the account holder, the mule, genuinely doesn’t know they’re part of it until it’s too late.
Bottom Line
If someone you don’t know is offering you 15 to 20 percent to move money through your own bank account, you are not the vendor in that relationship. You are the account.
—
Tell me more about how the recruitment message works
The recruitment message isn’t random spray-and-pray. It’s a funnel with a specific sequence, engineered to filter for exactly the right kind of target and then move fast off any platform where someone might intervene.

Where it starts: public, low-cost bait
TikTok and Instagram, not because they’re the only platforms available, but because they’re built for exactly this. Short video content with an attractive profile (often a woman, often using stock or stolen photos) posting something vague and aspirational: working from home, easy income, “message me to find out how.” No pitch happens in the public post. That’s deliberate. Public content that explicitly promises money-for-bank-account access gets flagged and removed fast, so the post stays vague and lets the DM do the real work.
The DM: a soft, personal-sounding opener
The message that lands in your inbox reads like it was written for you specifically, even though it’s a template. “We’re looking for representatives in Turkey” does two jobs at once. It sounds like a legitimate business role (a representative, not a launderer), and it flatters the recipient into feeling selected rather than targeted.
The push to WhatsApp
Almost immediately, the conversation moves off Instagram or TikTok DMs and onto WhatsApp. This matters more than it looks. Instagram and TikTok have fraud-detection systems watching DM patterns, and a scammer running this at scale, dozens of parallel conversations, doesn’t want a platform algorithm connecting the dots. WhatsApp is encrypted, has weaker automated fraud detection for this kind of one-on-one manipulation, and once you’re there, there’s no public trail left on the platform where the recruitment started.
The offer is framed as work, not finance
Notice the specific language: “we sell things on Facebook Marketplace and other places, we just need to use your account.” This is not framed as “let us launder money through you.” It’s framed as ordinary e-commerce logistics, a business that needs a local bank account for local sales. That framing matters because it gives the victim a story they can tell themselves, and later tell a bank or a police officer, that sounds mundane rather than criminal.
Why the commission number is exactly what it is
15 to 20 percent is calibrated. High enough to be genuinely attractive against Turkish inflation-era wages, low enough that it doesn’t sound implausible the way “50 percent” would. A number that’s too good triggers skepticism even in an eager target. This one is tuned to sit just inside believability.
Who actually responds
The targeting isn’t personal, it’s economic. Anyone scrolling TikTok for “easy income” during a period of currency devaluation is self-selecting into the funnel. The scammer doesn’t need to identify individuals. The economic conditions do the targeting for them, and the volume of people searching for exactly this kind of opportunity during hard times is what lets one operation run 20 to 30 victims at once without needing a sophisticated targeting system.
The tell, if you’re looking for it
Any message where the “job” is described in terms of what they need from you (your bank account, your patience, your trust) rather than what you’ll actually be doing (no product knowledge required, no hours specified, no real task described) is the signature. Real jobs describe the work. This describes the access.
Tell me more about the trust-building payout phase
This phase is the most expensive part of the operation for the scammer, and also the most important. It’s not overhead. It’s the investment that makes the eventual theft possible.
Why the money is real
The payments during this phase are not fake in any sense. Actual funds land in the victim’s account, actual withdrawals are made, actual profit is pocketed. This is the one part of the whole scheme where nobody gets cheated. That’s precisely the point. A con built entirely on lies collapses the moment someone checks. A con that pays out exactly as promised, for weeks, builds a track record the victim can verify with their own eyes, their own bank statement, their own spending money.
What the scammer is actually buying
Every dollar paid out during this phase is bought skepticism. Think about what it costs to make someone stop asking “is this too good to be true” after the fifth time it worked. It’s not cheap, and that’s exactly why the operation runs on volume, dozens of victims, so the eventual $9,000 to $20,000 extraction from each one comfortably covers the weeks of real payouts made along the way. The trust-building phase is priced into the con the same way a business prices in customer acquisition cost.
The behavioral trap being set
Each successful payout does something specific to how a person evaluates risk. The first payment resolves the initial “is this real” question. The second and third replace suspicion with routine, this is just how the arrangement works now. By week three or four, the victim isn’t evaluating the relationship anymore. They’re managing it, thinking about how to spend the money, maybe recruiting a friend, maybe increasing their own volume voluntarily. The scam has stopped being a question and become a fact of their financial life.
Why the amounts escalate gradually
The daily figures grow over the weeks, not because the scammer needs to, but because escalating amounts do two things. They make the arrangement feel like it’s working and expanding, which reads as legitimate growth rather than suspicious growth. And they normalize larger numbers moving through the account, so that when the eventual $9,000 request comes, it’s not a shocking jump from the pattern. It’s the next step in a trend the victim has already been living inside for weeks.
Why weeks, specifically, and not days
A shorter build-up wouldn’t survive contact with a reasonable person’s instincts. A few days of payments feels like it could still be a setup. Weeks cross a threshold where the human brain stops treating something as a hypothesis under test and starts treating it as an established fact of life. That threshold is different for every person, but the scammer doesn’t need to know exactly where it sits for you individually. They just need to run long enough that most targets in the funnel cross it.
The asymmetry that makes this work
The scammer’s cost during this phase is entirely capital they already control, funds they’re moving between accounts they operate anyway. Nothing they pay the victim during this window is money the scammer didn’t already have and control the destination of. Compare that to the eventual $9,000 extraction, which is money the scammer never had until the victim’s own trust delivered it to them. The entire trust-building phase is a controlled expenditure that unlocks an uncontrolled windfall.
The tell, if you’re inside it
The single clearest signal that you’re in a trust-building phase rather than a genuine arrangement is this: the relationship has been entirely one-directional in risk. You’ve never been asked to verify who they are, meet them, see identification, sign anything, or use a platform with any dispute mechanism. Every payment has flowed toward you, and the arrangement has cost you nothing, until the day it suddenly asks you to front money “just this once.” That structural asymmetry, weeks of zero risk followed by one request that inverts it completely, is the shape of the trap regardless of what story wraps around it.
Tell me more about the holiday squeeze tactic
This is the single moment the entire operation exists to produce. Everything before it is setup. Everything after it is cleanup. The holiday squeeze is where the risk flips from the scammer’s side to the victim’s, and the mechanics of why it works are worth taking apart carefully.
Why a real holiday, not a fake excuse
Bayram is nine days, genuinely observed, genuinely disruptive to business and banking in Turkey. The scammer doesn’t need to invent a plausible reason funds might be delayed, they borrow one that’s already true for everyone. A fabricated excuse invites scrutiny. A real, verifiable event requires none, because the victim already knows the holiday is happening and already expects some disruption to normal financial rhythms during it.
Why the ask flips direction
For weeks, money has moved one way: toward the victim. The squeeze is the first and only time the flow reverses. That reversal is disguised as continuity rather than a break in pattern, “we just need you to cover this one gap,” phrased as if it’s the same arrangement continuing, not a fundamentally different transaction. The victim isn’t being asked to evaluate a new proposition. They’re being asked to extend an existing one, which is a much lower bar cognitively.
Why the timing is airtight
A nine-day closure is long enough to sound like a real liquidity problem, and short enough to sound temporary and low-risk. “Nine days” implies an end date, a return to normal, your money coming back. Compare that to an open-ended request, “can you front some money indefinitely”, which would trigger far more hesitation. The bounded timeframe does real psychological work: it converts an unlimited-sounding risk into what feels like a defined, short-term favor.
The opportunity-cost trap
Here’s the part that’s easy to miss. The victim has been calculating their daily take for weeks: $50, $80, $90 a day. Nine days of holiday closure means nine days of expected income the victim assumes they won’t earn anyway, since “the business” is closed. The scammer’s ask isn’t framed as “give us money you’ll lose.” It’s framed as “keep your income flowing through the gap, and get paid for it same as always.” The victim isn’t just avoiding a loss, they think they’re avoiding an interruption to a routine that’s become part of their financial life. That reframing is what makes fronting $9,000 feel less like a risk and more like maintaining the status quo.
Why the amount jumps without alarm
By this point, the victim has already handled escalating daily volumes for weeks. $9,000 sounds large in isolation, but inside a relationship where amounts have been trending upward the entire time, it reads as the next data point in a trend rather than an outlier. This is exactly why the earlier trust-building phase escalates gradually rather than staying flat: it’s laying the groundwork so that this specific number doesn’t trigger a gut check.
Loss aversion locks the door
At the point the ask lands, the victim has weeks of real, collected profit and an established relationship they don’t want to lose. Refusing doesn’t just mean missing this one transaction, it risks the relationship itself, and with it, the ongoing income stream they’ve built their weekly rhythm around. The fear of losing future income outweighs caution about this one request. That’s loss aversion doing exactly what it does in every other context: making people protect what they already have, even at the cost of taking on new risk to do it.
Why it only needs to work once
The entire multi-week investment only has to produce a single successful squeeze. The scammer isn’t trying to extract money repeatedly from the same victim over months. One clean extraction per relationship, at the moment of maximum trust and minimum scrutiny, is the entire economic model. That’s why the squeeze isn’t tentative or softened, it’s precise, well-timed, and final.
The tell, if you’re inside it
The signature is the reversal itself. Any relationship that has flowed entirely in your favor for weeks, and then asks you to front money “just this once, just for a short window, because of something real happening in the world” is using the exact structure of this tactic, regardless of the specific cover story. The holiday is incidental. The direction-flip under time pressure, riding on weeks of accumulated trust, is the mechanism.
Tell me more about how the relay account works
The relay account is the piece that makes the whole structure survive contact with law enforcement. Without it, the scammer would be one wire transfer away from getting caught. With it, there’s a buffer that absorbs the investigation before it ever reaches them.
Who runs it
Almost certainly another person in roughly your position, someone recruited the same way, through the same kind of DM funnel, sometimes slightly further along in the “trusted representative” relationship, sometimes a total newcomer being tested with a single pass-through transaction before they’re offered the full recruitment pitch. The scammer doesn’t need a criminal accomplice here. They need someone who believes, at least in the moment, that they’re doing exactly the same kind of legitimate-sounding task you were doing.
What they’re told
The relay account holder typically believes they’re receiving a payment from one business contact and forwarding it to another, standard instructions inside whatever cover story they’ve been given. They may never learn your money came from a scam. They may believe they’re processing a legitimate transfer between two parties in a supply chain they’ve been told exists. The compartmentalization is deliberate: nobody in the chain except the scammer sees the whole picture.
Why one hop isn’t enough
If your $9,000 went directly from you to the person buying USDT, that’s a single, traceable hop. A bank or a police investigator connects sender and receiver in one step. Adding the relay account inserts a second party between the theft and the eventual crypto purchase, so investigators tracing the money have to identify, locate, and question an entirely separate person before they even get to the transaction that actually converts fiat to coin. Every additional hop multiplies the investigative work required, and multiplies the number of jurisdictions and banks that might need to cooperate.
Why it’s not always the same person twice
Sophisticated versions of this operation rotate relay accounts, sometimes using a given account for only one or two transfers before moving to a new one. That’s partly to limit any single account’s exposure to fraud-detection flags (a bank account suddenly receiving and immediately forwarding large irregular transfers is exactly the pattern transaction-monitoring systems are built to catch), and partly to limit how much any single relay-account holder learns about the operation before they’re replaced.
The account holder’s exposure
This is the person who ends up in the worst legal position in the entire chain, and it’s not accidental. They have no clean explanation for an inbound transfer from a stranger followed by an outbound transfer to another stranger, with no invoice, no contract, no legitimate business relationship on paper. You at least have weeks of your own bank statements showing a pattern of received “commission” payments that predates the theft, a story that at least holds some internal logic even if it’s ultimately a scam. The relay account holder often has nothing but a single, unexplained pass-through, which reads far more suspiciously to a bank’s fraud team or a prosecutor than your situation does.
Why this is the actual laundering step
In compliance terms, this is where placement (your money’s first entry into the criminal chain) transitions into layering (moving it through additional parties specifically to obscure the original source). The relay account’s only functional purpose is to break the direct line between your loss and the USDT purchase. It adds no value to any legitimate transaction. Its sole function is distance.
The tell, if you’re looking for it from the outside
If you ever look at a Turkish fraud case and see the same shape (a first account showing weeks of small inbound “commission” payments before one large outbound transfer, followed by a second account showing one unexplained inbound transfer immediately followed by an outbound transfer to a P2P crypto trade) you’re looking at this exact structure. The relay account is the seam between the personal betrayal of the mule and the anonymous mechanics of the crypto exit.
Tell me more about the P2P USDT seller side
Since we covered the basics of this already, let me go deeper into the angles we haven’t touched: how the order book itself works, what a seller’s incentives actually look like transaction by transaction, and where their legal exposure really sits.
How they actually get chosen as the seller
P2P platforms work as an order book, not a matchmaking service. The seller posts an ad: amount available, rate, accepted payment methods, sometimes a minimum KYC tier the buyer must have completed. The scammer isn’t hunting for a specific seller. They’re taking whatever offer sits at the top of the book when they need to convert. The seller has no idea a specific buyer exists until that buyer clicks their ad. This matters because it means the relationship is completely anonymous and completely disposable on both sides, there’s no ongoing counterparty relationship for a compliance officer to eventually notice as a repeating pattern between the same two people.
Why they don’t ask questions, structurally
Most retail P2P sellers are individuals or small merchant accounts, not institutions with a compliance department. The platform itself handles identity verification at onboarding, so the seller’s mental model is “the platform already checked this buyer’s ID, my job is just to confirm the bank transfer landed.” That’s a reasonable division of labor for a legitimate marketplace, and it’s exactly the gap the scammer’s whole operation is built to exploit. The platform verified who the buyer’s account belongs to. Nobody verified where that account’s incoming funds came from.
The KYC tier question
Platforms tier sellers and buyers by verification level and transaction volume. A basic-tier account might trade small amounts with minimal friction; higher volume triggers additional verification, source-of-funds questions, sometimes manual review. A scammer running this at scale has an incentive to keep individual transaction sizes and account volumes under whatever threshold triggers that extra scrutiny, another reason the $9,000-per-victim range shows up repeatedly rather than one $200,000 extraction. Staying under the radar of automated tiering is a design constraint on the whole operation, not an accident.
Merchant accounts versus casual sellers
There’s a meaningful difference between someone casually selling $500 of USDT a week and a “merchant” account doing meaningful daily volume. Merchant-tier sellers on most platforms take on more explicit obligations, sometimes contractual with the platform, sometimes closer to actual VASP-style responsibilities (VASP being Virtual Asset Service Provider) depending on jurisdiction and volume. A merchant seller doing meaningful daily turnover, if regulators ever looked closely at their book, has a harder time claiming total ignorance than someone doing one trade a month. Volume itself becomes a kind of implied duty of care in most regulatory frameworks, even where the specific rules are still catching up.
Why platform-level monitoring sometimes catches this and sometimes doesn’t
Exchanges do run transaction monitoring on their P2P order flow, watching for patterns like rapid buy-sell cycling, accounts trading exclusively with newly created counterparties, or unusual timing correlations. But P2P monitoring is structurally harder than monitoring the exchange’s own custodial flows, because the fiat leg happens entirely outside the platform, in the banking system, where the exchange has no visibility at all. The exchange can flag “this wallet received coin and immediately moved it off-platform,” but it can’t see that the fiat payment funding the purchase came from a stolen $9,000 four hops upstream. That blind spot between the banking rail and the crypto rail is the seam the entire scheme lives in.
The seller’s actual exposure, realistically
In most jurisdictions, a seller acting in good faith, using the platform’s own KYC, with no reasonable way to have known the buyer’s funds were stolen, has a genuinely defensible position if it ever comes to that. This isn’t the same legal exposure as the mule or the relay account holder, who each have an unexplained, out-of-pattern transaction directly on their own bank statement. The seller has a normal-looking trade on a platform designed for exactly this kind of trade. That asymmetry in exposure is part of why this model persists: everyone closer to the crypto end of the chain is progressively better protected, and everyone closer to the human recruitment end is progressively more exposed.
Tell me more about why the buyer walks away clean
The buyer’s protection isn’t luck. It’s structural, built into where they sit in the transaction chain relative to the actual theft.
They never touch the stolen money directly
By the time the scammer buys USDT, your $9,000 has already passed through at least one relay account. The scammer’s own bank account (or the one they’re using) only ever receives crypto, never your fiat. There’s no direct wire from you to them. That gap is doing all the work.
Their paper trail tells a true story, just not the whole story
When investigators pull the scammer’s bank or exchange records, what they find is completely accurate: a lira payment came in from a third party, USDT went out to that third party’s wallet. Nothing about that transaction is falsified. It’s a real trade at a real (if inflated) rate. The scammer can point to it and say, correctly, “I sold coin, I got paid, here’s the trade history.” Proving criminal intent from a clean-looking trade is a different burden than proving the transfer happened.
The relay account absorbs the legal exposure
This is the deliberate part. The relay account, run by someone in exactly your position, either another mule or a slightly more experienced one, is the one whose name is on the transfer that actually moved your stolen $9,000. When your bank flags the transaction or you file a police report, the trail runs to that account first. That person now has to explain an inbound transfer from a stranger and an outbound transfer to another stranger, with no legitimate business reason for either. That’s a much harder position to explain than the scammer’s, and it’s exactly why the scammer built the chain that way.
Jurisdiction does the rest
The scammer is usually operating from outside Turkey, often from a country with weak or slow cross-border cooperation on this kind of fraud. Even if a Turkish prosecutor builds a solid case against the relay account and traces it further, extraditing or even just serving legal process on someone in another country, especially one with limited MLAT (Mutual Legal Assistance Treaty) cooperation, is slow, expensive, and often doesn’t happen at all for a $9,000 case. Scale matters to prosecutors. A single mule’s loss rarely justifies the resources needed to chase someone abroad.
Volume makes them a moving target
Because they’re running the same play with 20 to 30 people simultaneously, the scammer isn’t sitting still waiting to see if one case against them develops. By the time any single victim’s report works its way through a bank’s fraud team, then to police, then possibly to a prosecutor, the scammer has moved on to new relay accounts, new social media profiles, and often new corridors entirely. The infrastructure is disposable. Only the technique is reused.
What “clean” actually means here
It doesn’t mean innocent. It means the evidentiary path to prosecute them specifically, as opposed to the person one step closer to the original victim, is longer, weaker, and crosses a border. That’s a structural advantage, not a legal one, and it’s exactly what the layering step in money laundering is designed to produce.
Something worth noting…
The example I mentioned is just one of many. Scammers operate in various ways, but the core strategy remains the same. They target vulnerable individuals in Turkey, those struggling financially, and offer them a glimpse of hope for earning money. They guide these people through a process where the victims believe they are making real money. Sometimes, the victims become greedy. The victim might express a desire to expand the operations, to which the scammer responds by saying they don’t have more money. However, if the victim can invest more, they can proceed with larger transactions. This is how scammers gain their victims’ trust. It’s a confidence scam. Understanding this is crucial because this type of scam is just one among many. There are dozens of other methods, and likely even more that haven’t been uncovered yet.


