man who falls for this stuff. i've been seeing "send me money to this account to get double that" scam for like 20 years, its hard to believe there are people who still don't know better.
Another idea is, hijack customer service request DM's from crypto exchanges, and lead customer to phishing login page. Perhaps could athorize API access to the account, and then change email back to original, without the owner realizing account breach.