Digital Crime Transformation
The Fraud Where Nothing Is Fake: Marketplace Triangulation as a Trust-Architecture Defect
Marketplace triangulation is routinely treated as a lapse in buyer vigilance; structurally it attacks role-to-agent binding by recombining the components of individually safe transaction modes so that local legitimacy survives while the global connection of roles is lost.
Marketplace triangulation — Dreiecksbetrug in German, triangle scam or third-party scam in English — is routinely treated as a lapse in buyer vigilance. Structurally it is nothing of the kind. It is an attack on role-to-agent binding, and it exploits not a missing protection but an unpreserved invariant: a marketplace offers more than one individually safe way to transact, and permits the components of those modes to be recombined without checking that the binding of roles survives the recombination. The cost of that unchecked composition is shifted onto the victim. No link in the chain is fake — only the connection between them.
The scheme is old and documented across post-Soviet and European marketplaces. This brief makes no claim about prevalence or trend; it treats the scheme as an unusually clean specimen of a structural fault that most anti-fraud advice is aimed away from.
What happens
A buyer finds a listing — a phone, a van, another high-value item — priced a little below market. They message, arrange to meet, and turn up. The goods are there; the seller is there; the item powers on and checks out. All of it is genuine. In advance, the fraudster copied a real listing, reposted its contents under their own name, and relayed between the true owner and the buyer. The owner was told a “friend” or “associate” would come to view the item; the buyer was told a “brother”, “husband” or “helper” would show it, but that payment should go separately, to a different account. The money reaches the fraudster; the goods stay with an owner who is left waiting to be paid.
The mechanism is documented, not hypothetical. NTSK.RU, citing the Orenburg regional police, reported in September 2022 an all-but-verbatim instance: a genuine van listed at 1.1 million roubles, a copied listing priced at 535,000, a buyer promised the vehicle for 500,000, an in-person viewing arranged with the real owner, an explicit instruction not to discuss price at the meeting, and 500,000 roubles transferred to the intermediary — who then vanished, leaving the owner unpaid and the buyer without the van. The goods were real, the viewing was real, the owner was real; only the seller and the payment route were fictitious. Russian descriptions of the same “three-way” scheme go back at least to 2017, and Austria’s state online-safety portal and Germany’s Verbraucherzentrale both catalogue the pattern among current classifieds frauds.
Two mirror variants circulate under one label — in one the payment flows to the real seller and the goods to the fraudster, in the other the payment flows to the fraudster and the goods stay with the owner — but they are the same structural attack, with the payment and goods legs mirrored.
The false classification, and its cost
The scheme is presented to the public as a problem of vigilance: the “red flag” is that one person shows the goods and another asks to be paid, and the remedy is to “stop and double-check”. This is the same move as “don’t trust phone calls” — an architectural failure recast as the user’s duty to pay closer attention. The classification is false because it aims at the wrong layer.
Conventional fraud forges an embodiment of trust — a counterfeit product, a forged document, a fabricated identity — and is therefore caught by inspecting that embodiment. Here nothing is forged; every embodiment survives inspection. The attack sits on a different layer: role-to-agent binding, the question of who is actually party to which side of the contract. Both honest parties correctly authenticate the objects and the people in front of them; neither authenticates the configuration of the deal. Every instinctive countermeasure — see the goods, meet in person, test the device — operates on embodiments and is blind to an attack on the agent schema.
The correct reclassification is not that the platform provides no defence. A marketplace usually offers more than one way to transact that is safe on its own terms. A platform-mediated path — funds held in escrow, released on completion, paid out only to a verified account tied to the listing — binds payee, seller and settlement into one authenticated chain. A physical path — inspect the goods in person and pay the person handing them over, on the spot — binds the roles differently but just as effectively: the payee and goods-presenter are the same party, while payment and handover are co-located and simultaneous. Kleinanzeigen documents both, disabling its protected “Sicher bezahlen” path for pickup-only listings and then recommending exactly that second, physical mode — cash on handover — as the safe alternative. Each mode, used whole, preserves the binding of roles.
The defect is that nothing prevents their components from being recombined. Triangulation takes the physical-inspection component of the second mode — real goods, a real viewing, a real owner present — and pairs it with a remote payment to a third party, a leg that belongs to neither safe mode. Every local mark of legitimacy survives the recombination; the global connectivity of roles does not. The scheme does not defeat the trust architecture; it exploits the fact that binding is preserved within each mode, though by different mechanisms, but not necessarily across their composition. That is where the cost is exported — to the party least equipped to bear it.
Why it works
The load-bearing analogy is the man-in-the-middle attack. The fraudster sits between two legitimate, good-faith endpoints as an unauthenticated relay; each endpoint verifies its own counterparty and their embodiments, while the channel between them is authenticated by no one. In cryptography this is solved by channel binding; in the recomposed transaction, no binding spans the payment leg and the goods leg.
The fraudster’s operative control instrument is the prohibition of horizontal communication. The instruction “don’t discuss the price” is no incidental courtesy — it exists to stop the two honest parties from exchanging the single sentence that collapses the scheme: what are you selling for, and to whom am I paying? The attacker’s position depends on preventing the endpoints from performing out-of-band mutual verification. Deny them the side channel, and the theatre falls apart in seconds.
Subtler still is the inversion of an ordinarily valid signal. Normally a mass of converging, genuine detail is good evidence: if this much is true, the rest is probably true. Everyday trust rests on that bridge. The scheme turns the bridge against the person crossing it — the abundance of authentic material does not lower the probability of the single lie, it conceals it. The one seam the attack must leave visible — one person shows, another collects — is not an oversight but a structural necessity: the money must bypass the holder of the goods, or the scheme cannot close. No link in the chain is fake — only the connection between them.
This is why vigilance is a poor remedy, on two counts. Operationally, to catch the scheme by attention a buyer would have to reconstruct the whole topology of the transaction by hand, in every deal — a reconciliation that does not scale and simply transfers the platform’s verification cost onto each participant. And more deeply: to hold that suspicion by default is to switch trust off as the mode of economising on verification on which ordinary exchange depends. The posture that reliably defends against this scheme is not heightened vigilance but its structural opposite, and to demand it of every buyer is to ask a market participant to stop being one.
The diagnostic grid
The same apparatus, applied along five axes. In the framework used here, the resource being extracted can be understood as predictability held in common: the fraudster draws private gain from the shared stock of predictability that makes the marketplace usable, leaving it thinner for every subsequent transaction.
Table 1. A five-axis reading of the extraction of predictability.
| Axis | Value in this case | Mechanism |
|---|---|---|
| Extraction vector | Criminal, structurally identical to passive platform externalisation | One logic of appropriation: private gain at the expense of a shared good; the platform lets the same cost fall outward by not policing composition |
| Trust layer | Role-to-agent binding (who is party to the deal), not embodiments | Every embodiment is genuine and passes inspection; the single false node is the unverified link between payment and counterparty |
| Sovereign posture | Domain controller (the platform) — provides several individually safe modes but does not enforce the binding invariant across their composition; state and consumer bodies — ex post advice | Each mode preserves role binding on its own; nothing checks that a recombination of their components does |
| Mode of inclusion | Fraudster — deliberate design; platform — structural permission | The unsafe cross-mode composition is permitted, not authored; the gap is in composition safety, not an intended trap |
| Who bears the cost | The buyer directly; the shared stock of predictability diffusely | Direct loss to the victim, plus general erosion of predictability drawn from every future transaction |
The sovereign posture here is not one row among the others but the variable conditioning the whole. Because the domain controller preserves binding within each mode but does not enforce the invariant across their composition, the extraction vector finds its opening exactly at the recombination. This is a governance posture, not merely a technical gap: a marketplace is the de facto governor of the transaction environment it structures, and where it chooses to enforce the binding invariant is a choice about where authority — and liability — will sit. And it is that opening that makes the infrastructure convertible: the same move, an unauthenticated relay between two trusting parties, scales from a household sale to any mediated transaction, including the delegation of action to an agent [Khimich, 2026]. What looks like a consumer-fraud footnote is a small instance of a general fault line in mediated exchange.
What to change
The remedy sits with the architecture, not the user, and it is concrete. The fix is not to build a protection the platform already offers, nor to push users out of the physical mode, which is safe used whole. It is to preserve the binding invariant across modes: to catch — or at least flag — a transaction that composes physical handover with payment to an account not bound to the goods-owner. A platform that structures the transaction environment and provides its communication or payment mechanisms should treat binding-preserving composition as a design principle, and expose the trust status of a transaction that violates it, rather than leaving its reconstruction to the buyer.
The binding principle itself must be stated carefully, because it is easy to overshoot. The requirement is not that payer, seller and goods-presenter be the same person — in ordinary commerce a courier, a spouse, a colleague or a firm’s representative legitimately shows goods on someone else’s behalf. The requirement is a verifiable link between the roles: the payee should be bound to the seller or principal, and any distinct presenter or collector should be bound to that same principal through an authenticated delegation. Triangulation is not the presence of a stand-in; it is a stand-in whose delegation no one has authenticated.
From this follows the allocation of responsibility. The cost currently loaded onto the victim returns, under a coupling of liability and insurance, to whoever presented the channel: the internalisation of a defect, not a net increase in total cost. This is the retail projection of an argument developed at the banking level in Parasites on Trust: the same misallocation of liability, in which the cost of a coercive or fraudulent infrastructure settles on the party least equipped to bear it rather than on the party that permitted it. For regulators and platforms, the operative act is to reclassify the incident from “a lapse by an inattentive buyer” to “a failure of the platform’s trust architecture to preserve role binding when transaction modes are composed” — because on that redefinition depends the question of who is billed.
Bottom line
The scheme is valuable as an unusually clean demonstration: the strongest intuitive signal of trust — I saw the goods, I saw the seller — is orthogonal to verifying who is actually party to the deal, and every anti-fraud measure built on inspecting embodiments is blind to an attack on the agent schema. The victim checked every embodiment he could inspect; the relation between those genuine elements was not authenticated by the channel, and he could establish it only by reconstructing the transaction out of band — the very step the fraudster’s script is built to suppress.
No link in the chain is fake — only the connection between them.
Sources
- NTSK.RU, citing the Orenburg regional police (UMVD), report on the Novotroitsk “GAZelle” case, 25 September 2022 — ntsk.ru
- “Схемы обмана при продаже на Avito” (earliest description of the “three-way” scheme), 29ust.ru, 6 October 2017
- Austrian federal online-safety portal, “Vorsicht vor Dreiecksbetrug bei Kleinanzeigenplattformen,” 14 April 2025 — onlinesicherheit.gv.at
- Verbraucherzentrale, “Betrug mit Kleinanzeigen: Diese Maschen sollten Sie kennen,” 23 September 2025 — verbraucherzentrale.de
- Postbank, classifieds-fraud advisory on payer / collector mismatch — postbank.de
- Kleinanzeigen Help Centre, “Sicher bezahlen” and safe-trading guidance (protected path; disabled for pickup-only listings, where cash on handover is recommended), accessed 2026 — hilfe.kleinanzeigen.de
Related work
- Khimich, R. & Churilov, Y. (2020). Trust and Its Embodiments in Digital Markets (Доверие и его воплощения на цифровых рынках). DOI: 10.5281/zenodo.21959521. — for the treatment of trust as a computable property of service architectures, the embodiments of trust, role-to-agent binding, and evidentiary force.
- Khimich, R. (2026). The Digital Transit of Coercion: Industrialization, Distribution, and the Emerging Architecture of Remote Violence. — for infrastructure convertibility and the appropriation of a shared commons of predictability.
- Parasites on Trust: Cross-Border Industrial Coercion and the Misallocation of Liability in British Banking (Turkhanov & Khimich, 2026). — for the misallocation of liability, of which the cost allocation argued here is the retail-level projection.