A scam needs
somewhere to hide.

Most of them hide in the same two places: a number that is not true yet, and a name that does not match the person receiving the money. Both of those are things a payment system chooses to show you. We are choosing differently.

None of it is compulsory. We are a product, not a policy.

Where this stands, before anything else

The identity and storage layers described here are built and running. The payment rail is not. This page describes how the mark is designed to behave when money moves, and we are publishing it before it exists so that it can be argued with while it is still cheap to change.

If you are reading this because something is happening to you right now, we cannot help you: we are not your bank and we do not hold your money. Call your bank's number from the back of your card, not from any message you were sent.

Scams are not one problem

The instinct is to treat fraud as a single enormous guessing game and throw a risk engine at it. That is why fraud detection feels like weather: invisible, probabilistic, wrong at the worst moment.

The better move is to take each scam apart and find the one thing it cannot work without. Some of those things are not clever attacks at all. They are design decisions, made decades ago, that a payment system could simply stop making.

Four scams, honestly ranked

These are not equally solved, and we are not going to pretend they are. Two of them fall apart completely. One shrinks a great deal. One stays hard forever.

The fake check

Structurally dead

Works only because a bank shows you money that has not arrived. Someone overpays you with a bad check, you see the balance, you wire the difference back, and the check bounces a week later. Remove the lie about finality and there is no scam left to run.

The refund reversal

Structurally dead

Works because a refund today is just a new payment wearing a refund's clothes, so it can be pointed anywhere. If money can only travel back along the path it came, there is nowhere to point it.

Friendly fraud

Mostly gone

A real customer disputing a real purchase they made, because nobody can prove otherwise. It is the largest category of chargeback loss there is.1 A signed chain from approval to delivery replaces an argument with a record.

The romance scam

Partly, and never fully

The victim genuinely approves. No signature and no cryptography can tell whether someone is lying to you about loving you. What the mark can do is make the one fact the scam depends on hiding impossible to miss.

Start with the easy one, because it is enormous

Check fraud is the payment method most subject to fraud in the United States, and it is still growing: 63% of financial institutions reported check fraud attempts in a single year and three quarters of US banks call it a major concern.2 The Americas absorbed roughly $21 billion in check fraud losses in one year, about 80% of the world's total.3

Nearly all of the consumer half of that runs on one sentence: available balance. It is a number your bank shows you that means we have provisionally credited this and may take it back. Almost nobody knows that. The scam is simply the gap between what the number says and what it means.

What the mark would say instead

Money in Liir is never just an amount. It carries a state: authorized, pending, settled, final. Those words appear on the money itself, not in a help article.

And unsettled money cannot be signed away. Someone sends you $5,000 and asks you to return $2,000 today? The mark will not sign it. Not because it detected a scam, and not because anyone forbade it, but because the money is not there yet and the mark will not pretend otherwise. That is arithmetic, not permission.

No risk engine. No AI. Just refusing to display a number that is not true yet.

An entire category of fraud, removed by telling the truth about time.

The refund that can only go home

A refund today is structurally identical to a payment. That is the whole vulnerability. It means a "refund" can be aimed at an account that has nothing to do with the original purchase, which is why the overpayment scam, the fake refund email, and the tech-support reversal all work with the same script.

In Liir a reversal is not a payment. It is a signed state change on the original transaction: the same two parties, the same authorization path, no destination field to fill in. You would open the mark and see the whole life of it:

When the trusted middle is the attack

PayPal's long-running promise was that it was the safer, easier way to pay, and for twenty years that was true. The safety came from standing in the middle: you never handed your card to the merchant, so the merchant could never lose it.

Standing in the middle is a real service. It is also an address.

Anyone with an account can send an invoice or a money request to anyone else, and scammers do, at volume. The email is genuinely from PayPal. The invoice is genuinely a PayPal invoice. It arrives as a real notification from a company the recipient already trusts, carrying a phone number that reaches the scammer's own support line, which is where the theft actually happens. State attorneys general have issued public warnings about it.4

Look at the shape of that. Nothing was forged. Nothing was breached. No password leaked and no system was compromised. The scam is only that a trusted intermediary is a channel. And a channel can be rented.

What we are and are not claiming

We are not claiming to be safer than PayPal. Safer is a claim you earn with years and a track record, and no paragraph on a company's own website has ever been evidence of it. Ask us again when we have moved a few million dollars without losing any of it.

The claim is about shape. A design with a trusted middle has a trusted middle to abuse. Liir has no account that can invoice you, no notification we send on a stranger's behalf, and no support line we could be impersonated at. A request for money is a signed object from a named counterparty or it does not exist, and the ceremony below shows you who signed it before anything can be approved.

You cannot rent a middle
that was never built.

Then the hard one

Romance scams took $1.16 billion from Americans in nine months, across 55,604 reports, up 22% in a year.5 Losses among people over sixty rose from $389 million to $584 million in twelve months.6 The median loss for someone in their late fifties is around $9,000, and the average is far higher, because the tail of this is people's entire retirement.5

Here is the number that tells you how the scam actually works. Of the money lost, 34% went by cryptocurrency and 17% by gift card: more than half through rails chosen for exactly two properties.5

51%
of romance scam losses go by crypto or gift card
Both
are irreversible and reveal nothing about who collects
$584M
taken from people over sixty in a year, up 50%

That is not a coincidence and it is not about technology preference. Scammers move victims onto those rails because those rails hide the recipient and cannot be undone. The concealment is not incidental to the scam. It is the scam.

So show them who is actually receiving the money.

Not a risk score. Not a warning banner. A person.

The ceremony

A person-to-person payment through the mark would not be Send $8,000? Yes / No. It would be this:

You are paying

Maria Hernandez

✓ Verified person

Liir established
March 2024
Identity last reverified
June 2026
Times you have paid them
Never
Destination account
Changed 2 days ago
$8,000.00

Irreversible once settled

Approve

And somewhere in Ohio, a woman looks at her phone and says: that's not Steve.

The mark is not guessing. It never reads a message, never scores a personality, never decides whether a relationship is real. It answers one question the scam spent six months preventing anyone from asking: who is on the other end of this?

The friction belongs on the first payment, not the big one

This is the part most fraud systems get backwards, and it matters more than the design of the card above. By the time someone is sending $8,000, they are committed, and they have been given an answer for every objection including the face: that's my shipping agent, that's my lawyer, my daughter is collecting it for me.

Scams escalate. There is almost always a small one first: $50, to see whether you will. So the full ceremony belongs on the first payment to any new human, at any amount, when the spell is thinnest and nothing has been sunk yet. The $8,000 confirmation should be a reminder of a face already seen, plus what changed since.

Nobody has to do any of this

Every proposal that looks like this eventually starts to smell like a checkpoint, so let us be plain about it while the page is still short.

The version of this idea that arrives with a statute behind it is a different product wearing the same diagram, and we would argue against it. An identity layer you cannot decline is not an identity layer. It is a checkpoint.

We are not building a face database

The obvious way to build the card above is to collect everyone's photograph, keep it on our servers, and serve it up when money moves. We will not do that, and you should hold us to it.

A face is the most reusable credential in existence and the only one that can never be changed after a breach. A company whose entire argument is nothing reusable should cross the boundary cannot then assemble the most valuable biometric database on the internet, indexed by legal name and payment history. That is not a trade-off. That would make us the thing we wrote a whole page against.

How it works instead

Your portrait lives in your own vault, on your hardware. LiirID verifies you once and signs a statement: the holder of this Liir is the verified person shown in the image with this fingerprint. We keep the statement. We do not keep the image.

When you are paid, your device presents the picture to the payer's device. We route a sealed envelope we cannot open. The same moment happens on screen, and there is no photograph of you on any server of ours to lose, sell, or be compelled to hand over. This is ordinary verifiable-credential architecture, published as a standard years ago.7

The feature that could hurt the people it is for

Every design like this eventually proposes the same thing: let a trusted family member approve large payments for an older relative. It is the obvious feature. It is also the most dangerous one on this page, and we would rather say so here than discover it later.

One in four domestic abuse survivors report credit taken out in their name by a partner, without consent, or because they were afraid to say no.8 Elder financial abuse is overwhelmingly committed by family. The person most likely to be named a guardian is drawn from exactly the population most likely to abuse it.

That last rule is the whole thing. A guardian control that requires the guardian's consent to remove is not a safety feature. It is a cage with a nice name.

What this does not do

The questions this raises

Doesn't this mean Liir sees every payment I make?

It must not, and that shapes the design. Everything on the card above (how old this Liir is, whether the destination changed, whether you have paid this person before) can be computed on your own device from what the other party presents. Spotting rings of accounts across the whole network is a different thing that would require us to watch everyone, and we would rather be able to say honestly that we cannot.

Isn't anonymous payment the whole point of digital money?

For browsing, reading, and proving you are old enough, yes: tell them nothing. For handing several thousand dollars directly to another human being, you should get to know who receives it. Those are different acts and it was a mistake to build them the same way. There are people for whom paying privately is a safety matter, and a mode for them has to exist; it should not be the default for a stranger asking for a wire.

Scammers will just adapt.

Yes. They will recruit verified humans and pay them to collect. That is a real adaptation and it costs them something enormous: a scam that needs a real identified person per victim is a business with a payroll. The mark does not end fraud. It moves it from something you run from a laptop to something you have to staff.

Why publish this before it is built?

Because a page like this is easier to argue with than a shipped product, and the criticism is worth more now. Also because we would rather be caught overreaching by a reader than by a person who lost their savings trusting the claim.

Liir cannot stop someone from lying to you.
It can stop the lie from hiding inside the payment.

A scam needs a gap between
what you were told and what happens.

The mark's only real trick is closing that gap and showing you what is inside.

or read How Liir Works · it is free on your own hardware

Sources

  1. Chargeflow, Friendly Fraud: the $132bn chargeback threat, and Chargebacks911, Chargeback Stats. Friendly fraud driving up to 75% of all chargeback losses, with more than 83% of enterprise merchants reporting it rising over three years.
  2. Federal Reserve Financial Services, 2026 Risk Officer Report, and the Association for Financial Professionals check fraud survey reported at Check fraud remains top threat. 63% of financial institutions reporting check fraud attempts in twelve months; 75% of US banks and credit unions naming it a major concern; checks the payment method most subject to fraud.
  3. Check Fraud Statistics: Trends, Data & Insights and Check Fraud Still on the Rise. Roughly $21bn in Americas check fraud losses, about 80% of the global total, of which an estimated $1.3bn was borne by US financial institutions.
  4. PayPal, Avoid Invoice and Money Request Scams, the Pennsylvania Attorney General warning reported at Pa. AG warns of PayPal invoice scam, and the Federal Trade Commission phishing warning noted by the New Hampshire Banking Department. PayPal documents the attack itself: anyone can invoice any other user, the notification is genuine, and the scam rides a fraudulent support number on a real invoice. We name this because the mechanism is structural rather than a failure of theirs to patch.
  5. US Federal Trade Commission data for 2025, reported in $1.16B lost to romance scams in 2025 and Romance Scam Statistics 2025–2026. $1.16bn reported lost across 55,604 reports in nine months, up 22% year on year; a median loss near $9,000 for adults aged 55–64; and a payment-method split of roughly 34% cryptocurrency, 17% gift cards, 15% wire and 14% bank transfer.
  6. FBI IC3 and FTC data reported by AARP, Older Adults Hit Hard by Fraud in 2025. Romance losses among people aged 60 and over rising from $389m to $584m in a year.
  7. W3C, Verifiable Credentials Data Model. A published Recommendation. Holder-presented, issuer-signed claims are a standard, not something we invented to justify keeping less of your data.
  8. Surviving Economic Abuse, What is coerced debt, and Adrienne Adams et al., Michigan State University, reported in Victims of domestic violence often stuck with financial debt. One in four victim-survivors report credit taken out in their name without consent or under fear; of 188 divorcing women studied in Texas, 67% carried coerced debt.

Where a figure comes from a study we could not read directly, the study is named and the report we did read is linked. Figures are current as of August 2026. If you find one of these wrong, we would rather hear it than keep printing it: hello@liir.net.

Keep reading: Why this exists · Can it be hacked? · The notary · we can prove when