The technology usually holds. The person is the exploit. Fake support scams are how careful, intelligent people lose their crypto, because the con arrives at the exact moment they are already frustrated and actively looking for help.
Why is there no such thing as crypto support calling you?
Because the structure of the industry does not produce it. Most wallet software is free and open source. There is no company with a support department and a phone number, because there is no customer relationship and no revenue from you to fund one. Hardware wallet makers have support, but they support devices, not your keys, and they have no ability to access your funds.
Exchanges do have real support teams. What they never do is contact you first and ask you to move funds, confirm a recovery phrase, install software or grant remote access. Support responds to tickets you opened. It does not phone you about a problem you had not noticed.
Once that is clear, the entire category collapses into one rule: unsolicited help is the attack. Consumer regulators make the same point; the US Federal Trade Commission notes that only a scammer will insist you pay or move funds in cryptocurrency to resolve a problem.
How do impostors find you?
They watch for people who have already announced that they need help, which is why the timing feels so uncanny.
- Public posts. Ask about a stuck transaction or a wallet error on X, Reddit or a project forum and automated accounts scrape the keywords and message you within minutes, often several in parallel.
- Search results and adverts. Searching for a support number or a wallet help page turns up paid listings and lookalike sites above the genuine one. Many wallet "support numbers" that rank in search do not belong to any wallet company.
- Cloned community accounts. In Discord and Telegram, an account copies a real moderator's display name and avatar and direct-messages you. The real moderators usually have DMs closed and say so publicly.
- Phone and SMS spoofing. Caller ID can be forged, so a call that appears to come from your exchange's real number proves nothing.
- Fake apps. Convincing clones reach app stores regularly, sometimes ranking above the real one for a period after launch.
What does the script look like?
Recognising the shape is the defence, because the individual details change constantly while the structure does not. It runs in five beats.
- A sympathetic opening. They are friendly, unhurried and appear knowledgeable. They may correctly name your wallet, your error message or your exchange, which is easy if you posted about it.
- A plausible explanation. Your wallet needs resynchronising, your account is flagged for a security review, your node is out of date, there is a known bug affecting your version. It sounds technical enough to be true.
- A move to a private channel. Out of the public thread and into direct messages, WhatsApp, Telegram or a phone call, where nobody can see what they are asking or warn you.
- Manufactured urgency. Your funds are at risk, the window closes soon, the validation must happen today. Urgency exists to stop you checking.
- The ask. It is always one of four things.
The four asks, in rough order of frequency:
- Your seed phrase or recovery words, sometimes typed into a legitimate-looking "wallet validation" web form rather than sent as a message
- A code from your authenticator app or an SMS code, which lets them complete a login or a withdrawal they have already started
- Remote access to your computer using a tool such as AnyDesk or TeamViewer, framed as the fastest way to fix it for you
- A transfer to a "secure wallet" or "validation address" while your account is investigated
Why are words like validate, sync and migrate the tell?
Because none of them are real wallet operations. A wallet does not need validating. There is no synchronisation process that requires support to see your recovery words. Nobody needs to migrate your funds to a safe address on your behalf, and no legitimate process requires you to whitelist a stranger's address.
These words exist in the script because they sound like plausible technical maintenance to someone who does not work with this daily, and because they give the victim a reason to hand over the secret that feels procedural rather than reckless. When you hear one, you have identified the scam. That is the whole signal.
Why do authority and urgency work so well?
They are the two levers of nearly every social-engineering attack, and in crypto they are inverted signals. Real support is patient. A genuine exchange agent will happily let you close the chat, verify through the official app and come back. They will never object to you hanging up and calling back on a number you looked up yourself.
A scammer cannot allow that, because verification kills the con. So pressure is not evidence that the situation is serious. Pressure is evidence that you are being scammed. The more urgent the framing, the more certain you should be.
This also explains why the scam catches competent people. It is not aimed at ignorance. It is aimed at a person in a hurry, mid-problem, who wants the problem solved.
Why is remote access worse than it sounds?
It deserves separate treatment because people underestimate it. Granting remote access is not showing someone a screenshot. Once the session is live they can see everything you do, in real time, and often control the machine.
That means they can watch you open your password manager and read the master password as you type it, browse your files for a photograph of a recovery sheet, open your email and reset credentials elsewhere, and install software that persists after the call ends. People agree to this because it is framed as the helpful option, and because the caller has already spent twenty minutes being pleasant.
There is no scenario in which a legitimate crypto support process requires remote control of your computer. If you have already granted it, assume every credential on that machine is compromised, not only the crypto ones.
What is the verification protocol?
Four steps, and they work regardless of how convincing the contact was.
- End the contact. Hang up, close the chat, stop replying. You owe an unsolicited contact nothing, and a real one will survive being ended.
- Discard everything they gave you. Do not use their link, their phone number, their app, their address or their support ticket reference. All of it is part of the attack.
- Reach the company yourself. Type the URL from memory or a bookmark you made, or use an app already installed on your phone. Open a support ticket through the official channel and ask whether they contacted you.
- Apply the absolute rule. No legitimate party ever needs your recovery phrase. Not support, not a developer, not an exchange, not a lawyer, not a wallet manufacturer, not the police. There is no exception, no emergency and no verification process that requires it. If someone asks, the conversation is over.
If you want a second opinion without involving a stranger, members can describe the situation to Ask Crypto AI privately and get an assessment before doing anything.
What should you do if you already gave something away?
Move quickly and in this order.
- If you shared a recovery phrase, treat every wallet from that phrase as compromised. Move any remaining funds to a wallet created from a completely new phrase, immediately. Do not attempt to secure the old one; it cannot be secured.
- If you gave a code or a password, change the password, revoke active sessions, remove and re-add two-factor authentication, and check for withdrawal addresses or API keys added to the account.
- If you granted remote access, disconnect from the internet, uninstall the remote software, run a security scan, and change credentials from a different device that was not in the session.
- Report it to the exchange, which can sometimes freeze funds that arrive on its platform, and to your national fraud reporting body: the FBI Internet Crime Complaint Center in the United States, Action Fraud in the United Kingdom, or the equivalent where you live. Keep the messages and addresses as evidence.
Then brace for the second wave. Victims are routinely contacted afterwards by "recovery specialists" who promise to trace and return the funds for an upfront fee. They are the same industry, sometimes literally the same people, working a list of known victims. Recovery of on-chain transfers is essentially impossible, and anyone claiming otherwise is selling you the second loss. Our guide to spotting crypto scams covers that pattern and its relatives.
How do you protect someone less technical?
Do not try to teach the taxonomy. The details change monthly and the categories will not stick. Teach one sentence: nobody legitimate will ever ask for your recovery words, and anyone who contacts you first is not who they say they are.
Add one behaviour: when in doubt, end the conversation and ask a specific named person in the family before doing anything. Giving someone a designated person to call converts a moment of pressure into a moment of delay, and delay is what defeats this attack. Broader habits worth building are in our crypto security best practices guide, and the security models of common wallets are covered in is Exodus wallet safe and is MetaMask safe. If you use an exchange, is Kraken safe shows what genuine exchange security features look like, and there is more in our scams and risk hub.
Frequently asked questions
Does crypto wallet support ever call you?
No. Most wallets are free open-source software with no support department at all, and hardware wallet makers support devices rather than funds. Exchanges have real support teams, but they respond to tickets you open and never contact you first to ask you to move money, share codes or install software. An unsolicited call is always an impostor.
How do scammers know I have a problem with my wallet?
Usually because you said so publicly. Automated accounts monitor X, Reddit, Discord and project forums for wallet and exchange keywords, then message anyone who posts about an error within minutes. Others buy search adverts targeting help-related searches. Avoid posting wallet details or error messages publicly, and expect messages if you do.
Is it safe to give someone remote access to fix my wallet?
Never. A remote session lets the other person watch everything you type, read files including photographs of recovery sheets, open your password manager and email, and install software that persists after the call. No legitimate crypto support process requires remote control of your machine. If you have already allowed it, treat every credential on that computer as compromised.
What should I do if I gave someone my seed phrase?
Act immediately, because those funds are now spendable by a stranger. Create a brand new wallet from a completely new recovery phrase and move any remaining assets to it straight away. The old wallet cannot be made safe by changing a PIN or password, since the phrase alone reconstructs every key. Then report the theft to the relevant exchange and fraud body.
Can stolen crypto be recovered?
Almost never once it has left your wallet. Blockchain transfers are final and there is no central authority that can reverse them. Funds are occasionally frozen if they land on a compliant exchange that acts fast, which is why reporting quickly is worthwhile. Treat anyone offering guaranteed recovery for a fee as a follow-up scam.
How can I tell a real Discord moderator from a fake one?
Real moderators very rarely message first and most keep direct messages closed, which is often stated in the server rules. Impostors copy the display name and avatar exactly, so check the underlying username and account age, and verify in the public channel where the real team can see and confirm. Any moderator asking for a seed phrase is fake.


