Focus on what the message asks you to do

A convincing logo, verified account, or familiar sender name does not establish that a request is legitimate. Compromised accounts and cloned websites can look ordinary. Pay attention when a message asks you to reveal credentials, install software, approve a signature, or move money.

Open the service through a saved address and check the account there. For support, start a new request through the official site. Do not use a telephone number, link, or contact provided by the suspicious message as your independent check.

The patterns that keep returning

Crypto scams often create a deadline so you act before verifying. A supposed wallet update asks for your backup, a support agent requests screen sharing, or an account warning directs you to a fake login. A copied interview or live stream can promote a giveaway that asks you to send crypto first.

  • Never provide recovery words or private keys to a support agent or a website.
  • Do not install remote-access software at the request of someone who contacted you.
  • Do not send crypto to unlock a prize, verify a wallet, or protect money from a supposed investigation.
  • Treat promises of guaranteed profit and private investment opportunities as reasons to investigate, not to deposit.
  • Ignore unfamiliar tokens or NFTs that direct you to a claim website. Their presence in your wallet does not mean you requested them.

A code can be phished as well as a password

A fake website can relay a password and current authenticator code to the real service. An authenticator app is therefore not a guarantee against phishing. FIDO-based authentication can help because it is tied to the service’s domain.

Before signing in, inspect the full hostname rather than a familiar word inside it. A padlock indicates an encrypted connection; it does not say that the operator is trustworthy. Use bookmarks and let your password manager match the saved domain.

Connecting and signing are different actions

Connecting a wallet commonly reveals an address. A later signature or transaction can grant permissions or move assets. Read each prompt separately, even when the website describes every step as harmless verification.

A hardware wallet does not make a malicious request safe. Confirm the asset, spender or destination, network, and amount where the wallet shows them. If the request is opaque or inconsistent with what you intended, cancel it.

Slow investment scams can look like a relationship

An unsolicited conversation may develop for weeks before the person introduces an investment platform. The site may show fictional profits and even permit an initial withdrawal. Later demands for taxes, verification deposits, or release fees can be part of the same scam.

Do not let another person direct your wallet transactions or choose where you deposit funds. Verify a provider independently and discuss an unexpected opportunity with someone outside that conversation before sending anything.

Respond according to what was exposed

If you entered an exchange password or code, use a trusted device to change credentials, revoke sessions, and contact the exchange. If you approved a suspicious token allowance, inspect and revoke the relevant permission through a verified tool. If recovery words were disclosed, treat the wallet keys as compromised and arrange a fresh wallet.

Preserve transaction hashes, destination addresses, URLs, messages, and dates. US users can report fraud to the FTC and internet crime to the FBI’s IC3. Be cautious of anyone charging an upfront fee to recover stolen crypto; victims are frequent targets of a second scam.

Sources & limits

Source review: Oct 1, 2026. Availability and provider terms can change.

Keep exploring