Security & Compliance

Crypto Scam Red Flags: Fake Support and Recovery Scams

Spot crypto scam red flags in fake support, investment, address-poisoning, invoice-substitution, and recovery schemes; contain damage and preserve evidence.

Crypto Scam Red Flags: Fake Support and Recovery Scams

Crypto scam red flags often appear together: urgency, secrecy, unfamiliar payment instructions, credential demands, or a promise to recover lost funds for an upfront fee. Verify the identity, domain, account, and wallet route through channels you opened independently before sending money or sharing access. Official sources reviewed August 26, 2026.

The checks apply to payment requests, job offers, investment pitches, support messages and refund instructions. They lead to one of three outcomes: continue through a verified channel, stop before sending, or preserve evidence and contain damage after exposure.

In this guide

Why crypto scams often succeed before the transaction

The blockchain normally executes the instruction it receives; it does not know whether a person was deceived. A scammer therefore tries to control the information around the transfer: who appears to be speaking, which website is opened, which address is copied, why the payment is urgent and what the victim expects to happen next.

Many transfers are difficult to reverse. Treat the decision before authorization as the main safety boundary. Do not rely on a promised refund, a support agent who contacted you first or a person who says they can recover a transaction later.

The current Ethereum security page emphasizes that unsolicited “support” contact is not legitimate and that recovery phrases and private keys must remain private. Its public guidance is shown in this article’s cover screenshot, captured 2026-08.

Eight red flags that should stop the payment

Red flag Typical story Safe response
Unsolicited support “Your account is compromised; move funds now” End contact and open the provider’s official app or bookmarked site yourself
Guaranteed profit “Risk-free return” or a fixed daily gain Do not deposit; a displayed balance is not withdrawable evidence
Pay to unlock money Tax, insurance, verification or recovery fee to release funds Stop; do not send a second payment to rescue the first
Secret or remote access request Password, OTP, seed phrase, private key, screen sharing Refuse, disconnect and secure the account from a clean device
Sudden destination change A supplier replaces the agreed address in chat Verify through a previously trusted second channel and issue a new route card
Third-party payer or refund An unrelated person pays, then asks for a refund elsewhere Freeze the refund and contact the provider or bank through official channels
Job requires a deposit Pay for training, equipment, account activation or task completion Verify the employer independently; legitimate wages do not require a crypto deposit
Isolation and deadline “Do not tell your bank/family” or “send in ten minutes” Pause; involve another trusted person before taking any irreversible step

One red flag can be enough to stop. Several red flags together are not made safe by a professional-looking website, a small successful withdrawal or a friendly relationship built over weeks.

Verify the identity outside the conversation

Do not ask the same account that contacted you to prove itself. Build a separate verification path:

  1. Write down the claimed person, company, legal entity and purpose of payment.
  2. Navigate to the official domain from a bookmark, regulator listing or independently typed address.
  3. Locate the company’s support or contact details on that domain—not in the incoming message.
  4. Contact the known person or company through a second channel already on record.
  5. Ask them to restate the invoice number, amount, asset, network and destination without showing them your answer first.
  6. Check whether the request matches the contract, invoice and normal business process.
  7. Stop if the story changes, documentation is refused or the counterparty insists on staying inside one private chat.

Caller ID, social-media verification marks, search ads and copied logos can be spoofed. HTTPS only means the connection to that domain is encrypted; it does not mean the domain belongs to the claimed company.

Fake exchange support follows a predictable script

An impersonator commonly claims that an account is under attack, creates urgency, and asks the victim to click a link, disclose login details or transfer funds to a “safe” wallet. The FBI/IC3 public notice below documents this pattern and advises users to reach the exchange through independently located official contact details.

FBI and IC3 public service announcement warning that scammers impersonate cryptocurrency exchange staff, create urgency, request login information or links, and then steal funds

FBI Internet Crime Complaint Center public notice, captured 2026-08. The notice is evidence of the impersonation pattern; it does not imply that a U.S. reporting channel replaces local reporting in another country.

Real support should not ask for your seed phrase, private key, password, one-time code, authenticator backup, passkey recovery material or remote control of your device. If a conversation began from an unsolicited call, direct message or search advertisement, treat every link and phone number inside it as untrusted.

Check the website and app without trusting appearance

Use a simple domain check before signing in or connecting a wallet:

  • read the registrable domain from right to left and look for misspellings or added words;
  • open the provider from a saved bookmark or official app-store listing reached independently;
  • compare the domain with the provider’s published help or legal pages;
  • do not install an app, browser extension or remote-access tool from a chat attachment;
  • reject pages that require a seed phrase merely to view a balance, fix a transaction or “synchronize” a wallet;
  • do not connect a wallet to inspect a public transaction hash—block explorers do not need wallet secrets.

If a provider is regulated for the service you intend to use, verify the exact legal entity and permitted activity on the current regulator page. A copied license number, a company registration or an app-store presence is not an endorsement and may not cover crypto transfers.

Prevent address poisoning and invoice substitution

Address poisoning places a look-alike address in transaction history so a user later copies the wrong destination. Clipboard malware can replace a correctly copied address before it is pasted. Invoice fraud can replace the payment route through a compromised email account.

Use this procedure for a material payment:

  1. Generate or request fresh receiving instructions.
  2. Confirm the asset and exact network before looking at the address.
  3. Copy from the current receive screen, not transaction history.
  4. Compare the complete address where the interface permits, not only the first and last characters.
  5. Confirm any memo or tag separately.
  6. Read the destination back through a known second channel.
  7. Use an allowlist only after the address has been independently verified.
  8. Send a crypto test transaction guide and wait for the intended account to credit it.

A successful on-chain transfer to the wrong person remains a successful blockchain transaction. The goal is not only a “Success” status; it is credit to the intended recipient under the agreed invoice.

Recognize crypto recovery scams and payment fraud

Payment scam: a fake supplier, client, authority or relative asks for an irreversible transfer. Verify identity, invoice and destination.

Investment scam: a platform shows profits, may permit one small withdrawal, then demands more deposits or fees. Do not use the displayed balance as proof of assets or liquidity.

Relationship or job scam: trust is built before crypto is introduced. Separate the relationship from the financial proposal and verify the employer, contract and payment purpose outside the conversation.

Recovery scam: after a loss, a “lawyer,” investigator, hacker or recovery agent promises guaranteed retrieval for an upfront crypto payment. Stop. Preserve evidence and use official provider, bank and law-enforcement channels.

No one can guarantee recovery of an irreversible transaction. A person who knows your loss amount or wallet address may have obtained it from public blockchain data, a leaked victim list or the original scammer.

A five-minute stop-check before sending

Answer all eight questions with evidence:

Check Pass condition
Who is requesting payment? Identity confirmed through an independent channel
Why is payment due? Contract, invoice or family purpose is documented
Why crypto? It is an agreed option, not a threat or unlock condition
Which asset and network? Exact pair appears on both live sender and receiver screens
Who controls the destination? Intended recipient confirmed it independently
What secrets are requested? None—no password, OTP, seed phrase or private key
Can the route be tested? Test can exceed the current minimum without material risk
What happens if it fails? Stop and escalation path exists before the main amount

If any answer is unknown, the correct result is do not send yet. A pause is a completed safety decision, not a failed payment.

If you already sent funds or disclosed a secret

Act in this order and do not pay a recovery fee:

  1. Stop communicating and stop all additional transfers.
  2. Preserve URLs, usernames, phone numbers, messages, invoices, wallet addresses, TxIDs, bank references and timestamps with timezone.
  3. Contact the exchange, wallet provider, bank or payment service through its official channel; provide public transaction details and the case facts.
  4. If a password or OTP was exposed, secure the email account first, then reset the affected account from a clean device and revoke active sessions.
  5. If an API key was exposed, revoke it and review permissions and transaction history.
  6. If a seed phrase or private key was exposed, treat that wallet as compromised. Get qualified help through a verified channel and move remaining assets only after preparing a clean wallet safely.
  7. Warn the real person or company if their email or messaging account may be compromised.
  8. File reports with the appropriate local authority and preserve case numbers.

Do not delete the conversation in anger. Screenshots help, but exportable messages, email headers, URLs, transaction records and original files may provide stronger evidence.

Reporting and evidence for users in Cambodia

Cambodia’s National Police operates an online scam-complaint portal at hotline.police.gov.kh. The portal states that submitted information and evidence must be accurate and that a complainant may still be asked to appear in person. CamCERT also publishes an incident-reporting page for cybersecurity incidents and technical assistance.

If a Cambodian bank or regulated financial service was involved, contact that institution immediately using a trusted number or app. Preserve the bank reference and ask what recall, hold or fraud-report process is available; do not assume recovery is possible. If there is immediate danger, identity theft or a substantial loss, use the appropriate police channel rather than relying only on a platform chat.

Prepare one evidence folder containing:

  • a factual timeline with dates, times and timezone;
  • the original contact channel and claimed identity;
  • complete URLs and registrable domains;
  • wallet addresses, networks, token identity and TxIDs;
  • exchange order, withdrawal or deposit references;
  • bank or card references where applicable;
  • messages, invoices and files in their original form;
  • actions already taken and official case numbers.

Share secrets with nobody. A seed phrase, private key, password or OTP does not belong in an ordinary report attachment.

You have enough evidence to decide or report

Before a legitimate payment proceeds, you should be able to show that the identity, purpose, asset-network pair, destination, minimum, fee preview and test credit were independently verified. After an incident, completion means additional loss has been stopped, exposed access has been secured, evidence is preserved, and reports have been filed through real channels. It does not mean a recovery promise has been obtained.

Current first-party references used for this review:

Educational information only. It is not legal, financial or recovery advice. If funds, identity documents or account access are at risk, contact the relevant provider, financial institution and local authority promptly.