The most expensive message in crypto is not a phishing link. It is a helpful stranger who arrives before you ask for help.

You post a question in a project’s Discord. Ninety seconds later, someone with an official-looking username DMs you: “Hi, I’m from the support team, I saw your issue in the channel. Let’s resolve this privately.” Or your phone rings, and the caller says they are from your exchange’s security department, and there is suspicious activity on your account that must be addressed right now.

Both are the opening move of the same play. The FBI’s Internet Crime Complaint Center documented it in an August 2024 alert on scammers impersonating cryptocurrency exchange employees: the contact is unsolicited, the tone is urgent, the story is an account problem or an attempted compromise, and the fix always ends with you handing something over — login information, a clicked link, identity documents, or access to your device.

This guide breaks the scam into its working parts: how the funnel finds you, the three endings it is built to reach, what the aftermath looks like on-chain, and the one rule that makes the whole structure collapse.

The One Rule

Real support never contacts you first.

Not by phone. Not by DM. Not by email about an account you didn’t write in about. Support in crypto is reactive: you open a ticket through the official help center, and the conversation happens there, or through email from the company’s official domain about the ticket you opened.

This is not a custom or a best practice. It is a published invariant, and you can verify it on the support pages of the largest wallet in the industry. MetaMask’s “How to contact MetaMask Support” page states it in three consecutive sentences: support “will never reach out to you first by direct message or email,” MetaMask “does not have a phone number,” and it “will never ask you for your Secret Recovery Phrase.” The company’s official channels page adds the corollary: emails about open tickets come only from the support domain, and anyone asking for your secret recovery phrase is running a scam, full stop.

Almost every serious exchange and protocol publishes some version of the same rule. The details differ; the invariant doesn’t. So when someone contacts you first, the question “is this real?” has already been answered by the fact of the contact itself.

How the Funnel Finds You

The scam is engineered around timing, and the timing is not accidental.

The support-channel ambush. You have a problem — a stuck withdrawal, an airdrop claim that errors out, a sync issue — and you do what people do: you post about it in the project’s public Discord or Telegram channel, or you reply to the project on X. Attackers watch these channels continuously, and the response is fast because it has to be: a “support agent” DMs you within minutes, often before real community members answer. The username matches the project’s naming style. The avatar looks right. The message references your actual problem, sometimes quoting it back to you.

Everything after that moves you out of public view. “Let’s continue in private so we can verify your identity.” Public channels are hostile terrain for the scam — real moderators and community members can interrupt. A DM is a clean room.

The inbound call. The second variant needs no trigger from you. Your number is on a leaked or scraped list — a data broker dump, an old exchange KYC breach, a signup form from years ago — and the caller claims to be from your exchange’s security or compliance team. The FBI’s alert describes the script: there is a problem with your account, or someone is trying to compromise it right now, and you need to act immediately to protect your funds. Caller ID is not evidence. Numbers can be spoofed to display the exchange’s real support line, which is why the FBI’s first piece of advice is to hang up and call back using only the number listed on the official website — never a number the caller provides.

The search-engine trap. The third entry point is the result page itself. You search for your wallet’s or exchange’s support contact, and the top result is an ad for a lookalike support site — the same logo, the same layout, a phone number that reaches a professional-sounding “agent.” The tell here is structural: a company like MetaMask has no phone number to find. If the contact you found is a phone line, it is not the wallet maker’s support, no matter how well the site is built.

What all three variants share is the inversion: they come to you. Once you internalize that real support only ever answers, never initiates, every one of these openings reads as what it is.

The Three Endings

The funnel is flexible about the story but rigid about the destination. Every fake support conversation is built to end in one of three places, and knowing them in advance is usually enough to break the spell mid-conversation.

Ending 1: The phishing page

The “agent” needs to “verify your account.” You are sent to a support portal or wallet-verification page — a site that mirrors the real one down to the favicon. The page asks for the thing it was built to collect: exchange login credentials and a 2FA code, or, on the wallet side, your seed phrase entered into a twelve- or twenty-four-box form “to confirm ownership.”

There is no version of this that is real. No exchange asks for your password over a support chat, and no wallet maker has ever needed your seed phrase for anything — support can read your public address, which is all a diagnosis ever requires. A seed phrase entered into a web form is a wallet drained within minutes, usually from an automated wallet drainer that has the sweep transaction queued before you finish clicking submit.

Ending 2: The verification signature

This one is subtler, and it catches people who “would never share their seed phrase” — because they never do.

Your wallet needs to be “synchronized” with the new security system, or your identity needs to be “verified on-chain,” or your stuck transaction needs to be “released.” The fix is a signature request pushed to your wallet. The message is rendered as hexadecimal garbage, or the request UI says you are signing something harmless, and the agent stays on the line, calmly telling you this is routine.

It is one of two attacks wearing the same coat:

  • A token approval. You are not verifying anything — you are authorizing a contract to spend a specific token, or an unlimited amount of it. This is the mechanics behind infinite approvals, and the drainer waits until you have refilled the wallet or the gas price is cheap.
  • A raw eth_sign message. On wallets and accounts that still allow it, signing raw arbitrary data can produce a signature that moves funds. This is the classic eth_sign phishing pattern, and it is the reason hardware wallets push you to read exactly what you are signing on the device screen.

The rule that cuts through every variant: no support process in crypto requires a signature. Reading your public address is free and needs nothing from you. Anything else is extraction.

Ending 3: The remote session

The “technician” cannot diagnose the problem remotely — they need you to install a remote-access tool or a screen-sharing app “so engineering can see what’s happening.” Once the session is live, the ending depends on the operator’s patience.

The fast version is a smash-and-grab: watch your screen until you unlock your wallet, then act in the seconds it stays unlocked, or read credentials and 2FA codes directly off your display as you type them into the “support portal.” The slow version is worse — the remote tool is a delivery mechanism for an infostealer, which harvests browser passwords, session cookies, and wallet extension vaults, then phones home. You close the “resolved” ticket feeling helped; the extraction happens days later from a device you still trust.

There is no diagnostic in the world that requires a stranger to control your device. That is not support. That is handing over the keys and watching politely.

What the Aftermath Looks Like On-Chain

If the ending already happened, the transaction history tells you which one it was — and that determines your next move.

A seed-phrase compromise is the cleanest signature: everything with value leaves in one burst, including the ETH or gas token itself, because the attacker controls the keys outright. A malicious approval is the opposite: your ETH balance sits untouched, gas is spent only by the attacker’s own transactions, and specific tokens disappear in transactions you can find in your history — signed by you, at a moment the “agent” was walking you through “verification.” Paste your address into any approval-revocation tool and the grant is sitting there, explicit, with a date and time.

Either way, the funds route through a chain of fresh addresses toward an exchange deposit or a mixer. That trail is what investigators work with, and it is why the first hours matter: exchange-side freezes are possible only while the funds are still sitting at a KYC’d off-ramp. The full playbook — what to preserve, how to revoke approvals, where to file, what a freeze request contains — is in what to do in the first 24 hours after a theft, and the reporting mechanics are in how to report a crypto scam. Tools that read wallet labels can tell you whether the receiving cluster is already tagged as a drainer cash-out — useful both for triage and for your report.

The Verification Protocol

When you genuinely need support, the safe path takes thirty seconds longer and cannot be hijacked:

  1. Close the conversation. Do not “just ask one more question.” Every additional message is attack surface.
  2. Navigate to the official site yourself. Type the domain or use your own bookmark. Do not use any link, phone number, or email address the “agent” provided — this is the FBI’s explicit guidance in its exchange-impersonation alert.
  3. Use the help center inside the product. Exchanges put support inside the logged-in app or website; wallet makers publish a single support domain. If you have a ticket, replies come through that channel only.
  4. In Discord, verify roles in public. Real staff are visible in the server’s member list with a role badge, and they answer where others can see. A “moderator” who exists only in your DMs has no verifiable existence.

And the four asks that end any doubt, because each one is an automatic fail: a password or login, a seed phrase or private key, a 2FA code, or remote access to your device. No real support interaction in the history of crypto has required any of the four.

Round Two: The Recovery Follow-Up

The fake support scam has a sequel, and it opens on the same wound. Days after the loss, someone messages you: they are from a “blockchain analytics firm” or a “recovery team,” they have already located your funds, and for a fee — or an upfront “gas deposit” — they can get them back.

The FBI flags this follow-on explicitly in the same alert, pointing to its separate advisory on fake recovery services. The structure is always the same: an upfront payment, a stretch of “processing,” then a bigger payment to “release the funds,” until the victim stops paying. The scam works because the target list is already built — you are known to have lost money and to be desperate.

We cover the full anatomy, including the free channels that actually exist (exchange freeze requests, law enforcement referral, court-ordered forfeiture) in crypto recovery scams explained. The short version of that page applies here with full force: anyone who contacts you first promising recovery is running the second half of the scam that just hit you.

Why It Keeps Working

Every surface the scam borrows is a surface you have been trained to trust, and none of it is authenticated.

Caller ID was built to display who owns a line, not to prove who is speaking, and spoofing it is trivial. A Discord username and avatar cost nothing to copy and take seconds to register. A support website can mirror a real one for the price of a lookalike domain. The “agent” will often have your real name, your real account details, and the real problem you posted minutes ago — not because they work at the exchange, but because breaches and public channels have already published the raw material. Each borrowed detail feels like proof, and none of it is.

The second ingredient is time pressure. “Someone is trying to access your account right now” is engineered to make verification feel like the risky option — as if the two minutes it takes to hang up and open the official site is the window in which the imaginary attacker wins. It inverts the actual risk math: the only scenario in which you lose money in those two minutes is the one where you stay on the line.

The third is that the scam arrives attached to a real problem. Most victims were not idle targets; they had a genuine stuck withdrawal or a failed claim and went looking for help. The scam does not need to invent a pretext — it intercepts an existing one, which is why the ambush variant centers on public support channels. That interception is also its weakness: the timing is too good. Real support does not answer a Discord post in ninety seconds. An impossibly fast, impossibly helpful responder is the scam announcing itself.

Fake support survives on a single asymmetry: the scammer knows the script and you don’t. The script always opens the same way — they find you, before you find them. Now you know what that means.

Frequently Asked Questions

How do I know if a crypto support agent is real?

Real support never contacts you first. If someone calls, DMs, or emails you about a problem with your account that you never reported, they are a scammer regardless of how official the caller ID, profile, or email looks. Close the conversation, open the exchange or wallet's official website yourself, and use the help center listed there. On Discord, real staff answer in public channels or through official ticket systems — not through DMs that arrive seconds after you post a problem.

Does MetaMask or my wallet provider have a phone number?

MetaMask states plainly that it does not have a phone number, and that anyone calling you as MetaMask support is a scammer. Most wallet providers and DeFi protocols are the same: support happens through official help centers and email from official domains, only for tickets you opened. Any phone-based 'crypto support' you found through a search ad should be treated as fake by default.

What do fake support scammers ask for?

Four things, and all four are disqualifying: your password or login credentials, your seed phrase or private key, a one-time 2FA code 'to verify your identity,' or permission to install remote-access software like a screen-sharing or device-control app. The FBI's August 2024 alert on exchange-employee impersonation describes the same pattern: urgency, an account problem, then a request for login information, a link, or identity documents.

They asked me to sign a 'verification' transaction to fix my account. Is that normal?

No. There is no customer-support process in crypto that requires you to sign a transaction. A 'wallet synchronization' or 'identity verification' signature is one of two attacks: a token approval that lets a drainer contract spend your funds later, or a raw eth_sign message that can move assets on some wallets. Legitimate support can read your public address; it never needs your signature to 'check' anything.

I already gave access or signed something. What now?

Treat it as an active incident, not a lost cause. If you shared credentials, change the password and revoke sessions from a clean device. If you signed something, check and revoke token approvals immediately, then move remaining assets to a fresh wallet with a new seed phrase. Save the scammer's handles, links, and any transaction hashes, then file reports — IC3 if you are in the US, your local cybercrime channel elsewhere, and a freeze request to the exchange that received the funds. And ignore anyone who messages you first offering to recover the funds: per the FBI, fake recovery services are the follow-up act to this exact scam.