There is a particular cruelty to fake customer support scams. They do not target people at random. They target people who are already worried, who have already noticed a delayed withdrawal, a locked account, or a suspicious login, and who are actively searching for help. That moment of anxiety is exactly what the scam is built to exploit.
How the scam typically unfolds
The pattern shows up across nearly every major platform, but the structure repeats. A user posts a question in an exchange's public Telegram or Discord server, or replies to a real company's post on X asking for help. Within minutes, an account with a support sounding name and a company logo as its profile picture sends a direct message offering to help resolve the issue right away.
Coinbase has publicly warned that scammers actively monitor its own community channels for exactly this kind of opening, watching for users who mention a problem so they can jump into the conversation posing as staff before a real representative responds. Because the fake account often appears within the same channel as genuine users and moderators, the setting itself lends false credibility to the impersonator.
What the fake agent asks for
Once contact is made, the fake agent asks for one of a few things: your account email and a verification code sent to it, your seed phrase or private key to help resolve a wallet issue, or remote access to your device through a screen sharing tool so they can walk you through a fix. Every one of these requests is something a real support team would never ask for, because none of them are needed to genuinely troubleshoot an account. A recovery phrase in particular grants full and permanent control over a wallet, and no legitimate support interaction requires it.
No legitimate exchange or wallet support team will ever ask for your seed phrase, private key, or remote access to your device. Any request for these is the scam itself, not a step toward fixing a problem.
A fake support conversation, message by message
A concrete walkthrough shows how quickly the manipulation escalates once contact is made. Consider a user who posts in an exchange's public Discord server, "my withdrawal has been pending for six hours, is something wrong." Within two or three minutes, a private message arrives from an account named something like "Exchange Support | Sarah" with the exchange's logo as its avatar.
- Message one: "Hi, I saw your message in the server. I'm one of the support agents here, sorry for the delay you're experiencing. I can look into this for you right now."
- Message two: "Can you confirm the email linked to your account so I can pull up your ticket."
- Message three, after the user replies: "I see the issue, there's a flag on your withdrawal from our security system. To clear it I'll need you to verify ownership of the wallet. Can you open your wallet app and go to the recovery phrase section."
- Message four, if the user hesitates: "I completely understand the caution, that's actually a good sign you're security conscious. This is a standard verification step we use for exactly this kind of flag, and it stays on our secure internal system, it's never stored."
Notice the structure. The agent responds fast enough to feel attentive rather than suspicious. The early questions, an email address, are things a real support process might plausibly ask, which builds a small amount of trust before the actual request arrives. And when the user pushes back, the scammer reframes the hesitation itself as a positive trait rather than getting defensive, which is a deliberate technique to keep the target engaged rather than ending the conversation. By the time the recovery phrase request arrives, several minutes of rapport have already been built, and a slight majority of targets who have gotten this far will comply rather than break off contact.
How the scam differs by platform
Telegram and Discord
These platforms allow anyone to create an account with a custom display name and profile picture in seconds, with no verification tying the name to a real identity. A scammer can join dozens of public crypto servers simultaneously, using bots to scan for keywords like "stuck," "pending," or "help" in real time, and respond to multiple potential victims in parallel. Server moderators do ban these accounts once reported, but a new one can be created just as quickly, which is why the pattern persists on both platforms despite years of user reports.
X and other public social platforms
On X, the scam usually appears as a reply underneath a real company's own post, or underneath a user's public complaint tagging the company. The fake account replies publicly first, often before the real company does, then moves the conversation to direct messages once contact is established. Some of these accounts pay for a verification style badge available to any paying subscriber, which can create a false impression of legitimacy for users who do not realize the badge no longer functions as proof of identity the way it once did on the platform.
Phone based fake support
A less discussed but still common variant uses fraudulent phone numbers placed in search ads or fake directory listings, so that a user searching for a company's support line reaches a scam call center instead. These operations can sound highly professional, sometimes using hold music and scripted call routing that mimics a real company's phone tree, and they rely on victims trusting a voice on a phone call more readily than a text message from an unfamiliar account.
The scale of the problem
Impersonation scams targeting crypto users grew by roughly 1,400 percent year over year through 2025, according to industry fraud tracking, with the average amount lost per incident climbing over 250 percent to roughly 2,764 dollars. Some of the most organized activity has been tied to loosely affiliated online groups that specifically coordinate fake support operations across Discord and Telegram, treating it as a repeatable playbook rather than an improvised trick.
Variations to watch for
- Fake support phone numbers placed in search engine ads or fraudulent listings that appear above real company results
- Cloned help center websites with a live chat widget staffed by a scammer, reached through a phishing link
- Fraudulent support tickets that ask you to log in through an embedded link rather than the app or official site directly
- Follow up scams where a second fake agent poses as a fraud recovery specialist after the first scam is discovered, offering to retrieve the stolen funds for an upfront fee
That last pattern is especially damaging because it targets people twice in a row, first through the fake support contact and then through a fake recovery offer. Anyone approached this way should read our guide on fake recovery agents before engaging further, and should never pay an upfront fee to anyone claiming they can retrieve stolen funds.
How to tell real support from an impersonator
- Real support almost never initiates contact through a direct message after you post publicly, they generally ask you to open a ticket through the official app or website
- Real support never asks for your seed phrase, private key, or full password under any circumstance
- Real support does not ask to install remote access software to fix a wallet issue
- Real support communicates through verified channels listed on the company's own official website, not through a link sent in chat
If you are unsure whether a message is genuine, the safest move is to stop the conversation and navigate independently to the platform's official site by typing the address yourself, then look for the same offer or ticket through your verified account. Never click through a link the alleged support agent provides to "verify" anything.
Building a habit that resists social pressure
Most people already know, in the abstract, that they should never share a seed phrase. The scam succeeds anyway because it does not present itself as a request for a seed phrase, it presents itself as a routine step in solving an existing problem, delivered by someone who appears responsive and knowledgeable at a moment of genuine stress. The most reliable defense is not memorizing a rule but building a habit of ending any conversation the instant a request for sensitive information or remote access appears, regardless of how reasonable the explanation sounds or how much rapport has already been built. A short pause, closing the chat window and reopening the platform independently, is often enough to break the momentum a scammer is relying on.
- If a support conversation ever asks for a recovery phrase, private key, or full password, end it immediately rather than asking for clarification
- Never install remote screen sharing software at the request of someone you contacted through a public comment or who contacted you first
- If you need to escalate a real issue, use the official support ticket system inside the app itself rather than any external chat
- Keep a mental note that a fast, friendly response to a public complaint is not evidence of legitimacy, since speed is precisely what a scam account optimizes for
If you already gave information to a fake agent
If you shared a password or verification code, change it immediately from a device you trust and enable additional security on the account if the platform allows it. If you shared a seed phrase or approved a transaction, treat that wallet as fully compromised and move any remaining funds to a new one right away, since a compromised seed phrase gives permanent access that a password change cannot undo. Document every message, username, and timestamp involved, since this record matters if you later report the incident or need it for an investigation.
Frequently asked questions
Because that person has already signaled they have a problem and are looking for a fast solution, which makes them more likely to trust an offer of quick help and less likely to scrutinize the person offering it. Scammers actively monitor public support channels for exactly this signal.
No, never, under any circumstance. A seed phrase gives complete and permanent control over a wallet, and no legitimate support process requires it. Any request for one, regardless of how official the person sounds, is a scam.
They copy the real company's logo and branding directly from its official pages, and on some platforms they can register a display name that closely matches the real handle. The account itself is not verified, so checking for an official verification badge and the exact handle spelling is a useful check.
Move any remaining funds to a brand new wallet with a freshly generated seed phrase immediately, since the compromised wallet should be considered permanently unsafe. Document the interaction and consider reporting it to the platform being impersonated and to relevant fraud authorities.
Sources and further reading
- Consumer Protection Tuesday: How Scammers Are Targeting Crypto Communities on Discord and Telegram · Coinbase
- Crypto Impersonation Scams Target Investors · Bitdefender