Scam defense / Updated 2026-08-13
The Support Agent Who Contacted You First: How Fake Help Desks Take Over Crypto Accounts
Real support answers tickets you opened; it never opens the conversation. Learn how fake exchange help desks work, why 'move your funds to a safe wallet' is always theft, and how to verify.
How this guide is checked
Official sources first, no wallet connection, no guaranteed returns.
Reviewed on 2026-08-13 by WildWildCrypto Safety Desk. Method: Human editorial review with official-source checks, affiliate-disclosure checks, and no-financial-advice checks.
Publisher: WildWildCrypto Editorial. Corrections go through the contact page. We do not ask for seed phrases or tell you what to buy.
fake crypto support scam matters because A message arrives saying there is a problem with your account. It carries the right logo, the right tone, and a name that matches a real company — and the thing it wants you to do is protect yourself, urgently.
This guide gives you a test that does not depend on judging how official something looks, explains the three things a fake help desk will ask for and what each one actually costs you, and sets out the verification habit that closes the whole category.
You will learn the direction-of-contact rule, where impersonators find you, why 'move your funds to a safe wallet' is definitionally a theft, what the 2025 federal data shows about the scale, and what to do first if you have already engaged.
The one thing impersonators cannot fake
Almost every checklist for spotting a fake message asks you to grade its appearance. Look for spelling errors, check the sender's address, see whether the logo is right. That advice made sense when fakes were sloppy. It has aged badly: branding is copied perfectly, sender names are registered with characters that look identical to the real ones, and phone numbers are spoofed to display an institution's real caller ID. Grading appearance now means competing with people whose full-time job is appearance.
There is a structural feature they cannot copy, because it is not a property of the message at all. It is the direction the contact travelled. Genuine support is reactive: you open a ticket, you start a chat, you call a number you found yourself, and a reply comes back into that channel. Fraud is proactive: it has to reach you, because you were never going to reach it. The FBI's advisory on exchange impersonation describes the opening move plainly — the fraudster makes contact by unsolicited call or message, claims to be exchange staff, and says there is a problem with your account or that someone is trying to compromise it. Read that as a rule rather than a description and it does real work: an unsolicited contact about your account can be discarded without you ever assessing whether it looks convincing. You are no longer grading a forgery. You are noticing that a conversation started from the wrong end.
Checklist
- Real support answers channels you opened; it does not open them.
- Logos, sender names, and caller ID are all cheaply faked.
- Direction of contact is structural — it cannot be forged.
- Unsolicited contact about your account: stop reading, start verifying.
- You never have to judge whether the message 'looks real'.
How they find you, and why the handle looks right
Impersonators do not usually guess. Public spaces where people ask for help are the hunting ground: a project's community chat, a support forum, the replies under an exchange's social media post, a comment describing a stuck withdrawal. Someone posting a problem in public has self-identified as a person who currently wants help from that company, and a direct message arrives minutes later from an account whose display name and avatar match the official one. The FBI's guidance on tech and customer support impersonation notes that criminals pose as representatives across a wide range of services and explicitly includes cryptocurrency exchanges in that list, alongside banks, utilities, and software vendors — the same playbook, aimed at a faster and less reversible payment rail.
The other route is that you go looking and find them. Searching for a company's support number or help page can surface paid advertisements and lookalike sites positioned above the real result, so the number you dial is one the scammer bought placement for. This is why 'I contacted them, they did not contact me' is not by itself sufficient — the direction rule only protects you if the destination came from somewhere you trust. Reach a company through its own app, a bookmark you saved, or the domain typed by hand, and treat search results and links in messages as untrusted routes to a trusted-looking place.
Checklist
- Asking for help in public marks you as a target.
- Lookalike handles use near-identical characters and real avatars.
- Search ads and cloned support pages catch people who go looking.
- Get contact details from the official app, a bookmark, or a typed domain.
- Never call a number or open a link supplied by whoever contacted you.
The three asks, and what each one actually costs
Whatever the story, a fake help desk needs one of three things, and it helps to know the cost of each before you are under pressure. The first is your credentials — the password, and then the two-factor code, usually framed as 'verifying your identity' or 'confirming it is really you'. Handing over a one-time code is the moment the account changes hands, which is why no legitimate support process asks for one; the code exists precisely to prove you and not the caller are present. The second is control of your device, usually through remote-support software installed 'so we can fix it for you'. That grants a stranger your screen, your session, and anything you unlock while they watch, and the FBI's guidance is direct about it: do not allow an unknown individual who contacted you to have control of your devices or accounts.
The third ask is the one specific to crypto, and it is the most final. You are told your funds are at risk and must be moved immediately to a 'safe wallet', a 'secure account', or a 'protected address' — an address the caller supplies. It sounds like protective advice, and it is the entire theft. No legitimate institution needs your assets to travel in order to secure them: a real provider freezes withdrawals, locks the session, or disables the account, all of which happen where the funds already are. The federal guidance makes the general form of the rule explicit, warning that government and law enforcement will never ask you to send money by wire, cryptocurrency, crypto ATM, gift card, or by mailing cash — and the same logic extends to a company that supposedly employs the person calling you. Treat any instruction to move your own money to safety as a confession. Once a transfer leaves your wallet it does not come back, which is why this ask is reserved for the payment rails that cannot be reversed.
Checklist
- Ask 1 — password and 2FA code: the code is the handover, never share it.
- Ask 2 — remote-access software: hands over screen, session, and anything you unlock.
- Ask 3 — 'move funds to a safe wallet': the theft itself, always.
- Real providers secure an account in place; assets never need to move.
- Crypto transfers are final, which is why this rail is chosen.
What the 2025 federal data shows about the scale
This is not a fringe category. The FBI's 2025 Internet Crime Report recorded 1,008,597 complaints and $20.877 billion in reported losses, a 26% rise in losses over the previous year. Within that, tech and customer support fraud accounted for 47,794 complaints and $2,134,675,818 — the third-largest loss category of the year, behind only investment fraud and business email compromise, and ahead of romance scams. Government impersonation added a further 32,424 complaints and $797,943,193. The report also breaks out account takeover fraud carried out through impersonation of financial institution support: roughly 4,700 complaints and $359.7 million, which is a narrow slice describing this exact manoeuvre.
Two further figures put it in context. Complaints carrying a cryptocurrency descriptor numbered 181,565 with $11,366,669,732 in losses, so crypto is where a large share of all reported fraud value now lands. And the age distribution is stark: complainants aged 60 and over filed 201,266 complaints with $7.7 billion in losses, more than any other group. If you help an older relative with anything technical, the direction-of-contact rule is the single most useful thing to hand them, because it requires no technical knowledge to apply — it is a rule about who started the conversation, not about how convincing it was.
Checklist
- 2025 total: 1,008,597 complaints, $20.877 billion lost, up 26%.
- Tech/customer support fraud: 47,794 complaints, $2.13 billion — third-largest by loss.
- Government impersonation: 32,424 complaints, $798 million.
- Account takeover via impersonated financial-institution support: ~4,700 complaints, $359.7 million.
- Cryptocurrency-flagged complaints: 181,565, totalling $11.37 billion.
- Complainants aged 60+: 201,266 complaints and $7.7 billion — the most exposed group.
The callback habit, and the hardening underneath it
The response to an unsolicited account warning is not to argue, test the caller, or ask questions that might expose them. It is to end the contact and re-establish it yourself. Hang up or close the chat, then reach the company through its official app or a number you find independently, and ask whether anything is actually wrong. This costs a few minutes and is completely reliable, because it does not require you to be right about the message. The FBI's advice on exchange impersonation is the same: do not respond even if it appears official and demands immediate action, and do not visit websites or click links the caller sends. Urgency is the pressure that stops people doing this, so treat urgency itself as the signal — a genuine problem will still be there in ten minutes, and any real institution will wait while you call back.
Underneath the habit, a few structural changes make the whole category harder to run against you. Move two-factor authentication off SMS where you can, since text codes can be intercepted by the SIM-swap route covered in our SIM-swap guide; an authenticator app is better, and a hardware security key is better still because it is bound to the real domain and will simply not produce anything on a lookalike site. Turn on withdrawal address allowlisting with a time delay if your exchange offers it, so a compromised session cannot immediately send funds somewhere new. Keep long-term holdings in self-custody rather than on an account that a persuasive phone call can reach, which is the trade-off our exchange versus self-custody guide walks through. And decide now, calmly, that you will never install remote-access software at the request of someone who contacted you — that decision is much harder to make in the middle of a convincing emergency.
Checklist
- End the contact first; verify second, through a route you chose.
- Never use a number, link, or app supplied by the person contacting you.
- Treat urgency as evidence against the caller, not for them.
- Move 2FA off SMS; a hardware security key resists lookalike domains.
- Enable withdrawal allowlists and time delays where offered.
- Decide in advance: no remote-access software, ever, on inbound contact.
If you have already engaged
Act in order of what is still recoverable. If you gave a password or a two-factor code, change the password immediately from a device you trust, revoke active sessions, and re-enrol two-factor from scratch so any device the attacker registered is cut off — then do the same for the email account attached to it, because whoever controls the email can reset everything else. If you installed remote-access software, disconnect the machine from the internet before anything else, uninstall it, and treat every credential entered on that machine as exposed. If you use the same password anywhere else, change it there too.
If funds have already moved, the money is very likely gone, and the most valuable thing you can do next is protect what remains and avoid the follow-up. Move any remaining balances to a wallet whose keys were generated on a clean device and never touched the compromised session. Report it — in the United States through ic3.gov, and to the exchange, which can sometimes freeze funds that have not yet been withdrawn — and keep transaction hashes, addresses, timestamps, and screenshots, since that record is what makes any later action possible. Then expect the second approach. Losses attract recovery scams, and the FBI's own reporting treats these as a distinct and large category; anyone who contacts you offering to retrieve your funds for an upfront fee is running the same play against a person they know has already paid once. Our guide on the first hour after a crypto scam covers that sequence in more detail. Finally, be gentle with yourself about it: these operations are competent, rehearsed, and designed to work on attentive people under time pressure, and treating the loss as evidence of carelessness mostly stops people reporting it.
Checklist
- Credentials given: change password, revoke sessions, re-enrol 2FA — email account first.
- Remote software installed: disconnect the device, uninstall, treat all credentials as exposed.
- Funds moved: relocate what remains to keys generated on a clean device.
- Report to ic3.gov and to the exchange; preserve hashes, addresses, and screenshots.
- Expect a recovery scam next; no legitimate service charges an upfront fee to get funds back.
- Being targeted is not carelessness — shame is the reason most of this goes unreported.
Authority sources used
Outbound links are included for verification and entity authority, not decoration.
- Public Service Announcement I-080124-PSA: FBI Warns of Scammers Impersonating Cryptocurrency ExchangesFBI Internet Crime Complaint Center (IC3)
- Tech/Customer Support and Government ImpersonationFBI Internet Crime Complaint Center (IC3)
- 2025 Internet Crime ReportFBI Internet Crime Complaint Center (IC3)
- What To Know About Cryptocurrency and ScamsFederal Trade Commission
FAQ
How can I tell a real support agent from a fake one?
Use the direction the contact travelled rather than how the message looks, because appearance is the part impersonators have already mastered — logos are copied exactly, display names are registered with characters that look identical to the real ones, and caller ID is spoofed to show an institution's genuine number. The structural difference is that genuine support is reactive. It answers a ticket you opened, a chat you started, or a number you found yourself, and it replies into that same channel. Fraud has to initiate, because you were never going to contact it. The FBI's advisory on exchange impersonation describes the opening move exactly this way: an unsolicited call or message claiming to be exchange staff, reporting a problem with your account or an attempt to compromise it. So an unsolicited contact about your account can be set aside without any assessment of its content. If you are unsure whether a real issue exists, end the contact and reach the company through its official app, a saved bookmark, or a number you look up independently — never through anything the person who contacted you supplied.
Support told me to move my crypto to a safe wallet. Is that ever legitimate?
No. This is the single clearest signal in the whole category, and it is worth memorising as an absolute. No legitimate exchange, wallet provider, bank, or law enforcement agency needs your assets to move in order to protect them. A real provider secures an account where it already sits — it suspends withdrawals, terminates sessions, locks the account, or disables API keys. Every one of those actions happens without your funds going anywhere. An instruction to send your holdings to a 'safe wallet', 'secure account', 'protected address', or 'vault' controlled by anyone else is the theft itself, dressed as protection, and it is chosen precisely because crypto transfers cannot be reversed once confirmed. Federal guidance states the general principle plainly, warning that government and law enforcement will never ask you to send money by wire transfer, cryptocurrency, crypto ATM, gift card, or by mailing cash — and no company employing a real support agent works differently. If you hear this sentence, the conversation is over; you do not need to hear the rest of the explanation.
Why do scammers target people asking questions in public forums?
Because a public question is a free, accurate signal of intent. Someone who posts about a stuck withdrawal, a failed transaction, or a locked account in a project's community chat, a support forum, or the replies under an exchange's social media post has just announced that they currently want help from that specific company and are expecting a reply. An impersonator monitoring those spaces can send a direct message minutes later from an account whose display name and picture match the official one, referencing the exact problem you described — which makes it feel like the system worked rather than like a stranger arrived. The FBI's guidance on tech and customer support impersonation lists cryptocurrency exchanges alongside banks, utilities, and software vendors as brands criminals routinely pose as, which is the same technique aimed at a faster and less reversible payment rail. The practical defence is to expect it: assume any direct message that follows a public question is hostile until proven otherwise, and take the conversation back into the official app or support portal yourself. Real support answers in the channel you used.
How large is this problem compared with other crypto scams?
Large enough to sit near the top of national fraud statistics. The FBI's 2025 Internet Crime Report recorded 1,008,597 complaints and $20.877 billion in reported losses, up 26% year over year. Tech and customer support fraud alone accounted for 47,794 complaints and $2,134,675,818 — the third-largest loss category of the year, behind investment fraud and business email compromise, and ahead of romance scams. Government impersonation contributed a further 32,424 complaints and $797,943,193, and the report separately breaks out account takeover carried out via impersonation of financial institution support at roughly 4,700 complaints and $359.7 million. Cryptocurrency-flagged complaints numbered 181,565 with $11,366,669,732 in losses. The demographic detail matters too: complainants aged 60 and over reported 201,266 complaints and $7.7 billion, more than any other age group. That combination — enormous totals and a heavy skew toward older victims — is why the direction-of-contact rule is worth passing on to family, since applying it needs no technical knowledge at all.
What should I do first if I already gave a scammer access?
Work in order of what can still be saved. If you shared a password or a two-factor code, change that password immediately from a device you trust, revoke all active sessions, and re-enrol two-factor authentication from scratch so any device the attacker registered loses access — and do the email account attached to it first, because control of the email is control of every reset link. If you installed remote-support software, disconnect that machine from the internet before doing anything else, uninstall the software, and treat every credential ever typed on it as exposed. If funds have already left, they are very likely unrecoverable, so the priority shifts to protecting the remainder: move it to a wallet whose keys were generated on a clean device and never touched the compromised session. Then report it — through ic3.gov in the United States, and to the exchange, which can occasionally freeze funds still on its platform — and preserve transaction hashes, addresses, timestamps, and screenshots. Finally, expect a follow-up approach offering to recover your money for a fee. That is a separate scam targeting people already known to have lost funds, and paying it is the second loss.