Attacks
Somebody posing as help, reaching you first, after you asked a question in public. You post a problem in a Discord, a Telegram group or a reply on X. Within minutes somebody helpful appears in your direct messages. They have the right display name, the right avatar and a support ticket link. Real support almost never contacts you first, and real support never needs your seed phrase or a screen share.
What it is
You post a problem in a Discord, a Telegram group or a reply on X. Within minutes somebody helpful appears in your direct messages. They have the right display name, the right avatar and a support ticket link. Real support almost never contacts you first, and real support never needs your seed phrase or a screen share.
How it plays out
You ask for help in public
Bots watch for keywords like "stuck", "failed transaction", "cannot withdraw".
Help arrives privately
Fast, friendly, and with a name and picture copied from a real team member or moderator.
You are moved to a ticket or a form
Which asks you to connect a wallet, import a seed phrase to "validate", or install remote access software.
Or they offer to walk you through it
On a screen share, so they can watch you type.
What gives it away
- Anyone who contacts you first about your funds.
- A request to validate, sync, restore or migrate a wallet.
- Any request for a seed phrase, a private key, or a screen share.
- A support link that is not on the project’s own domain.
- Direct messages in a server where staff have said they never message first.
How to not be caught by it
- Turn off direct messages from server members in Discord and Telegram.
- Only use support routes you navigated to yourself from the official site.
- Never share a screen while a wallet is open.
- Assume the first person to help you privately is the attacker, and verify in the public channel.
If it already happened
- Disconnect any remote access session immediately and shut the machine down if unsure.
- If you entered a seed phrase anywhere, move funds now from a clean device. That phrase is burned.
- Revoke approvals for any wallet you connected.
- Report the account in the server it came from so the moderators can ban it.
Common questions
How common is fake support and impersonation?
Common enough that it has a name and a playbook. The specific numbers move constantly, so rather than quote a figure that will be wrong next quarter: assume you will meet this one, and set your wallet up so meeting it is survivable.
Can the money be recovered?
Once a blockchain transaction confirms, no. What reporting can occasionally do is get funds frozen at the exchange where a thief tries to cash out, which is why reporting quickly is worth doing even when it feels pointless.
Does a hardware wallet stop this?
It stops anything that needs your keys, because the keys never leave the device. It does not stop you approving a malicious transaction on the device itself, so read what the screen says before you press confirm.
Where to go next
Check your setup before you need to
An hour on a screen share, going through your wallets, your approvals, your backups and your recovery plan. You click everything and we never ask for keys.