Home › Knowledge Hub › Impersonation scams
Crypto impersonation scams
An impersonation scam borrows someone else's credibility. The scammer poses as a crypto exchange, a wallet provider, a support agent, a celebrity, or a government official, using copied logos, near-identical usernames, spoofed caller ID or lookalike domains. The defence is the same regardless of who they claim to be: end the contact and reach the organisation yourself using details you looked up independently.
The one habit that defeats all of it
Whoever they claim to be, the answer is the same.
End the contact. Find the organisation yourself. Contact them through a number or address you looked up independently.
Not the number they gave you. Not the link in the message. Not the phone number in the sponsored search result, those are bought by scammers routinely. Type the official domain yourself, or use a number from the back of your bank card.
A genuine organisation will never object to you calling them back. Someone who pressures you not to is telling you what they are.
Fake support agents
The most common version, and the mechanism is simple: they watch for people asking for help.
You post publicly about a problem with an exchange or wallet, on X, Reddit, Discord or Telegram, and within minutes several accounts reply or message you privately. They are attentive, they use the right terminology, they have a profile picture matching the company's branding.
Then they ask for one of:
- Your seed phrase or recovery phrase: for "verification" or "wallet migration"
- Remote access to your computer, via AnyDesk or TeamViewer
- A screen share while you log in
- A small verification transaction to "confirm ownership"
- Your login credentials or a 2FA code
Real support never needs any of these. Not your recovery phrase, not remote access, not a test payment. There is no legitimate exception, and no scenario in which a genuine support agent will insist otherwise.
A practical habit: never discuss an account problem in a private message initiated by someone who approached you. Open a support ticket through the company's own site instead.
Exchange and wallet impersonation
These arrive as urgent emails or texts: unusual login activity, account suspension, a required verification, a security upgrade, a withdrawal you did not authorise.
The link goes to a lookalike domain, one character different, a different top-level domain, or a hyphenated variant. The page is a pixel-accurate copy that captures whatever you type.
Never reach your exchange through a link in a message. Type the address or use a bookmark. If the message describes a real problem, you will see it when you log in normally.
Watch also for sponsored search results. Scammers buy advertising against exchange names, and the fake result sits above the real one.
Celebrity and giveaway impersonation
The promise is that sending crypto returns more. It never does, and the pattern is old enough to predate crypto entirely.
Modern versions are more convincing: hijacked verified accounts, deepfake video of well-known figures, livestreams replaying old footage with an overlaid wallet address, comment sections filled with fake confirmations.
No legitimate giveaway requires you to send cryptocurrency first. A verified badge proves nothing, accounts get compromised, and verification can be purchased on some platforms.
Government and law enforcement impersonation
The most frightening version, and increasingly common.
Someone claims to be from the tax authority, the police, a financial regulator, or a fraud investigation unit. There is an investigation, a warrant, an unpaid liability, or your assets are at risk and must be moved to a "secure" account.
Government agencies do not call demanding cryptocurrency. They do not ask for seed phrases. They do not require you to move funds to protect them. Legitimate matters arrive as written correspondence to your registered address, with a case reference you can verify by calling the agency independently.
This overlaps directly with recovery fraud. In Australia, criminals have been impersonating the AFP and filing false ReportCyber reports in victims' names, then quoting the genuine reference number to sound official. A real-looking case number proves nothing.
How to verify anyone
- Stop the conversation. Urgency is manufactured. Nothing legitimate collapses because you took ten minutes.
- Look up the organisation yourself by typing the domain.
- Contact them through their published channel and ask whether the contact was genuine.
- Check the sending address character by character. Lookalike domains rely on you skimming.
- Ask for it in writing, on official letterhead, to your registered address.
- Tell someone before acting. Describing it aloud is often the moment it becomes obvious.
What to preserve
- The full conversation, exported from the app rather than screenshotted
- The exact username, handle, phone number or email address used
- Screenshots of the profile, including the URL, impersonation accounts get removed quickly
- The domain they sent you to, even if it is now dead
- Transaction hashes and destination addresses for anything you sent
- The organisation they claimed to represent: report it to that organisation too, because they track impersonation and may have takedown routes you do not
Then work through the first 48 hours guide and file with the right channel for your country.
If you gave up your seed phrase
Assume the wallet is permanently compromised. Move any remaining assets to a newly created wallet immediately, attackers frequently run scripts that sweep anything arriving in a compromised address.
Changing a password does not help. The recovery phrase is the wallet.
Expect a second approach
Impersonation victims are targeted again, often by someone impersonating an investigator or a recovery service. Read how to spot a recovery scam before replying to anyone.
Frequently asked questions
How can I tell a fake support account from a real one?
Start from the position that a support agent who contacted you first is fake, real support does not monitor social media for people to message privately. If you need help, open a ticket through the company's own website. Anyone asking for a seed phrase, remote access or a verification payment is a scammer regardless of how convincing the profile looks.
The account had a verified badge. Doesn't that mean something?
Very little. Verified accounts are compromised regularly, and on some platforms verification can be bought. Treat a badge as no evidence at all when money or credentials are involved.
They knew my name and details of my account. How?
Data breaches, previous scams, and information you have posted publicly. Knowing details about you is not evidence of legitimacy, it is standard preparation, and it is exactly what makes these approaches persuasive.
A government agency called about my crypto. Could it be real?
Almost not, if they phoned you and asked for cryptocurrency, a seed phrase, or a transfer to a secure account. Agencies do not operate that way. Hang up and call the agency back on a number you looked up yourself.
I let someone screen share while I logged in. What now?
Treat every credential they could see as compromised. Change passwords from a different device, starting with email, then exchanges. Reset two-factor authentication. If a wallet was open, move remaining assets to a new one. If they installed remote access software, uninstall it and run a security scan.
Should I report it to the company they impersonated?
Yes, in addition to police. Exchanges and wallet providers track impersonation of their brand and often have takedown routes for fake domains and accounts. It will not recover your funds, but it can stop the same setup being used against someone else.
Check what can be done
Nine questions and an honest answer about your specific case.
Evaluate my case free