Staying Safe

Seven Messages That Take Money From Crypto Beginners

A stranger offers to escalate your stuck withdrawal three minutes after you complain about it in public. That timing is not luck, and it is the whole trick.

Seven Messages That Take Money From Crypto Beginners

"Hi — I saw your post. I work on the withdrawals team. What's the email on the account?"

"Is this official? The badge says support."

"Yes. I can escalate it, but I need the code that was just sent to you."

Three minutes earlier you had posted in a public group asking why a withdrawal was still pending. Nobody replied to help. Somebody replied to sell.

The scripts below are not clever. They keep working because they arrive at the exact moment you are annoyed, worried or in a hurry, and because they use the vocabulary of the thing you were already doing. Each heading is roughly the line you will actually see.

"I'm from support, I can escalate this for you"

Nobody from a real exchange messages you first. Not on Telegram, not on X, not on Discord, not on Reddit, not by phone. Support is a door inside the app and the official site, and it only opens from your side.

The people who find you are watching public channels for complaints. A pending withdrawal, a failed verification, a question about a locked account — each one identifies someone frustrated enough to accept help from a stranger. What follows is a request for a verification code, a password, a seed phrase, or a "sync" you have to authorise. Any of those hands over the account.

There is a paid variant too: fake support numbers bought as search ads, so that calling "Binance customer service" reaches someone very willing to talk. Exchanges of this size do not run inbound phone support for account recovery.

Close the message and open a ticket from inside the app. If the message came by phone, hang up and call nothing back.

The link goes to a domain that reads correctly at a glance: one letter added, a different ending, a character that looks like the one you expect. The page is a copy of the real thing. You type your email, password and two-factor code, and the account empties while you are still looking at a loading spinner.

One signal covers this entire category: you are being asked to enter credentials on a page you did not navigate to yourself.

Two cheap defences. Bookmark the real domain and enter the site only through the bookmark, never through search results or a link someone sent you. And set an anti-phishing code so that genuine emails carry a string you chose — both settings live in the same security menu, and neither takes two minutes.

"Look at what I made this week"

Sometimes it is a stranger posting profit screenshots. Sometimes it is someone who matched with you on a dating app three weeks ago and has been pleasantly uninterested in money until now. Sometimes it is a group chat you were added to where everybody is doing well.

Screenshots cost nothing to fake, and so do the group members agreeing with each other. The number on a screen is not evidence of anything.

The signal that matters is not the screenshot. It is the invitation to a platform you have never heard of, or an app installed from a link rather than a store. On that platform, every figure you see is written by the person who built it. Your balance rises pleasantly for weeks. It keeps rising until you try to withdraw, at which point there is a tax to pay first, or a minimum to reach, or a compliance deposit.

"1% a day, principal protected"

Guaranteed returns do not exist in this market. There is no exception to check for.

Staking, lending and liquidity provision produce real yields, and every one of them has a variable rate and a way to lose money — validator penalties, borrower default, impermanent loss, the platform itself failing. A product describing its return as fixed is either hiding the risk or paying old depositors with new deposits, and the second kind always looks flawless right up to the week it stops.

The higher the promised rate, the shorter the remaining life of the scheme. "Stable 300% annually" is not an ambitious investment. It is a countdown.

"You've received 5,000 tokens"

Something appears in your wallet that you never bought, showing a healthy dollar value. To sell it, you have to approve it first.

That approval is the product. Signing it can grant a contract permission to move assets you do care about, and once the signature exists, the transfer happens without asking again.

Treat unsolicited tokens as furniture. Do not trade them, do not approve them, do not click the links in the token description, do not visit the site named in the token's own name. Hide it from view and carry on. Reviewing the approvals your wallet has already granted, and revoking the ones you do not recognise, is a sensible thing to do once a quarter.

"Send it to this address"

This one is quiet. Malware that watches the clipboard replaces a copied wallet address with the attacker's at the moment you paste. Addresses are long, interfaces abbreviate the middle, and the swap is designed to survive a glance.

After pasting, check the first six characters and the last six against the source. Most people check only the beginning, which is exactly what the attack is built for. For anything large, send a minimum test amount, confirm it arrived, then send the rest. Withdrawal address whitelists on the exchange side also stop this one dead, since funds can only leave to addresses you added in advance.

"We can help you recover the funds you lost"

This arrives after something has already gone wrong, often within days of you posting about it publicly, and it is the cruellest of the set. Some of these operations are run by the same people who took the money the first time. They know exactly how much you lost, which makes their opening message unnervingly credible.

They ask for an upfront fee, a "blockchain unlock" payment, or remote access to your machine so they can "trace" the transaction. There is no recovery service that can reverse a confirmed on-chain transfer. None. Where funds land on an exchange, the only route that ever produces results is a police report and the exchange's own compliance team, and neither of those solicits you by direct message.

The one thing all seven share

Different stories, same mechanism: every one of them is rushing you. Escalate now. Verify within 24 hours. The window closes tonight. The account will be frozen tomorrow.

So the single most useful rule is about time rather than technology. Anything pushing you to act immediately gets an automatic pause, and then independent verification through a channel you opened yourself — the app you typed in, the bookmark you saved, the support ticket you raised. Legitimate business survives you taking twenty minutes. Fraud does not, which is why it never gives you twenty minutes.

If you have not opened an account yet, the same instinct is worth carrying into the very first decisions about where you buy, and into what a trade actually costs — because inflated promises about fees and returns come from the same place as everything above.

And if you are reading this three days too late, having already sent money somewhere: report it to your local fraud authority and your bank, tell the exchange, and then ignore every single person who contacts you about getting it back.