BeginnerGuide

How to Verify a Support Agent Is Real (They Never DM First)

Learn how to verify a crypto support agent, spot fake support messages, and confirm official help channels before you reply.

By Niki

Immediate guidance: Treat unsolicited contact as fake

Treat unsolicited support contact as fraudulent. Close the message and start a new request from the official app or domain; never share a seed phrase, private key, password, 2FA code, or remote device access.

Never share a recovery phrase, private key, password, or two-factor code with anyone offering support.

How to Verify a Support Agent Is Real (They Never DM First)

Key Takeaways

  1. Legitimate crypto support does not start conversations. Real help desks respond to tickets you open. If a "support agent" contacts you first by direct message, email, text, or phone call, treat it as fake until proven otherwise.
  2. Verification means going backwards, not forwards. Never verify an agent using links, phone numbers, or badges inside the message they sent you. Close the message, open the official app or website you already trust, and start again from there.
  3. Impersonation is now one of the largest categories of crypto loss. Chainalysis reported that impersonation scam activity grew more than 1,400 percent in 2025 compared with 2024, and the FBI recorded more than 11 billion dollars in reported crypto losses across all fraud types in the same year.

Why Fake Support Became the Main Attack on Everyday Users

For years, the headline crypto losses came from protocol exploits and exchange breaches. That has changed. The most common way an ordinary user loses money today is not a smart contract bug. It is a conversation.

According to the Chainalysis 2026 Crypto Crime Report, impersonation scams grew more than 1,400 percent compared with 2024, and the average amount paid to these scam clusters increased by over 600 percent. The same report estimated that roughly 17 billion dollars was lost to scams and fraud in 2025, with impersonation tactics and AI-generated content overtaking direct cyber attacks as the leading method of stealing funds.

The FBI's Internet Crime Complaint Center recorded a similar shift. Its 2025 Internet Crime Report logged 1,008,597 complaints, and complaints involving cryptocurrency reported the highest losses of any category, with 181,565 complaints totalling more than 11 billion dollars. Tech support scams alone accounted for about 2.1 billion dollars in reported losses and remained among the top five threats by both victim count and dollar loss.

Individual wallets are the target. Chainalysis counted roughly 158,000 personal wallet compromise incidents affecting about 80,000 unique victims in 2025. These are estimates drawn from traced on-chain activity and filed complaints, so the real totals are likely higher.

The reason attackers moved to impersonation is simple. Breaking cryptography is hard. Convincing a worried person to paste twelve or twenty four words into a form is not.


The One Rule That Blocks Most of These Attacks

Real support never sends the first message.

Major companies have made this an explicit policy precisely so that users have one clean test. Ledger states that it will never call users, never send the first direct message, and never ask for a 24-word recovery phrase. Coinbase states that it will never call you out of the blue and that its official support handles are limited to a small published set of accounts. Coinbase also warns that it will never call or text you to hand you a new seed phrase or wallet address to move funds to.

The policy exists to remove judgement from the equation. If the rule is absolute, you do not have to assess whether a particular DM looks convincing. You only have to notice that it arrived unrequested.

One warning about the rule itself. Scammers know it and use it as camouflage. Researchers who mapped fake Telegram support groups found that impersonator admins routinely put "never DM first" in their own display names and pinned messages, then invited users to message them privately for help. A profile that advertises the rule is not proof that the profile follows it.


What Real Support Will Never Ask For

If any of the following appears in a conversation, the conversation is over. There is no legitimate version of these requests.

RequestWhy it is always a scam
Your seed phrase or recovery phraseIt is the master key to the wallet. A real company cannot use it, does not need it, and cannot store it. Ledger says there is no legitimate scenario in which it asks for the phrase through any channel.
Your private keySame as above. Anyone holding it controls the funds permanently.
Two-factor codes or one-time passwordsThese exist to stop someone else logging in as you. Reading one aloud defeats the entire purpose.
Remote access software installationTools such as screen sharing or remote desktop apps hand over the device. Coinbase states its agents never ask users to install software or remote into a device.
Moving funds to a "safe wallet" or "vault"No support process involves transferring your assets somewhere else for protection. Coinbase explicitly warns against calls or texts offering a new seed phrase or address to move funds to.
A wallet signature to "verify" or "sync"Signatures approve transactions and token permissions. A verification signature is usually a drain approval.
A payment to unlock, release, or recover fundsRecovery fees, gas fees, and unlock fees are the standard structure of a second-stage scam.

Five Checks Before You Reply to Anyone Claiming to Be Support

Step 1. Ask who started the conversation. If it was not you, the default answer is no. This single question resolves the large majority of cases.

Step 2. Leave the message entirely. Do not tap a link, do not call a number in the message, do not scan a QR code, and do not click the profile's website field. Every one of those is controlled by the sender.

Step 3. Reopen the official surface yourself. Launch the app from your home screen, or type the domain you already know into the browser, and find the help section there. If a ticket exists, it will appear in your account. If no ticket exists, no agent should be contacting you.

Step 4. Compare the identity, not the display name. Display names and profile pictures can be copied exactly. Usernames and account identifiers cannot. Check the handle character by character against the one published on the company's own website.

Step 5. Slow the clock down deliberately. Manufactured urgency is a core part of the script, with scammers claiming an account is compromised or funds are at risk to trigger panic. A real support queue can wait an hour. A scam cannot, because delay gives you time to check.


Platform by Platform Verification

PlatformWhat scammers exploitHow to actually verify
TelegramDisplay names are freely editable and can be identical to a real admin's. Usernames are unique, so impersonators use lookalikes such as a zero in place of the letter O or a capital I in place of a lowercase L.Open the official public group, find the admin list, and check the exact username there. Note that many real projects have no Telegram support at all.
DiscordCopied avatars, nicknames matching moderators, and fake "verification" bots in servers with a single channel.Check the account's mutual servers, join date, and role badge inside the server itself, not in the DM. Real staff answer in public channels or ticket threads.
X (Twitter)Reply-guy bots that appear within seconds of any post mentioning a wallet or exchange, plus purchased checkmarks.Ledger advises treating any message that directs you to contact someone privately or on another platform as a scam attempt. Compare the handle to the one linked from the company's official site.
EmailSpoofed sender names and lookalike domains.Check the full sending domain, not the display name. Log into your account separately to confirm any claim the email makes.
PhoneCaller ID spoofing and fake help lines.Most crypto wallet companies do not offer inbound phone support at all. Coinbase states it will never ask you to contact an unknown number to reach it.
Search engines and Q&A sitesFake "official support numbers" seeded into blogs, quote sites, and forums to rank in search results.Never trust a support number found through a search engine. Take contact details only from inside the logged-in app or the official domain.

The search engine problem deserves its own note. Searching for a wallet's support number today returns pages of fabricated help lines published on quote aggregators and content farms, formatted to look official. They exist because scammers know a panicked user searches before thinking.


Red Flags in the First Three Messages

  • The agent contacted you first, in any medium.
  • The agent asks you to continue the conversation on a different app.
  • The message references a real event, such as a breach or an outage, to build credibility.
  • The agent claims your funds are at risk right now and must be moved.
  • The account is new, has few posts, and shares no mutual contacts or servers.
  • The agent avoids public channels and insists on private messages.
  • The writing is polished but the pressure never lets up. AI tools removed the old spelling and grammar tells, so clean English is not evidence of legitimacy.

What to Do If You Already Replied

  1. Stop the conversation immediately. Do not explain yourself or try to bait the scammer. Block and report the account.
  2. If you shared a seed phrase, treat the wallet as permanently compromised. Create a new wallet on a clean device and move any remaining assets. Never reuse the old phrase.
  3. If you signed a transaction or approval, revoke outstanding token permissions with a reputable approval tool, then move funds to a fresh address.
  4. If you installed remote access software, disconnect the device from the internet, uninstall the software, and change passwords from a different device.
  5. Rotate credentials and sessions. Change your exchange password, replace two-factor methods, and log out all sessions.
  6. Report it. File with your national cybercrime body, such as the FBI's IC3 in the United States, and notify the impersonated company through its official channels.
  7. Expect a second wave. Recovery scams are rising, with fake law firms and officials targeting scam victims and claiming they can retrieve lost funds. IC3 logged more than 10,500 recovery scam complaints and an estimated 1.4 billion dollars in losses. Nobody who contacts you unprompted can recover your crypto.

Frequently Asked Questions

Does a verified badge mean the account is real? No. Badges can be purchased on some platforms, transferred with sold accounts, or faked visually in screenshots. A badge is one weak signal among several. The published handle on the company's own website is the stronger check.

What if I opened a ticket first? Can support DM me then? Sometimes, but the safe habit is still to reply inside the ticket system rather than in a DM. If a message arrives elsewhere claiming to continue your ticket, go back into the official app and check whether the reply appears there.

Why do exchanges and wallet companies not just verify agents better? Many do publish staff lists and use ticket-only support. The gap is that scammers operate on platforms the company does not control, such as private messages on social apps. That is why the policy is a blanket rule rather than a verification feature.

Is it safe to video call an agent to confirm identity? Not reliably. AI-generated video and voice are now common in fraud. The FBI's 2025 report logged 22,364 complaints with an AI element and nearly 893 million dollars in associated losses, including voice clones and believable videos of public figures. Identity should be confirmed through official channels, not appearance.

Can I get my crypto back after a support scam? Usually no. On-chain transfers are final and cannot be reversed by any company. Funds are occasionally frozen when they reach a regulated exchange, which is why fast reporting matters, but recovery should never be assumed.


  • Social engineering: Manipulating a person into taking an action or revealing secrets, rather than attacking software.
  • Seed phrase (recovery phrase): The list of words that regenerates a wallet's private keys. Anyone who holds it controls the funds.
  • Wallet drainer: Malicious code that empties a wallet once the user approves a transaction or signature.
  • Token approval: A permission granted to a smart contract to spend tokens on your behalf, which can be revoked.
  • Recovery scam: A follow-up fraud that targets previous scam victims by promising to retrieve lost funds for a fee.

Sources

  • Chainalysis, 2026 Crypto Crime Report: Scams, chainalysis.com
  • Chainalysis, 2025 Crypto Theft Reaches 3.4 Billion Dollars, chainalysis.com
  • FBI, Cryptocurrency and AI Scams Bilk Americans of Billions, 2025 Internet Crime Report press release, fbi.gov
  • FBI Internet Crime Complaint Center, 2025 IC3 Annual Report, ic3.gov
  • Coinbase Help, Technical support and impersonation scams, help.coinbase.com
  • Coinbase, How to Spot and Stop Customer Support Scams, coinbase.com
  • Ledger, Ongoing phishing campaigns, ledger.com
  • U.Today, Ledger Issues Urgent Warning on Fake Accounts and Recovery Phrase Scams, April 2026
  • Timsh.org, Scam Telegram: Uncovering a network of groups spreading crypto drainers
  • GoCrypto, How To Spot A Telegram Scam, gocrypto.com

This article is educational and does not constitute financial, legal, or security advice. Figures cited are reported or estimated totals from the sources listed and may be revised.

Not sure which problem you have?

Use the Fixing Crypto Mistakes hub to identify the transaction, wallet, network, or exchange issue before taking another action.

OPEN TROUBLESHOOTING HUB

Share Transmission

Broadcast this signal to your network