Scam patterns
Fake support: urgency with borrowed branding
Impersonators appear where users are already looking for help.
Research articles and reference entries are published in English. Navigation is available in seven languages.
In this article
A support impersonator borrows a recognised logo and arrives with an explanation for the user's problem. The demand may involve a transfer, a recovery phrase, an installation or remote access. The convincing part is often the timing: the user has just posted about a failed transaction or a known incident.
Verify through a separate route
Open the provider's established website or application independently. Do not rely on the disputed message's links, phone number or verification screenshot. A copied staff name can be accurate while the person using it is an impostor.
Never give a recovery phrase to a person claiming to diagnose a wallet. Genuine possession of the phrase would give spending power, not merely visibility into an error. A request to move money to a safe account should be verified through the existing account relationship.
MASTR's MiCA research shows how real regulatory changes can supply the story. SecondFi's official warning shows the same problem after a security incident. The lesson is to authenticate both the person and the requested action.
Sources
- ESMA: misuse of its name, logo and identity
- SecondFi: official security-incident and impersonation guidance
- MASTR: Crypto Survival Guide, four original panels
Research checked 5 September 2026. Historical cases retain the date and legal status of the cited record.