Anatomy of a Fake Support Scam, Step by Step
A reconstruction of a live attempt, in order, with the exact moment each piece of trust was manufactured.
Priya Raman · 3 min read
This reconstruction is based on a conversation a reader forwarded, with details changed. The structure is identical to dozens of others, which is the point: this is a script, executed repeatedly.
Step 1: the target identifies themselves
The victim posted in a public forum asking why a transaction had been pending for forty minutes.
This is the recruitment step, and it is entirely automated. Accounts monitor public channels for words indicating a problem. Posting a question about a stuck transaction is an advertisement that you hold crypto and are currently anxious about it.
Elapsed time before first contact: under five minutes.
Step 2: a credible identity
The reply came from an account using the wallet’s name and logo, with a plausible follower count and a history of posts.
These accounts are cheap. Names are near-copies with a substituted character. Follower counts are purchased. Post history is scraped.
Step 3: a reasonable first request
The attacker asked for the transaction hash.
This is important. The hash is public information and gives the attacker nothing. Asking for it is exactly what real support does, and complying costs nothing, which is precisely why it is the first ask. The victim has now done something harmless and is in a conversation.
Step 4: demonstrated competence
The attacker looked up the hash and correctly explained that the transaction was stuck because the fee was too low.
This was true and verifiable. The victim checked it on an explorer and confirmed it.
Being right about a checkable fact is the single most effective trust-building move in the script. It converts a stranger into an expert.
Step 5: manufactured urgency, gently
“If it stays pending past the mempool timeout it may drop and you would need to resend.”
Technically true, practically irrelevant, and it introduces a deadline where none existed. Note the tone: helpful, not alarming. Aggressive urgency triggers suspicion. Mild urgency does not.
Step 6: the tool
A link to a page that looked like the wallet’s site, on a domain one character different from the real one.
The page was a functional copy, including a working navigation bar. The only page that did anything was the one the victim was sent to.
Step 7: the ask
The page requested the recovery phrase, described as “syncing your wallet with the validator.”
This phrasing does a lot of work. It is technical enough to sound like a procedure and vague enough to avoid the words that trigger alarm. It never says “enter your seed phrase to prove ownership.”
Step 8: the drain
Had the phrase been entered, the wallet would have been emptied within seconds, typically by an automated script watching for submissions.
In this case the victim stopped, because they remembered a flat rule with no exceptions.
What made it work as far as it did
| Step | What it manufactured |
|---|---|
| Public question | A target with a known problem |
| Branded account | Apparent authority |
| Harmless first ask | Compliance and conversation |
| Accurate diagnosis | Genuine credibility |
| Soft deadline | A reason to act now |
| Lookalike domain | Familiar surroundings |
| Technical phrasing | A procedure rather than a request |
At no point did the attacker do anything obviously suspicious until the final step, and by then six earlier steps had established that this person was helpful and correct.
The defence that works
Not vigilance. Vigilance fails, because the attacker is better at this conversation than you are.
A rule that admits no exceptions: the recovery phrase is never typed anywhere except into a wallet you opened yourself, to restore a wallet you own. No support request, no validation, no sync, no migration, no verification.
The transaction in this case cleared on its own after about two hours, exactly as it would have with no intervention at all.
If you need real support
Navigate to the site by typing the address yourself, never through a link. Use a venue where support is a ticket system rather than a direct message, such as an exchange you can actually contact, and treat any unsolicited message claiming to be support as fraudulent by default.
Move any remaining funds to a wallet with a newly generated seed phrase before anything else. Then revoke token approvals, and report the incident to your local authorities and the exchange involved. Do not pay anyone who promises to "recover" your coins. That is a second scam, aimed at victims of the first.