Nobody legitimate will ever ask for your seed phrase. Not support. Not us. Nobody.
Case filescams and phishing

Anatomy of a Fake Support Scam, Step by Step

A reconstruction of a live attempt, in order, with the exact moment each piece of trust was manufactured.

Priya Raman · 3 min read

This reconstruction is based on a conversation a reader forwarded, with details changed. The structure is identical to dozens of others, which is the point: this is a script, executed repeatedly.

Step 1: the target identifies themselves

The victim posted in a public forum asking why a transaction had been pending for forty minutes.

This is the recruitment step, and it is entirely automated. Accounts monitor public channels for words indicating a problem. Posting a question about a stuck transaction is an advertisement that you hold crypto and are currently anxious about it.

Elapsed time before first contact: under five minutes.

Step 2: a credible identity

The reply came from an account using the wallet’s name and logo, with a plausible follower count and a history of posts.

These accounts are cheap. Names are near-copies with a substituted character. Follower counts are purchased. Post history is scraped.

Step 3: a reasonable first request

The attacker asked for the transaction hash.

This is important. The hash is public information and gives the attacker nothing. Asking for it is exactly what real support does, and complying costs nothing, which is precisely why it is the first ask. The victim has now done something harmless and is in a conversation.

Step 4: demonstrated competence

The attacker looked up the hash and correctly explained that the transaction was stuck because the fee was too low.

This was true and verifiable. The victim checked it on an explorer and confirmed it.

Being right about a checkable fact is the single most effective trust-building move in the script. It converts a stranger into an expert.

Step 5: manufactured urgency, gently

“If it stays pending past the mempool timeout it may drop and you would need to resend.”

Technically true, practically irrelevant, and it introduces a deadline where none existed. Note the tone: helpful, not alarming. Aggressive urgency triggers suspicion. Mild urgency does not.

Step 6: the tool

A link to a page that looked like the wallet’s site, on a domain one character different from the real one.

The page was a functional copy, including a working navigation bar. The only page that did anything was the one the victim was sent to.

Step 7: the ask

The page requested the recovery phrase, described as “syncing your wallet with the validator.”

This phrasing does a lot of work. It is technical enough to sound like a procedure and vague enough to avoid the words that trigger alarm. It never says “enter your seed phrase to prove ownership.”

Step 8: the drain

Had the phrase been entered, the wallet would have been emptied within seconds, typically by an automated script watching for submissions.

In this case the victim stopped, because they remembered a flat rule with no exceptions.

What made it work as far as it did

Step What it manufactured
Public question A target with a known problem
Branded account Apparent authority
Harmless first ask Compliance and conversation
Accurate diagnosis Genuine credibility
Soft deadline A reason to act now
Lookalike domain Familiar surroundings
Technical phrasing A procedure rather than a request

At no point did the attacker do anything obviously suspicious until the final step, and by then six earlier steps had established that this person was helpful and correct.

The defence that works

Not vigilance. Vigilance fails, because the attacker is better at this conversation than you are.

A rule that admits no exceptions: the recovery phrase is never typed anywhere except into a wallet you opened yourself, to restore a wallet you own. No support request, no validation, no sync, no migration, no verification.

The transaction in this case cleared on its own after about two hours, exactly as it would have with no intervention at all.

If you need real support

Navigate to the site by typing the address yourself, never through a link. Use a venue where support is a ticket system rather than a direct message, such as an exchange you can actually contact, and treat any unsolicited message claiming to be support as fraudulent by default.

If this has already happened to you

Move any remaining funds to a wallet with a newly generated seed phrase before anything else. Then revoke token approvals, and report the incident to your local authorities and the exchange involved. Do not pay anyone who promises to "recover" your coins. That is a second scam, aimed at victims of the first.

phishingsocial-engineeringcase

Related cases