Nobody legitimate will ever ask for your seed phrase. Not support. Not us. Nobody.
Case filescams and phishing

Multi-Stage Attacks: When the First Contact Is Not the Ask

Sophisticated operations separate reconnaissance from execution by weeks. The early stages look harmless because they are.

Priya Raman · 2 min read

Most published advice describes attacks that resolve in one interaction. The more expensive ones do not.

The structure

Stage one: identification. The attacker establishes that you hold something worth taking. Sources include on-chain activity, public posts, data breaches, and conversations in communities.

Stage two: profiling. Building a picture. Which venues you use, which wallet, what you hold, who you interact with, what you care about.

Stage three: contact. Establishing a relationship in a context that is not about money. A professional connection, a community interaction, a shared interest.

Stage four: the pretext. Something that makes the eventual request plausible. A job opportunity, a collaboration, a technical problem.

Stage five: execution. The malware, the signature request, or the transfer.

Weeks or months can pass between stages three and five.

Why it defeats standard advice

Every rule of thumb operates on stage five. Do not click unexpected links. Do not run unfamiliar code. Do not sign what you do not understand.

By stage five, none of those feel unexpected, unfamiliar or unexplained. The context was built specifically to make the request ordinary.

The recognisable patterns

The fake job interview. Weeks of recruitment process, then an assessment containing malware.

The collaboration. A project proposal requiring you to review a document or repository.

The relationship scam. Weeks of genuine conversation before any platform is mentioned.

The community insider. Months of helpful participation before a direct message asking for something.

What actually defends

Structural separation. Nothing about the relationship changes what a compromised device can reach if the device holds nothing and has no access.

Run unfamiliar code on a machine with no keys, no credentials and no sessions. This defeats the technical stages regardless of how convincing the social ones were.

A separate wallet for connecting. A signature can only reach what the signing address holds.

Verification through independent channels. Contact the company through its published number rather than through the person who approached you. This survives any amount of relationship building.

A delay on anything irreversible. A withdrawal allowlist with a waiting period, offered by venues including a licensed exchange with a published address, converts an immediate action into one you can reconsider.

The uncomfortable conclusion

You cannot reliably detect a well-run multi-stage operation. The people running them are professional, patient, and better at the social part than you are at noticing.

What you can do is arrange things so that being fully deceived has a bounded cost. That is a different discipline from vigilance and it is the only one that scales against an attacker who is willing to spend two months on you.

If this has already happened to you

Move any remaining funds to a wallet with a newly generated seed phrase before anything else. Then revoke token approvals, and report the incident to your local authorities and the exchange involved. Do not pay anyone who promises to "recover" your coins. That is a second scam, aimed at victims of the first.

targetedreconnaissancepatience

Related cases