Fake support and recovery scams: the second theft

·5 min read·By SSP Editorial Team
SSP Academy cover: fake crypto support and recovery scams

Fake support and recovery scams: the second theft

Some of the most effective crypto scams don't target people who are careless. They target people who are already in trouble.

Something has gone wrong — a transaction is stuck, a balance looks off, funds were stolen — and you go looking for help. Within minutes, someone finds you. They're friendly, fast, knowledgeable, and they sound exactly like the help you were looking for. They are the second attacker, and for many victims they take more than the first one did.

How they find you

The trigger is almost always a public request for help.

You post in a project's community channel, reply to an official account, or search for a support number. Scammers monitor exactly those places. Within minutes of a complaint, accounts with official-looking names and logos reply publicly or, more often, message you privately: "Hi, I'm from the support team, I can help you with this."

Search engines and app stores are the other entry point. Fake "support" sites buy ads for wallet names, and fake helpline numbers get planted on forums and review sites.

The single most useful fact to remember: legitimate support does not cold-message you. If you asked publicly and someone reached out privately, that is the scam announcing itself.

What they ask for

The script varies. The destination doesn't. Eventually you'll be asked for one of these:

Your seed phrase, framed as "validating your wallet", "resynchronising", or "restoring access". This is the whole game. Nobody legitimate ever needs it, for any reason — the difference between what can spend and what can only watch makes that absolute.

A connection and a signature on a "diagnostic" or "rectification" site. This is the drainer route: an approval or permit disguised as a repair step — the same mechanism that powers fake airdrop claims.

Remote access to your computer, so they can "look at the problem". Once they're on your screen, they don't need to ask for anything.

A fee. Pay a small amount to "unlock" funds, "cover gas for the recovery", or "verify ownership". Then a slightly larger one. Then another.

Recovery scams: robbing the robbed

The cruelest variant targets people who've already lost money.

After a theft, victims are contacted by "blockchain investigators", "asset recovery firms", or even fake law-enforcement agents promising to trace and return the stolen funds — for an upfront fee. Some cite real transaction hashes from your theft, which makes them look credible; that data is public to anyone.

The honest reality is harsh. Transactions on a public blockchain cannot be reversed by anyone. Funds sent to an attacker can sometimes be frozen if they land at a regulated exchange that cooperates with law enforcement, but that happens through police and the exchange — not through a stranger who contacted you and wants payment first.

Anyone who guarantees recovery in exchange for an upfront fee is running the second half of the same crime.

What SSP support can and cannot do

It's worth being specific about our own position, because it is the template for every legitimate wallet.

SSP is non-custodial. We never hold your keys, which means we structurally cannot do the things scammers promise. We can't recover funds that were sent somewhere. We can't reverse or cancel a confirmed transaction. We can't "unlock" or "validate" a wallet, because there is nothing on our side to unlock.

And we will never ask for your seed phrase, a private key, remote access to your device, or a payment to fix a problem.

Legitimate recovery in SSP happens inside the SSP apps, on your own devices, by you — restoring from your seed or using the wallet-recovery flow in SSP Key. There is no version of recovery that involves reading your words to a person. Anything that does is not recovery.

The patterns that give them away

They contacted you first. Especially privately, especially right after you asked for help in public.

They want to move the conversation. From a public channel to DMs, Telegram, WhatsApp or a phone call — anywhere with no witnesses.

They need something only you should have. Seed, key, screen access, signature.

They create urgency. "Your wallet is compromised, act now", "the recovery window closes in an hour".

They ask for money to get your money back. There is no legitimate version of this.

They use real details. Your transaction hash, your address, the amount you lost. All public. None of it proves anything.

What to do instead

Ask only through official channels you reach yourself — the project's own website typed by hand, the support link inside the app. Never a number from an ad, a search result, or a DM.

Assume every unsolicited helper is an attacker. You lose nothing by ignoring a real one; you can lose everything by trusting a fake one.

If funds were stolen, move what remains to a fresh setup, report the theft to the police and to any exchange the funds reached, and keep records. That's the realistic path. It's slow and uncertain, and it doesn't involve paying anyone upfront.

Tell someone you trust before you act. These scams depend on isolation and panic. A second opinion, even from someone non-technical, breaks the spell surprisingly often.

The first theft takes what was in your wallet. The second one takes what you have left, plus whatever you'll pay to get the first back. Knowing that support never comes looking for you is enough to stop it.

Share this article

Related articles