Night Study/Guides/Scam emails, calls and SIM swaps

Fake crypto exchange support calls and messages: four scripts and how to end them

Some exchanges say in writing that they will never call you. Whatever yours says, a conversation you did not start cannot be checked from inside it, so it gets the same answer every time: end it, then look at the account yourself. The four openings below cover most of what people actually get.

Screenshot of the Binance help page showing examples of phishing emails, including a dialog reading Source Not Verified
The exchange's own page of phishing examples, read September 2026. Published 11 December 2018 and still the reference it points people to, which says something about how stable these scripts are.

If they are on the line right now: say "I do not take security calls, I will check my account myself", and hang up. You do not have to be sure it is a scam, be polite about it, or hear them out. Then, from a browser you open yourself, sign in and look at whatever they said was happening.

If you already said or did something during the call, skip to what to do about it.

The single rule that covers all four: if you did not start the conversation, do not act inside it. Direction of first contact is the tell, before any of the content matters.

It is worth being clear about why that rule holds, and what it does not depend on. Some platforms state it outright: Binance.US says it will never call you and will not contact you by telephone. Not every exchange publishes the same sentence, and Binance's own verification tool accepts phone numbers for checking, so do not rest everything on "they never call". The rule works without it. Anything genuinely wrong with your account can be seen inside the account, and a caller cannot be checked at all. Hanging up costs a genuine caller nothing and costs an impostor everything.

Opening one: "we detected unauthorised access"

The most common. Urgent, alarming, and immediately followed by an offer to help you secure the account. The help involves moving your funds to a "safe" address the caller provides, or reading back a code they have just triggered.

What it is after: either a withdrawal you perform yourself, or the verification code that lets them perform it. The emotional shape is the point — fear first, then a rescuer. Nobody thinks clearly in the first ninety seconds of being told their money is being stolen.

What to do: end the conversation. Then, separately, go and look at the account's own login record. If something really is wrong you will see it there, and if it is, the response is the first-hour sequence rather than anything the caller suggests.

Opening two: "your verification is stuck, I can push it through"

Softer, and aimed at a specific moment — the days after submitting identity documents, when you are already waiting and already anxious. It often arrives as a reply inside a social platform thread where you complained about the delay, which is why complaining publicly about a pending verification is a worse idea than it seems.

What it is after: your documents, your login details, or remote access to your computer. Sometimes a fee, but the fee is usually secondary to the credentials.

What to do: nothing, which is genuinely the hardest instruction in this article. Reviews take as long as they take, and nobody outside the review can speed it up. The account-opening walkthrough covers what actually causes these delays, and most of them are fixable by you.

Opening three: "this is a routine security check"

Calm, bureaucratic, and the most effective of the four on people who consider themselves careful. There is no urgency and no drama. Someone polite works through a checklist, confirms details they already know — your name, your email, perhaps a recent transaction — and gradually moves towards details they do not.

The confirmed details are the mechanism. Each correct fact they recite makes the next request more plausible, and by the time the conversation reaches a code or a password it feels like the eighth item on a list rather than the point of the call.

Nine reasonable minutes, then one unreasonable request.

What to do: notice the shape rather than the content. Any request that would let someone else act on your account is out of bounds regardless of how reasonable the preceding nine minutes were. No genuine support process needs your password, your authenticator code, your recovery phrase, or control of your screen, and Binance.US, for one, states that its representatives will never ask for your password.

Details being correct is not evidence of legitimacy. Email addresses, names and even partial transaction histories circulate after unrelated breaches. If a caller knows your anti-phishing code, that is not reassurance — that is a sign your inbox or account has already been read, and it is a reason to end the call and start the response.

Opening four: "you have an unclaimed balance"

The one that arrives when nothing is wrong. A promotion, an airdrop, a rebate, a refund from a previous loss. It is the only one of the four that leads with pleasure rather than fear, and it works for the same reason the others do: it supplies a reason to act quickly on someone else's instructions.

What it is after: usually a connection or approval given on a page they control, or an upfront payment to release a sum that does not exist.

What to do: if a promotion is real, it will exist inside your account when you log in yourself. That is the same check as the fourth email check, and it settles every version of this without any judgement about the message.

Why scammers picked you: how they found your number or email

Approaches are not random, and understanding the selection makes the pattern much easier to spot in advance.

Three lists exist, roughly. There is the broad list: email addresses and phone numbers circulating after breaches of services with nothing to do with crypto. Contact from this list is generic, arrives in volume, and is cheap to send. There is the interest list: people who have publicly identified themselves as holding crypto — in a forum, under a video, in a reply to an exchange's social account. Contact from this list is better written and mentions the right platform. And there is the event list: people who have said something specific and recent, such as complaining about a stuck verification or a lost balance. Contact from this list is the most convincing, because it responds to a real situation.

You can usually tell which list you are on from the first line. Generic urgency means the broad list and can be deleted without thought. Correct platform, correct tone, no specifics means the interest list. Reference to something that has actually happened to you means the event list, and that is the one to take seriously as a signal — not because the message is genuine, but because somebody has read what you wrote and decided you are worth the effort.

The practical consequence is that what you post is a security setting, in the same way that your second factor is. A complaint about a pending review, posted publicly, moves you from one list to a more expensive one. That is not an argument for silence — people should be able to ask for help — but it is worth knowing the price, and worth asking in a way that does not identify the account, the amount, or the timing.

It also means that a first approach is usually followed by more. Once you are on the more expensive list, you stay there, and the second attempt tends to be better than the first. Treating each message as a fresh coincidence is how people who declined three approaches eventually accept the fourth.

How to end a fake support call without an argument

People lose here not because they were fooled but because they stayed on the line. Politeness is the lever, so the counter is a sentence that is already prepared and does not require you to be rude or clever.

Something like: "I do not take security calls. I will check my account directly." Then hang up. There is no need to verify who they are, explain your reasoning, or catch them out — all three keep the conversation going, which is the only thing the caller needs.

If the call got further than that — if you read a code out before the shape of it registered — what that code authorised decides what happens next. Money is not always the thing that was taken.

Two practical notes afterwards. Do not call back on a number the caller gave you, or one from a search result. If you want to contact support, reach it from inside the account. And if the approach came by phone, assume your number is on a list and expect more of them; that is also an argument for checking that your number cannot be used to change anything important, which is its own subject.

What to check after a fake support call, in order

Five minutes, and it is worth doing even when you are fairly sure you gave nothing away, because the point of the call is often to find out whether you will answer at all.

  1. Open the account yourself. Type the address or use your own bookmark. Not a link they sent, not a search result.
  2. Look for the thing they said was happening. A withdrawal, a login, a restriction. If it is not there, the call was the whole event.
  3. Read the login and device list. An unfamiliar session means the call was the second half of something, not the first.
  4. Check the withdrawal address list and the API keys. These are where a quiet change gets left behind, and neither shows up on the balance screen.
  5. Block the number or account, and do not reply to the follow-up. There is usually a follow-up.

What to do if you already gave a fake support agent something

People are too embarrassed to look this up. The scripts depend on it. Find what you handed over.

A verification code, password or recovery phrase

Treat the account as compromised now, not after you have checked whether anything happened. What that particular code authorised decides the order of the next ten minutes.

You installed something, or shared your screen

That device is no longer trustworthy. Do everything from a different one: change the exchange password and the email password there, revoke sessions, and get the remote-access software off the first machine before you use it for anything again.

You moved funds to an address they gave you

Report it to the exchange immediately, through the support system inside your account, with the transaction identifier and the destination address. There is one concrete payoff to being fast. If the funds land at another regulated platform, a fast report can support a freeze there. A confirmed transfer cannot be reversed by anyone.

You paid a fee, or gave card details

Contact your bank or card issuer and say the payment was obtained by deception. Card payments have chargeback routes that crypto transfers do not.

Only your name and email, or nothing at all

No action beyond the five steps above. They already had those, which is how they reached you.

One thing not to do in any of those branches: do not accept help from whoever contacts you next. A loss you have just reported, or just talked about, is the signal the second approach selects for.

There is no document to cite for the contents of a scam script, so this piece gives no figures. The platform statements quoted above come from Binance.US's safety and security tips (that it will never call you and never ask for your password) and from Binance Verify (that Binance will never request funds or tokens via private communications), both read on 3 October 2026. Other exchanges word their policies differently, which is why the rule here rests on who started the conversation rather than on any one company's promise. The four openings are a description of patterns reported publicly by people they were used on, not a study.