Advertisement
Advertisement
When you lose access to a cryptocurrency account, panic can make a convincing scam look like helpful customer service. A person may contact you through social media, WhatsApp, Telegram, email or a search advert and promise to restore your funds quickly. They may ask for your password, one-time password, private key or recovery phrase.
That is the danger. Legitimate support can help you follow an account-recovery process, but it cannot safely ask you to hand over the secrets that control your account or wallet.
Advertisement
For Nigerians using crypto platforms, wallets and payment services, the safest rule is simple: use only the platform’s official app or website, start the recovery process yourself, and never share credentials that can authorise a transaction.
Table of Contents
What legitimate support may ask for
Real support teams need enough information to understand your problem and confirm that you are using the correct recovery route. Depending on the service, they may ask for:
- The email address or phone number connected to your account.
- A general description of the problem, such as a forgotten password, locked account or failed identity check.
- The date and approximate details of a transaction that appears in your account history.
- A ticket number or previous support conversation.
- Identity documents through the platform’s secure verification page, where the provider’s process requires identity verification.
- A screenshot of an error message, provided it does not reveal passwords, codes, wallet addresses linked to sensitive activity or other private information.
These requests should happen through an official support channel. You should be able to open the platform’s website or app yourself, find its help centre and submit a ticket without relying on a stranger’s link.
What legitimate support will never request
A genuine support representative should not need the information below to “unlock” your account or approve a withdrawal. Anyone asking for it should be treated as a serious warning sign.
Your password
Your password is designed to be known only by you. Support may explain how to reset it, but it should not ask you to send the current password or create a new password for an agent.
Your one-time password or authentication code
Security codes from an authenticator app, text message or email can help someone pass a login or withdrawal check. A scammer may claim that the code is needed to verify your identity. In reality, giving it to them can help them access the account while you are still speaking to them.
Never read an OTP to a caller, paste it into a chat or forward a security email. If you receive an unexpected code, change your password through the official app and review your account activity.
Your seed phrase or recovery phrase
A self-custody wallet is controlled by a recovery phrase, also called a seed phrase. It may consist of a series of words shown when the wallet is created. Whoever has this phrase may be able to control the assets in the wallet.
There is no legitimate reason to send your recovery phrase to a support agent, “validation service” or recovery expert. Do not type it into a website, upload a photograph of it or store it in an ordinary chat. If somebody says your wallet must be “synchronised” by entering the phrase on a website, stop immediately.
Your private key
A private key is another highly sensitive credential connected to control of a crypto wallet. It should remain private. Support cannot reverse a blockchain transaction by collecting your private key, and handing it over can put the wallet at risk.
Permission to control your device
Be cautious if a supposed agent asks you to install remote-access software, share your screen or allow them to control your phone or computer. This could expose your email, banking apps, password manager, wallet and saved documents.
Screen sharing can also reveal a recovery phrase or authentication code without you intentionally sending it. Legitimate support should not require unrestricted access to your device.
A payment to release or recover your funds
Scammers often demand a “verification fee”, “tax”, “unlocking charge”, “gas payment” or “anti-money-laundering deposit”. They may promise that the payment will be refunded or added to the recovered balance.
Some genuine platforms may charge clearly stated service or network fees in specific situations, but an unexpected person contacting you privately and demanding crypto or cash is not a safe way to handle fees. Confirm any charge inside the official platform, not through a private message.
How recovery scams usually work
Recovery scams often target people who have already experienced a problem. You may post online that you cannot log in, lose access to a wallet or have sent funds to the wrong address. A fake helper then replies with confidence and urgency.
The scammer may copy a company logo, use a name similar to a real employee or direct you to a website that looks professional. They may ask you to act immediately because your account is supposedly at risk. The aim is to make you reveal a secret, sign a harmful transaction or send money.
One important distinction is that custodial accounts and self-custody wallets have different recovery possibilities. A crypto exchange may provide a password reset or identity-verification process for its own account. A self-custody wallet generally cannot reset or replace a lost recovery phrase. If the phrase is lost, a person claiming to recover the wallet for a fee deserves extreme suspicion.
A safer account-recovery workflow
- Stop responding to unsolicited contacts. Do not click their links or continue a conversation simply because they know your username.
- Open the official app or type the known website address yourself. Avoid links sent through comments, direct messages and unexpected emails.
- Use the built-in password-reset or support option. Read the instructions carefully and check the web address before entering information.
- Protect your email account first. If an attacker controls your email, they may be able to reset other accounts. Change the email password and enable multi-factor authentication where available.
- Review account activity. Look for unfamiliar logins, changed withdrawal details, new devices, API access or transactions you did not approve.
- Secure the device. Remove suspicious remote-access applications, update the operating system and run a trusted security check.
- Save evidence. Keep usernames, wallet addresses, transaction IDs, screenshots and payment records. Do not delete messages before documenting them.
- Report the impersonator. Use the platform’s official reporting channel and report financial fraud to the relevant authorities or service providers in your location.
What to do if you already shared sensitive information
Act quickly, but do not pay a second “recovery expert” who promises to fix the first scam.
- Change the affected password from a trusted device.
- Sign out other sessions if the service provides that option.
- Revoke unfamiliar app connections, API keys and withdrawal permissions.
- Contact the official platform through its verified support centre.
- Move any remaining assets to a secure wallet only after checking that the destination and device are safe.
- If a recovery phrase was exposed, treat the wallet as compromised. Create a new wallet and transfer remaining funds using a clean device, if it is safe and technically possible.
- Contact your bank or payment provider immediately if you sent money from a bank account or card.
Do not assume that a transaction can be reversed because you have reported it. Blockchain transfers may be difficult or impossible to reverse, which makes prevention and fast reporting especially important.
A quick test for suspicious support
Before following instructions, ask three questions:
- Did I contact this person first through an official channel?
- Are they asking for a secret that could log in, approve a transaction or control a wallet?
- Are they creating pressure, demanding payment or promising guaranteed recovery?
If the answer to either of the last two questions is yes, stop. Find the official website independently and begin again there.
The safest recovery advice
Real support helps you use a provider’s recovery process; it does not take possession of your account. Passwords, OTPs, recovery phrases and private keys must remain private, even when the person asking sounds knowledgeable or claims to work for a popular platform.
For beginners and experienced users alike, the best protection is a calm process: verify the channel, protect your email, inspect every request and never let urgency override basic security. In crypto, refusing to share one secret can protect everything connected to it.
Advertisement
