← Crypto Scam Library · Risk checks · Research

Fake Support & Impersonation: The Human Layer

By Verixia Research · reviewed 2026-08-05 · educational — not financial advice

What it is

Impersonation scams put a trusted face in front of the theft: a 'support agent' who DMs after you post a problem, a cloned Twitter/Telegram handle one character off the real one, a 'project team' member offering a fix or an allocation. The goal is to move you to a drainer site, a poisoned address, or a seed-phrase prompt.

Legitimate projects do not DM first, never ask for your seed phrase, and never need remote access to your wallet.

How it works

Attackers monitor public channels for people posting wallet problems, then reach out privately with a scripted 'fix'. Cloned handles copy the avatar, bio and name; fake support portals mirror the real UI. The trust is manufactured in minutes and spent immediately.

The tells

Unsolicited DMs offering help; urgency ('act now or lose funds'); any request for your seed phrase, private key, or a 'validation' signature; a handle or URL that's almost-but-not-quite right; a 'giveaway' requiring you to send first.

How to avoid it

Treat every unsolicited DM as hostile. Resolve contract addresses from on-chain data and a project's verified channels, never from a message. Never enter a seed phrase into any website for any reason. When in doubt, do nothing — the urgency is the scam.

Other scam patterns