← Crypto Scam Library · Risk checks · Research
By Verixia Research · reviewed 2026-08-05 · educational — not financial advice
Impersonation scams put a trusted face in front of the theft: a 'support agent' who DMs after you post a problem, a cloned Twitter/Telegram handle one character off the real one, a 'project team' member offering a fix or an allocation. The goal is to move you to a drainer site, a poisoned address, or a seed-phrase prompt.
Legitimate projects do not DM first, never ask for your seed phrase, and never need remote access to your wallet.
Attackers monitor public channels for people posting wallet problems, then reach out privately with a scripted 'fix'. Cloned handles copy the avatar, bio and name; fake support portals mirror the real UI. The trust is manufactured in minutes and spent immediately.
Unsolicited DMs offering help; urgency ('act now or lose funds'); any request for your seed phrase, private key, or a 'validation' signature; a handle or URL that's almost-but-not-quite right; a 'giveaway' requiring you to send first.
Treat every unsolicited DM as hostile. Resolve contract addresses from on-chain data and a project's verified channels, never from a message. Never enter a seed phrase into any website for any reason. When in doubt, do nothing — the urgency is the scam.