BTC:
ETH:
SOL:
BNB:
XRP:
Identity threat

Impersonation scams: verify through a channel the message did not supply

A copied profile, compromised real account, fake support agent, or lookalike domain can make the wrong destination feel familiar. Break the contact path, authenticate independently, and preserve the identity and transaction evidence separately.

11 min readReviewed July 14, 2026Threat guide

The short answer

Impersonation transfers trust from a real team, wallet, exchange, influencer, or support service to an attacker-controlled account, domain, contract, wallet, or transaction. The bait may be a copied account, a hijacked legitimate profile, a fake reply, an unsolicited support message, a forged announcement, or a private group that mirrors a real community.

Do not verify the message using a link, phone number, handle, QR code, or support ticket it provided. Close it. Find the organization through a previously saved bookmark, installed app, independently typed domain, or trusted historical channel, then confirm the exact request and destination there.

Separate the forms of impersonation

  • Copy account: a lookalike handle, display name, avatar, bio, followers, and posts imitate the real account.
  • Compromised real account: the exact established profile posts an attacker's contract, download, recovery notice, or urgent announcement.
  • Fake support: an account monitors public complaints or enters DMs offering recovery, verification, refund, or wallet synchronization.
  • Fake team or partner: a person claims an employee, moderator, exchange-listing, market-maker, or influencer relationship.
  • Lookalike destination: a domain, app, extension, Telegram room, Discord server, token page, or contract copies the real one.
  • Relay scam: the attacker copies a real announcement but swaps the link, mint, recipient, or transaction request.

The correct response differs. A copy account can be rejected by account identity. A compromised real account passes that test, so the destination and announcement still require independent corroboration.

Break the channel before checking the story

The U.S. FTC advises people not to click links or call numbers in unexpected business messages. The same principle applies here: independently locate the real service, then ask whether the event, account problem, support case, airdrop, token, migration, or payment request exists.

Use at least two identity anchors where practical: an old bookmark plus the installed wallet, a long-standing website plus a historical social profile, or an official status page plus a known support portal. Cross-channel repetition is useful only when the channels are independently controlled; copied scam pages can cross-link one another.

Authenticate the account at the identifier level

Save the full profile URL and exact handle, not only display name and avatar. Compare account creation where available, historical name changes, old mutual links, official-site references, previous posts, and the context of the first suspicious message. Unicode lookalikes, inserted punctuation, transposed letters, and reply accounts using the original display name are easy to miss on mobile.

X states that its current blue check indicates an active Premium subscription and no longer uses the former independent active, notable, and authentic criteria. Record a badge's platform-defined meaning, but never let it authenticate a linked contract, support agent, or off-platform destination.

Verify every destination independently

Resolve the exact chain and full mint or contract from a trusted source, then confirm the pool, token metadata, website domain, app publisher, extension ID, download signer, recipient wallet, and transaction instructions. A legitimate brand can be attached to an unrelated asset; use the clone-launch provenance workflow whenever the message names a token.

A wallet connection is not the same as a transaction, and a transaction is not the same as the action described in the message. Decode transfers, approvals, delegates, program calls, sign-in messages, and requested networks before signing. “Verification,” “sync,” “rectification,” and “support recovery” are labels, not instruction types.

Real wallet support does not need your secret

Phantom's official support guidance says its support team will never DM users or ask for a Secret Recovery Phrase, and cannot access private keys or reverse blockchain transactions. Entering a recovery phrase into a website is not a normal wallet-connection flow. Any person who asks for a phrase, private key, remote screen control, or funds to “validate” or “unlock” the wallet is asking for control—not diagnostic information.

Move to the service's independently found support portal. Do not continue in a reply thread simply because the account answered quickly or knows public details about your transaction. Wallet addresses, failures, and balances are often public enough to make a fake agent sound informed.

Urgency is part of the authentication attack

Fake support and announcement scams use expiring claims, frozen accounts, limited migrations, surprise refunds, legal threats, account-security warnings, or “act before the hacker does” language to prevent independent checking. The FTC reports common impersonation patterns including copycat security alerts and fake giveaways, and warns that scammers often demand cryptocurrency.

Slow the process. A legitimate incident may be urgent, but an independent official channel should still be able to confirm it. Do not let secrecy requests, private tickets, deleted replies, or moderator status override destination verification.

Preserve evidence without deepening the contact

Capture the message URL or ID, exact handle and profile URL, timestamps, visible badge, room or server, full text, media, links, domains, phone or email, claimed identity, wallet addresses, contract or mint, QR destination, and transaction payload. Save the legitimate identity anchors used for comparison and note how you found them.

Screenshots preserve appearance, not always the underlying identifier. Add copied URLs, headers where safe, account IDs where the platform exposes them, and onchain signatures. Do not download unknown attachments, reply for more proof, send a test payment, or connect a burner merely to “see what happens.”

If you interacted, respond to the capability exposed

  • Clicked only: close the page, remove downloads, and inspect the device and browser without reusing the suspicious link.
  • Connected only: disconnect the site and review sessions; then inspect whether any message or transaction was also signed.
  • Approved or delegated: inspect and revoke the exact permission, while recognizing revocation cannot undo completed transfers.
  • Shared a key or phrase: treat every derived account as compromised and move remaining assets from a clean device to a newly generated wallet; do not reuse the exposed secret.

Follow the bot and DM response guide, fake-site checks, and seed and key containment workflow for the relevant exposure. Preserve evidence and report the account or domain through the platform's real interface.

An independent-verification workflow

  1. Stop the interaction. Do not click, reply, call, download, connect, sign, or send while authenticating the request.
  2. Preserve identifiers. Save exact account, message, domain, destination, claimed event, and time without relying on screenshots alone.
  3. Rebuild the trusted path. Open a known app or independently locate the official site, account, status page, and support portal.
  4. Verify the claim and destination. Confirm the event, support case, chain, full mint, recipient, download, and decoded wallet request.
  5. Assess exposure. Separate viewing, clicking, downloading, connecting, signing, approving, transferring, and sharing credentials.
  6. Contain and report. Take the response matched to the exposed capability, preserve onchain and platform evidence, and avoid overclaiming who operated the scam account.

What belongs in the journal

Record the claimed person or service, account URL and handle, account ID if available, message ID and timestamp, badge type, channel, wording, urgency tactic, every link and domain, full mint or contract, recipient wallets, transaction payload and simulation, trusted identity anchors, independent confirmations, interaction level, signatures and approvals, containment actions, reports, data gaps, and the narrow conclusion: copy account, compromised account, unverified identity, fake destination, or another supported finding.

Primary sources

Break the contact path

A message cannot authenticate its own sender.

Rebuild identity from a known channel, then verify the event, destination, and wallet request as separate claims before taking action.

Open the journal