Guides

Crypto Support Call Scam: What to Do When "Support" Tells You to Move Funds

Learn how fake Coinbase, Kraken, Ledger, Trezor, and Binance support calls work, how real support is verified, and the safest response before you move crypto.

Published May 10, 2026Updated August 1, 2026

A call, text, or email that says your crypto account is at risk can feel urgent. That urgency is the attack.

Fake support callers impersonate exchanges and wallet brands, cite a suspicious login or blocked withdrawal, and then push you to move funds, install remote-access software, reveal a code, approve a passkey prompt, or change account settings while they stay on the line. The safest first move is simple: hang up, do not click the link, and contact the company from the official app or website yourself.

This guide focuses on support-impersonation scams affecting Coinbase, Kraken, Binance, Ledger, Trezor, and other crypto users.

Short answer

If “support” tells you to...Treat it as
Move funds to a “safe” walletA scam
Share a seed phrase, private key, password, 2FA code, device-approval code, or passkey approvalA scam
Install AnyDesk, TeamViewer, screen sharing, or remote-control softwareA scam
Change API permissions or security settings while they coach youA scam
Trust a phone number you found in search resultsUnsafe until verified
Continue an unexpected Kraken call that is not verified inside the appA scam risk

Real support may help you lock an account, review a case, or point you to official steps. Real support does not need your seed phrase, does not need remote access to your device, and does not need you to transfer crypto to prove ownership.

The 2026 detail people can miss: some support is real, but the verification method matters

This topic got more confusing because not every platform handles voice support the same way.

Coinbase still says support communications must be initiated by you and that Coinbase phone support does not make outgoing calls. Ledger says it does not offer phone support. Trezor warns that any request for a wallet backup, PIN, password, or code is a scam.

Kraken, however, now documents real voice support in specific situations. The important detail is how it works: Kraken says voice support is available only through its mobile apps when a Call us option appears, or through a call arranged in advance with support. During a real call, Kraken says the app shows an in-app verification banner or prompts you to verify the call with a one-time code. That means a random number from Google, an unexpected inbound call, or a call without in-app verification should still be treated as suspicious.

So the rule is not “all crypto support calls are fake.” The rule is: a real support call must be verified through the platform’s documented channel, not through caller ID or urgency.

How the scam usually works

The script often starts with a believable alert: “Your withdrawal is pending,” “Your account was accessed from another country,” “Your API was changed,” or “Your wallet needs to be secured.” The caller may know your name, email, or old breach data. That does not prove they work for the company.

A common pattern is:

  1. the scammer creates panic with a fake security issue;
  2. they keep you on the phone so you do not stop to verify;
  3. they push you into a login, 2FA approval, API change, remote-access install, or transfer;
  4. they drain the account or social-engineer you into doing it yourself.

Binance has also warned about fake support calls that pressure users to change API settings. That matters because a scam does not always end with “send funds to this wallet.” Sometimes it ends with you expanding permissions that let the attacker act later.

What real support will never need from you

Regardless of the brand, these requests should stop the conversation immediately:

  • your seed phrase or backup words;
  • your password;
  • a 2FA code, device approval code, or passkey approval you did not start yourself;
  • remote access to your phone or computer;
  • instructions to remove security protections;
  • instructions to change API permissions because of a call;
  • a transfer to a “safe” wallet, “temporary vault,” or “verification address.”

If the caller asks for one of those, you do not need more proof. End the call.

What to do in the first five minutes

  1. End the conversation. Do not argue, confirm details, or follow instructions “just to check.”
  2. Do not click the link. Open the exchange or wallet site from your own bookmark, typed URL, or official app.
  3. Check whether the event is real inside the platform. Review security notices, active sessions, withdrawals, and device history.
  4. Lock the account if the platform offers it. Coinbase and Kraken both document compromised-account flows.
  5. Change passwords from a clean session if needed. Use a device you trust.
  6. Review withdrawals, devices, API keys, and allowlists. If anything changed, treat the account as compromised.
  7. Move funds only after independent verification. If a wallet seed phrase was exposed, create a fresh wallet yourself and move funds on your own terms.

If you already signed a suspicious transaction, also review wallet approval scams and dangerous permissions. If you already typed a seed phrase into a website, assume that wallet is compromised and follow seed phrase exposed.

Exchange account risk vs self-custody wallet risk

For an exchange account, the attacker usually wants login access, a 2FA approval, a passkey confirmation, a malicious API change, or a withdrawal to an address they control. Your best defense is account hardening: strong 2FA or passkeys, withdrawal allowlisting, anti-phishing tools where supported, and a clean email account. Start with the crypto exchange account security checklist.

For a self-custody wallet, the attacker usually wants your recovery phrase or a malicious signature. A hardware wallet helps keep keys off your computer, but it cannot protect you if you willingly send funds to the scammer or type your seed phrase into a fake site. For broader patterns, read common crypto scams and fake crypto wallet apps.

When should you move funds?

Do not move funds because a caller tells you to. Move funds only after you independently verify a real compromise.

If an exchange login may be compromised, use the official account-lock or support flow first. If a self-custody seed phrase was revealed, generate a new wallet yourself and transfer from the old wallet to the new one. If you are moving coins from an exchange into cold storage, use your own withdrawal checklist, not instructions from a caller. The safe path is covered in how to move crypto from an exchange to a hardware wallet.

How to verify support safely

  • Type the official domain yourself or use the official app.
  • Do not trust phone numbers shown in search ads.
  • Do not continue a support case through Telegram, WhatsApp, Discord, or X DMs.
  • For Kraken, trust the in-app verification banner or arranged in-app verification flow, not caller ID.
  • For Coinbase, remember that phone support should start from you, not from an unsolicited call.
  • Keep a written record of the time, number, email, and any transaction IDs.

Once the immediate call is handled, close the gaps the scammer was aiming at: work through the crypto exchange account security checklist, then read the SIM swap attacks on crypto exchange accounts guide if your account still depends on SMS.

Bottom line

If crypto support contacts you first and tells you to move funds, share secrets, install remote access, or change security settings while they coach you, treat it as a scam. The one exception is a support flow you can verify inside the official app or account channel itself. In crypto, the verification method matters more than the caller’s story.

Explore more

Guides worth reading next