• 5 mins read
  • Published

Telegram crypto scams hit wallets with fake support ploys

Guido Molinari Blockchain economics and tokenomics writer EgonCoin

Post by Guido Molinari

Telegram crypto scams hit wallets with fake support ploys EgonCoin © egoncoin.com
Telegram crypto scams hit wallets with fake support ploys © egoncoin.com

Crypto scammers are ramping up attacks on Telegram, posing as support or recovery agents. They use urgent messages and phishing tricks to steal login codes and seed phrases, putting users' accounts and wallets at risk if they respond.

Scammers are taking advantage of Telegram's popularity with crypto users. They pretend to be customer support or recovery agents, sending urgent messages and using believable stories to get people to hand over sensitive information. If a user falls for it, they can lose control of their Telegram account, self-custody wallet, or exchange account in minutes-often before they realize what's happening.

How scams hijack accounts

Most scams start with a sudden warning: maybe a fake account lock, a failed withdrawal, or a claim that law enforcement or the platform can help recover lost funds. Scammers copy official usernames and avatars. They push the conversation into a private Telegram chat. Their aim is to make the chat feel like normal support, so users keep sharing details without stopping to check if the contact is real.

Telegram surpassed 900 million monthly active users in 2024, making it a prime target for impersonation and support-style crypto scams.

Reuters

The scam usually follows a set pattern: a fake alert, someone pretending to be support or law enforcement, a phishing link or fake ticket page, and then a demand for a phone number, login code, two-factor code, or seed phrase. Once the scammer gets these details, they can take over the session, empty wallets, or drain exchange accounts. Many scammers start on another platform, then insist that support is only available on Telegram.

Red flags and high-risk requests

If someone asks for your phone number, login code, or seed phrase, that's a major warning sign. A Telegram login code is a one-time password. If you share it, an attacker can log in to your account on a new device. Telegram's official FAQ says these codes only show up in the verified in-app service chat and should never be shared. Scammers often claim they need the code to prove ownership or fix an urgent problem.

Seed phrases are even more sensitive. If anyone asks you to "sync a wallet," "unfreeze funds," or "import a phrase into a ticket form," it's almost always a scam. If a seed phrase gets out, attackers can drain the wallet, and there's little chance of getting the funds back. The same goes for requests to send crypto to "safe addresses" or off-platform transfers-real support never asks for this.

Chainalysis reports that scams remained the largest source of on-chain illicit activity in 2023, with billions lost to wallet-drainer and account-takeover fraud. This highlights the ongoing risk for crypto users on platforms like Telegram.

Chainalysis 2024 Crypto Crime Report

Detection and response

The best way to spot these scams is to look for warning signs, not just how "professional" the chat seems. Watch out for direct messages from strangers with urgent claims, people who can't prove who they are, requests for login codes or seed phrases, and pressure to join private groups for support. If you see even one red flag, end the chat right away.

If you've already shared a code or approved something suspicious, act fast. Cut off contact, check your active Telegram sessions, change your passwords, and look for any unauthorized withdrawals or approvals. Only get help through Telegram's in-app support, the Internet Crime Complaint Center (IC3), the Federal Trade Commission's ReportFraud portal, or the help center of your exchange or wallet provider. The IC3 has said publicly it never contacts people directly for information or money and does not work with law firms or crypto recovery services.

Official guidance and industry context

Telegram's own guides say support is only available through the app's official channels-not through social media or private messages. The FBI has warned about scammers pretending to be the IC3, and the FTC has a portal for reporting fraud. Never follow links or instructions from unknown contacts. Always check support claims through public, official sources.

These credential-stealing scams aren't unique to Telegram, but the app's big crypto user base and easy private chats make it a favorite for attackers. Other scams-like fake giveaways, job offers, malware apps, and subscription traps-often set the stage for credential theft before the "recovery" script appears. As reported earlier, the growth of crypto services and platforms has brought new risks and attack methods, so users need to stay alert and always verify.

Telegram itself isn't unsafe by default, but the risk jumps when users talk to unverified accounts or answer suspicious requests. The best defense is to refuse all requests for login codes, seed phrases, or off-platform transfers, and to keep all credential management inside official, documented channels. Spotting and refusing scams early works far better than trying to recover after credentials are stolen.

The FBI and IC3 say crypto scams in the U.S. keep rising, with phishing and social engineering among the top attack methods. The IC3's public alerts stress that the agency never reaches out to victims on Telegram or asks for payment or credentials for recovery. If you think you've been targeted, lock down your accounts and report it through official channels right away.

Phishing attacks in crypto often play on the confusion around wallet recovery and the urgency of support requests. Unlike banks, self-custody wallets use seed phrases that can't be reset or reversed if leaked. That means a successful scam can be devastating for users who don't spot the warning signs in time.

Related articles