How we checked this
We reviewed the linked sources and keep this page updated when the record changes. Use the source list below to verify the details.
When a crypto recovery contact reaches you first: what to do
Source-tracked CryptoRescue article.
Short answer
Summary: If someone claiming they can recover your lost crypto contacts you first, treat the message as high risk until you verify it independently. The safest order is: do not pay, do not share sensitive information or account access, preserve only the evidence already visible to you, check the claimed organization through contact details you find yourself, then block and report the sender.
Date checked: 2025-02-14. Reporting routes, support processes, and platform tools can change by country and service.
Why an unsolicited recovery message is risky
CISA warns that social engineering and phishing often rely on unsolicited contact, urgency, impersonation, malicious links or attachments, and requests for sensitive information. FTC guidance also tells consumers not to pay more money to recover from a scam and to keep records of the contact. Those broad warnings fit cold outreach from someone claiming they can get funds back.
A convincing story is not proof that the sender is real. A message can use a genuine company name, copied branding, or details from a prior incident without showing that the sender actually represents that organization. The safer standard is independent verification through a public website or published contact channel you locate yourself.
What to do in the next 10 minutes
Do not send money. Do not share passwords, one-time codes, private keys, or wallet recovery phrases. Do not click links, open attachments, connect a wallet, or install software just because the sender says it is needed for tracing, verification, or release of funds.
2) Preserve evidence without increasing exposureSave only what is already visible. Useful evidence can include the chat thread, timestamps, sender profile, phone number or email shown, claimed organization name, visible website address, wallet address, and any payment request. Avoid clicking anything suspicious while collecting that information. FTC guidance says to keep records related to the scam, while CISA warns against interacting with suspicious content.
3) Verify the claim outside the conversationIf the sender says they represent an exchange, wallet provider, support team, or public authority, check that through the organization's official website or published contact page that you find independently. Do not rely on phone numbers, links, or documents sent in the message itself.
Quick decision table
| If the message says... | Main risk | Safer response | What to verify independently |
|---|---|---|---|
| “We already found your funds” | False confidence and pressure | Do not pay or rely on the claim | Whether the organization and contact route are official |
| “Pay a fee first” | More financial loss | Stop engaging and save the request | Whether the named organization warns about advance-fee demands |
| “Connect your wallet” | New approvals or asset exposure | Do not connect through the message | The real support process published by the service |
| “Install this tool” | Device or account compromise | Do not install it from the message | Whether the organization actually uses that process |
| “Move funds to a safe wallet we control” | Further asset loss | Do not transfer funds based on the message | Official security guidance from the claimed service |
| “Send your recovery phrase, private key, or code” | Loss of wallet or account control | End the conversation | The service's published security guidance |
| “We are from support, compliance, or an authority” | Possible impersonation | Verify through independently found channels | The official website and listed contact methods |
Evidence checklist
Use a narrow checklist. The goal is to preserve identifiers and requests, not to continue the exchange.
- Screenshots of the chat, ideally with visible timestamps
- The sender's displayed name, handle, profile link, phone number, or email
- Any wallet address, QR code, payment instruction, or transaction reference shown
- Any website address, domain, app name, or software download mentioned
- Any request for fees, release payments, verification payments, codes, or account access
- The date, time, and platform where the contact happened
Do not test links, open files, connect a wallet, or keep the conversation going just to see what happens next. CISA's phishing guidance warns that interacting with suspicious messages can increase risk.
Safe shutdown steps
After you save key evidence and verify any claimed organization independently, the lower-risk next step is usually to stop replying, block the sender, and use the platform's reporting tools if available. FTC guidance says to stop contact with scammers and keep documentation. Platform-specific reporting options still need to be checked live because they vary by service.
- Screenshot the conversation and sender profile first
- Do not pay, click, connect, install, or share sensitive information
- Verify any claimed organization through a public channel you found yourself
- Block the sender
- Report the account through the platform, if that option exists
- Keep your records together in case you later need them for official reporting or support
If you already shared something
The next step depends on what you exposed. If you only replied, you may mainly face more scam contact. If you shared access details, recovery information, one-time codes, opened links, connected a wallet, or installed software, stop relying on the unsolicited message and move to the official security or support pages for the affected service or device.
If you shared a wallet recovery phrase or private keyTreat that as serious exposure. Do not send more money and do not continue following instructions from the unsolicited contact. Go to the official security guidance for the wallet or service involved, using a web address you find yourself.
If you shared exchange login details or one-time codesStop using the conversation as your guide and go directly to the official support or security pages of the affected service using independently found contact details.
If you installed software or opened a fileDo not continue taking instructions from the sender. Use official support or security resources for the affected device or account instead.
What to watch for next
Follow-up contact often changes names and roles after the first approach fails. Be cautious if you see:
- New accounts claiming to be from “compliance,” “investigations,” or “escalations”
- Pressure to move the conversation to another app, phone number, or private channel
- Fresh payment demands described as taxes, release charges, verification steps, or insurance
- Lookalike support pages or websites sent after you stop replying
Before you act, verify these details live
Because reporting and support routes vary, check these items in real time before taking further steps:
- The official website of any company or institution named in the message
- The platform's current block and report tools
- The official support or security page for any wallet, exchange, email account, or device involved
- Country-specific cybercrime or fraud reporting options where you live
FAQ
Usually, the safer approach is to preserve evidence, verify independently if needed, and then stop replying, block, and report.
What if they know my wallet address or transaction details?That can make the message look more convincing, but it still does not prove the sender is legitimate. Verification should come from a trusted public source outside the message.
Can a real company ever contact me this way?Do not assume a message is genuine just because it uses a real company's name. Check the official website and published contact methods independently before you act.
What if I already paid?Do not send more money. Preserve the payment request and conversation, then move to independently verified support or reporting channels. FTC specifically warns against paying someone who promises to recover money lost to a scam.
What if I already clicked, connected, or installed something?Stop following instructions in the message and move to official support or security guidance you find independently for the affected service or device.
Source note
This article is based on public cyber-safety and consumer-protection guidance about unsolicited contact, phishing, impersonation, suspicious links and attachments, software-install requests, and preserving records after a scam approach. It is harm-reduction guidance, not a promise of recovery or a complete legal guide for every country.
Sources
Update log
- 24 Jul 2026Published with source tracking and reader-safety context.
- CorrectionsIf a source changes or a claim needs clarification, this page can be updated from the editorial desk.