Sources checked

How we checked this

We reviewed the linked sources and keep this page updated when the record changes. Use the source list below to verify the details.

Source links attached Safety context included Corrections open

Key points

Summary: If a supposed recovery contact approaches you after a crypto loss, the safest order is usually: preserve evidence, stop engaging, block, and report. Save exact contact details, full message history where available, any wallet or payment instructions, and any claimed company or case identity. Do not send more money, share seed phrases or private keys, or give remote access to your device.

Date checked: This guidance was reviewed against the available source pack for this update. The source pack supports general cyber-safety and reporting caution, but it does not strongly support platform-specific or regulator-specific recovery-scam procedures, so this article keeps claims narrow and evidence-led.

What changed

This update puts evidence preservation ahead of general scam background. Broad public cyber-safety guidance supports using trusted reporting channels and keeping enough information to describe what happened. For a suspected impersonation or recovery approach, that means preserving the contact trail, the payment trail, and the claimed identity trail before the account disappears or the conversation is lost.

This article also draws a firmer line between preserving evidence and prolonging contact. Save what is already visible, then disengage. If the person is pushing for live wallet actions, remote access, or immediate payment, immediate safety comes first.

Old article audit

No prior article URL or full earlier text was provided for direct comparison in this update. Because of that, this audit is limited to common weak points in older recovery-scam guidance rather than a line-by-line rewrite of a published page.

The main gap this refresh addresses is evidence quality. A cropped screenshot may miss the username, timestamp, URL, wallet address, or the wording of a payment demand. Preserving fuller records can make later reporting clearer, even if those records do not prove who was behind the contact.

What to preserve before you block

The practical goal is simple: keep the details that show who contacted you, what they asked for, where they wanted money sent, and who they claimed to be. Capture what is visible without continuing the conversation longer than necessary.

Contact details

Save the exact display name, username or handle, profile link if visible, phone number, email address, website or domain, and the platform where the contact appeared. It also helps to note how the approach started, such as a direct message, email, comment reply, or referral.

Message history

Preserve the conversation as completely as the platform allows. Full screenshots with visible timestamps are usually more useful than isolated images. For email, keep the original email in your inbox if possible instead of relying only on a screenshot.

Wallet and payment details

If the person provided a wallet address, QR code, payment rail, or transaction instructions, save them exactly as shown. If you already sent funds, keep the transaction hash, receiving address, and network details. Those records can document the transaction, but on their own they do not identify the real-world controller of the address.

Claimed identity details

Save any claimed company name, role, case number, support address, office address, registration claim, or document image the person used. Treat these as claims to verify later through independently found channels, not as proof that the contact is genuine.

Evidence checklist at a glance

What to saveWhy it mattersBest version to keepImportant limit
Profile name, handle, or linkIdentifies the account used to contact youFull profile capture plus exact text or URLProfiles can change, disappear, or be copied
Full chat or emailPreserves context, timing, and wordingFull screenshots or original messagesPartial captures can remove key context
Wallet address or QR codeDocuments where payment was requested or sentAddress, network, QR code, and transaction hashDoes not by itself prove real-world identity
Payment demandShows amount, reason given, and urgencyScreenshot with full wording and timingA single image may miss earlier pressure or follow-up claims
Claimed company or case identityHelps later verificationName, title, case number, website, document imageOfficial-looking documents can be faked
Website or domainUseful for later checking and reportingFull URL and page captureScam pages may change or vanish

Wallet requests that should raise concern

Broad cyber-safety guidance supports caution around sensitive access, credentials, and device control. For this topic, that means treating requests involving wallet secrets, unfamiliar links, or device access as a serious warning sign.

Save these requests before you disengage
  • Any request for your seed phrase or private key
  • Any request to install software, an extension, or a mobile profile
  • Any request for remote access to your phone or computer
  • Any request to connect your wallet to a link they sent
  • Any request to sign a message or approval you do not understand
Why this matters

These requests can move the situation from impersonation into direct account or wallet compromise. If that pressure is happening in real time, do not stay in the conversation just to gather more evidence. Preserve what you already have and cut contact.

Payment demands to document

If the contact asks for money, preserve the exact wording of the demand, the amount, the reason given, any deadline, and the requested payment method. This article does not assume every scam uses the same script, so the safest approach is to document the demand exactly as presented.

What to capture in each demand
  • Amount requested
  • Currency, token, or payment method requested
  • Wallet address or destination details
  • Deadline or urgency language
  • Claimed reason for the payment
  • Any promise tied to payment, such as release of funds or case progress

Identity claims to verify independently

If the person says they represent a company, investigator, legal service, or public authority, preserve the claim and verify it separately. The safest path is to locate the official website or public contact page yourself rather than using links or numbers sent by the person who approached you.

Identity details worth saving

Save the claimed employer name, title, support contact, office location, case reference, registration claim, and any badge or certificate image shown in the conversation.

Practical steps: preserve, disengage, report

  1. Save the exact contact details used to reach you.
  2. Preserve the full message history or email where possible.
  3. Record any wallet addresses, QR codes, transaction hashes, and network details.
  4. Save each payment demand with the amount, timing, and explanation given.
  5. Save all claimed identity details and document images.
  6. Stop sending money and stop following links or wallet instructions from the contact.
  7. Verify any claimed organization through an independently found official channel.
  8. Block and report once you have preserved what you reasonably can.

What readers should watch next

  • A follow-up from a different account using the same story
  • New pressure to pay a final or urgent fee
  • Requests to move to another app or platform
  • Escalation to remote-access or wallet-connection requests

Sections to update

Rewrite priorities

Keep the opening practical and move the evidence checklist near the top. The article should stay focused on what to preserve, what not to share, and how to verify identity claims through independent channels.

Claims that still need stronger sourcing

The current source pack does not strongly support detailed claims about:

  • regulator-specific recovery-scam scripts
  • exchange or wallet support practices
  • platform-specific message export or evidence-retention features
  • jurisdiction-specific reporting outcomes

Sources

Update log

  1. 22 Jul 2026Published with source tracking and reader-safety context.
  2. CorrectionsIf a source changes or a claim needs clarification, this page can be updated from the editorial desk.