How we checked this
We reviewed the linked sources and keep this page updated when the record changes. Use the source list below to verify the details.
Key points
Summary: If a supposed recovery contact approaches you after a crypto loss, the safest order is usually: preserve evidence, stop engaging, block, and report. Save exact contact details, full message history where available, any wallet or payment instructions, and any claimed company or case identity. Do not send more money, share seed phrases or private keys, or give remote access to your device.
Date checked: This guidance was reviewed against the available source pack for this update. The source pack supports general cyber-safety and reporting caution, but it does not strongly support platform-specific or regulator-specific recovery-scam procedures, so this article keeps claims narrow and evidence-led.
What changed
This update puts evidence preservation ahead of general scam background. Broad public cyber-safety guidance supports using trusted reporting channels and keeping enough information to describe what happened. For a suspected impersonation or recovery approach, that means preserving the contact trail, the payment trail, and the claimed identity trail before the account disappears or the conversation is lost.
This article also draws a firmer line between preserving evidence and prolonging contact. Save what is already visible, then disengage. If the person is pushing for live wallet actions, remote access, or immediate payment, immediate safety comes first.
Old article audit
No prior article URL or full earlier text was provided for direct comparison in this update. Because of that, this audit is limited to common weak points in older recovery-scam guidance rather than a line-by-line rewrite of a published page.
The main gap this refresh addresses is evidence quality. A cropped screenshot may miss the username, timestamp, URL, wallet address, or the wording of a payment demand. Preserving fuller records can make later reporting clearer, even if those records do not prove who was behind the contact.
What to preserve before you block
The practical goal is simple: keep the details that show who contacted you, what they asked for, where they wanted money sent, and who they claimed to be. Capture what is visible without continuing the conversation longer than necessary.
Contact detailsSave the exact display name, username or handle, profile link if visible, phone number, email address, website or domain, and the platform where the contact appeared. It also helps to note how the approach started, such as a direct message, email, comment reply, or referral.
Message historyPreserve the conversation as completely as the platform allows. Full screenshots with visible timestamps are usually more useful than isolated images. For email, keep the original email in your inbox if possible instead of relying only on a screenshot.
Wallet and payment detailsIf the person provided a wallet address, QR code, payment rail, or transaction instructions, save them exactly as shown. If you already sent funds, keep the transaction hash, receiving address, and network details. Those records can document the transaction, but on their own they do not identify the real-world controller of the address.
Claimed identity detailsSave any claimed company name, role, case number, support address, office address, registration claim, or document image the person used. Treat these as claims to verify later through independently found channels, not as proof that the contact is genuine.
Evidence checklist at a glance
| What to save | Why it matters | Best version to keep | Important limit |
|---|---|---|---|
| Profile name, handle, or link | Identifies the account used to contact you | Full profile capture plus exact text or URL | Profiles can change, disappear, or be copied |
| Full chat or email | Preserves context, timing, and wording | Full screenshots or original messages | Partial captures can remove key context |
| Wallet address or QR code | Documents where payment was requested or sent | Address, network, QR code, and transaction hash | Does not by itself prove real-world identity |
| Payment demand | Shows amount, reason given, and urgency | Screenshot with full wording and timing | A single image may miss earlier pressure or follow-up claims |
| Claimed company or case identity | Helps later verification | Name, title, case number, website, document image | Official-looking documents can be faked |
| Website or domain | Useful for later checking and reporting | Full URL and page capture | Scam pages may change or vanish |
Wallet requests that should raise concern
Broad cyber-safety guidance supports caution around sensitive access, credentials, and device control. For this topic, that means treating requests involving wallet secrets, unfamiliar links, or device access as a serious warning sign.
Save these requests before you disengage- Any request for your seed phrase or private key
- Any request to install software, an extension, or a mobile profile
- Any request for remote access to your phone or computer
- Any request to connect your wallet to a link they sent
- Any request to sign a message or approval you do not understand
These requests can move the situation from impersonation into direct account or wallet compromise. If that pressure is happening in real time, do not stay in the conversation just to gather more evidence. Preserve what you already have and cut contact.
Payment demands to document
If the contact asks for money, preserve the exact wording of the demand, the amount, the reason given, any deadline, and the requested payment method. This article does not assume every scam uses the same script, so the safest approach is to document the demand exactly as presented.
What to capture in each demand- Amount requested
- Currency, token, or payment method requested
- Wallet address or destination details
- Deadline or urgency language
- Claimed reason for the payment
- Any promise tied to payment, such as release of funds or case progress
Identity claims to verify independently
If the person says they represent a company, investigator, legal service, or public authority, preserve the claim and verify it separately. The safest path is to locate the official website or public contact page yourself rather than using links or numbers sent by the person who approached you.
Identity details worth savingSave the claimed employer name, title, support contact, office location, case reference, registration claim, and any badge or certificate image shown in the conversation.
Practical steps: preserve, disengage, report
- Save the exact contact details used to reach you.
- Preserve the full message history or email where possible.
- Record any wallet addresses, QR codes, transaction hashes, and network details.
- Save each payment demand with the amount, timing, and explanation given.
- Save all claimed identity details and document images.
- Stop sending money and stop following links or wallet instructions from the contact.
- Verify any claimed organization through an independently found official channel.
- Block and report once you have preserved what you reasonably can.
What readers should watch next
- A follow-up from a different account using the same story
- New pressure to pay a final or urgent fee
- Requests to move to another app or platform
- Escalation to remote-access or wallet-connection requests
Sections to update
Keep the opening practical and move the evidence checklist near the top. The article should stay focused on what to preserve, what not to share, and how to verify identity claims through independent channels.
Claims that still need stronger sourcingThe current source pack does not strongly support detailed claims about:
- regulator-specific recovery-scam scripts
- exchange or wallet support practices
- platform-specific message export or evidence-retention features
- jurisdiction-specific reporting outcomes
Sources
Update log
- 22 Jul 2026Published with source tracking and reader-safety context.
- CorrectionsIf a source changes or a claim needs clarification, this page can be updated from the editorial desk.