How we checked this
We reviewed the linked sources and keep this page updated when the record changes. Use the source list below to verify the details.
Short answer
If a message says it is from an exchange’s compliance, risk, or security team but arrives through a personal messaging account, do not treat the message itself as proof. The safer approach is to open the exchange’s official website or app yourself and check whether the same issue appears there through a normal support, security, or account-notice path. Public cyber-safety guidance consistently recommends independent verification instead of using links, contact details, or instructions supplied inside an unexpected message.
Summary box
- Treat unsolicited compliance or security chats as unverified until you confirm them independently.
- Do not click links, scan QR codes, open attachments, or send funds from the conversation.
- Use the exchange website or app you opened yourself, not the route provided by the sender.
- Save evidence before you report, block, or delete the contact.
Why this kind of contact needs caution
Phishing and social-engineering messages commonly rely on urgency, authority, and account-problem claims. A message about “compliance,” “suspicious activity,” or “verification” can sound routine while still trying to push you into unsafe actions. That is why the channel matters: a direct message from a personal account is not self-authenticating, even if it uses formal language or exchange branding.
Date-checked noteDate checked: this article is based on the public cyber-safety sources listed below that were available at the time of drafting. It does not assume that all exchanges use the same support or compliance-contact process. If your exchange publishes its own contact or anti-phishing policy, check that policy directly before acting.
What to verify first
Do not try to confirm the sender by continuing in the same chat. Instead, type the known website address yourself or open the official app you normally use, then look for a support center, account alert, or message center. This follows standard anti-phishing guidance: navigate independently rather than through details supplied in the suspicious message.
Check for a matching notice on your accountIf the message claims there is a restriction, review, verification problem, or security issue, look for a matching sign inside the account environment you opened yourself. If you cannot find any corresponding alert, ticket, or notice, that does not prove the message is fake, but it is a reason to slow down and verify further through official support.
Judge the request, not the profile pictureA logo, job title, copied case number, or polished wording is not enough to establish identity. Public cyber guidance places more weight on independent confirmation than on appearance inside a message.
Stop if the sender wants something unsafeBe especially cautious if the sender asks you to:
- share passwords or one-time codes
- click a login link or open an attachment
- install software
- allow remote access
- send money, deposits, or release fees
- move assets to another wallet for “safekeeping”
Fast checklist before you reply
Use this practical list before you do anything:
- Pause the conversation.
- Do not click, scan, download, or sign anything from the chat.
- Open the exchange website or app yourself.
- Check for a matching notice, restriction, or ticket.
- Use only published support channels you found independently.
- Save screenshots, usernames, wallet addresses, and message text if the contact appears suspicious.
- Report and block the sender after you preserve the evidence you need.
Red flags and safer responses
| Message or situation | Why it needs caution | Safer next step |
|---|---|---|
| “Reply here now or your account will be frozen.” | Urgency is a common pressure tactic. | Open the official app or site yourself and look for a matching notice. |
| “Pay a fee or deposit to unlock withdrawals.” | Payment pressure tied to access is a major warning sign. | Stop and verify through official support you opened independently. |
| “Send us the code we just texted you.” | One-time codes can help someone access your account. | Do not share the code; use only verification flows you started yourself. |
| “Use this QR code or link to complete compliance checks.” | Unsolicited links and QR codes are common phishing tools. | Type the known web address yourself or use the official app. |
| “Move your assets to a safe wallet while we investigate.” | A transfer can be framed as protection when it is really theft. | Pause and verify through official support before moving anything. |
| “Do not contact regular support.” | Isolation is a classic social-engineering tactic. | Use normal published support channels anyway. |
Reader examples
Treat the message as unverified. Open the exchange independently and check for any real notice or ticket. If nothing matches, continue only through official support you found yourself, not through the chat.
Example: “A payment is required before withdrawals can be released.”Do not send money based only on a direct message. A demand for payment tied to account access is a serious warning sign and should be checked through official support opened separately.
Example: “Send the code we just texted you so we can confirm your identity.”Do not share the code in chat. One-time codes are used in account access and verification flows, so giving them away can expose the account.
Myth vs reality
Reality: Branding and reference numbers can be copied. Independent confirmation is more reliable than appearance alone.
Myth: “If they know some details about me, they must be authorized.”Reality: Partial personal or account information is not enough to prove authority. Keep using a separate official route to verify the claim.
Myth: “If the issue is real, I have to solve it inside the same chat immediately.”Reality: Pressure to act quickly is common in phishing and impersonation attempts. Slow down and verify through a channel you opened yourself.
What to do next
- Stop replying.
- Do not click links, scan QR codes, or open attachments.
- Open the official app or website yourself.
- Check for matching notices or support messages.
- Report the contact through the platform’s published support route if available.
Use official account-safety routes you opened yourself. Depending on what happened, practical steps may include changing your password, reviewing security settings, checking recent activity, ending active sessions if the platform offers that option, and contacting official support. Preserve the conversation and related details as evidence, but avoid continued back-and-forth with the sender.
Common mistakes to avoid
- Trying to verify the sender inside the same conversation.
- Using phone numbers, websites, or forms supplied in the message.
- Sending a small “test” payment.
- Installing software or accepting remote-help requests.
- Assuming formal wording means the contact is genuine.
FAQ
Not on its own. A personal account or direct-message channel should be treated as unverified until you confirm the claim through an official route you opened yourself.
What if the message mentions compliance, AML, or suspicious activity?Those topics can arise in legitimate account reviews, but they can also be used to create pressure. The safer response is the same: verify the claim through the exchange’s official app, website, or published support path that you accessed independently.
Should I block the account immediately?First save evidence if you can do so safely. After that, reporting and blocking can help reduce further contact.
What should I never share in that chat?Do not share passwords, one-time codes, seed phrases, private keys, or remote-access access to your device.
Sources
Update log
- 26 Jul 2026Published with source tracking and reader-safety context.
- CorrectionsIf a source changes or a claim needs clarification, this page can be updated from the editorial desk.