Module 8 · Practicing Safely / 8.4
Notice what the request is trying to make you do.
The costume changes. The dangerous action is often familiar.
Imagine asking a wallet question in a public forum. A private message arrives: “Support here. We can fix this before your funds are locked.”
The name looks official. The reply is quick. The link opens a page asking for your recovery phrase.
You do not have to identify the person behind the message to reject that request. The secret they want would let someone else control the wallet.
Start with the action, not the costume.
Impersonation borrows a trusted name, logo, voice or face. A copied account or convincing video does not authenticate an instruction. Fake support can offer a solution to a problem you just described publicly.
A wallet-validation scam asks you to “sync,” “unlock” or “verify” a wallet by revealing recovery material. Do not give a website or helper those secrets. Use only the documented recovery process for your verified wallet when you deliberately need to recover it.
Fake apps can copy a genuine product and collect secrets during setup. Malicious sites may instead ask for a transfer, a broad token allowance, or a signature whose meaning is hidden. A request without an immediate fee can still grant dangerous authority.
Reach genuine support independently through a verified route. An unsolicited message is a reason to verify, rather than proof by itself. No urgency or familiar name should replace checking the actual request.
“Support here. We can help.” The greeting alone does not tell you what you will be asked to authorize.
A growing balance can be a drawing.
A relationship investment scam may build trust over weeks or months before introducing a platform. Its screen shows profits; a small early withdrawal may even work. Later, a supposed tax or unlock fee appears when you try to leave.
The displayed balance is not independent proof that the assets exist. Sending more to release it can deepen the loss. A real-world friendship or a previously trusted account can also be exploited; verification still matters.
Giveaway scams ask for a payment before a larger payment comes back. Pump-and-dump schemes build demand through promotion while organizers plan to sell into it. A rug pull can remove liquidity or abuse a project’s control powers after attracting buyers.
Promises of guaranteed high returns, unexplained yield and rewards driven mainly by recruiting new participants deserve scrutiny. Ask who pays, what activity produces the payment, and what happens without new money. A research report can expose gaps; it cannot guarantee that you will catch every fraud.
Some scams change where the money goes.
Address poisoning puts a lookalike address into transaction history, hoping you will copy it later. Clipboard malware changes an address between copying and pasting. Checking only a few characters can miss the substitution.
Get the recipient’s full address through a verified route and compare it with the transaction you sign. Use the trusted device screen where available. Recheck the asset, network and memo too. Do not treat a tiny unexpected transfer or token as an invitation to visit a claim site.
The common pressure is to shorten the space between a request and your decision. A deadline, a promised reward, a threat, embarrassment or affection can all do that. Being targeted is not evidence that you are foolish. Slow the action and bring in an independent person when the request is hard to assess.
If something has already happened, stop the next loss.
Stop sending funds and stop following the suspicious instructions. Save transaction identifiers, addresses, messages and dates without exposing recovery secrets. Contact the affected service through an independently verified route and report to the relevant authorities where you live.
The next step depends on what was exposed. A stolen account password calls for securing the account and its recovery channels from a trusted device. An unwanted allowance may need revocation. A leaked recovery phrase requires a new secure wallet and a careful response; disconnecting a website cannot make the old keys private again.
Do not improvise a rescue transfer on a compromised device. Automated theft can make recovery more complicated. Seek help from the genuine provider’s documented process and suitable independent expertise without handing anyone your secrets.
Be wary of a second person promising guaranteed recovery for an upfront payment. Recovery scams target people who already lost money. Fast reporting can help, but recovery is not assured. The aim is to preserve evidence and avoid making the loss larger.
The idea to keep
Look for the requested transfer, secret, signature or permission. Then verify through a route the requester did not supply.
Calm helps you inspect the request. It does not replace technical checks, and a loss is never a reason to trust the next promise of certainty.