Simple Base SwapSimple Base SwapOpen app
← All articles
Aug 20, 2026·5 min read

Fake support scams: why no one from a wallet team will ever DM you first

basesecurityself-custodyscams
base

Most people picture a hack as something technical: malware, a cracked password, a cloned website. In self-custody wallets, a large share of losses start much simpler. Someone sends a message. It looks helpful. It is not.

This is impersonation, sometimes called fake support or a social engineering scam. Instead of attacking your wallet, the scammer attacks your trust. Understanding how it works is one of the most useful things you can do to protect yourself, because no browser extension or audit can stop a conversation.

What the scam actually looks like

The setup varies, but the pattern repeats:

A reply that looks like an official account. You post a question in a project's Discord, X (Twitter) replies, or a Telegram group, something like "why is my transaction stuck" or "how do I bridge to Base." Within minutes, an account with a logo, a verified looking checkmark, or a name like "Support" or "Official Help" replies and offers to sort it out privately.

A direct message you never asked for. You get a DM claiming to be from a wallet provider, an exchange, or a project team, saying there is a problem with your account, a security issue, or a reward waiting for you. The message creates urgency: act now or lose access, claim now or miss the deadline.

A fake support channel. A scam account, or a compromised real one, posts a link to "official support" that leads to a website or a form asking you to "verify your wallet" by entering your recovery phrase or private key.

A screen share or remote access request. In more elaborate versions, the scammer asks you to install a remote desktop tool "so support can see the issue," then waits for you to open your wallet.

In every version, the goal is the same: get you to type your recovery phrase or private key somewhere, sign a transaction you do not understand, or move funds to an address they control.

Why it works

These scams do not rely on technical sophistication. They rely on three things that are true of almost everyone at some point:

You are confused. Something did not work the way you expected, so you are looking for an explanation, and a fast, confident answer feels like relief.

You are in a hurry. The message implies a deadline, a limited window, or a risk of loss, which pushes you to act before you think it through.

You assume official-looking means official. A logo, a checkmark, or a name that matches a real project is easy to copy. None of it proves who is actually on the other end.

The one rule that stops almost all of it

No legitimate wallet provider, exchange, or project team will ever ask for your recovery phrase or private key. Not to "verify" your wallet, not to "unlock" funds, not to "sync" your account, not for any reason. There is no support ticket, no verification step, and no recovery process that requires it. If a message asks for either one, it is a scam, full stop.

The same applies to being asked to sign a transaction you do not understand as part of a "fix." A support agent walking you through connecting your wallet to a site and signing something is walking you through draining it. See wallet signature requests explained for what a signing prompt should actually look like before you approve one.

A few practical habits

Do not DM first, and be suspicious of anyone who DMs you first. Real support teams for most projects respond in public channels or through a ticket system you initiate yourself, not by sliding into your inbox.

Go to support through a source you already trust, such as a bookmark you saved earlier or a link from the project's official site that you typed in yourself, not a link someone sent you in a reply or DM.

Treat urgency as a red flag, not a reason to hurry. Scammers create time pressure because it works. A genuine issue with your wallet is not going to get worse in the ten minutes it takes you to slow down and check.

Never install remote access software because someone in a chat asked you to. There is no support workflow that requires giving a stranger control of your screen.

If in doubt, close the conversation and verify independently. Search for the project's official channels yourself, or ask in a different, public place whether the account contacting you is legitimate. Scammers rely on you staying inside the conversation they started.

What to do if you already shared something

If you typed your recovery phrase or private key anywhere, assume that wallet is compromised, even if nothing has moved yet. Move any remaining funds to a new wallet with a freshly generated recovery phrase as soon as you can, using a device you trust. See keep your recovery phrase safe for how to generate and store a new one properly, and do not reuse the old phrase for anything going forward.

If you approved a transaction you do not recognize, check and revoke any lingering permissions using the approach in how to check and revoke token approvals, then move remaining assets to a clean wallet regardless.

The takeaway

Impersonation scams do not exploit a bug in Base or in your wallet software. They exploit the fact that a friendly, confident message is hard to distrust in the moment. The wallet itself has no way to warn you that the person typing to you is not who they claim to be. That judgment call is yours, and the simplest version of it holds up in almost every case: nobody legitimate will ever ask for your recovery phrase, and nobody legitimate needs to DM you first.

Ready to try it yourself?

Create a non-custodial wallet on Base in seconds. No account, no sign-up.

Open the web app