Crypto funds gone after 'customer service' remote access trick, is there any way to recover?

asked 19d ago12 views28 answers
0

Hey everyone, feeling pretty sick about this. I usually consider myself pretty savvy, but I messed up big time.

I got an email, looked super legitimate, purporting to be from Kraken support. Said there was an 'unusual login attempt' on my account and I needed to verify my identity urgently. I clicked the link, it took me to what looked exactly like the Kraken login page. Logged in, and then it asked me to download a 'security patch' that was actually a remote access tool. Before I knew it, someone was moving my BTC and ETH right before my eyes. They cleared out about AUD 15,000 worth of crypto. It happened so fast, like 10 minutes from clicking the link to everything being gone. I've reported it to Kraken, changed all my passwords, and contacted my bank. Is there literally *anything* else I can do? Or is it just gone for good? Really desperate for some advice here.

Mentioned in this discussion
Kraken· neutral
#remote-access-scam#phishing#crypto-recovery#kraken#scam-victimasked by Charlie Anderson · Hobart, Australia

28 Answers

47

Charlie, this is a textbook example of a social engineering attack combined with remote access Trojan (RAT). The initial phishing email created urgency, leading you to a spoofed login page, and then the 'security patch' was the RAT.

For recovery, unfortunately, the chances are extremely low. Once crypto leaves your control and is moved, especially after being processed through mixers or multiple addresses, it's virtually impossible for individuals or even law enforcement to claw back. However, reporting it is still crucial. The transaction hash for the stolen funds is your most important piece of evidence. You can use blockchain explorers like Etherscan (for ETH) or various BTC explorers to see where the funds went initially. Provide these to Kraken and the authorities. Sometimes, if the funds land on a KYC-enabled exchange, that exchange *might* be able to freeze them if law enforcement acts quickly, but this is rare and often too slow for the speed of crypto transfers. Beware of anyone claiming guaranteed recovery; they are exploiting your desperation. Consider ChainAbuse if you can trace the funds to a known scam address.

Charlotte Wilson · Gold Coast, Australiaanswered 19d ago
28

Man, I'm so sorry this happened to you. Remote access scams are particularly nasty because they bypass so many security layers by getting *you* to grant access. Unfortunately, with crypto, especially once it's off an exchange and into a scammer's wallet, recovery is incredibly difficult, if not impossible. The decentralized nature that makes crypto powerful also makes it hard to reverse transactions.

Your best bet is what you've already done: report to Kraken. They might be able to trace it *if* it went to another exchange wallet, but often these guys move it fast through mixers or multiple addresses. Also, make sure you report it to your local police and the FBI IC3, even if you're in Australia, as a general cybercrime report. Sometimes, if enough people report the same addresses, authorities can build a case, but it's a long shot for individual recovery. Watch out for 'recovery services' that promise to get it back for an upfront fee; they are almost always scams themselves.

Omar Khan · Al Ain, UAEanswered 19d ago
17

Oh god, Charlie, that's absolutely terrifying. My sister almost fell for something similar last year, except it was a bank one. They just sound so convincing, don't they? It's like your brain just switches off for a second because of the urgency.

I don't have much to add on the recovery front beyond what Omar said – it's usually really tough once it's gone from a crypto wallet. But please, please make sure you've scanned your computer for malware. These remote access tools can leave backdoors. Also, change passwords on *every single* online account you have, especially anything financial or email. Even if they didn't touch it this time, they might have installed keyloggers or something to get your other logins. And set up 2FA *everywhere* you possibly can. It's not foolproof, but it helps. Thinking of you, this sucks.

Fatima Al Qasimi · Ras Al Khaimah, UAEanswered 19d ago
35

This is exactly why you need to be so paranoid with crypto. NEVER click links in emails for exchanges or wallets. Always, and I mean ALWAYS, go directly to the official website by typing the URL yourself or using a trusted bookmark. If Kraken *really* needed you, they'd message you within your *logged-in* account or call you, not send an email asking you to download stuff. They want you to panic and not think clearly. It's a classic social engineering tactic. It's a hard lesson, mate, but let this be a warning to everyone else reading: verify everything, assume nothing is real until proven otherwise.

Thomas Bauer · Cologne, Germanyanswered 19d ago
22

Ugh, feel your pain, Charlie. I fell for a fake Coinbase link that drained some ETH a couple years ago. Not remote access, but still a phishing link that got me. I reported it to Coinbase and the FBI IC3, but honestly, nothing ever came of it. The funds were long gone by the time anyone looked into it. It's like throwing a message in a bottle into the ocean. Sometimes it gets found, but the chances are slim.

The hardest part is getting over the self-blame, you know? Like, how could *I* be so stupid? But these scammers are professional manipulators. They prey on fear and urgency. Don't beat yourself up too much, but definitely use it as a learning experience. Stings like hell now, but prevention is the only real cure in this space. Sorry to be a downer, but that's been my experience.

Daniel Martin · Phoenix, USAanswered 19d ago
14

Mate, I'm genuinely sorry to hear that. Happened to a friend of mine, different exchange, but same remote access trick. They promise to help you 'secure' your account but they're just getting control. He lost about 8k in BNB and SOL. Reported it to the local police here, and the exchange, but nothing. It's been like 6 months and he just had to write it off. It's soul-crushing. Just remember it's not your fault, these scumbags are good at what they do. I really hope you have better luck than my friend did.

Jonas Becker · Hannover, Germanyanswered 19d ago
19

Ugh, Charlie, this is a nightmare scenario. I nearly got caught by a similar scam a few months back, but it was for my bank account, not crypto. Luckily, I got suspicious before I downloaded anything.

Beyond reporting it to Kraken and authorities like IC3, one thing people sometimes forget is to check *all* their connected accounts. If they got remote access to your computer, they might have accessed other stored passwords, browser extensions, or even your email. Make sure your email is super secure with a unique password and 2FA, as it's often the 'master key' to everything else. You've done the right things so far by changing passwords and alerting your bank. Keep an eye on your credit reports too, just in case they snagged any personal info. It's a pain, but worth the paranoia right now.

Henry Wilson · Canberra, Australiaanswered 18d ago
41

Charlie, this is a very common and effective scam type. The remote access part is crucial here because it gives them direct control, making it hard to dispute the transactions as 'unauthorised' in the traditional sense, as *you* technically initiated the download/connection. From a blockchain forensics perspective, you can track the funds using tools like Chainalysis (or just Etherscan/Blockchair for public addresses) to see their path. If the funds move to a well-known exchange, law enforcement *can* issue subpoenas to try and identify the recipient and freeze funds, but this is a lengthy and uncertain process.

Most often, the funds are quickly moved through multiple wallets, sometimes via privacy-enhancing services (mixers/tumblers), making direct tracing to a specific person incredibly difficult. The harsh reality is that for most individual victims, recovery is rare. Your actions of reporting to Kraken and law enforcement are correct, but manage your expectations. And as others said, be wary of 'recovery specialists' asking for upfront fees; they're almost universally fraudulent.

Jack Quinn · Galway, Irelandanswered 18d ago
25

Bonjour Charlie, so sorry to hear this. It's a truly awful experience, and many of us have been there in some form or another. It's important to understand *why* crypto recovery is so hard compared to traditional banking. With a bank, there's a central authority (the bank itself) that can reverse transactions or freeze accounts. With decentralized crypto, once a transaction is confirmed on the blockchain, it's irreversible. There's no 'undo' button.

The only slight hope is if the scammer is sloppy and sends the funds directly to an account on a regulated exchange (like Coinbase or Kraken themselves) where they are KYC'd. In that very specific scenario, law enforcement with sufficient legal process could theoretically get those funds frozen. But scammers usually know this and move funds quickly through many layers. Your best recourse now is purely legal and investigative, hoping that enough cases against these specific scam addresses lead to a larger bust. Keep all your documentation, screenshots, transaction IDs, everything. This helps build the case, even if individual recovery is unlikely.

Louise Richard · Paris, Franceanswered 18d ago
10

Man, that totally sucks, Charlie. Seriously, don't beat yourself up too much. These guys are pros at making things look legit and exploiting fear. You did the right thing by reporting it to Kraken and changing your passwords. That's step one. Also, scan your computer for any lingering malware just to be safe.

Like everyone else is saying, getting crypto back once it's gone is a huge uphill battle. It's not impossible, but it's very, very hard. Just focus on securing everything else you have now. Turn on 2FA for literally everything financial. Maybe use a hardware wallet for any significant crypto holdings in the future, it adds an extra physical layer of security that remote access can't bypass. Keep your head up, mate. It's a tough lesson but you're not alone.

Christopher Hernandez · Seattle, USAanswered 18d ago
12

That email was a classic phishing attempt, unfortunately. The 'unusual login' notification is a very common tactic. They create a fake site that looks identical to the real Kraken login page, and once you enter your credentials, they're theirs. The remote access tool download is the part that really seals the deal for them, giving them direct control.

Sadly, once crypto is moved off-exchange and through multiple wallets, recovery is exceptionally difficult, almost impossible for the average user. The blockchain is designed for transparency, not anonymity, but tracing funds through mixers and peer-to-peer transactions is a monumental task.

Your best bet is to report this to the FBI's Internet Crime Complaint Center (IC3). While they don't recover funds directly, they can sometimes track patterns and potentially link these attacks to larger criminal organizations. Also, if you can identify any wallet addresses involved, you can input them into a blockchain explorer like Etherscan to see where the funds have moved. It won't recover them, but it might provide more data for law enforcement.

Isabella Bergeron · Quebec City, Canadaanswered 18d ago
9

Oh man, that’s brutal. I know that feeling, like your stomach just drops. I fell for something similar last year, not crypto though, but it was a fake Microsoft support email. They got me to download a remote access thing too. Lost a few hundred quid, thankfully not thousands.

What stung the most was how *real* it all looked. The emails, the website. Made me question everything. For a few weeks, I was just staring at my screen waiting for the next scam email to pop up, totally paranoid.

Best thing I did after changing passwords was to set up two-factor authentication (2FA) on EVERYTHING. Not just my crypto. My email, my bank, even my social media. Use an authenticator app if you can, not just SMS, because they can intercept those too. Stay strong, mate.

Yi Tay · Singapore, Singaporeanswered 18d ago
2

AUD 15,000? That's a lot of dough. And you let them access your computer? Seems a bit naive, if you ask me. I mean, c'mon. If Kraken contacts you, it's never by email asking for login details or remote access. They'd have a verified announcement on their platform.

Always go directly to the source. If you get an alert, don't click the link. Open your browser, type in the official website address yourself, and log in from there. It takes an extra 30 seconds but saves you thousands.

Reporting it is good, but don't expect much back. It's crypto, it's practically the Wild West. Buyer beware.

Andreas Fischer · Munich, Germanyanswered 18d ago
7

Oh no, that's absolutely awful. I'm so sorry you're going through this. It sounds like a terrible experience, and it’s completely understandable that you’re feeling sick.

Don't beat yourself up too much. These scams are designed to look incredibly convincing, and they prey on people's urgency. You did the right things by reporting it to Kraken and your bank, and changing passwords. That's crucial.

Sometimes, if the funds haven't been moved too far or mixed extensively, law enforcement *can* trace them. Filing a report with the FBI's IC3 is definitely the right step. They have specialized units for this sort of thing. Keep all the documentation you have – screenshots, email headers, transaction IDs. Every little bit helps.

Amanda Williams · Denver, USAanswered 18d ago
5

This just happened to my mate Dave last month. Same thing – fake Kraken email, 'urgent verification', remote access tool download. He lost about R200,000 ZAR. It was devastating.

He felt so stupid afterwards, like you probably do now. But honestly, these guys are good. They use psychological tricks to make you panic. Dave spent weeks just feeling sick and angry.

He reported it to the police here in South Africa, but they basically said crypto is too hard to trace. He also filed a report with the FBI IC3. It's a long shot, but it's something. He's also looking into ChainAbuse, which apparently helps victims track stolen crypto. Might be worth a look.

Connor Smit · Cape Town, South Africaanswered 18d ago
10

Ugh, that's the worst kind of scam. I had a similar situation a while back, not Kraken but a different exchange. Got an email saying my account was compromised.

Clicked the link, logged in, and then *bam*, it asked for verification which involved downloading some software. I got suspicious right at that moment, thankfully. I closed the browser immediately and didn't download anything.

I called the exchange's official support line immediately – *not* the number from the email, but one I found on their website. They confirmed it was a scam. They even thanked me for calling and not falling for it.

So, yeah, the key takeaway for me was: always verify communications by going directly to the official website or app, never through links in emails or unexpected messages. And if they ask you to download *anything* to 'fix' a security issue? Red flag. Huge red flag.

Maximilian Wagner · Berlin, Germanyanswered 18d ago
8

Man, I feel this. I got hit last year with a fake Coinbase support scam. They had me on a live chat, pretending to help me with a transaction issue. Took control of my screen and ended up draining my account. It was about $5k USD.

I was so mad at myself. I’m usually so careful. But they are so convincing, with fake support badges and everything. I reported it to Coinbase, and they basically said 'tough luck, not our fault if you give away access'.

I did file a report with the FBI IC3. Haven't heard anything back, but figured it was better than doing nothing. I also checked out Chainalysis, they have tools to track crypto, but you need to be a forensic expert to use them, or pay a lot. Anyway, hang in there. It sucks.

Logan Lavoie · Calgary, Canadaanswered 18d ago
3

Remote access tool? That’s a bold move. Normally these phishing scams are just about stealing your login details so they can log in themselves. Giving them direct control is next level.

Look, I'm not trying to pile on, but asking someone to download software to fix a security issue? That should have been an instant stop sign. Especially if it wasn't initiated by you through their official support portal. Reputable exchanges like Kraken won't ask you to download random .exe files, especially not for login verification.

Your bank might be able to do something if you funded the crypto purchase with fiat recently, but for the crypto itself? Once it's out, it's out. Especially if it went through any sort of mixer or privacy coin. Good luck with the reporting, but manage your expectations.

Paul Richter · Berlin, Germanyanswered 18d ago
6

Oh goodness, that sounds absolutely horrific. I can only imagine how you must be feeling right now – that sense of violation and loss must be immense.

What you experienced is a textbook example of a 'vishing' (voice phishing) or 'smishing' (SMS phishing) attack that escalated into remote access malware. The scammers are getting incredibly sophisticated.

It’s fantastic that you’ve already taken immediate action by contacting Kraken and your bank, and changing passwords. That's exactly what you should do. Reporting it to the FBI IC3 is also vital. Even if recovery isn't possible, these reports help law enforcement build cases against these criminal groups. Keep copies of all communications and transaction details.

Charlotte Nguyen · Sydney, Australiaanswered 18d ago
11

Aw mate, that’s rough. I’m sorry to hear it. The fake support scam is nasty. I had a very similar scare a few months back, but luckily I realised just in time.

I got an email supposedly from Binance about suspicious activity. I clicked the link, and it looked spot on. But when it asked me to download a 'security update' file, my gut just screamed NO.

I immediately went to the Binance website myself, logged in, and there was no message about suspicious activity. Then I checked my email provider's spam folder – turns out the original email had been flagged as phishing but my provider buried it.

Always, always, *always* check the email sender's address VERY carefully. Like, look at the domain name. Scammers use variations like kraken-support.com or kraken.security.net. The real one is just kraken.com. It’s a small thing, but it can save you a fortune.

Henry Evans · London, United Kingdomanswered 18d ago
4

This is exactly why I refuse to give *any* remote access to my computer, ever. Especially not to some random 'support' person who contacted me out of the blue. If I have a problem, I contact them. I don't wait for them to contact me.

I've heard stories like yours all too often. People lose their life savings. It's heartbreaking. My own dad almost fell for a similar scam last year, but he was just asking me about it before he clicked any links. I told him to hang up and call the company directly.

People need to understand that crypto exchanges will NEVER ask you to download software or grant remote access to 'verify' your account. That's a massive red flag. Report it, yes, but honestly, the chances of getting that AUD 15k back are slim to none, especially if it's already been moved around.

Lucas Jones · Perth, Australiaanswered 18d ago
9

Be very careful with any 'recovery services' that might contact you now. There are often scammers who target victims of previous scams, promising to recover lost funds for an upfront fee. They're basically the same people, or their associates.

If anyone reaches out claiming they can get your crypto back, especially if they ask for money first, it's almost certainly another scam. Stick to official channels like the FBI IC3 or maybe a reputable blockchain analytics firm if you have the funds to hire one (but that's usually for institutions).

Don't click on any more suspicious links, don't download anything else, and be extra skeptical of any unsolicited contact. That initial scam was bad enough; don't let them get you twice.

Jules Laurent · Bordeaux, Franceanswered 18d ago
7

Oh no, this is awful. I had something *very* similar happen. Not Kraken, but an exchange called ZG.com. I got an email saying my account needed urgent verification. Clicked the link, it looked legit, and then... it asked for remote access to 'fix' my IP address.

I was so naive. I let them in. Before I knew it, my account was empty. They took about $10k USD. It was a nightmare. I felt so stupid, so exposed.

I reported it to ZG.com, but they were useless. Basically said it was my fault. I filed with the FBI IC3 and also reported it to ChainAbuse. ChainAbuse helped me at least track the funds for a bit, but they ended up in some privacy wallet. It's been months, and no sign of it. But reporting it felt like *something*.

Marie Fischer · Cologne, Germanyanswered 18d ago
3

Remote access? Mate, that's basically inviting them in and handing them the keys. You gotta be kidding me. Did you not see the alarm bells?

I get phishing emails all the time. I just delete them. If I ever think something is legit, I go straight to the website myself, never through a link. And I certainly never download anything from a support email. That’s asking for trouble.

Crypto is risky enough without making it easy for thieves. Your bank might get your money back if it was a direct transfer from your bank account, but the crypto itself? Once it's on the blockchain and moved, you can kiss it goodbye. Filing with the IC3 is your best bet, but don't hold your breath.

Harry Brown · Bristol, United Kingdomanswered 18d ago
10

I'm so sorry this happened to you. That's a horrible feeling, like being robbed in your own home. I've been there, thankfully not with crypto, but a scammer posing as my bank's fraud department called me last year.

They said there was suspicious activity on my account and I needed to verify some transactions by telling them the codes sent to my phone. Yeah, I know. Stupid, right? They used those codes to transfer money out of my account.

What I learned is that real banks and reputable crypto exchanges will NEVER ask you for verification codes sent to your phone or email, nor will they ask you to download software or grant remote access. If you get any such request, it's a scam. Hang up, close the window, and call the company directly using a number you know is legitimate. It's a hard lesson, but a vital one.

Ashley Jones · Denver, USAanswered 18d ago
8

That's a nasty one. Phishing combined with social engineering and malware. They're hitting all the bases. The remote access tool is the critical part here; it bypasses the need to crack your keys or passwords directly after they steal them.

Your bank may offer some protection for the initial fiat deposit if you can prove it was a fraudulent transaction, but for the crypto itself? Once it leaves the exchange wallet, it's basically on the public ledger.

Your best recourse, as others have said, is reporting to the FBI IC3. Beyond that, you could explore using a blockchain analytics service, but that's usually quite expensive. Some victims have had success using platforms like ChainAbuse to report and potentially track stolen assets, though recovery is never guaranteed. Document everything meticulously.

Conor O'Brien · Cork, Irelandanswered 18d ago
7

Ugh, that email trick. I nearly fell for something similar last year with my energy provider. They said my account was overdue and I needed to click a link to update my payment details. It looked so real, the logo was perfect.

But I hesitated. I remembered my neighbour telling me about fake bills, so I ignored the email. Instead, I went to the energy company's website myself and logged in. Everything was fine there. The email was totally fake.

It's so easy to get caught out. The best defence is to be super skeptical of any unsolicited communication, especially if it creates urgency. And *never* click links or download files from emails. Always navigate to the official website yourself. It sounds basic, but it’s the most effective way to avoid these remote access scams.

Liam Byrne · Dublin, Irelandanswered 18d ago
1

Oh man, that's rough. Sounds like a classic 'support scam' combined with remote access malware. They impersonate a legitimate service (Kraken in your case) and then trick you into giving them the keys to your kingdom. The remote access tool is the most devastating part because it bypasses normal security measures.

Unfortunately, recovering crypto once it's moved off an exchange and into a scammer's wallet is incredibly difficult, bordering on impossible. These transactions are final on the blockchain. Think of it like sending cash – once it's in someone else's hand, it's gone.

Your best bet now, beyond what you've already done, is to report it to the FBI's Internet Crime Complaint Center (IC3). While they don't recover funds directly in most cases, they do collect data that can help track down these criminal networks. Sometimes, law enforcement can get warrants for exchanges if there's enough evidence and volume, but it's a long shot for individual cases like this. Keep copies of *everything* – the emails, screenshots of the fake site, your communications with Kraken, bank statements. Every detail helps.

Grace Ryan · Galway, Irelandanswered 18d ago

Your answer

You'll be asked to sign in to post.