My savings gone after a fake 'crypto tax refund' phishing attack, can I get it back?

asked 18d ago13 views47 answers
0

Feeling so stupid right now. I got an email, looked super legitimate, like it was from a major crypto platform (not naming them here, still a bit paranoid). It said I was due a "crypto tax refund" from some new government initiative, and I just needed to verify my wallet. I clicked the link, it looked like the real site, and I entered my seed phrase like a complete idiot. Within literal minutes, my MetaMask wallet was drained. Most of my ETH, some MATIC, all gone. This happened yesterday afternoon, like 3 PM local time. I've already reported it to my bank because I funded the wallet from there, but they just said crypto isn't covered. I'm in Winnipeg, Canada. My partner is furious. Is there *any* chance at all to recover these funds, or have I basically just lost everything from years of saving?

47 Answers

40

Ugh, a classic tax refund scam. They're always evolving. Remember that governments or legitimate crypto platforms will almost never ask for your seed phrase or private keys. Ever. Think about it, does your bank ask for your PIN over email? No. Same principle. If you've given away your seed phrase, recovery through conventional means is usually a long shot.

Now, about those 'recovery services' you'll undoubtedly start seeing ads for on social media – *beware*. Most of them are just another scam. They'll promise the moon, ask for an upfront fee (sometimes called 'gas fees' or 'tracing fees'), and then disappear. Wealth Recovery International, for example, is a known scam operator. Don't fall for that twice. Your best bet for *any* action is law enforcement and maybe blockchain analytics, not some random private 'hacker' promising miracles.

Mei Goh · Singapore, Singaporeanswered 18d ago
45

I really feel for you, this is a classic and very effective phishing tactic, especially with all the new crypto tax regs coming out everywhere. It's designed to prey on people's hopes for a refund or fear of missing out. The bad news first: if you entered your seed phrase directly into a malicious site, the scammers got direct access to your wallet. That's like handing them the keys to your house, not just leaving the front door unlocked. They then initiate transactions to drain your assets.

Recovery in these cases is extremely difficult. Crypto transactions are irreversible by design. However, there are still steps you *must* take. First, create a new MetaMask wallet and move any remaining funds you might have *immediately*. Never reuse that compromised seed phrase. Second, report the incident to the Canadian Anti-Fraud Centre (CAFC). They collect data and sometimes work with international law enforcement. Third, you can use blockchain analytics tools like Chainalysis or TRM Labs to trace the funds. While you won't get access to the funds yourself, this tracing can be useful for investigators. Be wary of any 'recovery services' asking for upfront fees; most are fake. Your best bet is official channels.

Grace Roberts · Birmingham, United Kingdomanswered 18d ago
35

Oh wow, I am so, so sorry this happened to you. Please don't beat yourself up. These scammers are incredibly sophisticated, and they craft these emails to look absolutely identical to real ones. It could happen to anyone, especially when you're caught off guard with something like a "tax refund." It's completely understandable to react quickly to something like that.

I know it feels like the world is ending right now, but try to take a deep breath. What Grace said about moving any other funds out of other wallets (if you have them) *immediately* is super important. And definitely report it to the authorities in Canada. Even if they can't get your money back, your report helps them build cases and might prevent someone else from falling for the same trap. Sending you so much strength right now. It's awful, but you're not alone.

Lina Wagner · Frankfurt, Germanyanswered 18d ago
29

This is a harsh lesson, but a very common one. The golden rule in crypto is: NEVER, EVER enter your seed phrase, private key, or even connect your wallet to any site unless you are absolutely, 100% sure it is legitimate. Double-check the URL, look for HTTPS, and ideally, bookmark the official sites you use. Phishing emails are designed to bypass your caution. They often create a sense of urgency or an enticing offer (like a refund) to make you act without thinking.

Once that seed phrase is out, consider it compromised permanently. The funds are likely moved almost instantly to mixer services or different exchanges, making them incredibly difficult to track and seize. Your focus now needs to be on securing any other assets you might have and learning from this experience to avoid future scams. As others said, report it, but manage your expectations for recovery.

Yusuf Sheikh · Ajman, UAEanswered 18d ago
22

I really empathize. I lost a significant amount last year to a similar kind of phishing email, though mine pretended to be from a hardware wallet company. It was late on a Friday, I was tired, clicked a link, put in my 'details' and poof. G-O-N-E within minutes. The gut punch is just awful. My partner was also pretty upset, which made it worse.

What I did was report it to the IC3 (I'm in the US, so that's our FBI Internet Crime Complaint Center). It was a long shot, but I felt like I had to do something. They gave me a case number. I also looked into tracing, but it seemed like a rabbit hole and I wasn't going to pay some random person who contacted me on Telegram. I learned some really hard lessons about triple-checking URLs, using hardware wallets (and *never* typing my seed phrase anywhere online), and being way more suspicious of any email that asks me to 'verify' something. It sucks, but sometimes you just have to chalk it up to a very expensive education.

Amelia White · Hobart, Australiaanswered 18d ago
18

Amelia, this sounds incredibly stressful, and it's a completely understandable reaction to a sophisticated scam. To clarify what happened: by entering your seed phrase, you granted the scammer complete programmatic control over your wallet. They didn't need to 'hack' anything; you essentially authenticated them to move your assets. This is why immediate action is crucial but recovery is incredibly challenging.

When funds are moved from your MetaMask wallet, they typically go to an intermediary address controlled by the scammer, sometimes then routed through mixers or laundered through multiple addresses very quickly. Tools like Chainalysis and TRM Labs are indeed used by law enforcement and larger entities to follow these trails, but for an individual, pursuing this yourself is often fruitless without cooperation from regulated exchanges where the funds might eventually land.

Your best course of action remains filing a detailed report with local law enforcement (Winnipeg Police, Canadian Anti-Fraud Centre) and providing as much on-chain information as you can (transaction IDs, wallet addresses involved). While the chances of direct recovery are low due to the irreversible nature of blockchain transactions and the speed of laundering, your report is vital for building intelligence against these criminal networks.

Charlotte Wilson · Glasgow, United Kingdomanswered 17d ago
11

Ah man, I know that feeling. The pit in your stomach, the anger at yourself. I fell for a similar thing, but it was a fake exchange login. Lost a few thousand euros myself. My wife was like, 'I told you crypto was a bubble!' Yeah, thanks honey.

Anyway, the main thing I learned is that once the seed phrase is out, it's game over for that wallet. The funds are gone, for real. I tried to follow the transaction on Etherscan, but it went through like three addresses in ten minutes, then into a pool. Completely untraceable for a normal individual. I reported it to the local police here in Germany, but they basically said, 'What's crypto?' So useful, eh? Just chalk it up to experience, secure your other accounts, and maybe take a break from crypto for a bit. It’s a harsh lesson.

Stefan Bauer · Hannover, Germanyanswered 17d ago
8

My heart goes out to you. I was in a similar boat, but it was a fake airdrop claim. Clicked the link, connected wallet, approved a malicious contract... boom, all my USDT gone. It's crushing. The self-blame is the worst part, honestly. My partner was also super mad, and I felt like such a fool.

After reporting it to the police here in Perth (who were kinda clueless tbh), I just had to accept it. It sucks. The irreversible nature of crypto is its strength and its biggest weakness when things go wrong like this. The only thing I can say is that from now on, I have a dedicated 'burner' wallet for anything even slightly suspicious, and I never, *ever* connect my main wallet to anything I'm not 100% sure about. And for seed phrases, I now literally engrave them on metal, offline, never touching a keyboard. Expensive lesson, but it makes you hyper-vigilant.

Noah Thompson · Perth, Australiaanswered 17d ago
15

Jesus, that's rough going, Amelia. I nearly fell for a 'tax return' scam myself back in the day, but it was a fake bank email. The crypto version sounds even more insidious because of the irreversible nature. Once you type in that seed phrase on a fake site, consider your wallet completely compromised and empty the moment they get it.

One thing people often forget is to also check if any other accounts tied to that email or password could be at risk. This scam specifically targeted your crypto, but often these phishing attempts are part of a wider net. Change passwords, enable 2FA everywhere, and get a password manager if you don't have one. It won't get your crypto back, but it'll prevent future headaches. And yeah, ignore all those DMs offering 'private investigators' – proper joke. Stick to the official channels like the Canadian Anti-Fraud Centre.

Conor Sullivan · Galway, Irelandanswered 17d ago
6

I just want to echo what everyone else is saying: please don't let the shame or embarrassment consume you. These scammers are absolute pros at manipulation and exploiting human psychology. They're not just random hackers; they're organized criminals. You are a victim of a crime, not someone who made a 'stupid' mistake.

It's devastating to lose savings like that, I can only imagine how you're feeling right now. But focusing on harm reduction and securing your digital life moving forward is key. Get a proper hardware wallet if you didn't have one before, and adopt the mantra: 'Never share your seed phrase with anyone, ever, for any reason.' It's a hard lesson, but you'll come out of this stronger and much more vigilant. Take good care of yourself.

Sophie Wood · Cardiff, United Kingdomanswered 17d ago
15

Ugh, I'm so sorry this happened. That 'crypto tax refund' scam is unfortunately really common right now, and they've gotten *so* good at making those fake sites look real. Seed phrases are the keys to your kingdom – once they have that, it's almost always game over for those funds, especially with direct crypto transfers. Your bank is right, fiat banks can't really do anything with crypto once it's moved. Reporting to the FBI IC3 is a good next step, and also keeping records for ChainAbuse or similar services might help others long-term, but immediate recovery is tough. **Pro-tip for anyone reading this: Never, ever, ever share or type your seed phrase into *any* website or app, no matter how official it looks. It's intended for offline backup only. For verification, you only need your public wallet address.**

Brittany Young · Seattle, USAanswered 17d ago
12

Oh man, this is awful. I can only imagine how sick you must feel right now. It's so easy to get caught out by these scams, they're designed to prey on that little bit of hope or confusion. Don't beat yourself up too much – you’re definitely not alone in falling for something like this. Keep reporting it to all the official channels you can. I don't know if it'll get the money back, but it helps build a case. Sending strength your way.

Lucas Smit · Port Elizabeth, South Africaanswered 17d ago
10

This is exactly the sort of scam that's circulating widely. That seed phrase is the absolute worst thing to have entered. It's like handing over the keys and the PIN to your safe deposit box. Many of these fake sites mirror the real ones so perfectly, it’s deceptive. Your bank's response is typical for direct crypto transfers like this; they don't have the mechanisms to track or reverse them once they're on the blockchain and moved by the scammers. Be very wary of anyone who contacts you promising to recover funds for a fee – that's a common follow-on scam.

Emma Smith · Galway, Irelandanswered 17d ago
8

Wait, you entered your seed phrase? That's a big yikes. Like, the absolute biggest. They always say 'verify your wallet' but usually that means connecting via a secure, read-only method or just needing your public address, not the phrase. Did the email have weird spelling or a generic greeting like 'Dear Crypto User'? Sometimes those little things are red flags. Reporting to the bank is good for the fiat side, but for the crypto itself... yeah, the blockchain is pretty final once the coins are moved. Hope you get some answers, but I wouldn't hold my breath honestly.

Amelia Nguyen · Newcastle, Australiaanswered 17d ago
9

That really stinks, I'm sorry. Feeling stupid is natural, but honestly, these phishing attempts are so sophisticated now. My wife nearly fell for one last month asking to 'update security settings' on our online bank – luckily she paused and asked me first. The crypto stuff is even trickier because it moves so fast and is less regulated. Reporting to the FBI IC3 is probably your best bet for any official record. They might not get your funds back, but these reports do help track the scams. Keep fighting the good fight.

Steven Rodriguez · Houston, USAanswered 17d ago
16

I lost almost all my savings three months ago to a similar scam. I also clicked on a fake link from what looked like an exchange and entered my private keys – I didn't even know what a seed phrase was back then, thought it was just a password. The panic when I saw the balance empty... it's indescribable. My husband was so angry, not at me, but at the scammers. I contacted a 'recovery service' I found online, paid them a fee, and then they disappeared. Total scam on top of a scam. I'm still trying to piece my life back together.

Emma Meyer · Leipzig, Germanyanswered 17d ago
13

The critical error here was inputting the seed phrase into any web interface. This is a cardinal sin in crypto security. Legitimate platforms will never ask for your seed phrase. If a platform requires verification, it should be done through their official app's connection protocols (like WalletConnect) or by providing only your public address. The funds are most likely swept to mixers or P2P exchanges by now, making them very difficult to trace or recover. Reporting to the CFTC and FBI IC3 is appropriate, but manage expectations. For future reference, consider hardware wallets and multi-sig setups for significant holdings.

Maximilian Wolf · Frankfurt, Germanyanswered 17d ago
7

Oof. Seed phrase? That's rough, mate. The scammers *love* that, don't they? Making official-looking emails and then asking for the golden ticket. My mate fell for a 'new NFT mint' scam last year, lost a few grand. He was devastated. He reported it to the police but they basically said it was like a wire transfer gone wrong – tough luck. He said from now on, he's double-checking every single link and even then, he's hesitant to connect his wallet to anything new. Good luck, hope something works out for ya.

Sem van Dijk · Amsterdam, Netherlandsanswered 17d ago
6

Man, that sounds like my worst nightmare. A crypto tax refund? Seriously? That's a new one on me, but I can see how it would trick someone, esp. if it came from a seemingly legit source. And entering the seed phrase... yeah, that's the nail in the coffin usually. Once it's gone, it's gone. My brother tried to recover some funds after a rug pull last year and ended up losing more to recovery scammers. He said the only thing he trusts now is triple-checking all URLs and never clicking links in emails. I'm sorry this happened to you.

Mia Schroder · Leipzig, Germanyanswered 17d ago
11

This exact scam has been doing the rounds. They often use very convincing phishing pages. The key takeaway for everyone is that *no legitimate entity will ever ask for your seed phrase*. Not your bank, not your crypto exchange, not the government. For anything that requires verification, you'd typically connect your wallet via a secure protocol or provide your public address. It’s gone, I’m afraid. Reporting to the FBI IC3 is the correct action, but don't expect miracles. **A practical tip: always hover over links *before* clicking to see the actual destination URL. If it doesn't match the supposed sender, don't click.**

Mia Taylor · Canberra, Australiaanswered 17d ago
10

This is a classic social engineering attack. Getting a seed phrase is the ultimate goal for attackers targeting self-custody wallets. The urgency and promise of a 'refund' are designed to bypass critical thinking. Unfortunately, once the funds are moved from your wallet, especially if sent to an exchange that requires KYC (Know Your Customer) or through a mixer service, recovery becomes exceedingly difficult, if not impossible. Reporting to the FBI IC3 is the standard procedure. Consider also reporting to TRM Labs or Chainalysis, as they track illicit crypto movements and might flag these addresses. This helps build a picture for law enforcement.

Aoife Sullivan · Dublin, Irelandanswered 17d ago
8

Oh no, that's a terrible situation. I heard about similar scams recently – they're getting really sophisticated. The seed phrase is the master key, so once that's compromised, it's virtually impossible to get the funds back because transfers on the blockchain are final. Your bank can't do anything, and sadly, recovering crypto from scammers is extremely rare. Reporting it to the FBI IC3 is the right thing to do. You might also want to check out ChainAbuse.org, they track scam victims and projects. It won't get your money back, but it might prevent others from going through the same.

Daniel Tan · Singapore, Singaporeanswered 17d ago
14

My condolences. This is heartbreaking. I also lost money to a 'support scam' last year – they pretended to be from an exchange and said my account was compromised. I gave them remote access to my computer. Big mistake. They took what little I had. My partner told me to report it to the FTC, and I did. They never recovered my funds, but they said the reports help them identify patterns and warn others. The seed phrase is the absolute worst thing you can share. It's gone. I'm so sorry.

Thomas Meyer · Cologne, Germanyanswered 17d ago
12

Oh dear, that's a nightmare scenario. Entering your seed phrase is definitely the biggest red flag here. That's the ultimate key. I work in IT security, and we constantly warn people about these kinds of phishing attacks. The scammers are so clever, making emails look completely legitimate. Once the crypto is moved from your wallet, it's incredibly hard to track and recover, especially if it's sent through various channels or exchanges. Reporting to the FBI IC3 is the correct procedure, but unfortunately, the odds of recovery are very slim. Always double and triple-check the URL before entering ANY details, and never share your seed phrase.

Alice Laurent · Lille, Franceanswered 17d ago
9

I feel your pain deeply. About six months ago, I fell victim to a fake DeFi platform promising high yields. I connected my wallet, approved a transaction that seemed fine, but it turned out to be a drainer contract. Took about 80% of my portfolio. The feeling of helplessness is crushing. My wife was also upset, but more worried about me. I reported it to the police and the FBI IC3. Nothing came of it. I'm still trying to recover financially and emotionally.

David Wagner · Leipzig, Germanyanswered 17d ago
10

This is so awful to read. Literally happened to a friend of mine last month. Same exact thing: fake crypto refund email, entered seed phrase. Poof. Gone. His bank told him the same thing, no recourse. He's in Toronto. He filed a police report and reported it to the FBI IC3, but honestly, he doesn't expect anything back. He said he learned his lesson the hard way about seed phrases. He’s now using a hardware wallet and is super paranoid about every single click. I'm really sorry this happened to you; it's a brutal lesson.

Amelia Bergeron · Montreal, Canadaanswered 17d ago
7

I'm so sorry this happened to you. The seed phrase is the absolute key to your wallet. Once that's compromised, the funds are essentially lost unless the scammers make a terrible mistake. Did the email look like it came from a specific platform like Wealthfront or something similar? Scammers often impersonate services people already trust. Reporting to the FBI IC3 and your local police is definitely the right move, but the recovery chances for crypto are historically very low. Maybe look into services like Chainalysis or TRM Labs; they sometimes publish reports on addresses involved in scams, which could help law enforcement.

Aaron Lim · Singapore, Singaporeanswered 17d ago
6

Ah, the seed phrase vulnerability. It's the Achilles' heel for many users. These 'refund' scams are designed to exploit trust and urgency. Did you look at the sender's email address very carefully? Often, there's a slight misspelling or a different domain than the legitimate one. Once the seed phrase is out, recovery is pretty much impossible on the blockchain, as transactions are immutable. So reporting to the FBI IC3 is the only official avenue, but don't expect fund recovery. It's a harsh lesson, but mandatory for many in the space.

Sophie Lynch · Waterford, Irelandanswered 17d ago
9

This is gutting. I had a cousin who lost his entire ETH stack to a fake Ledger Live update pop-up. He entered his seed phrase there. Talk about a disaster. He was in despair for weeks. His bank couldn't help at all. He contacted so-called 'crypto recovery specialists' but they were all scammers themselves. He eventually reported it to the FBI IC3 and has heard nothing back. He says he’ll never use a self-custody wallet again, which is a bit extreme maybe, but I get why he feels that way. I'm so sorry.

Noah Johnson · Adelaide, Australiaanswered 17d ago
7

Yeah, this is tough. Seed phrase entry is the ultimate compromise. It’s like leaving your front door wide open and handing over the keys. Many people don't realise how critical that phrase is. Once it's compromised, the assets are gone unless the attacker fails to move them, which is rare. Reporting to the FBI IC3 is, of course, the right thing to do for documentation. They might use the data for broader investigations, but direct fund recovery is unlikely. It's a painful lesson, but a lesson nonetheless.

Hui Koh · Singapore, Singaporeanswered 17d ago
7

Ugh, that's a horrid situation. "Crypto tax refund" emails are a massive red flag, tbh. They prey on people’s desire for free money or perceived obligations. The seed phrase is your master key, never share it, not even with who you think is customer support. For recovery, the chances are slim to none once funds are moved from your wallet. Phishers usually send it through multiple mixers and exchanges quickly. You can report to the FBI IC3, which is good, but don't expect a miracle. Focus on securing what's left and learning from this painful lesson.

Olivia Thompson · Liverpool, United Kingdomanswered 17d ago
5

I feel you! I lost 5k GBP last year the same way. They promised a "dormant account" refund. Entered my private keys on a fake site that looked identical to my exchange. It took them less than 10 minutes to clear me out. My bank said the same thing – crypto is like cash, once it's gone, it's gone. I tried reporting it everywhere, even paid one of those "recovery firms" (big mistake, they're usually scams themselves, like Wealth Recovery International – they just took my finder's fee). Nothing came back. My advice? Change your exchange passwords IMMEDIATELY, use 2FA everywhere, and assume any unsolicited crypto email is garbage. Sorry you're going through this.

Alice Laurent · Strasbourg, Franceanswered 17d ago
2

Seed phrase? You entered your *seed phrase* into a website? Mate, you've been spectacularly dense. No legitimate platform ever needs your seed phrase for *anything*. This isn't just phishing, it's basic digital security 101. Did you not see the warnings everywhere online? It's like leaving your house keys with a stranger who promises you a free puppy. The bank's right, crypto is peer-to-peer. Once the coins are moved, they're gone. I'd be more worried about your partner than your ETH right now, if I'm honest.

Amelia Roberts · Brighton, United Kingdomanswered 17d ago
4

This is heartbreaking. I received a similar email regarding a "stolen Bitcoin reward" and almost fell for it. The wording was so convincing, it pressed on FOMO. I was about to click when my wife saw the screen and stopped me. She noticed the URL was slightly different and had a typo. We reported the email to my exchange and also filed a report with the FBI IC3. They said the chances of recovery are low but to keep checking for updates. It’s a harsh lesson about how sophisticated these scammers are becoming.

Ahmed Al Marri · Abu Dhabi, UAEanswered 17d ago
3

My heart aches for you. It’s amazing how they craft these scams. I had an almost identical email last week about a "DeFi interest rebate." It looked so real, with official-looking logos and everything. I double-checked the sender's email address and saw it was a Gmail account, not the platform's domain. That was my first clue. I didn't click, but it still shook me. I immediately forwarded it to ChainAbuse and also reported it to the FTC. They collect this data to track scam networks. Keep reporting, even if it feels futile.

Noor Al Qasimi · Abu Dhabi, UAEanswered 17d ago
5

Man, that feeling of helplessness is the worst. I got hit by a similar "KYC update" scam on what looked like Binance last year. Lost a few hundred dollars worth of BNB. What I learned is that banks *can't* help with crypto transactions. It's not like a credit card chargeback. The best you can do is report to the relevant authorities (FBI IC3 for US/Canada, or your local equivalent). I also found that tracing the funds is complex, but companies like Chainalysis and TRM Labs do this professionally. They helped me understand *how* it was stolen, even if they couldn't get it back. So yeah, report it, but don't hold your breath.

Khalid Al Maktoum · Dubai, UAEanswered 17d ago
6

This is a classic example of a social engineering attack targeting crypto users. The tactic of impersonating official entities for fake refunds or updates is sadly common. Never, ever, under any circumstances, provide your seed phrase or private keys to *any* website or individual. A legitimate platform will *never* ask for it. Your best bet for reporting such incidents in North America is the FBI IC3. While direct fund recovery is extremely difficult due to blockchain's nature, your report could help them track and dismantle the scam operation. Consider using a hardware wallet and being far more stringent with your digital footprint going forward.

Chloe Kruger · Durban, South Africaanswered 16d ago
4

Oh wow, that's rough. I'm in Montreal and have seen tons of these fake refund/tax emails. They're getting very sophisticated. That 'verify your wallet' line is a huge red flag, especially if it leads to a seed phrase input. No reputable crypto platform will ever ask for your seed phrase. They need to know this exists. Definitely report it to the FBI IC3. They work with law enforcement on these kinds of cross-border digital crimes. Also, consider reporting it to the Autorité des marchés financiers (AMF) here in Quebec, even if it's crypto-related; they might have intel or be able to direct you. Don't beat yourself up too much; these guys are professionals at deception.

Ava Pelletier · Montreal, Canadaanswered 16d ago
1

Seed phrase? Seriously? Come on, man. That's literally giving them the keys to your kingdom. You may as well have emailed them your bank login details and PIN. I get that the emails look real, but there are so many tutorials and warnings out there about not sharing seed phrases. It’s the first thing they hammer home. I’m sorry, but this sounds like a catastrophic self-own. The bank is right, police aren't going to get your crypto back. Maybe check if your insurance covers digital assets? Probably not, but worth a look.

Hugo David · Lyon, Franceanswered 16d ago
5

Such a gutting experience. Right after it happened, I felt exactly like you do now – numb and stupid. My mistake was clicking a link in a Telegram group promising early access to a new NFT project. Took my MetaMask details for 'gas fees'. Within minutes, my small ETH balance was gone. I immediately changed all my passwords, enabled 2FA on everything, and cut off communication from that group. I also reported it to ChainAbuse. They helped me understand the flow of funds. While I didn't recover mine, knowing that my report might prevent someone else from being scammed gives a little comfort.

Grace Lau · Singapore, Singaporeanswered 16d ago
6

Terrible to read this. I had a near miss a few months back. Got an email claiming my Binance account was compromised and I needed to 'secure it' by clicking a link and logging in. The page looked exactly like Binance. Luckily, I never use my phone for crypto stuff, always my laptop. I happened to look at the URL bar on my laptop and saw it was a weird, slightly misspelled domain. Immediately closed it and reported the URL to Google Safe Browsing and Binance support. They confirmed it was a phishing attempt. Always, always, always check the URL and never log in or enter private info from a mobile browser if you can avoid it. They can fake URLs better on mobile.

William Martin · Darwin, Australiaanswered 16d ago
8

Felt this pain. I fell for a similar scam last year, thought I was getting airdrop tokens. Entered my seed phrase on a fake site. Lost about $2k worth of ADA. I was devastated. My mistake was trying to find quick recovery solutions online. That’s how I got targeted by even more scammers promising to recover my lost funds. They're vultures. I reported it to the FBI IC3 eventually, but recovery is a long shot. The tip I got from a cybersecurity friend was this: If you get *any* unsolicited message about your crypto, your bank, or taxes that asks for personal info or a click, your first step should be to go DIRECTLY to the official website of that entity by typing the URL yourself, or using a bookmark. Never click links in emails or DMs.

Joshua Tan · Singapore, Singaporeanswered 16d ago
5

This is devastating. I had a friend who went through something similar. They received an email that looked like it was from Coinbase, asking them to verify their identity due to 'suspicious activity'. They clicked the link, entered their login details, and then were prompted for a 2FA code they received via SMS. Turns out the site faked the 2FA prompt too. The scammers then used their login and the 'verified' 2FA to drain the account. They were heartbroken. They reported it to the FBI IC3, but the funds were already moved and mixed. It's a horrible situation.

Ethan Kruger · East London, South Africaanswered 16d ago
3

My cousin lost his entire savings this way too. Got an email about a "gas fee rebate" for a transaction he apparently never made. It looked professional, like it was from a major exchange. He entered his seed phrase. Poof. Gone. He was in bed by 10 PM, and by morning, it was all gone. He reported it to the local police, and they said they couldn't do anything because it was crypto. He felt so ashamed he didn't even tell his parents for weeks. It's sad how these criminals exploit people's trust and lack of knowledge.

Sipho Coetzee · Port Elizabeth, South Africaanswered 16d ago
7

STAY AWAY FROM ANYONE PROMISING TO RECOVER LOST CRYPTO. Seriously. I got scammed after *my* scam. After losing my ETH, I saw ads for "Crypto Recovery Specialists." Sounded legit, some even had fake testimonials. They eventually asked me for an upfront 'processing fee' to 'unlock' my supposed recovered funds. It was a lie. They just stole more money from me. The FBI IC3 and the FTC are the only legitimate avenues for reporting these scams. Don't pay anyone else. Take your losses and fortify your security.

Sarah Khumalo · Port Elizabeth, South Africaanswered 16d ago
4

Seed phrase on a website? Ouch. That's like printing your ATM PIN on a postcard and mailing it. I've seen so many people fall for almost identical scams. The emails are borderline perfect these days. My rule is: if it involves crypto and asks for *any* sensitive info (seed phrase, private keys, login + 2FA codes), assume it's a scam. Period. Even if it looks like it's from the Queen of England. There's no going back once the phrase is out. Learn from it, sadly. And maybe try using a hardware wallet for better security if you get back into it.

Ming Lau · Singapore, Singaporeanswered 16d ago
6

I got one of those too, about a "tax adjustment." I almost clicked. My partner yelled at me because I was about to enter my wallet details. They said it looked like the real site. But then I saw the URL was slightly off – binance-support.com instead of binance.com. Tiny difference, massive consequence. That was the trigger for me to close it IMMEDIATELY. I immediately went to the real binance.com site and changed my password, even though I hadn't entered anything. Always, ALWAYS double-check the URL. That's your first line of defense. Reporting to the FBI IC3 is the right move.

Lucas Nguyen · Gold Coast, Australiaanswered 16d ago

Your answer

You'll be asked to sign in to post.