§ — Article

Coinbase Scam Calls, Emails and Texts: How Impersonation Works.

How a Coinbase scam call, email or text works, what Coinbase, Trust Wallet and Binance never ask for, and what to do in the first hours after a loss.

StarCompliance Desk
Editorial
Sep 28, 2026·11 min read
Share
Coinbase Scam Calls, Emails and Texts: How Impersonation Works
Article
№ 565

A Coinbase scam call, email or text usually does not mean that Coinbase itself was hacked. It is a script: someone posing as support tells you your account is at risk, gets a code, a password or a seed phrase out of you, and then persuades you to move your funds to a "safe" wallet that belongs to them. The same script runs under the names of Trust Wallet, Crypto.com, Binance, Bybit, MetaMask, Ledger and PayPal. This article explains how the script works, what the real companies say they never do, what to do in the first hours after a loss, and when stolen funds can realistically be frozen.

What does a Coinbase scam call, email or text actually look like?

The opening is an alert. A text says a withdrawal or a new login was detected and gives a number to call "if this wasn't you". An email copies Coinbase branding and links to a login page that is not Coinbase. Or the phone rings first, and the caller already knows your name, your email and roughly what you hold.

From there the Coinbase scam follows a fixed order:

  • The threat. Your account is "compromised", a "hacker is inside it", funds will be lost within the hour.
  • The verification. To "prove it is you", read out the code that just arrived by SMS, or log in through a link they send.
  • The fix. Move your balance to a "secure vault", a "safe wallet" or a new wallet whose seed phrase they dictate to you.
  • The tools. Install a screen-sharing or remote-access app "so an engineer can help".

Every step is designed either to make you authorise the transfer yourself or to give the attacker enough access to do it. That is why victims often later search "coinbase hacked": the account felt hacked, but the transaction was signed with their own credentials.

Was Coinbase hacked, or was my account taken over?

In most cases it is the account, not the exchange. An account takeover through impersonation leaves the exchange's systems untouched; the attacker simply holds your password, your 2-step code or your seed phrase for long enough to send the funds out.

There is one documented event that explains why the calls became so convincing. In its Form 8-K filed with the SEC in May 2025, Coinbase disclosed that a threat actor had paid contractors or employees in support roles outside the United States to collect customer data from internal systems. The data included names, addresses, phone numbers, emails, masked Social Security numbers, government ID images and account data such as balance snapshots and transaction history. The filing states that passwords and private keys were not compromised and that the personnel involved could not access customer funds. The company said it was reviewing its anti-fraud protections because the data could be used in social-engineering attempts.

This explains why such impersonation attempts can appear highly convincing. A caller who can quote your address and your last transactions sounds like support. They still need you to hand over the code or move the funds.

An exchange hack is a different event. When the FBI attributed the theft of about $1.5 billion from Bybit in February 2025 to North Korean actors, the assets were taken from the exchange itself. Searches for "bybit hacked" and "binance hacked" mix both kinds of event; the impersonation scam is the one that targets individual users.

What do Coinbase, Trust Wallet, Crypto.com, Binance and MetaMask say they never do?

The companies being impersonated publish their own rules, and those rules are the fastest way to recognise a Coinbase scam message or someone impersonating Trust Wallet support.

  • Coinbase. Its help page on support and impersonation scams says no one will ever ask for your password, 2FA codes, or for you to transfer assets to a specific or new address, account, vault or wallet. Customer service agents will never ask you to secure, move or access your funds, provide or request a seed phrase, ask you to install software, or remotely access your device. Coinbase says it will never call or text you to give you a new seed phrase or wallet address.
  • Trust Wallet. Its phishing guide states that Trust Wallet will never ask for your secret recovery phrase, and that anyone who asks for it, including someone claiming to be support, is running a scam.
  • Crypto.com. Its help centre says Crypto.com will never send you a link to install software on your device or remotely access your account or device.
  • Binance. It runs Binance Verify, where you can check whether a URL, email address, phone number or Telegram handle belongs to Binance before responding to someone claiming to represent Binance.
  • MetaMask. Its security tips say MetaMask will never ask you to provide your Secret Recovery Phrase.

One nuance matters for the "coinbase scam call" question. Coinbase notes that, in certain support scenarios, an agent may call back after a disconnected support call and re-verify you. So a call alone does not prove fraud. A request for a code, a seed phrase, remote access or a transfer does.

Why do the verification-code and "safe wallet" tactics work so well?

Because they borrow the language of security. A one-time code is meant to prove you are you, so reading it to a caller who "needs to verify you" feels like cooperation. In reality the code lets the caller prove they are you. The US Federal Trade Commission puts it bluntly in its alert "Never move your money to protect it": never share a verification code, and anyone who says you have to move your money to protect it is a scammer.

The "safe wallet" is the payoff. In a Coinbase code scam the attacker may never gain direct access to your account at all; you send the funds out yourself, to an address they control, because they told you the old one was compromised. The same happens with "coinbase wallet scam" and Trust Wallet scams, where the caller dictates a new seed phrase: they generated it, so they already own the wallet you are about to fill.

A fake support site closes the loop. The link in the email or text opens a copy of the real login page, captures what you type, and passes it to the attacker in real time.

How is this different from a fake exchange?

An exchange impersonation scam uses a real company's name to get into a real account or wallet you already own. The funds existed, were yours, and left through a transaction you or the attacker signed.

A fake exchange is a different fraud: the platform was never an exchange. You deposited into a website that showed a growing balance and then demanded a fee or a tax before any withdrawal. There was no account to take over, only deposits to addresses the operators controlled.

A third pattern overlaps with both: the wallet drainer, where a fake support site asks you to "connect" and "sign" to fix a problem, and the signature grants a contract permission to empty the wallet. For tracing purposes, all three end in the same question: where did the funds go after they left you?

What should you do in the first hours after losing funds?

Work in this order. The first two steps stop further losses; the last two build the record that every later action depends on.

  1. Stop. End contact with the caller. Do not install anything, do not send a "verification" amount, do not follow a second link. If the story changes to "one more step to reverse it", that is the same scam continuing.
  2. Secure. Change the exchange password, reset 2-step verification, remove any unknown devices and API keys. Coinbase's help page advises locking your account in the app if you suspect unauthorised access or suspicious activity and emailing [email protected]. If a seed phrase was exposed, move what remains to a new wallet created on a device you trust.
  3. Collect. Save the transaction hashes, the receiving addresses, the amounts and times, the phone numbers, the email headers and screenshots of every message. Do not delete the conversation.
  4. Report. Tell the exchange through its official in-app or website support, file a police report where you live, and in the US report to the FBI's Internet Crime Complaint Center. Our guide on how to report a crypto scam lists what each report is for and what to include.

Speed matters because stolen funds can move within hours, and the parties who can hold them need your hashes to act.

Where do funds stolen in a Coinbase scam go on-chain?

The first transfer goes to an address the attacker controls. From there the pattern is familiar to anyone who has traced a few of these cases: the funds are split or consolidated with other victims' funds, often swapped into a stablecoin or another asset, sometimes bridged to a different chain, and eventually sent towards a point where they can be turned into cash. In many cases, funds eventually reach a centralised exchange, OTC service or another identifiable service provider.

This is where an investigation has something to work with. Each hop is a public transaction, and crypto tracing follows those hops to an address that belongs to a party able to freeze funds: an exchange or a stablecoin issuer. In our process, stolen transactions are submitted to AML providers for flagging as early as possible after intake.

There are limits. We do not take Monero cases because its privacy features can make reliable tracing and evidentiary attribution impractical for our recovery process. Funds that stay in self-custody wallets with no regulated endpoint can be traced but not frozen.

When is a freeze or recovery realistic?

Two different clocks apply, and they should never be read as one.

The freeze clock. Based on our case experience, responses to freeze requests may sometimes be received within 2–4 days for exchanges and within 24–62 hours in Tether-related cases. Actual response times depend on the specific service, jurisdiction, supporting evidence and law-enforcement involvement. A freeze stops the funds from moving; it does not return them.

The recovery clock. Where frozen funds are returned from an exchange, the legal process typically takes 6–9 months. Based on cases handled by our team, recovery in Tether-related cases may take approximately 12–20 months or longer, depending on the legal process and the circumstances of the case. Complex cases range from 6 to 36 months. The legal steps (police reports, freeze requests, court orders) are carried out by local partner firms; we do not practise law. The whole sequence is set out on our recovery process page and in freeze vs. recovery: real timelines.

A case may be suitable for further recovery work when the funds can be traced to a party capable of freezing them and when the circumstances justify further action. Our published case threshold starts at $200,000; smaller cases are reviewed individually. We decline cases where the team sees no realistic prospect of recovery, and no one can promise the outcome: the decision to release funds belongs to the exchange, the issuer or a court. Our figures, each with its period, are on the data page.

Who contacts you after the loss, and why is it a second scam?

Expect a second approach. After a Coinbase scam, victims often hear from a "recovery agency", a "law firm" or an "exchange compliance officer" who says your funds have been located and can be released for a fee. The FBI described this pattern in PSA240624, noting that crypto scam victims further exploited by fictitious law firms reported losses of over $9.9 million between February 2023 and February 2024, and that law enforcement does not charge victims a fee for investigating crimes.

Our overview of how crypto gets stolen covers this second scam in more detail; the core rule is short: unsolicited contact from a recovery firm should be treated as a warning sign.

If the funds are traceable and the loss is significant, send us the transaction hashes: the assessment is free, and we aim to respond within two business hours, including when the answer is that there is nothing to pursue. Write through the contact page or message @StarCompliance on Telegram.

Coinbase scams: common questions

Does Coinbase ever call customers?

A support agent can call you back if a genuine support call you started was disconnected, and will re-verify you first. Coinbase says it will never call or text you to give you a new seed phrase or wallet address, and its agents will never ask for your password, 2-step code, remote access or a transfer of funds.

Is a text saying my Coinbase account was accessed a scam?

Treat it as one until you have checked inside the real app. Do not call the number in the message or tap its link. Open the app or type the website address yourself and review recent activity and devices there.

I read a verification code to a caller. What now?

Change your password and reset 2-step verification immediately, remove unknown devices, and check whether any withdrawal was made. If funds left, save the transaction hashes and report to the exchange, the police and, in the US, the FBI's Internet Crime Complaint Center.

Can a Coinbase scam be reversed by Coinbase?

A confirmed blockchain transaction cannot be reversed by the exchange it left from. What can happen is a freeze at the place the funds arrive, if that is an exchange or a stablecoin issuer, followed by a legal process that may lead to their return, which takes months rather than days.

Is a Trust Wallet scam different from a Coinbase scam?

The script is the same, but the target differs. Trust Wallet is self-custody, so the scammer needs your recovery phrase or a malicious signature rather than an account login. Trust Wallet states it will never ask for your recovery phrase.

How is this different from a fake exchange?

An impersonation scam takes funds from a real account or wallet you own. A fake exchange is a website that was never an exchange and simply kept your deposits while showing a fictional balance.

Someone contacted me unexpectedly and says my recovered funds will be released if I pay a fee. Should I pay?

Do not pay solely on the basis of an unsolicited claim that your funds have already been recovered or are ready for release. Unsolicited recovery offers after a loss are a known form of secondary fraud, and law enforcement does not charge victims fees. Check any firm you consider independently before paying anything.


This article is informational material, not legal advice, and no outcome is promised: decisions on freezing and releasing funds are made by exchanges, issuers and courts. Statements about Coinbase, Trust Wallet, Crypto.com, Binance and MetaMask are taken from their own help and security pages as of September 2026. Figures are from StarCompliance casework and are published, with the period each covers, on our figures page.

Previous
Article

Crypto Theft: What a Lawyer Needs From a Blockchain Investigator

Next
Article

Bitget Hack, 24 Sep 2026: Losses, Remaining Assets and Resilience

§ — Related reading

Continue down the thread.

§ — Engage

Got a case that rhymes with this one?
Start an intake.

Response within two business hours. Confidential. Success-fee terms on recovery work.