Library · When something goes wrong
How to spot a crypto recovery scam
The second loss is usually larger than the first. The tells are consistent, and they are visible before any money changes hands.
There is an entire industry built on people who have already lost crypto once. It is efficient, it is well-rehearsed, and it works because it arrives at the exact moment when someone is desperate and every alternative looks worse. The second loss is routinely larger than the first, because by then the victim has been persuaded that recovery is close.
Every one of the following is enough on its own to walk away. Most real cases carry several.
They contacted you. This is the strongest signal available. Public posts about lost funds are monitored continuously, on every platform, by people whose entire job is to reply. If a "recovery specialist", "blockchain forensics team" or sympathetic stranger appeared after you mentioned a loss anywhere public, that is not luck. Legitimate services do not trawl for victims.
They ask for your seed phrase or private key. No exception exists to this. Anyone who has your phrase has your funds, and needs nothing else from you. A genuine recovery process can work on partial information, on an encrypted file, or on your own machine — and any of those can be structured so the complete secret never has to leave your possession. Anyone who insists otherwise is not describing a technical requirement, they are describing the theft.
They want money before anything is recovered. Framed as an "unlock fee", a "gas fee to release the funds", "network validation", a "tax", a "smart contract activation", a mining deposit, or a retainer. There is always a next fee. The structure is designed so that each payment feels small next to the amount about to be returned, and so that stopping means losing what you already paid. That reasoning is the trap, and it is the same mechanism in every version of it.
They guarantee it. Nobody can. Whether a wallet is recoverable depends on what you still have, and that is not knowable before looking. A guarantee is a sales instrument.
They claim they can hack the blockchain, or brute-force a key from nothing. These are not services that exist. A private key with no fragments of a seed phrase is beyond any computer that will ever be built — not expensive, not slow, not possible. Anyone advertising it is either lying or is describing something else entirely.
They want remote access to your computer. A screen-sharing session with a stranger on a machine that has a wallet on it is the loss. It does not need to be a sophisticated attack after that point.
They show a dashboard with your funds "recovered", pending one last payment. A web page saying a number is trivially built. The only proof that funds moved is a transaction on the public ledger that you looked up yourself, on a block explorer you navigated to independently. Nothing on their site is evidence of anything.
They are impersonating someone real. Fake support accounts for every major wallet and exchange exist in volume, with matching names, logos and lookalike domains. Real support does not initiate contact, does not work over private messages, and cannot move your crypto. When in doubt, close the conversation and reach the company through an address you typed yourself.
Their credibility is entirely self-supplied. Testimonials on their own site, screenshots of gratitude, a stock-photo team, a company registration used as if it were regulation, and "as featured in" logos with no article behind them. None of it is checkable, which is why it is there.
They are hurrying you. A window closing, a wallet about to be "permanently locked", a fee that rises tomorrow. Nothing about a lost wallet is time-sensitive. The ledger does not expire, and a key that works today works in a year. Urgency exists only to prevent you checking.
What a legitimate service actually looks like. It tells you plainly which cases are recoverable and which are not, and it will tell you no. It never needs your complete seed phrase. It is paid on success, from the recovered funds, at a stated percentage. It explains the method well enough that you could understand it. It gives you something checkable — a name, an address, a jurisdiction. And it does not mind you taking a week to think.
If you have already paid one. Stop paying, immediately, however far in you are — the sunk cost is exactly what the structure is exploiting. Keep everything: addresses, transaction hashes, messages, names, the site. Report it to your national fraud body and to the platform where you were approached. And expect a second approach, often within weeks, from a "recovery of recovery" service or someone claiming to be law enforcement who can retrieve the money for a fee. Victim lists are resold, and being defrauded once makes you a qualified lead.
Our own position, so it is on the record. This website will never ask for a seed phrase or a private key, on any page, for any product, ever. There is no legitimate reason for a website to have one, so the constraint costs us nothing and the absence of it should disqualify anybody. Our methodology states it permanently.
Educational content, not financial advice. We are not a broker, exchange, custodian or adviser, and we never take custody of your assets. We will never ask for a seed phrase or private key. See the full disclaimer.