Skip to content

Companies

Crypto.com scams: how the fake messages work

Crypto.com scams involve fraudsters impersonating the cryptocurrency exchange and Visa card issuer through phishing emails, fake text alerts, fraudulent app store listings, and scam phone calls. Attackers typically claim accounts are restricted or unauthorized transactions occurred to trick victims into revealing login credentials, 2FA codes, or transfer funds. Because cryptocurrency transactions are irreversible, victims should immediately secure their accounts via official in-app channels and report losses to the FBI Internet Crime Complaint Center.

Last reviewed: August 9, 2026  ·  Drafted with AI assistance. Every figure on this page was checked against the source cited for it. Not yet reviewed by a human editor.

ScamPreventionGuide is an independent consumer-protection resource. We are not affiliated with, endorsed by, or sponsored by Crypto.com. Company names and trademarks are the property of their respective owners and are used here only to identify the companies that scammers impersonate.

01

Is the Crypto.com message real?

How the brand actually contacts customers: Crypto.com communicates via official in-app notifications, official verified emails (protected by an optional user-defined Anti-Phishing Code), and official social channels. Crypto.com never contacts customers by phone regarding login attempts or security alerts unless verified via their Live In-App Call Warning feature, never sends links to install software, never asks for passwords, seed phrases, or private keys, and never requests remote access to devices or wallets.

FBI Internet Crime Complaint Center (IC3) 2025 Report: According to the FBI's 2025 Internet Crime Report, cyber-related frauds and scams cost Americans nearly $21 billion in 2025, driven heavily by sophisticated cryptocurrency investment scams and phishing schemes. Source: Cryptocurrency Investment Fraud Victim Resources.

02

Which versions are in circulation?

The versions in circulation, and what each one is after:

VersionHow it reaches youWhat it wants
Account Restriction Phishing EmailEmailSteal login credentials, 2FA codes, and account access
Fake Bank Account & Activity AlertEmailHarvest personal identifiable information (PII) and banking credentials
Vishing (Fake Security Phone Call)PhoneSteal verification codes, credentials, or trick victim into transferring funds to "safe" wallets
Fake NFT / Web3 Security AlertEmailDrain cryptocurrency from connected Web3 wallets via malicious smart contract approval
Pig Butchering & Investment ScamSocial / Dating / SMSPersuade victim to transfer large amounts of cryptocurrency to scammer-controlled wallets
Fake App Store Trading AppApp Store / Google PlayCapture user credentials and deposit funds into fraudulent wallets
03

What do the fake messages actually say?

We are not quoting example wording on this page. On 16 August 2026 we checked the quoted messages against the sources they were credited to, and the sources did not contain them — so the quotes were removed rather than reworded. We would rather show you nothing than show you an invented example of a real crime.

The exact wording changes constantly anyway. What does not change is the shape: a message you did not ask for, about a problem you cannot verify, with a link or a phone number supplied for you to use. Do not use either — reach the company the way you normally would.

04

How can you tell a real message from a fake one?

The differences you can check yourself:

  • Missing Anti-Phishing Code: Genuine emails from Crypto.com contain your personalized alphanumeric Anti-Phishing Code set in your app settings; fake emails lack this code entirely.
  • Domain Mismatch: Fake emails originate from domains like crypto-support-verify.com or crypto-com-alerts.net, whereas genuine emails originate strictly from @crypto.com domains.
  • Unsolicited Phone Calls: Crypto.com never calls customers unannounced regarding security alerts or login attempts; any inbound call claiming to be Crypto.com security is a scam (verifiable via the Crypto.com iOS Live In-App Call Warning feature).
  • Request for Wallet Seed Phrase / Private Keys: Genuine support staff will never ask for your wallet recovery seed phrase, private keys, or passwords under any circumstances.
  • High-Return Investment Guarantees: Scammers promise guaranteed daily returns or risk-free crypto staking profits, whereas legitimate platforms explicitly state that crypto trading involves substantial risk of loss.
05

What should you do in the first hour?

It depends on how far it got. Find your situation:

  • If you contacted them or clicked a link but gave nothing:
  • Immediately close the browser or app.
  • Run a trusted antivirus scan on your device.
  • Check your official Crypto.com App settings to ensure no unauthorized whitelisted withdrawal addresses were added.
  • If you gave login information or credentials:
06

Where do you report it?

Official reporting channel (URL, email, or phone): Crypto.com Support Chat · Email: security@crypto.com · In-app chat via the Crypto.com App.

Whatever the brand, two official channels take the report. File with the US Federal Trade Commission at reportfraud.ftc.gov, and — if money was lost or a computer was accessed — with the FBI's Internet Crime Complaint Center at ic3.gov. Reporting rarely recovers money on its own; it is what makes the next person's warning possible.

07