What's going on
You get a text saying there has been a login from a device you don't recognise, or that a withdrawal has just been requested. It names a real exchange. It usually quotes an amount. And then it does something most scam texts don't. Instead of a link, it gives you a phone number and tells you to ring straight away if this wasn't you.
That swap from link to phone number is deliberate, and it makes this version far more dangerous than ordinary phishing. We have all been trained to distrust links. A phone number feels like the responsible option, because you're not clicking anything, you're ringing to check. But the number belongs to the criminals, and dialling it does their hardest work for them. You have made contact voluntarily, you're already frightened, and you believe you are talking to the good guys. Binance has publicly warned its customers about this exact tactic and told them not to ring numbers that arrive in unsolicited messages.
What it cost Sam Little
Sam Little, who appeared on the BBC series The Traitors, lost £40,000 to this scam in January. It was his life savings, money he and his wife had put aside to plan the next stage of their lives, and it was sitting in a cryptocurrency account.
It started with texts warning him that someone was trying to get into his account, telling him to ring a number for help. He rang it, because he believed he was contacting a legitimate support line. That was the only decision he made.
Here is the part worth reading twice. The people on the other end never asked him for a password. They never asked for a verification code. While he was on the phone to them, they manipulated the platform he normally used to reach his wallet, and before he understood what was happening the line went dead and the full £40,000 had gone.
"It feels like your world's just collapsing. You work solidly for years to build this up, and it's just gone."
Sam Little, speaking to the BBC
He reported it to Action Fraud. Months later there had been no full investigation and he had not recovered a penny. If you have ever assumed you would spot one of these because you would never hand over a password, that is exactly the assumption this scam is designed to walk straight past.
How the scam works
The text is only the doorbell. Everything expensive happens on the call that follows.
1. The alert arrives
Short, urgent, formatted to look automated. It quotes a withdrawal amount or a city for the supposed login, because specifics feel like evidence. It goes out in bulk to millions of UK numbers with no idea who holds an account anywhere. If you don't use the exchange named, you delete it. If you do, your heart rate goes up, and the scammers only need the second group.
Why it may land in a real message thread
Exchanges send genuine security codes by SMS using sender IDs like "Coinbase". Those IDs can be spoofed, and your phone groups messages by the name shown rather than by any verified sender. So a fake alert can drop straight into the same conversation as the real login codes you have had for years. Seeing it there proves nothing at all about who sent it.
2. You ring the number
What answers sounds exactly like a support line. Hold music, a menu, a professional greeting naming the exchange. The person who picks up is calm and helpful and never pushy, because pushiness would break the spell. They confirm the suspicious withdrawal you rang about, sound concerned, and place themselves firmly on your side against an attacker who does not exist.
The bit that wins your trust
Early on they will read something back to you. The last four digits of a card, an email address, a rough balance. It feels like proof they are inside the real system. It isn't. That information comes from data breaches bought in bulk, and it is there for this exact moment. Genuine verification runs the other way round. A real company asks you to prove who you are. It doesn't perform for you.
3. The safe wallet
Here comes the ask, wrapped in urgency. Your account is compromised, they say, and the attacker has an active session, so anything left in it is at risk. They will help you secure it right now by moving your holdings to a new wallet they set up with you, or to a recovery address their security team controls. They may stay on the line and talk you through every tap. The moment that transfer confirms, the money has gone. No chargeback, no bank to ring, no realistic prospect of getting it back.
The other three versions of the ask
- • Read out the code we have just sent you, which is the code that lets them in
- • Install AnyDesk or TeamViewer so we can secure the account, which is remote control of your device
- • Confirm your 12 or 24 word recovery phrase so we can verify ownership, which is your entire wallet
4. The clock and the callback
Every part of the call is built to stop you leaving it to check. They discourage you from hanging up, warn that ending the call lets the attacker finish the withdrawal, and offer to stay with you while you act. If you do hang up, expect a call back within minutes from a number that may now display as the exchange's real one, because caller ID is trivial to spoof. And if the theft works, your details go onto a list that gets resold, which is why a message offering to recover your lost crypto so often turns up a few weeks later. That's the same criminals coming back for the rest.
What these texts look like
These are examples based on messages reported across the UK. The exchange name rotates. The shape does not: something is wrong, it is happening now, and here is the one thing that fixes it.
"Withdrawal in progress"
The most reported version, and the one Sam Little received. A specific amount and a countdown, so it feels like you are watching your money leave in real time. The number is the payload.
"Coinbase: A withdrawal of 0.412 BTC has been initiated. If this wasn't you, call 0800 XXX XXXX within 30 minutes to cancel."
"New device login"
Names a city and a device to feel authentic. Exchanges do send real alerts like this, which is what gives the fake ones cover. The difference is the phone number bolted on the end.
"Binance: New sign in detected from Warsaw, PL (Windows). Not you? Contact security immediately on 0203 XXX XXXX."
"Account restricted"
Plays on the fear of being locked out of your own money rather than losing it to a thief. Usually dressed up as a compliance or verification matter so it sounds routine.
"Kraken: Your account has been restricted pending verification. Withdrawals are suspended. Call 0800 XXX XXXX to restore access."
"Confirm this code"
The quiet one. It turns up while somebody is already trying your password on the real site, and asks you to confirm the genuine code you have just been sent. Never reply to it.
"Your verification code is 481203. Reply YES to confirm this login attempt or call 0800 XXX XXXX to report it."
Why this catches people
This scam borrows its whole script from bank fraud and then removes every safety net that makes bank fraud survivable. With a bank, a wrong move can often be undone. Payments get recalled, cards get frozen, and reimbursement rules exist. With crypto there is none of that. A confirmed transfer is final, crypto held on an exchange is not covered by the Financial Services Compensation Scheme, and in most cases you cannot take a complaint to the Financial Ombudsman either.
There's a widespread idea that only careless people fall for this. It's wrong, and it's a dangerous thing to believe, because it stops you thinking it could happen to you. Sam Little never gave anyone a password. He rang a number he had been told to ring, and the rest was done to him while he waited. The scam hijacks a habit we were all right to build, which is to take a genuine security alert seriously and act on it quickly.
What makes it convincing
- • Real exchanges send genuinely similar security alerts
- • A phone number feels safer than a link, so people ring it
- • Sender IDs are easy to spoof, so it may sit in a real message thread
- • The caller reads back real details bought from data breaches
- • Caller ID spoofing means a callback can display the real number
What should make you stop
- • Any request to move funds to a different wallet or address
- • A phone number supplied inside the message itself
- • Anyone asking for a code, a password or a recovery phrase
- • A request to install remote access software
- • Pressure not to hang up, or a countdown of any kind
How to tell real from fake
Exchanges do send security alerts, and you should read them. What separates a real one from a fake is what it asks of you.
Real exchange alerts
- Tell you to open the app and check for yourself
- Never include a support phone number to ring
- Are mirrored by a notification inside the app itself
- Say a code will never be requested by anyone
- Lock a compromised account rather than emptying it
Scam texts
- Supply a number to ring or a link to tap
- Impose a deadline of 30 minutes, an hour, today
- Lead to a request to move funds somewhere safe
- Ask you to read out a code or install software
- Show no matching notification inside the real app
If you get one of these texts
Don't ring the number in the message
Not to check, not to cancel, not even to tell them where to go. Ringing it is the entire objective of the text, and a support line that answers your call is not evidence of anything.
Open the app yourself and look
Use the exchange's own app, or type the address in by hand. Real withdrawal requests and login alerts show up in your account activity. If there is nothing there, nothing was ever happening. Thirty seconds, and it settles the question completely.
Tighten the account while you're in there
Switch two step verification from SMS to an authenticator app or a hardware key, so a SIM swap can't hand somebody your codes. Set up a withdrawal address whitelist if the exchange offers one, and check nothing unfamiliar is already on it.
Holdings you aren't actively trading are safer in a wallet you control than sitting on an exchange.
Forward it to 7726
Free on every UK network. It lets your provider investigate the sender and block the route. Most exchanges also take phishing reports through their real support site, which is worth doing so the fake number gets taken down.
Report the number on CallerCheck
These campaigns run through callback numbers quickly, so a report filed today is worth far more than one filed next month. Somebody about to dial that number is exactly who it helps.
Already rang, or already moved funds?
Speed is the only thing that helps here. Work down this list and leave the self blame for later, because these calls are designed by professionals to be convincing.
-
1
Cut off any remote access immediately
If you installed AnyDesk, TeamViewer or anything similar, disconnect the device from the internet, uninstall the software and restart. Assume they saw everything on screen while connected, including any password you typed.
-
2
Move anything still sitting in a wallet you exposed
If you shared a recovery phrase, that wallet cannot be made safe. Create a fresh one on a clean device and move what is left now. If you only gave account credentials, change the password and revoke active sessions instead.
-
3
Contact the real exchange through its official app
Never through a number you were given. They can freeze the account, halt pending withdrawals and flag the destination address. If the transfer has not left the platform yet, this is the one window where it can still be stopped.
-
4
Ring your bank on 159 if card or bank details were shared
159 puts you straight through to your bank's fraud team. If you bought crypto by card during the call, say so, because a card payment is one of the very few parts of this that may still be disputable.
-
5
Report to Action Fraud and record everything
Ring 0300 123 2040 or report at actionfraud.police.uk, or Police Scotland on 101. Save the text, the number you rang, the times, and every transaction ID or destination address. Then ignore anyone who later offers to recover it for a fee, because that offer is the follow up scam and not a rescue.
The short version
Red flags
- • A phone number supplied in the text
- • Any deadline or countdown
- • Move your funds to a safe wallet
- • Requests for codes, passwords or a recovery phrase
- • Being asked to install remote access software
What to do
- • Don't ring the number in the message
- • Open the exchange's own app and check
- • Move two step verification off SMS
- • Forward the text to 7726
- • Report the sender on CallerCheck
A real exchange locks a compromised account. It never asks you to empty it.