Scam Identification Guide

Crypto Exchange Scam Texts

A text says someone is withdrawing from your Coinbase or Binance account, and gives you a number to ring. That number is the scam. Here's how the whole thing plays out.

SM
Telecommunications Security Editor
Published 10 min read

No exchange will ever ask you to move your crypto to a safe wallet

This is the line the whole scam is built to reach. Coinbase, Binance, Kraken and every other legitimate exchange secure a compromised account by locking it, not by asking you to send your money somewhere else. If anyone tells you to move your holdings to a new wallet, a vault, or a recovery address to protect them, you are being robbed. Full stop.

What's going on

You get a text saying there has been a login from a device you don't recognise, or that a withdrawal has just been requested. It names a real exchange. It usually quotes an amount. And then it does something most scam texts don't. Instead of a link, it gives you a phone number and tells you to ring straight away if this wasn't you.

That swap from link to phone number is deliberate, and it makes this version far more dangerous than ordinary phishing. We have all been trained to distrust links. A phone number feels like the responsible option, because you're not clicking anything, you're ringing to check. But the number belongs to the criminals, and dialling it does their hardest work for them. You have made contact voluntarily, you're already frightened, and you believe you are talking to the good guys. Binance has publicly warned its customers about this exact tactic and told them not to ring numbers that arrive in unsolicited messages.

7726
Free UK shortcode for reporting scam texts to your mobile network
£0
FSCS protection on crypto holdings, because it isn't covered (FCA)
Minutes
How long a crypto transfer takes to become permanent and untraceable

What it cost Sam Little

Sam Little, who appeared on the BBC series The Traitors, lost £40,000 to this scam in January. It was his life savings, money he and his wife had put aside to plan the next stage of their lives, and it was sitting in a cryptocurrency account.

It started with texts warning him that someone was trying to get into his account, telling him to ring a number for help. He rang it, because he believed he was contacting a legitimate support line. That was the only decision he made.

Here is the part worth reading twice. The people on the other end never asked him for a password. They never asked for a verification code. While he was on the phone to them, they manipulated the platform he normally used to reach his wallet, and before he understood what was happening the line went dead and the full £40,000 had gone.

"It feels like your world's just collapsing. You work solidly for years to build this up, and it's just gone."

Sam Little, speaking to the BBC

He reported it to Action Fraud. Months later there had been no full investigation and he had not recovered a penny. If you have ever assumed you would spot one of these because you would never hand over a password, that is exactly the assumption this scam is designed to walk straight past.

How the scam works

The text is only the doorbell. Everything expensive happens on the call that follows.

1. The alert arrives

Short, urgent, formatted to look automated. It quotes a withdrawal amount or a city for the supposed login, because specifics feel like evidence. It goes out in bulk to millions of UK numbers with no idea who holds an account anywhere. If you don't use the exchange named, you delete it. If you do, your heart rate goes up, and the scammers only need the second group.

Why it may land in a real message thread

Exchanges send genuine security codes by SMS using sender IDs like "Coinbase". Those IDs can be spoofed, and your phone groups messages by the name shown rather than by any verified sender. So a fake alert can drop straight into the same conversation as the real login codes you have had for years. Seeing it there proves nothing at all about who sent it.

2. You ring the number

What answers sounds exactly like a support line. Hold music, a menu, a professional greeting naming the exchange. The person who picks up is calm and helpful and never pushy, because pushiness would break the spell. They confirm the suspicious withdrawal you rang about, sound concerned, and place themselves firmly on your side against an attacker who does not exist.

The bit that wins your trust

Early on they will read something back to you. The last four digits of a card, an email address, a rough balance. It feels like proof they are inside the real system. It isn't. That information comes from data breaches bought in bulk, and it is there for this exact moment. Genuine verification runs the other way round. A real company asks you to prove who you are. It doesn't perform for you.

3. The safe wallet

Here comes the ask, wrapped in urgency. Your account is compromised, they say, and the attacker has an active session, so anything left in it is at risk. They will help you secure it right now by moving your holdings to a new wallet they set up with you, or to a recovery address their security team controls. They may stay on the line and talk you through every tap. The moment that transfer confirms, the money has gone. No chargeback, no bank to ring, no realistic prospect of getting it back.

The other three versions of the ask

  • • Read out the code we have just sent you, which is the code that lets them in
  • • Install AnyDesk or TeamViewer so we can secure the account, which is remote control of your device
  • • Confirm your 12 or 24 word recovery phrase so we can verify ownership, which is your entire wallet

4. The clock and the callback

Every part of the call is built to stop you leaving it to check. They discourage you from hanging up, warn that ending the call lets the attacker finish the withdrawal, and offer to stay with you while you act. If you do hang up, expect a call back within minutes from a number that may now display as the exchange's real one, because caller ID is trivial to spoof. And if the theft works, your details go onto a list that gets resold, which is why a message offering to recover your lost crypto so often turns up a few weeks later. That's the same criminals coming back for the rest.

What these texts look like

These are examples based on messages reported across the UK. The exchange name rotates. The shape does not: something is wrong, it is happening now, and here is the one thing that fixes it.

"Withdrawal in progress"

The most reported version, and the one Sam Little received. A specific amount and a countdown, so it feels like you are watching your money leave in real time. The number is the payload.

"Coinbase: A withdrawal of 0.412 BTC has been initiated. If this wasn't you, call 0800 XXX XXXX within 30 minutes to cancel."

"New device login"

Names a city and a device to feel authentic. Exchanges do send real alerts like this, which is what gives the fake ones cover. The difference is the phone number bolted on the end.

"Binance: New sign in detected from Warsaw, PL (Windows). Not you? Contact security immediately on 0203 XXX XXXX."

"Account restricted"

Plays on the fear of being locked out of your own money rather than losing it to a thief. Usually dressed up as a compliance or verification matter so it sounds routine.

"Kraken: Your account has been restricted pending verification. Withdrawals are suspended. Call 0800 XXX XXXX to restore access."

"Confirm this code"

The quiet one. It turns up while somebody is already trying your password on the real site, and asks you to confirm the genuine code you have just been sent. Never reply to it.

"Your verification code is 481203. Reply YES to confirm this login attempt or call 0800 XXX XXXX to report it."

Why this catches people

This scam borrows its whole script from bank fraud and then removes every safety net that makes bank fraud survivable. With a bank, a wrong move can often be undone. Payments get recalled, cards get frozen, and reimbursement rules exist. With crypto there is none of that. A confirmed transfer is final, crypto held on an exchange is not covered by the Financial Services Compensation Scheme, and in most cases you cannot take a complaint to the Financial Ombudsman either.

There's a widespread idea that only careless people fall for this. It's wrong, and it's a dangerous thing to believe, because it stops you thinking it could happen to you. Sam Little never gave anyone a password. He rang a number he had been told to ring, and the rest was done to him while he waited. The scam hijacks a habit we were all right to build, which is to take a genuine security alert seriously and act on it quickly.

What makes it convincing

  • • Real exchanges send genuinely similar security alerts
  • • A phone number feels safer than a link, so people ring it
  • • Sender IDs are easy to spoof, so it may sit in a real message thread
  • • The caller reads back real details bought from data breaches
  • • Caller ID spoofing means a callback can display the real number

What should make you stop

  • • Any request to move funds to a different wallet or address
  • • A phone number supplied inside the message itself
  • • Anyone asking for a code, a password or a recovery phrase
  • • A request to install remote access software
  • • Pressure not to hang up, or a countdown of any kind

How to tell real from fake

Exchanges do send security alerts, and you should read them. What separates a real one from a fake is what it asks of you.

Real exchange alerts

  • Tell you to open the app and check for yourself
  • Never include a support phone number to ring
  • Are mirrored by a notification inside the app itself
  • Say a code will never be requested by anyone
  • Lock a compromised account rather than emptying it

Scam texts

  • Supply a number to ring or a link to tap
  • Impose a deadline of 30 minutes, an hour, today
  • Lead to a request to move funds somewhere safe
  • Ask you to read out a code or install software
  • Show no matching notification inside the real app

If you get one of these texts

1

Don't ring the number in the message

Not to check, not to cancel, not even to tell them where to go. Ringing it is the entire objective of the text, and a support line that answers your call is not evidence of anything.

2

Open the app yourself and look

Use the exchange's own app, or type the address in by hand. Real withdrawal requests and login alerts show up in your account activity. If there is nothing there, nothing was ever happening. Thirty seconds, and it settles the question completely.

3

Tighten the account while you're in there

Switch two step verification from SMS to an authenticator app or a hardware key, so a SIM swap can't hand somebody your codes. Set up a withdrawal address whitelist if the exchange offers one, and check nothing unfamiliar is already on it.

Holdings you aren't actively trading are safer in a wallet you control than sitting on an exchange.

4

Forward it to 7726

Free on every UK network. It lets your provider investigate the sender and block the route. Most exchanges also take phishing reports through their real support site, which is worth doing so the fake number gets taken down.

5

Report the number on CallerCheck

These campaigns run through callback numbers quickly, so a report filed today is worth far more than one filed next month. Somebody about to dial that number is exactly who it helps.

Already rang, or already moved funds?

Speed is the only thing that helps here. Work down this list and leave the self blame for later, because these calls are designed by professionals to be convincing.

  1. 1

    Cut off any remote access immediately

    If you installed AnyDesk, TeamViewer or anything similar, disconnect the device from the internet, uninstall the software and restart. Assume they saw everything on screen while connected, including any password you typed.

  2. 2

    Move anything still sitting in a wallet you exposed

    If you shared a recovery phrase, that wallet cannot be made safe. Create a fresh one on a clean device and move what is left now. If you only gave account credentials, change the password and revoke active sessions instead.

  3. 3

    Contact the real exchange through its official app

    Never through a number you were given. They can freeze the account, halt pending withdrawals and flag the destination address. If the transfer has not left the platform yet, this is the one window where it can still be stopped.

  4. 4

    Ring your bank on 159 if card or bank details were shared

    159 puts you straight through to your bank's fraud team. If you bought crypto by card during the call, say so, because a card payment is one of the very few parts of this that may still be disputable.

  5. 5

    Report to Action Fraud and record everything

    Ring 0300 123 2040 or report at actionfraud.police.uk, or Police Scotland on 101. Save the text, the number you rang, the times, and every transaction ID or destination address. Then ignore anyone who later offers to recover it for a fee, because that offer is the follow up scam and not a rescue.

The short version

Red flags

  • • A phone number supplied in the text
  • • Any deadline or countdown
  • • Move your funds to a safe wallet
  • • Requests for codes, passwords or a recovery phrase
  • • Being asked to install remote access software

What to do

  • • Don't ring the number in the message
  • • Open the exchange's own app and check
  • • Move two step verification off SMS
  • • Forward the text to 7726
  • • Report the sender on CallerCheck

A real exchange locks a compromised account. It never asks you to empty it.

Frequently Asked Questions

Do Coinbase or Binance ever ring customers?
Not out of the blue, and never to ask you to move funds. The major exchanges run support through their app or website, and Binance has publicly warned customers not to ring phone numbers that arrive in unsolicited messages claiming to be from them. Treat any unexpected call or callback number as fake by default. If you genuinely need support, start inside the official app, because that way you control who you are talking to.
They never asked me for a password. How did they get in?
This is what happened to Sam Little, and it catches people who thought they knew the rules. Not every version of the scam needs your credentials. Some talk you into installing remote access software so they can work on your device directly. Some interfere with the platform you are using while they keep you talking. Some simply keep you on the phone long enough that you are not looking at your account while it empties. Refusing to give out a password is a good habit, but on its own it is not protection. Not ringing the number is.
The number that rang me back showed as the real exchange. How?
Caller ID spoofing. The number shown on your screen is supplied by whoever places the call, and it can be set to anything they like, including a number you have saved as a contact. Your network does not verify it. So "it came from their real number" is never proof of anything. The same goes for SMS sender IDs, which is how fake alerts slip into genuine message threads.
Can I get my crypto back if I transferred it?
Usually not, and it is better to hear that plainly. A confirmed blockchain transfer cannot be reversed, crypto is not protected by the FSCS, and most crypto activity falls outside the Financial Ombudsman's remit. The exceptions are narrow. Funds that have not yet left the exchange may be freezable if you contact the platform fast, and a card payment used to buy crypto during the scam can sometimes be disputed with your bank. Report it to Action Fraud either way. And be very wary of anyone who contacts you afterwards promising recovery for a fee.
Why does SMS two step verification make this worse?
Two reasons. Codes sent by text can be talked out of you on a phone call, which is exactly what the caller is angling for. And SMS depends on your phone number, so a SIM swap, where a criminal persuades your network to move your number onto their SIM, hands them your codes with no conversation at all. An authenticator app or a hardware security key keeps the second factor on a device you physically hold, which closes both routes. It is the most useful five minutes you can spend on this.
I don't even have an account with the exchange in the text. Why me?
It was never aimed at you specifically. These messages go out to enormous lists of UK mobile numbers with no knowledge of who holds what. Most people who get one don't use the exchange named and delete it without a thought, and the campaign still pays if a small fraction do. Worth knowing, because when a message happens to name your exchange it can feel like proof somebody is inside your account. It's coincidence, at scale.

About the Author

Telecommunications Security Editor

Fraud Prevention Specialist

Sarah is a telecommunications security enthusiast with a background in mobile network fraud prevention. At CallerCheck, she reviews spam report submissions, identifies emerging scam patterns, and keeps our guides up to date with the latest call blocking techniques. She monitors industry developments from Ofcom, UK Finance, and major network providers to ensure our advice reflects current best practices.

Phone Scams Call Blocking Mobile Security Fraud Prevention
Updated Published 5th August 2026 Fact-checked by CallerCheck Editorial Team

Got a fake exchange alert with a number to ring?

Report it on CallerCheck so the next person checks the number before they dial it.

We value your privacy

We use cookies to enhance your browsing experience, analyse site traffic, and show personalised ads. You can choose which cookies to accept below. Read more about cookies on CallerCheck.co.uk

Cookie Settings

Manage your cookie preferences

Essential Cookies

Always Active

Required for the website to function. These cannot be disabled as they are necessary for security and basic functionality.

callercheck_sessionSession management
XSRF-TOKENSecurity (CSRF protection)
cookie_consentStores your preferences

Analytics Cookies

Help us understand how visitors interact with our website by collecting anonymous information.

Google Analytics
_gaVisitor identification (2 years)
_ga_*Session state (2 years)
_gidUser distinction (24 hours)

Advertising Cookies

Used to show you relevant ads and support our free service. Disabling won't remove ads, but they'll be less relevant.

Google AdSense
Contextual and personalised advertising

Functional Cookies

Enable enhanced functionality like social sharing buttons and embedded content from third-party services.

YouTubeEmbedded videos
Google MapsEmbedded maps
View full Cookie Policy