How to Spot a Crypto Phishing Call in 2026
The scam call that targeted me in 2023 was run by humans reading a script. The 2026 version of that same call can use an AI-cloned voice, reference your real transactions from breach data, and spoof the exchange's actual support number on your caller ID. The production quality went up. The playbook underneath did not change at all.
That is the good news. You do not need to out-tech them. You need fixed rules that no production quality can beat.
The anatomy is always the same three beats. Manufactured urgency: your account is compromised, your funds are moving, act now. Manufactured authority: official-looking numbers, real employee names pulled from LinkedIn, emails from domains one letter off. Manufactured helpfulness: they are calling to save you, and they just need one small thing, a code, a password, a wallet connection, an app install.
Every variation you will ever encounter is those three beats in a different costume. So the defense is not spotting the costume. It is refusing the beats.
Rule one: inbound contact is guilty until proven innocent. If they called, texted, or emailed you first, treat it as hostile no matter how it looks. Hang up. Open the app yourself, or type the site address by hand. If something is genuinely wrong with your account, it will be visible when you log in through the front door.
Rule two: codes are for entering, never for sharing. A 2FA code exists for one purpose, you typing it into a login screen you opened. Anyone who asks you to read one aloud, no matter who they claim to be, is stealing from you at that exact moment. There are no exceptions, which is what makes the rule usable under stress.
Rule three: urgency is the signature of the crime. Real institutions freeze suspicious activity and wait for you. Only thieves need you to act in the next ninety seconds, because delay is when victims think. The stronger the time pressure, the more certain the scam.
Rule four: verify on a second channel you initiated. Get a strange call about your account? Check the account in the app. Get a wild message from a family member needing money? Call them back on the number you have always had. AI voices have made "I recognized the voice" worthless as verification. The callback habit fixes that permanently.
Then close the loopholes in advance. Use an authenticator app or hardware key instead of SMS codes where possible, because SIM swaps are still routine, I was targeted for one during my crypto years. Never install remote-access software at a caller's request. And decide today that no legitimate person will ever ask you to move funds to a "safe wallet." That request is the endgame of every version of this scam.
The scammers upgraded their tools. The rules that beat them have not changed in twenty years. Fixed rules, decided in calm moments, executed without negotiation. That is the entire defense, and it works at any level of production quality.
One email a week. No fluff.
The best of the daily articles, plus what I am seeing across 20+ DTC ad accounts. The only channel no platform can take away.
Subscribe free →