You post a complaint in a signal group, and minutes later an 'admin' with the same avatar and a near-identical username offers to help. It is not the admin — it is someone who watched you post. One rule defeats the whole script: verified support never messages first, and never asks for a secret.

The message that arrives too fast

You post in a signal group. Maybe a question — "my entry never filled, is TP1 still valid?" Maybe a complaint — "third losing call this week, how do refunds work?" Either way, you have just told a room full of strangers two things: you use this channel, and right now you are frustrated or confused.

Minutes later a direct message lands. The sender has the channel's avatar. The display name reads exactly like the admin you have seen post pinned updates. The username is almost right — one extra letter, a swapped l for a capital I, an underscore that was not there before. The message is warm and helpful: "Hi, I saw your message in the group, sorry for the trouble — let me sort this out for you."

That is the whole scam, and it is already most of the way to your money. Everything after this point — the "verification portal," the "secure wallet migration," the request to read back a code — is just the closing sequence. The opening move, the unsolicited DM, is the part you can catch for free, before a single secret leaves your hands. This piece is about the shape of that opening move and the one rule that ends it.

Why does support never message you first?

Start with the single fact that collapses the entire script: real support does not initiate a private message.

This is not a ChainRated opinion. It is written plainly on the security pages of the exchanges themselves. Kraken's scam-protection guidance (accessed August 2026) states that its support team will never ask for your password, for the removal of 2FA methods, or for remote access to your device, and steers users toward bookmarked links and verified tickets rather than incoming contact. Coinbase's technical support and impersonation guidance makes the same point: legitimate staff will not reach out to ask for credentials, codes, or a transfer to a "safe" wallet. Binance has repeatedly warned that its representatives will not DM users first or request credentials; an unsolicited message claiming to be staff is, by their own statement, an impersonator.

The same holds for a signal channel's admin. A genuine operator handles support in the open group, through a pinned contact method, or through a ticket link that you go to — not by sliding into your DMs the instant you look unhappy. When a channel's own posts describe how support works, they are telling you what the real thing looks like; anything that does not match is the tell. This is exactly why reading a channel's pinned message and other red flags before you ever pay is worth the two minutes — it is where the real contact route is supposed to live.

So the first half of the rule is simple: an unsolicited first DM offering help is, on its own, enough to walk away. You do not need to prove the account is fake. The direction of contact already did.

How does the impostor look so convincing?

The reason people fall for this is not stupidity. It is that the fake is engineered to pass a glance, and a glance is all most of us give a Telegram profile.

Here is what the impersonator copies, and where each copy breaks:

  • The avatar. Identical, because they saved the real admin's photo and re-uploaded it. A profile picture is public and proves nothing about who holds the account.
  • The display name. Also identical — display names are free text and can be set to anything, including the real admin's name character for character. Two accounts can carry the same display name at the same time.
  • The username (the @handle). This is the one thing that must be unique on Telegram, so it is the one thing they cannot copy exactly. So they get close: @Chain_Support becomes @Chain__Support; a lowercase l becomes a capital I that renders nearly the same; a 0 stands in for an O. Coinbase's write-up on how scammers target Discord and Telegram communities describes exactly this pattern — impostors who mirror an admin's name and photo and operate from a handle that differs by a character.
  • The "admin" or "verified" label. Faked with an emoji in the name, or a claim in the bio. Telegram does not grant blue-check style verification to ordinary channel admins, so a badge you see inside a display name is decoration, not proof.

The defense is not to become a forensics expert. It is to notice that none of the things they copied are the things that matter. Avatar, name, even a convincing bio are all skin. The only identity signal — the exact username — is the one they had to alter, and the alteration is the fingerprint. When in doubt, go back to the group, open the message the real admin actually posted, and tap through to that profile. Compare the handle letter by letter. If the DM came from a different handle, the DM is not the admin.

What are they actually steering you toward?

The DM is the door. Past it, every version of this scam is trying to extract one of a small number of things, and all of them are secrets that real support has no reason to want. The U.S. Federal Trade Commission's guidance on tech-support impostor scams names the core move: an impostor manufactures a problem only they can fix, then asks you to hand over access or move your money to "protect" it.

In crypto the asks are specific:

  • Your seed phrase or recovery words, framed as "we need to restore/verify your wallet." Anyone with your seed phrase owns the wallet, permanently. No legitimate party ever needs it.
  • A 2FA or login code read back to them. A common variant: "we just sent a verification code to confirm it's really you — can you paste it here?" The code they triggered is the login to your account; reading it back hands them the door.
  • API keys for your exchange, sold as "connecting you to priority support" or "migrating your account." A withdrawal-enabled key is a remote hand on your balance — which is the whole reason API keys demand their own security discipline, separate from your password.
  • A "verification" or "sync" link that opens a page dressed as your exchange or wallet and simply captures whatever you type, or prompts a wallet signature that drains it.

The second half of the rule closes here: verified support never asks for a secret — not a seed phrase, not a code, not a private key, not a withdrawal-enabled API key, and never to move funds to a wallet it names. Kraken, Coinbase, Binance, and the FTC all say the same thing in different words. If the person on the other end needs any of those to "help" you, the request itself is the proof, regardless of how right the profile looks.

Why the manufactured hurry?

Notice the tempo of these DMs. There is almost always a clock: your account is "flagged," a "pending unauthorized withdrawal" needs stopping, a "limited-time" fix expires. The urgency is not incidental — it is load-bearing. Hurry is what stops you from doing the ten-second check that would end the whole thing: go back to the group, compare the handle, and remember that support did not message you first.

Real problems with a real channel do not resolve in a panicked DM at the speed of a stranger's typing. They resolve slowly, in the open, through the route the channel published. If a message is engineering speed, that is your cue to slow down, not to comply. The engineered rush is itself a red flag, and it sits alongside the others in our checklist for reading a signal channel.

The check, in the order you can actually run it

When a helpful DM arrives, run these in sequence. You can stop at the first one that fails, because any single failure is enough.

  1. Did they message me first? If yes, stop. Support does not do that. Nothing below even needs checking.
  2. Does the exact username match the admin who posts in the group? Go to the group, open a real admin post, tap the profile, compare the @handle character by character. A near-miss is a miss.
  3. Are they asking for a secret or a transfer? Seed phrase, code, private key, withdrawal-enabled API key, or "send funds to this wallet to secure them" — any of these ends the conversation. No exception exists in which real support needs them.
  4. Is there a clock? Manufactured urgency is a tell in its own right. Slow down instead of speeding up.

If a DM fails even one of these, block and report it inside Telegram and move on. There is no upside to keeping the thread open, and no message you can send that verifies a stranger who opened by breaking rule one.

What if the group itself is the problem?

One uncomfortable case is worth naming. Sometimes the "impostor" is not a lookalike hiding from the admin — it is the channel's own operator running the play from a second account, or an admin who profits when subscribers get drained. A channel whose economics reward sending you somewhere lossy will not police the DMs its members receive. That is not a stretch; it is one of the documented ways signal operations actually earn, where the revenue sits in what happens to you off-platform, not in an honest subscription.

The rule still holds, which is the point of having a rule. It does not depend on the DM sender being an outsider. Whoever is on the other end, if they messaged first and they want a secret, the answer is the same.

The one line to keep

You cannot control whether a scammer copies an avatar, and you cannot control whether they land in your DMs the minute you post. What you can control is whether you answer the door and what you hand through it — and that is where the loss actually happens.

So carry one line and let it do all the work: verified support never messages you first, and never asks you for a secret. Everything the impostor built — the stolen photo, the near-perfect handle, the warm tone, the ticking clock — is designed to get you past that line. It only works if you let it. If the worst has already happened and you handed something over, act on it as an incident, fast, using the steps in what to do after a channel scams you — the sooner you rotate keys, revoke API access, and move funds, the more of the damage stays inside your control.