Coinbase scam calls come from criminals posing as Coinbase support or security staff, and Coinbase says it will never make an unsolicited phone call to a customer or ask you to move your crypto. If a “Coinbase” caller tells you your account is under attack, hang up, open the Coinbase app yourself, and lock your account from the Security settings if anything looks wrong.
The rest of this guide explains how the fake calls usually unfold, why the callers often know so much about you, and the exact settings that make a drained account much harder.
Does Coinbase ever call you?
Not out of the blue. Coinbase’s help center lists what its agents will never do: ask you to “secure, move, or access your funds,” give you a seed phrase or ask for yours, ask for your password or 2-step verification code, ask you to install software, or remotely access your device. The same page says Coinbase will never call or text you “to give you a new seed phrase or wallet address to move your funds to,” and that Coinbase “DOES NOT offer insurance products,” a detail that matters because some callers pitch fake “account insurance.”
Coinbase’s April 2025 consumer-protection post puts it bluntly: “Coinbase will never call you out of the blue.” If you want to talk to Coinbase, you start the contact through the Help Center or the app, never through a number someone sends you. The help center warns that “Coinbase will never ask you to contact an unknown number to reach us.”
One caveat: the caller ID proves nothing. Coinbase notes that “scammers can spoof legitimate phone numbers”, so a call that shows a real Coinbase number can still be fake.
How a fake Coinbase call works
Coinbase published a minute-by-minute reconstruction of a typical case in February 2025. Condensed:
| Time | What happens |
|---|---|
| 3:22 pm | A text says a Bitcoin transfer was suspended for fraud and asks you to press 1 or 2. |
| 3:23 pm | A caller claiming to be “Coinbase Security” reads back your address, email, part of your SSN and your balances to prove they are real. |
| 3:25 pm | The caller tells you to install Coinbase Wallet, a real self-custody app, and calls it a “secure wallet.” |
| 3:35 pm | You are walked through moving your crypto into that new wallet. The caller either supplies the seed phrase or asks you for it. |
| 4:05 pm | The funds appear in the wallet, which builds trust. The caller asks about other wallets, such as a Ledger. |
| 4:25 pm | Everything is drained. Because the scammer had the seed phrase, they controlled the “secure wallet” from the start. |
The pattern has variations. Some callers ask for a one-time code “to verify you,” which actually approves a sign-in or a withdrawal. Some send a link to a cloned login page. On-chain investigator ZachXBT reported in February 2025 that scammers were cloning the Coinbase site “nearly 1:1” and sending emails with fake case IDs. What stays constant is the ending: you are told to move funds somewhere “safe,” and that somewhere belongs to the scammer.
Why the callers know your details: the 2025 Coinbase data breach
On May 15, 2025, Coinbase disclosed that criminals had bribed and recruited overseas support agents to pull customer data for exactly this kind of social engineering. Coinbase said it affected fewer than 1% of monthly transacting users, and a filing with the Maine attorney general put the number at at least 69,461 people, with data access running from December 26, 2024, into early May 2025.
According to Coinbase, the stolen data included names, addresses, phone numbers and emails; the last four digits of Social Security numbers; masked bank account numbers; government ID images; and account balance snapshots and transaction history. Coinbase said login credentials, 2FA codes, private keys and customer funds were not taken. The attackers demanded $20 million, Coinbase refused and set up a $20 million reward fund instead, and its SEC filing estimated $180 million to $400 million in remediation costs and voluntary customer reimbursements. In December 2025, Indian police arrested a former support agent in Hyderabad in connection with the breach.
The practical lesson: a caller who knows your address, balance and last four SSN digits is not proving they work at Coinbase. That information has been for sale. Even before the breach was public, ZachXBT estimated that Coinbase users were losing about $300 million a year to social-engineering scams, including $65 million in the preceding two months.
Coinbase support scam red flags
Any one of these is enough to end the call:
- The call is unexpected. Coinbase does not cold-call customers.
- You’re told your account is compromised and you must act now. Urgency is the tool; Coinbase’s own post lists panic tactics as a red flag.
- They ask for a code, password or seed phrase. Coinbase never asks for these.
- They want you to move crypto to a “secure,” “safe,” “vault” or “new” wallet or address. This is the theft itself.
- They ask you to install an app or screen-sharing tool. Coinbase agents never remotely access your device.
- They mention insurance, a regulator or law enforcement. Coinbase says fraudsters impersonate regulators and police too.
- They send a phone number or link to “reach support.” Real support is reached from inside the app or Help Center.
The FTC’s general rule for crypto applies here as well: scammers pose as trusted companies, claim your account is compromised, and tell you to move money “for protection.” Our 12-point checklist for protecting your accounts covers the same habits across banks and other apps.
How to lock your Coinbase account
If you think someone has your password, you gave out a code, or a caller has been talking you through steps, lock the account first and investigate second. Coinbase’s help center gives these steps:
In the mobile app: open the menu, go to Account & settings, then Security, then Lock Account, and confirm.
On the web: sign in at Coinbase.com, go to the account security page, and select Security, then Lock Account.
What locking does, per Coinbase:
- It signs you out on all devices.
- You can still sign in, review transactions and contact support.
- Trading, sending, receiving and account changes are paused.
To unlock, you sign in, pass 2-step verification and choose Unlock account. If the lock was set from a different device or by Coinbase, you have to verify your identity. After unlocking, crypto sends stay paused for 24 hours, which gives you a short buffer if something is still wrong.
Locking stops future moves from your Coinbase account. It does not recall crypto that has already left, and it does not protect funds you moved into a self-custody wallet whose seed phrase someone else has.
Settings that make a fake Coinbase call fail
Locking is the emergency brake. These settings make the scam much harder to pull off in the first place:
| Setting | What it does | Source |
|---|---|---|
| Security key or passkey for 2-step verification | Coinbase recommends it over other methods; there is no six-digit code a caller can talk you out of. | Coinbase Help |
| Address book allowlist | Limits sends to addresses already in your address book; a newly added address only becomes usable after 48 hours. | Coinbase Help |
| Separate email used only for Coinbase | Makes phishing emails to your everyday inbox easier to spot. | Coinbase blog |
| Delete unused API keys | Removes access you may have forgotten you granted. | Coinbase blog |
| Review active sessions and devices | Shows web sessions, apps and devices signed in, so you can remove unknown ones. | Coinbase Help |
| Secure the email account itself | Coinbase advises 2-step verification on your email and checking for forwarding rules you didn’t set. | Coinbase Help |
The allowlist is the one that most directly defeats the “move it to a safe wallet” script: to turn it on, you go to Settings, then Allow list, and follow the prompts. Turning it off also takes 48 hours (unless you do so within 8 hours of switching it on), so a scammer on the phone cannot simply have you disable it and send the funds in the same call. You need your 2-step verification method to change it.
If you already talked to a fake Coinbase caller
- Hang up. Do not call back on any number the caller gave you.
- Lock your Coinbase account using the steps above.
- Email Coinbase security. The help center tells people contacted by suspected scammers to disconnect and email security@coinbase.com.
- If you moved crypto into a wallet the caller helped set up, treat that wallet as compromised. Anyone who has the seed phrase controls it.
- Change your Coinbase and email passwords and switch 2-step verification to a security key or passkey.
- Report it. The FTC lists ReportFraud.ftc.gov, the FBI’s ic3.gov, and your exchange as places to report crypto fraud. Keep screenshots, transaction IDs and the times of calls.
Our step-by-step for the first hour after money is stolen covers banks, cards and police reports in more detail.
A word on recovery offers: after a loss, some people get calls from “recovery” services promising to trace and return stolen crypto for a fee. The FTC’s advice that only scammers demand payment in crypto up front applies to them too. If a large sum is involved, a lawyer you find yourself, not one who contacts you, is the right person to ask about options.
What to watch out for
- Real data, fake caller. After the 2025 breach, some fake callers can quote genuine account details. Treat accuracy as a warning, not reassurance.
- Real apps used as the trap. Coinbase Wallet is a legitimate app. The scam is not the app; it is someone else knowing the seed phrase.
- Texts that start the chain. In Coinbase’s reconstruction, the first contact was an SMS asking you to press a key. A text that invites a callback is the same scam.
- The scale. The FBI’s 2025 Internet Crime Report counted over $11 billion in cryptocurrency-related losses reported in 2025. Exchange impersonation is one of many routes into that total.
- Reimbursement is not automatic. Coinbase said it would voluntarily reimburse retail customers who sent funds to scammers as a direct result of the 2025 incident before its May 15, 2025 post, after a review. That was a one-time decision tied to that incident, not a standing guarantee.
How we checked this
We built this guide from Coinbase’s own help center pages, security blog posts and SEC filing, the FTC’s crypto scam guidance, the FBI’s 2025 Internet Crime Report, and reporting from TechCrunch, CoinDesk and BleepingComputer. Menu names in the Coinbase app can change, so follow the help center if the labels differ. Facts checked on September 25, 2026.




