Crypto
Crypto Fraud and Scam Intake: A Support Playbook
Crypto fraud intake should reduce further harm, preserve what the customer reports, and reach the right owner quickly without promising recovery.

Start with safety and nonjudgmental listening
A person reporting a scam may be distressed, embarrassed, coerced, or still communicating with the suspected scammer. Use plain language, avoid blame, and follow the provider’s urgent script. Ask whether the contact is ongoing, whether account access may be compromised, and what immediate approved protective route applies. Do not tell the customer to confront a suspected fraudster, send more funds, install software, share a screen, or disclose credentials. Never represent an intake conversation as an investigation or a recovery service.
Preserve evidence without collecting secrets
Capture the customer’s own chronology, channels used, names or handles presented, relevant provider references, amounts and assets as reported, destination information if policy allows, screenshots through an approved evidence channel, and steps already taken. Record the source of every fact. Do not request private keys, seed phrases, one-time codes, passwords, or remote access. Preserve original files and timestamps according to policy rather than copying sensitive material into free-form chat notes.
Route by harm and authority
Account takeover, active coercion, suspected impersonation, unauthorized activity, vulnerable-customer risk, law-enforcement contact, sanctions or AML concern, and complaint handling can require different owners. The SEC, CFTC, and FTC publish warnings and reporting routes for crypto-related scams, but provider-specific procedures and jurisdiction control. Support can point to reviewed official resources; it should not decide whether conduct legally constitutes fraud, securities misconduct, a tax event, or a reportable transaction.
Set honest recovery expectations
Crypto transfers may be difficult or impossible to recover depending on facts, provider, asset, network, destination, and legal process. Do not guarantee recovery, reimbursement, tracing, freezing, or law-enforcement action. Explain the provider’s actual process, the information received, the owner assigned, and how the customer will be contacted. Track urgent-route speed, evidence completeness, repeat victimization signals, unsupported promises, abandoned handoffs, and whether sensitive information was protected.
Build the control table
| Control | Support role | Authorized owner |
|---|---|---|
| Customer facts | Capture minimum necessary information | Validate identity and record |
| Explanation | Use dated approved sources | Approve policy and wording |
| Consequential action | Preserve request and route | Decide or execute under procedure |
| Uncertainty | State limits and escalate | Investigate and respond |
Govern knowledge and human handoff
Every answer should point to a dated, owned source. Separate provider policy from public education and customer-specific system facts. Require review for legal, financial, investment, tax, AML, sanctions, fraud, custody, identity, privacy, security, accessibility, and jurisdiction questions. Log the knowledge version, verification state, decision boundary, receiving owner, and customer confirmation. Test handoffs end to end; a generated summary is useful only if the destination can verify its provenance and the customer knows who is responsible.
Test privacy, resilience, and accessibility
Collect the minimum information needed for the approved purpose, use authorized channels, and define access, retention, redaction, recording, consent, export, and deletion controls. Provide accessible interaction, error recovery, a human alternative, and reviewed language support without inventing a language count. Test outages, stale sources, integration failures, duplicate events, rate limits, malicious prompts, attempted secret disclosure, and emergency handoff with synthetic data. Document the result, limitation, owner, and rollback path.
Apply scope and qualified review
This article provides general operational information, not legal, financial, investment, tax, AML, sanctions, fraud, custody, privacy, security, accessibility, or compliance advice. Provider status, transaction, asset, wallet model, customer, jurisdiction, systems, partners, contracts, and current law control. A configured conversational system may assist approved intake and routing, but this article does not claim LumiTalk holds or moves crypto assets, controls wallets or private keys, performs regulated decisions, provides investment or tax advice, clears sanctions or AML reviews, guarantees recovery or compliance, reads live transaction, account, or blockchain state, or provides exact availability, language, or integration coverage.
Primary sources
Use current primary sources as the factual floor, then obtain provider-specific and jurisdiction-specific qualified review. What To Know About Cryptocurrency and Scams · ReportFraud.ftc.gov · 5 Ways Fraudsters May Lure Victims Into Scams Involving Crypto Asset Securities · Customer Advisory: Understand the Risks of Virtual Currency Trading
Continue through the Crypto cluster
Use the hubs and service page for cluster context, then compare adjacent guides before implementing a workflow. Crypto resource hub · Fintech resource hub · LumiTalk for crypto operations · Crypto Customer Support: An Operations Guide · Crypto Account Access and Identity Support · Crypto Wallet and Custody Support Guide
Quick answers
Frequently asked
What should support do first after a crypto scam report?
Follow the provider’s urgent safety script, reduce further disclosure, preserve the report, and reach the designated fraud or security owner.
Can support recover stolen crypto?
Support should never promise recovery; available actions depend on the provider, facts, asset, network, destination, jurisdiction, and authorized specialists.
What evidence is useful?
A customer chronology, contact channels, relevant references, destinations if policy permits, original messages, and actions already taken—without passwords or private keys.
Where can a customer report a crypto scam?
Use provider-specific routes and reviewed official options such as FTC ReportFraud, SEC tips or complaints, CFTC complaints, and appropriate law enforcement.
Crypto Fraud and Scam Intake Playbook
Map one customer journey, its approved source, authority boundary, owner, evidence, and safe handoff before expanding.








