Skip to main content

How to spot scams and phishing

How to recognise the scams that target Loop users, and exactly what to do if something has already gone wrong.

Loop is non-custodial, which is the point of it: your wallet is yours and nobody else can move what is in it. The other side of that is real. Nobody can undo it for you either, so the defence has to happen before, not after.

Almost every loss we see starts the same way. Someone is helpful, urgent and convincing, and asks for one small thing.

The one rule that stops nearly all of it

Nobody from Loop will ever ask you for your private key, seed phrase, password, passkey, verification code, authentication code, API secret or session data. Not part of it, not to verify you, not in a screenshot, not on a screen share.

Loop does not use a seed phrase at all. There are no recovery words, and you were never given any. So if somebody asks you for your Loop seed phrase, that on its own tells you they are not from Loop.

Nobody from Loop will ever ask you to send funds to verify, unlock, restore or recover a wallet, to transfer assets to a support wallet, to install wallet software or an extension, or to sign something we have not explained.

If any message asks for one of those, it is a scam. There is no exception, and it does not matter who it appears to come from.

Emails saying your security settings changed

There is a phishing campaign using our name right now. The emails claim that something on your account has been switched off and needs to be turned back on, and they give you a button to do it. Wording we have seen includes a claim that two-step verification was paused and can be re-enabled with one click.

Two things give it away.

First, we do not send emails like that. We will never write to you asking you to click through and re-enable a security setting.

Second, look at the sender address rather than the display name. These come from domains that have nothing to do with us. The name in your inbox can say anything at all, and it proves nothing.

Do not click the button. If you want to check something about your account, open the official Loop site yourself in a new tab. Forward us the email with the full sender address if you can, because that helps us get the domain taken down.

A name and a logo prove nothing

Impersonators copy profile pictures, names, badges and roles. They message first, privately, often right after you have posted a problem in public. Real support does not do that.

Reach support through the official channels yourself. Do not trust an unsolicited direct message, even from what looks like a moderator or a team member.

The payment scams, so you recognise them

These come up again and again: a pending fee that must be cleared, a wallet unlock fee, a recovery fee, a verification deposit, a tax or clearance fee, a top-up "for gas" sent to a private address, a fee to release a reward, and someone selling you an invitation code.

All of them are the same scam wearing different clothes. Loop never asks for any of them, and invitation codes are not for sale by anyone.

Signature and connection requests

A signing request can be dangerous even when it shows no transfer. A signature can grant permissions.

Do not approve requests from apps you do not know, messages you do not understand, unexpected delegations, requests whose details differ from what you intended to do, anything opened through a link someone sent you, or anything presented to you by "support".

If you cannot explain what a request does, do not sign it. Nothing is lost by refusing and checking first.

If you have already shared a credential

Act now, and do not be embarrassed. This happens to careful people.

Stop using that credential. Do not send it to us, and do not send us part of it. Message us straight away and tell us what was shared and where.

We will be honest with you about what follows: we cannot freeze assets or reverse anything on the network. What we can do is look at what has happened and help you protect whatever you still control.

If you see a transaction you did not authorise

Message us immediately. Do not sign, approve or cancel anything else while you wait.

Send us your public wallet address, the transaction hash, roughly when it happened, the asset and amount, and the destination address if you can see it. Tell us whether you recently approved any connection, delegation or signature request, and whether you were dealing with any site, bot or person that now seems suspicious.

Again, honestly: we cannot freeze, cancel, reverse or recover a network transaction, and we will not tell you otherwise. We can read the record and tell you what happened, and that is often the difference between stopping the bleeding and losing more.

Reporting a fake site or account

Do not click further links, do not reply, do not send funds, do not sign anything, and do not delete the messages.

Send us the URL, the username, screenshots and roughly when it happened. Reporting it protects the next person as much as you.

Related

Did this answer your question?