The Call That Almost Had Me Fooled: A Crypto Phishing Story

Vested Partners A Multi-Family Office Blog

Fishing hook attached to a paper with login credentials
I spend my career helping people protect their money. Today, I was reminded that even knowing what to look for doesn't make you immune.

I manage money for a living. I coach clients on fraud risk, cybersecurity hygiene, and avoiding financial scams. And just today, I nearly got taken anyway. Here’s what happened, and more importantly, what to watch for if it happens to you.

It started with an email that appeared to be from Coinbase security, alerting me that someone had requested a phone number change on my account, something I had not done. The email looked real. The concern felt real. So I called the number provided. That was my first mistake.

The person on the other end was professional, calm, and knowledgeable. They walked through a detailed fraud investigation script, asking about recent logins, whether I’d used public Wi-Fi, and whether I’d shared my credentials with anyone. They described a suspicious login attempt from overseas and explained that my two-factor authentication may have been bypassed. All of it sounded plausible. They even told me my account would need to go through a multi-day “security review,” which would have given them time to work without my interference.

After establishing credibility over 10 to 15 minutes, the representative suggested I temporarily move my crypto assets to a third-party platform called “SafePal,” framed as a safety measure while the investigation was underway, with full insurance and protection guaranteed. For what it’s worth, SafePal is a real and legitimate crypto wallet app, which is exactly what makes it such an effective tool for scammers. Any request to move your assets during a supposed security review is the scam itself.

What ultimately tipped me off was a small detail. While scrolling through the original email, I noticed something odd embedded in the signature, a reference to the LDS Church that had no business appearing in a financial security communication. It was enough to make me stop. I told the representative I was ending the call and would contact Coinbase directly through their publicly listed phone number. They didn’t push back, which was another sign something wasn’t right.

I ended the call, looked up Coinbase’s official support number independently, logged into my account directly through the official website to check my account status, and made a plan to change my password only after confirming I was working with the real Coinbase team.

Here are the takeaways:

  1. Never call a number from a security email. Look it up independently every time.
  2. Legitimate companies will never ask you to move assets as part of a security process. Ever.
  3. Urgency is a weapon. Fraudsters create time pressure so you act before you think.
  4. Sophisticated doesn’t mean immune. The script these callers use is specifically designed to disarm people who consider themselves financially savvy.
  5. One small detail can save you. In this case, an odd signature line in an email was the tell. Slow down and read everything.

If this can happen to someone who spends their career thinking about financial risk, it can happen to anyone. Trust your instincts, verify independently, and never let someone else’s urgency become your decision. If you are ever unsure about an email you receive from us or one of our partners (i.e. Schwab, Altruist, etc.), please call our office before doing anything.

– David

Client Success Stories

Join Our eNewsletter