BaitPath

A friend's account got taken over and is asking you for money

Right avatar, right name, right way of talking. There is exactly one way to be sure, and it requires no technical knowledge at all.

Case file cover: high-contrast geometric composition of doubled offset rectangles
File B-12 cover is a programmatic geometric composition and does not depict any real account.

This one succeeds not through clever wording but by bypassing evaluation entirely. You are not assessing a stranger — you are answering a friend, and scrutiny does not switch itself on for friends.

First: compromised account, or lookalike

On your screen they look nearly identical, but they need different checks.

A compromised account is your friend's actual account, operated by someone else. History is real, mutual contacts are real, past conversation is there. Hardest to spot, because apart from the current messages everything matches. It also tends to be wide: several of their contacts may be receiving similar messages simultaneously.

A lookalike is a new account using their photo and name. More visible flaws: recently created, no history, wrong mutual-contact count, sometimes a barely perceptible character difference in the name. If this "friend" only just added you, this is very likely what it is.

Thirty seconds of triage

  • Scroll up. Is there history? When was the last exchange?
  • Check when the contact was added. New, or "added you again", means treat it as a lookalike.
  • See whether your original contact still exists. If both are present, the new one is fake.

Why crypto changes the risk shape

A crypto transfer cannot be reversed once complete, and there is no third party to ask.

Conventional payments sometimes retain a route: a bank dispute, tracing through the receiving institution. Those may fail, but they exist. Once an on-chain transfer confirms, control has moved and no institution can roll it back.

So "send it and sort it out later if something is wrong" does not apply here. Verification has to happen before the transfer, because afterwards there is no second attempt. That is also why this pattern increasingly asks for crypto rather than a conventional payment.

The only reliable move: a separate channel, dialled by you

Do not verify inside the existing conversation. Use a completely independent channel, and initiate it yourself. If you keep one sentence from this page, keep that one.

The reason is direct. If the account is under someone else's control, everything happening in that window is controlled by them. They see your questions, can supply whatever confirmation you request, and can decline a voice note with an excuse. Verifying inside a compromised channel is asking the other side to vouch for itself.

A separate channel means: phone them on the number already in your contacts, not one supplied in the conversation. Or reach them on a different platform. Or ask a mutual friend. What matters is that you start it, and that the route was not mentioned in the current chat.

These do not count as verification

  • Asking for a voice note or video in the same chat. Can be refused, excused, or answered with prepared material. Not a dependable test.
  • Calling a new number they just gave you. They chose the number and they arrange who answers.
  • Asking "is this really you". The answer contains no information.

A line you can copy

If you cannot reach them right away and would rather not be blunt, use this. Its purpose is not to expose anyone — it is to move the decision back to you.

Copy this

"I'm in the middle of something — let me call you later to confirm and we'll sort it then. If it's genuinely urgent, please ask someone else in the meantime."

It does three things at once: no accusation, no explanation, and a checkpoint on your schedule. A real friend will not mind. Anyone else loses the thing they need to keep pushing.

For a harder check, use a detail only the two of you know that has never appeared in any conversation. That second clause matters: anything discussed before is visible to whoever controls the account. Ask about something that happened in person, not something you talked about.

And a caution about the harder check: do not send the shared-memory question through the same chat. Whoever holds the account sees it, and buys time to look for the answer in your history.

How they typically handle being checked

Knowing these in advance matters, because when you hear one it is a signal, not a reason to be accommodating.

Most common is time pressure: needed now, cannot wait, within the next few minutes. Pressure has exactly one function, which is to shorten the interval in which you would check — and no genuine emergency gets worse because you spent three minutes on a phone call.

Next, reasons a call is impossible: broken phone, in a meeting, abroad, bad signal. Each is individually plausible, which is what makes them usable. Do not assess whether the reason is reasonable; look only at the result. If the result is that you cannot verify, stop.

Then, redirecting the recipient: send it to a colleague, or to this address. A friend genuinely borrowing money does not route you to a third party. That one stands almost on its own.

Finally, emotional pressure — either hurt at being doubted, or unusually smooth acceptance. Both are worth noting. Real people react variously to suspicion, but rarely pivot straight to sentiment.

The variant where other people appear to vouch

A harder version of this happens inside a group rather than a private message, and it works by borrowing the group's credibility instead of one person's.

The shape: a request appears in a chat you are part of, and within a short time one or two other accounts respond supportively — confirming the story, saying they have already helped, or simply reacting in a way that makes the request look accepted. What you are watching is not a conversation, it is a scene.

It is effective because it changes what you are evaluating. Alone, you would assess a claim. In a group, you are assessing a claim that other people seem to have already assessed, and that shortcut is very hard to switch off deliberately.

Two things make it checkable anyway. Look at who is agreeing. Accounts that are new to the group, quiet until now, or that you cannot independently place are not corroboration. And the vouching is always fast — genuine responses to an unusual request are scattered and hesitant, not prompt and aligned.

The rule does not change

Corroboration inside the channel is not verification of the channel. If the group itself is the thing being exploited, everything happening inside it is available to whoever is running it. The same answer applies: leave the conversation and reach the person through a route you opened yourself.

Sounding like them stopped being evidence

This used to be where these attempts failed: stilted phrasing, the wrong nickname, different punctuation habits. Many people still rely on it, and it no longer holds up.

Two reasons, both concrete. First, whoever has the account has your entire conversation history. A few screens back shows how you address each other, what you discuss, and the register you use. Copying a style with that much reference material is not difficult.

Second, rewriting text into a different voice is now cheap. There is no need to discuss tooling — only to accept the conclusion: writing style is no longer a working defence.

So shift the weight of judgement from "does this sound like them" to "is the shape of this request right". Shape means the parts that do not depend on wording: is money involved, where is it going, can you verify through another channel, how urgent is it. Those cannot be imitated, because they are behaviour rather than expression.

In one line

"It sounds exactly like them" is no longer usable as proof. Only one thing is: you opened an independent channel and reached the actual person.

Signals that need no verification at all

Any one of these ends the conversation

  • Crypto is requested, and you have never dealt that way with each other. First on the list.
  • The receiving address or account is not theirs. Any form of "send it to someone else".
  • The amount sits just below where you would stop to think. That is deliberate, to suppress the impulse to check.
  • You are asked not to tell anyone. Borrowing money needs no secrecy; the request exists to cut off your cross-checks.
  • A neutral greeting arrives first, then the ask. Standard opening — it confirms the account is live and that you reply.

These sit alongside the other impersonation patterns. The full taxonomy is in the five shapes a crypto scam takes; to compare exact phrases against known structures, use the script matcher.

If the money has already gone

Stated plainly: we do not promise recovery is possible. What follows is general sequence, not an outcome.

First, stop. These attempts usually come with a second request — wrong amount, needs resending. What is lost is settled; what is next is not.

Second, preserve everything: conversation screenshots with account details and timestamps, transfer records, the address or account used, and any contact details supplied. Capture context, not just the key lines.

Third, reach the real person and tell them their account may be compromised. The value here is less for you than for the other people on their contact list.

Fourth, report according to the rules where you live, and file with any platform involved. Procedures differ by jurisdiction. The branching version — by asset type and current state — is in the first 72 hours checklist.

Do not do this

Do not engage any recovery service. Anyone who contacts you after a loss promising to get funds back is the most concentrated second-scam channel there is — they are working from a list of people who have demonstrably paid once and badly want to fix it.

If the account taken over is yours

Regain control first, notify contacts second. Reversed, your clarification can simply be deleted by whoever still holds the account.

Regaining control means: change the password from another trusted device, sign out all other sessions, review and remove unfamiliar devices and login methods, and confirm the linked phone number and email have not been changed — that last one is the most commonly missed, and if they have been altered a password change alone is not enough.

Once you have it back, tell your contacts the window of time involved and what was sent in your name. If the account is linked to any trading platform, check the security settings there too — particularly two-factor and withdrawal settings, covered in SMS, authenticator app, hardware key.