These are not conclusions we invented. They are boundaries platforms state repeatedly in their own security material. Putting them in one place is useful because when any single one is crossed, you can stop the conversation without evaluating anything else.
Why remembering "never does" beats remembering "scammers say"
Because one list is finite and the other is not.
Scripts get refreshed constantly — new hook, new identity, new reason. Remember ten and the eleventh works. Platform boundaries are set by how the business actually operates, and they do not bend for an individual user. If something falls outside them, the packaging is irrelevant.
This is also why the page is a list. You will need it while distracted, hurried, or half-awake — conditions unsuited to reading prose and well suited to checking items. The tickable companion is the official source checklist.
1 · Never contacts you first, and never messages you privately
Contact runs one direction: you initiate from inside the official app or site, and support answers there. There is no process in which support adds you on a social app, messages you in a group, or rings from an unknown number about a problem with your account.
The most overlooked part is the trigger. Many people are not picked at random — they asked a question publicly, left contact details, or mentioned which platform they use. The gap between a public request for help and an incoming private message is often very short. Full breakdown in how fake support finds you.
If it happens
Do not reply, do not open links, do not add anyone. If you are genuinely worried about your account, close the conversation, open the official app yourself, and raise it through the in-app support entry. A real problem is visible there. If it is not visible there, there is no problem.
2 · Never asks for a code, password, seed phrase or private key
What these four share: the platform either already has it, or should never have it. A one-time code was sent by the platform, so it does not need reading back. A password is stored irreversibly and support cannot see it. A seed phrase and private key belong to a self-custody wallet, a separate system entirely.
Requests are packaged as procedure — verifying identity, clearing a flag, assisting your transaction. Do not weigh the reason. Look at what is being requested.
On seed phrases, absolutely: other than you restoring your own wallet in a wallet application, any page or person asking for a seed phrase is a scam, without exception. Why it is equivalent to the assets themselves is in why a seed phrase must never be photographed.
If it happens
Stop immediately. If you already gave out a code: change the password, review and end other sessions, and confirm your withdrawal whitelist and two-factor settings have not been altered. Cut off access first, work out how it happened second.
3 · There is no such thing as a "safe account"
No platform asks you to move assets to a safe account, protected account or secured address. Operationally it makes no sense: if a platform assesses an account as risky, it restricts that account — it does not ask you to send the contents elsewhere.
The script works because it reframes the highest-risk action available — moving assets out — as protection. The direction is reversed, and reversed directions are hard to notice under stress.
Worth memorising verbatim
Any instruction to move assets out of your account "to protect them" is a description of the loss itself. Genuine protective measures never require you to transfer anything.
If it happens
Do not transfer; end the conversation. If you are concerned, open the official app yourself and review login history and device list. Freeze the account or disable withdrawals if you want to — those controls exist and need nobody's involvement.
4 · Never asks for remote access to your device
No support process requires remote assistance software, screen sharing, or you following spoken instructions step by step. Technical support happens in their systems; they have no need to see your screen.
This one is more dangerous than the others because it cancels them. Once someone can see your screen, codes are visible as they arrive, two-factor is bypassed in effect, and they can complete an entire operation in front of you while you believe a problem is being fixed. Screen sharing silently voids "never tell anyone your code".
If it happens
Refuse, without explaining. If software is already installed: disconnect from the network, uninstall it, then change your password and review active sessions from a different device. Not from the device that was accessed.
5 · Never promises a certain return
When a legitimate platform describes anything yield-bearing, it describes the risk and the uncertainty alongside it — that is a compliance requirement. So any framing of a return as certain — capital protected, guaranteed, fixed daily, risk-free arbitrage — cannot be coming from the platform officially.
This also covers "campaigns", "internal channels" and "limited-time products" presented in a platform's name. What matters is not the size of the number but whether it is stated as certain. Certainty is the defect. Recognition method in three tells shared by every high-yield platform.
If it happens
Search the campaign name inside the official app. A real campaign is findable through official channels; one you cannot find does not exist. Do not check via a link they supplied — that is letting them supply their own evidence.
6 · Never collects payment through a private channel
Platform fees are charged one way: deducted within your account. No personal payment details, no designated third-party account, no additional charge for deposits, unlocking, tax, verification or expediting.
This one usually appears last, and often after a loss: funds cannot be withdrawn, and a payment is required first. Its purpose is not the money — it is confirming you will still pay. The same logic drives recovery-service scams, covered in your account got frozen, what to do first.
If it happens
Do not pay, and treat the request as the finding. No legitimate process requires paying to get your own money back. If you have already paid once, there will be another — stopping here matters more than recovering the last one.
Quick reference
Everything above, compressed. Scan the middle column when something is happening; if anything matches, do what the right column says.
| Boundary | What crossing it looks like | What to do |
|---|---|---|
| No unsolicited contact | Unknown number, social app add, group DM, claiming to be staff | End it; ask again yourself through in-app support |
| No credential requests | Wants a code, password, seed phrase or key — usually as "verification" | Stop; if a code was given, change password and end all sessions |
| No safe account | Move assets to a "protected" or "secure" address | Do not transfer; check login history yourself, freeze if needed |
| No remote access | Install remote software, share screen, follow spoken steps | Refuse; if installed, disconnect, uninstall, change password elsewhere |
| No guaranteed returns | Capital protected, fixed daily, risk-free, "internal" campaigns | Search the campaign in the official app; absent means non-existent |
| No private billing | Personal payment details for deposits, unlock fees, tax, verification | Do not pay; treat the request itself as the conclusion |
A note on using it under pressure. The table is designed to be read while something is happening, which means reading only the middle column. Do not start at the left and work across; start by looking for anything that matches what is currently being asked of you, and only then read the row it sits in.
That ordering matters because the natural failure here is not missing a rule — it is reading all six, finding them all reasonable, and continuing the conversation anyway. The table is a matcher, not a reminder.
Why six and not ten
Because a checklist's usefulness is inversely proportional to its length. A fifteen-item list is not recalled at the moment you need it, and this judgement is always required when you are distracted, hurried or just woken up.
These six were selected on one criterion: none requires you to judge who the other party is — only to observe what is happening. Anything needing you to assess whether a person is trustworthy or a reason is plausible was excluded, because in a scenario the other side has prepared, your assessment is at a disadvantage.
What got dropped includes "watch for awkward phrasing" and "check whether the profile looks suspicious". Those worked a few years ago and are steadily less reliable: writing style can be copied, profiles can be duplicated. Behavioural boundaries do not shift because someone performs well.
If you keep only one
Anything that requires you to leave the official channel you opened yourself — stop there. Into a DM, another app, a link, an address. Every one of the six crossings passes through that step. It is the one unavoidable junction in the whole structure.
Near-misses: things that feel like violations and are not
A hard-edged list has a cost: it produces false alarms. Four situations trip people regularly, and all four are legitimate. Knowing them keeps the list usable, because a rule that fires constantly gets ignored.
Marketing email from the platform. Product announcements, campaign notices, newsletters — these are ordinary, and they arrive unsolicited by definition. What separates them from a violation is what they ask for: nothing. They inform, they do not request information and they do not contain a field where you enter credentials. Treat the content as advertising and the link as untrusted, and there is nothing to resolve.
Identity verification handled by a third-party vendor. Many platforms outsource document checking, so the flow may hand you to a differently branded interface partway through. This looks alarming and is normal. The distinguishing feature: you were handed there by the official app in a flow you started, not sent a link. If you cannot trace how you arrived, back out and restart from inside the app.
The app asking for device permissions. Camera for document capture, notifications for security alerts, occasionally biometrics. These are requested by the operating system, at the moment they are needed, and are refusable. That is entirely different from being asked to install remote access software — a permission prompt grants a capability to the app you chose; remote software grants control to a person.
A genuine support agent asking for account details. Real support may ask you to confirm identifying information — an account identifier, a transaction reference, when you registered. That is legitimate. What is never legitimate is the specific set in rule two: codes, passwords, seed phrases and keys. The distinction is between details that identify you and secrets that authorise actions.
The test that resolves all four
Ask which direction the interaction started in, and what is being requested. Something you initiated, asking for identifying information, is normal. Something that reached you, asking for a secret or a transfer, is not. Those two questions sort every case above without needing to memorise the exceptions.
Cases that look like exceptions and are not
The list is deliberately hard-edged, so a few normal things need distinguishing from breaches.
Platforms do send notifications. Login alerts, withdrawal confirmations, announcements — normal. The difference is that a notification informs one way: it does not want a reply, does not request information, and does not contain a link where you enter credentials. The right response to any notification is to open the app yourself, not to tap the link inside it.
Identity verification does require documents. But submission happens only inside the official flow, never through a chat app and never collected by a person. Anything you already submitted will not be requested again by support.
Platforms do have promoters. A promoter is not the platform. They may recommend that you register, but the same boundaries apply: no credential requests, no asset transfers to them, no guaranteed returns. We are a promoter ourselves, and these constraints apply to us equally — set out in why "the exchange is giving you X% back" is a warning sign.
One closing point. These six judge behaviour, not identity. You never have to establish who someone is or prove they are fake. If a boundary is crossed, ending the conversation costs nothing — real support does not evaporate because you went and asked again inside the official app.
A last word on why a short list beats a long one. Rules you can recall without looking are the only rules that operate while something is happening, and the situations these six cover are exactly the situations in which you will not be calmly consulting a reference page.
The six are also unusually durable. Interfaces change, scripts change, and the platforms themselves change; what does not change is that a legitimate operator has no working reason to want your key, your code, or your funds in an account it controls. That is a fact about how the systems are built, not about current tactics, so the list should still hold next year.