Scam awareness · safety first
How scammers find you
Scammers don’t need your data — they create the crisis. Learn the channels they use to reach people with forgotten wallets, and the simple rule that blocks most of them.
By Robbert Bink · ~6 min read · Published 13 August 2026 · Last reviewed: 13 August 2026
Scammers don’t find you — they place themselves where you’re already looking. Paid ads on recovery searches, fake “support”, DMs after you post a question, and fake tool downloads are the four main channels. One rule blocks almost all of them: never share your wallet file, your seed phrase or remote access with anyone who contacted you first.
Before you click anything, run the red-flag checklist and read why online “crackers” can’t work.
They advertise where you search
Search “wallet password recovery” or “btcrecover” and the paid results are often scam pages: recovery “services”, lookalike domains one letter off the official name, or fake tool download sites. Scammers dominate these keywords precisely because desperate people click them.
- Check the exact domain — typosquats (one letter changed, a different TLD, a hyphen) are the tell.
- Only use official sources — the tool guide links the real btcrecover, hashcat and John repositories, and nothing else.
- Treat every paid ad as hostile until you have verified the business independently.
They pose as support
Post a question about a wallet and the DMs arrive: “we’re from the official wallet team”, “we need to verify your account”, “send your recovery phrase to confirm”. Real wallet teams never DM you first, never ask for your seed, and never ask you to “verify” by sending files or phrases.
- Official support is on official channels only — the app itself, the official docs, verified accounts.
- A DM from “support” is a scam until proven otherwise — and it never needs your seed to prove anything.
- Never install a “support tool” they send you — that’s how malware lands on your machine.
They hunt in comments and forums
Recovery threads attract “I know a guy” posts, fake success stories and shills who redirect you to a paid service. The pattern is always the same: they promise what the math doesn’t allow, then ask for the file or the fee. The red-flag guide shows exactly what that looks like.
They build fake tools
“Wallet password hacker” downloads, fake mirrors of btcrecover or hashcat, and “online unlocker” sites that ask you to upload your file. The first bundle malware; the last one collects your wallet file. The real tools are free, open source, and run offline — see which tool to use and why online “crackers” can’t work.
The pattern behind all of it
Every one of these channels runs the same four-step play:
- Urgency — “act now”, “your wallet is at risk”.
- Secrecy — “don’t tell anyone”, “don’t use other services”.
- Payment — an upfront fee, a “deposit”, or an “insurance”.
- Access — your file, your seed, or remote access to your machine.
If a conversation hits any two of those four, it is a scam until proven otherwise.
The simple rule that blocks most of it
- Official sources only — repositories, docs and the app itself, nothing found in ads or DMs.
- Never share the seed phrase — for any reason. Never share the file or the hash with someone who contacted you first; a written, trusted recovery process is the only exception.
- Never allow remote access — real recovery runs on your copy, offline.
- If they contacted you first, it’s a scam until proven otherwise. Legitimate services don’t hunt for desperate clients.
Frequently asked questions
How do scammers find me if I haven’t posted anything?
They don’t need your posts. Paid search ads, typosquat domains and fake tools reach people who search for recovery terms; fake “support” hunts in public threads and social channels. The crisis itself makes you findable.
Are Google or Bing ads for wallet recovery services legitimate?
Treat every paid recovery ad as hostile until proven otherwise. Scammers dominate these keywords precisely because desperate people click them. Check the real domain, check the business, and never upload anything.
Is it safe to download btcrecover or hashcat from a random site?
No. Fake mirrors bundle malware. Download only from the official repositories and documentation — the tool guides on this site link exactly those, and nothing else.
Why do scammers want my wallet file if they can’t crack it?
Your file is valuable even without a cracked password: it can be sold, used in future attacks, or combined with other leaked data. It can also be uploaded and stored without your knowledge. Never share it.
Sources & references
Keep going — it’s all free
Your wallet file stays on your machine
Everything that works runs offline on your own computer, with official tools and your file in your hands. Start with the tool comparison, then follow the walkthrough for your case.