Fake Robinhood OTP Text Scam: The Exact Wording Scammers Use
If you searched for the text you just received, here's the short answer: the OTP code in it is very likely real, but everything else in the message is not from Robinhood. This is a live phishing pattern that combines a genuine one-time password with a fake "support" phone number, and it's currently one of the most searched-for scam texts online. Below are the exact message templates in circulation, why the real code makes the scam convincing, and what to do depending on whether you already called the number.
Over the past few weeks, we've seen a spike in searches for the exact wording of a specific text message: something claiming to be from Robinhood, mentioning a one-time password or a newly connected API key, and asking the recipient to call a phone number if they didn't authorize it. If you're reading this because you just got one of these texts, the message below is almost certainly the same pattern, and the phone number in it does not belong to Robinhood.
The Exact Text Messages Circulating Right Now
Here are the message templates as they've been reported, reproduced exactly so you can compare against what you received. Scammers rotate the phone number and the OTP digits, but the structure and wording stay nearly identical.
Variant 1: Fake New API Key Connected
"Robinhood account notification: a new API key (phantom-integration) has been successfully connected to your Robinhood account with trading and transfer permissions enabled. If this activity was not initiated by you, contact Robinhood right away by calling +1 888-577-8805."
Variant 2: Fake One-Time Password for a Withdrawal
"Robinhood: your one-time password (OTP) is 622815. Please do not share this code with anybody. Wasn't you that requested this withdrawal? Contact us at +1 (888) 895-3189 immediately."
"Robinhood: your one-time password (OTP) is 256618. Please do not share this code with anybody. Wasn't you that requested this withdrawal? Contact us at +1 (888) 874-3013 immediately."
Variant 3: Short-Form New API Key Alert
"Robinhood: new API key detected on your account. If this not you, call us right away +1 (888) 658-8246."
Notice the pattern: three different phone numbers, two different framings ("new API key connected" and "OTP for a withdrawal"), but the same closing instruction every time, call this number if it wasn't you. That closing line is the actual attack. Everything before it exists only to create urgency. For the broader pattern behind these messages, including versions with fabricated IP addresses and wallet hashes, see our full breakdown of the Robinhood text scam.
Already called one of these numbers?
Tell us what happened and we'll help you lock down the account and trace any funds that moved. Speed matters most in the first hour.
Why the OTP Code in the Text Is Often Real
This is the part that makes the scam so effective, and it's the question we get asked most about this specific pattern: if it's a scam, why does the six-digit code actually match what I see in my account or app?
The answer is that the scammer isn't sending you the OTP. Robinhood is. Here's the mechanic step by step:
- The scammer already has your phone number or email, usually harvested from a previous data leak, a phishing site, or a purchased leads list.
- They start a real login attempt or password reset on your actual Robinhood account, entering your phone number into the real app or site.
- Robinhood's real system sends a real one-time password to your real phone, exactly as it's designed to do.
- Within moments, a second text arrives from the scammer impersonating Robinhood, telling you a withdrawal or API key change is in progress and to call a number to stop it.
- You call, believing you're protecting your account. The person on the other end, posing as "Robinhood security", asks you to "verify your identity" by reading back the code you just received.
- The moment you read the code aloud, the scammer enters it into the real login flow they started in step 2, completing their own access to your account.
This technique is a form of real-time phishing sometimes called OTP relay or OTP interception. It's not unique to Robinhood: the same mechanic has been documented against Coinbase, Binance, and traditional bank accounts. The brand name in the text is whatever platform the attacker is currently targeting; the six-step process behind it doesn't change.
The Red Flags, Even When the Code Looks Real
- The callback number is never Robinhood's real support line. Robinhood's official number is published only on its own app and website, never inside a text message.
- Legitimate OTP texts never ask you to call anyone. A real one-time password message tells you the code and tells you not to share it. It has no phone number and no call-to-action.
- Urgency language: "right away", "immediately". Real security systems lock the account automatically if something looks wrong; they don't rely on you calling within minutes.
- A support agent asking you to say the code out loud. No legitimate platform's support process ever requires you to read a one-time password to an agent. That single request is the whole scam.
What to Do If You Already Called the Number
If you called and read out a code, treat the account as compromised right now, not later.
- Open the official Robinhood app directly (not any link from the text) and change your password immediately.
- Revoke every active session and API key under account security settings. The "phantom-integration" API key mentioned in Variant 1 is a real category of access that, once granted, can move funds without further confirmation.
- Enable app-based two-factor authentication instead of SMS, so a stolen text code alone can no longer complete a login.
- Check for pending withdrawals, including any transfers to an external crypto wallet or exchange. Attackers frequently route stolen brokerage funds into crypto specifically because it moves fast and is harder to reverse through a bank.
- If funds have already left the account, especially into cryptocurrency, get a transaction hash and contact a blockchain forensics team immediately. The earlier a transfer is traced, the higher the chance of identifying the receiving exchange and requesting a freeze before the funds are cashed out.
What to Do If You Only Received the Text
If you got the message but haven't called the number or clicked anything, you're likely still safe, but confirm it rather than assume it.
- Log into Robinhood directly through the official app and review recent login activity and connected API keys.
- Do not call the number in the text, and do not reply to it.
- Report the message to Robinhood's official support channel and delete it.
- If the same number or wording shows up again, it's worth screenshotting: this exact pattern is actively being tracked by security researchers and reporting it helps get numbers shut down faster.
This Isn't Just a Robinhood Problem
The brand changes, the technique doesn't. The same OTP-relay mechanic has been used against crypto exchange accounts directly, where the stakes are often higher because crypto transfers can't be reversed the way a bank wire sometimes can. If you hold assets on Binance, Bybit, Coinbase, or any exchange linked to the same phone number, treat any unexpected OTP or "new device connected" text with the same suspicion, verify only through the official app, never by calling a number from the message itself.
The one rule that stops this scam every time
No legitimate platform will ever ask you to read a one-time password to a support agent, on any channel, for any reason. If a message or a phone call asks you to say your code out loud, the conversation is the attack. Hang up, open the official app directly, and secure the account from there.
Frequently Asked Questions
Is a text saying "Robinhood: your one-time password (OTP) is..." real?
Why would scammers send a real OTP code if they're the ones scamming me?
I called the number and gave them information. What do I do now?
I only received the text and didn't call. Am I safe?
Does this scam only target Robinhood users?
My crypto exchange account was drained after a scam like this. Can it be recovered?
Get a Free Assessment of Recovery Chances
Send your TX hash or case description — honest answer on recovery chances within 15 minutes.