You get a text. It says your Robinhood account has a new API key linked to an external wallet. It lists an IP address, a date, trade and transfer permissions. It ends with a phone number and the words: "If this wasn't you, please call."

The text looks like something Robinhood's security team would send. The detail level is high. The tone is calm and professional. Your first instinct is to call the number.

Do not call the number.

What the Fake Robinhood Text Looks Like

The message is designed to appear as a routine security notification. It contains specific-sounding technical data to make it feel legitimate. A typical version reads:

Robinhood Security Alert

A new API key has been linked to your account.
Permissions: Trade, Transfer
IP Address: 128.51.100.XX
Linked wallet: 0x7f3a...d92c
Date: January 23, 2026 at 2:14 AM

Safety Reminder: If this wasn't you, please call +1 (888) 497-XXXX

The message avoids any link. That is intentional. Most people know not to click suspicious links. A phone call feels different. A phone call feels like talking to a real person. That is exactly why the scammers chose it.

The technical details serve one purpose: to make you believe the threat is real. An API key. A specific IP address. A wallet address. A precise timestamp. None of it is connected to your actual account. It was generated to look convincing.

Why This Scam Is More Convincing Than Most

Most phishing attempts rely on urgency and fear. This one adds a layer of apparent technical legitimacy. When a message contains an IP address and a wallet hash, it reads like data pulled from a real system. The average person has no way to verify whether that IP or wallet is real.

The absence of a link is also a trust signal in disguise. You have been trained to distrust links in suspicious messages. A number to call bypasses that instinct entirely.

The word "Safety Reminder" softens the urgency. It does not say "Your account has been compromised." It says "if this wasn't you." That phrasing shifts the burden to you. You now feel responsible for verifying rather than alarmed into reacting.

The scam also targets the moment when you are alone and private. A phone call is harder to screenshot, share, or verify against a checklist. Once you are on the call, the pressure escalates fast.

The Most Important Thing to Understand

These texts go out in bulk. Thousands of phone numbers receive the same message on the same day. The sender does not know whether you have a Robinhood account. The sender does not know your name. Your number came from a data breach or a marketing list that has nothing to do with Robinhood.

Receiving this text is not evidence that your account was accessed. It is not evidence that anyone knows you use Robinhood. It is a mass-cast net designed to catch anyone who happens to have an account and panics.

Robinhood has confirmed it is seeing a rise in financial scams and maintains safeguards to monitor and disrupt fraudulent activity. The company does not initiate contact through unsolicited texts asking you to call a phone number.

Free download

First 30 Minutes After Crypto Theft

PDF checklist: 6 steps to take immediately. Every hour of delay lowers your recovery chances.

Download free checklist →

Free · no registration

Report the scam — we'll tell you exactly where to file

Fill in a short form and get a personalised filing guide: FBI IC3, FTC, Interpol or your exchange. Free.

Report a scam →

10 Steps to Take If You Get This Text

1. Do not call the phone number

That number connects directly to a call center staffed by trained fraudsters. They will answer in a professional tone. They will use Robinhood's name, branding, and terminology. Their goal is to extract your login credentials, one-time authentication codes, or approval for a fund transfer. Hanging up is the correct response. Do not engage, do not explain yourself, do not ask questions.

2. Do not reply or click anything

Replying to the text — even with "STOP" or "wrong number" — confirms to the sender that your number is active and monitored. This makes your number more valuable to scammers and will result in more attempts. Do not click any link in the message, even if the link looks like an official Robinhood domain.

3. Check your account directly

Open the official Robinhood app on your device. Do not search for Robinhood online from the message context. Inside the app, check your security alerts, recent activity log, linked external apps, and any API or third-party access settings. If everything looks normal, your account was not accessed. If you see unfamiliar activity, change your password immediately from inside the official app.

4. Enable two-factor authentication

If you have not already turned on two-factor authentication (2FA), do it now. Use an authenticator app such as Google Authenticator or Authy rather than SMS-based 2FA. SMS codes can be intercepted through SIM-swap attacks. An app-based code lives only on your device and cannot be redirected to a scammer's phone.

5. Use strong, unique passwords

Reusing passwords across financial accounts is one of the most common ways accounts get compromised. If your Robinhood password matches any other account, change it. Use a password manager to generate and store a unique, random password. Do not store passwords in notes apps, browser autofill, or cloud documents.

6. Report the scam to Robinhood

Forward the message or a description of it to reportphishing@robinhood.com. Robinhood's security team tracks these campaigns. Each report helps them identify the infrastructure behind the attack and take action. Also mark the message as spam inside your messaging app so your carrier can build detection signals from it.

7. Block the sender number

After reporting, block the number so it cannot contact you again. The number is likely a disposable VoIP line that will be abandoned quickly, but blocking it prevents any follow-up texts. Most messaging apps allow you to block and report in one action from the message thread.

8. Audit your linked apps

Log into your Robinhood account and navigate to the connected apps or API access section. Remove any third-party application you do not recognise or no longer actively use. Old integrations you forgot about can become entry points if those third-party services are later compromised.

9. Screenshot and save as evidence

Before you delete the message, take a full screenshot that includes the sender number and the timestamp. Save it to your photos and back it up. If you later need to file a report with the FBI, FTC, or your state attorney general's office, this screenshot is the primary piece of evidence. You cannot recover a deleted message after the fact.

10. If funds were already moved, act immediately

If cryptocurrency was transferred out of your account before you spotted the scam, time matters more than anything else. On-chain tracing can follow the funds — but every hour of delay makes recovery harder.

Act now · Free initial assessment

Crypto already moved? Start the tracing process now.

On-chain forensics can track funds to centralised exchanges where a legal freeze request can be filed. The window is narrow. Contact us immediately.

Report the scam → Message on Telegram

How Robinhood Impersonation Scams Actually Work

What happens on the other end of that phone call is a carefully scripted process. These operations run like a business. There are scripts, supervisors, and escalation paths for difficult targets.

When you call, the person who answers will introduce themselves using a real-sounding name and a fake employee ID. They will confirm your concern about the API key alert. They will tell you the threat is active and that action is needed immediately to protect your account.

From there, the script has two main paths. The first is credential harvesting: they ask you to verify your identity by providing your email, password, and the 2FA code sent to your phone. Once they have those three pieces, they own your account.

The second path targets crypto directly. They tell you the linked external wallet is attempting a large withdrawal. To cancel it, you need to "confirm" by approving a transaction in your wallet app. What you are actually approving is an outbound transfer to their wallet.

The technical jargon throughout the call is deliberate. Words like API key, transfer permissions, and wallet hash signal authority. Most people do not know exactly what these terms mean in this context, which makes them harder to dispute. Confusion keeps you on the call.

Is This a Sign Your Data Was Leaked?

Not necessarily from Robinhood. Phone numbers travel far from their origin. A number that appeared in a retail data breach three years ago may now be circulating across dozens of marketing lists and data broker databases. Scammers buy these lists in bulk and blast them without knowing who uses what financial service.

That said, it is worth checking. Visit haveibeenpwned.com and enter your email address. The site cross-references known public data breaches and tells you which ones your email appeared in. If you see financial services or crypto platforms on that list, change those passwords and review your accounts.

If your number appeared in a breach, there is little you can do to remove it from the internet entirely. But you can reduce your surface area. Opt out of data broker sites, limit the platforms that have your phone number, and use app-based 2FA so your phone number stops being a security factor.

If you want help understanding whether your information was specifically exposed — or if you suspect your account was actually accessed — use our scam report tool for a free initial assessment.

Frequently Asked Questions