Vishing
Vishing (voice phishing) is a scam where criminals call you by phone, impersonating exchange support, bank fraud departments, or government agencies. In crypto, vishing typically targets exchange users: the caller claims your account is compromised and urgently needs your 2FA code, password, or seed phrase to "protect" your funds. No legitimate support team ever calls to ask for these.
How Vishing Differs from Email Phishing
Email phishing relies on deceptive links and fake websites — it requires the victim to click and navigate. Vishing removes that friction: a real human voice creates immediate pressure. The caller controls the pace, can respond to objections in real time, and can exploit emotional states (fear, urgency, confusion) far more effectively than a static email. Victims who would never click a suspicious link have provided seed phrases verbally under the pressure of a convincing phone call.
In the crypto context, vishing is particularly dangerous because the information targeted — seed phrases, 2FA codes, passwords — grants irreversible access to funds. A successful email phish might require a follow-up action; a successful vishing call can result in the attacker draining a wallet within minutes of hanging up.
Common Crypto Vishing Scripts
Attackers typically run one of three scenarios:
- The fake security alert. "We've detected suspicious login activity on your Binance account from a device in [foreign country]. To protect your funds, I need to verify your identity. Please provide your 2FA code." The sense of active threat, combined with personal details sourced from data leaks, makes this highly convincing.
- The fake account freeze. "Your account has been flagged for compliance review. To prevent permanent suspension, you need to complete verification now. I'll walk you through the process." The caller creates urgency around account closure to override the victim's rational judgment.
- The fake law enforcement or Interpol call. "This is the financial crimes division. Your wallet is associated with a money laundering investigation. To clear your name, you must transfer your funds to a secure escrow address we control." This targets victims who already feel vulnerable and fear criminal consequences.
How Attackers Research Their Targets
A vishing call is rarely cold. Attackers prepare by using leaked databases (email addresses, phone numbers, exchange usernames from past breaches), social media profiles showing cryptocurrency interest, public blockchain addresses linked to social media handles, and dark web marketplaces where exchange account credentials are sold. The caller may know your name, your approximate balance category, your country, and recent transaction activity — enough to appear like legitimate support.
Caller ID spoofing via VoIP services allows the attacker to display the official phone number of the exchange. Seeing "Binance Support" on your screen as the displayed number is not evidence the call is genuine — it is trivially forged.
The SIM Swap Connection
Vishing and SIM swap attacks are frequently combined in the same attack chain. In the first stage, the attacker ports your phone number to a SIM card they control — typically by social engineering your mobile carrier into believing they are you. With your number, they receive all SMS-based 2FA codes and password resets. In the second stage, they call you posing as your mobile carrier or the exchange, claiming there has been a security incident with your number and asking you to "confirm" details. The combination of controlling your number and obtaining verbal confirmation gives them everything needed to fully take over your accounts.
Advanced vishing operations in 2025–2026 increasingly use AI voice cloning. With as little as a few minutes of publicly available audio (YouTube interviews, podcast appearances, social media videos), attackers can clone a victim's voice or impersonate a trusted figure — a bank manager, a colleague, a family member — with high fidelity.
Golden Rules Against Vishing
The single most important rule: hang up and call back. If you receive an unexpected call from exchange support, a bank, or any institution, end the call. Find the official support number on the institution's real website (type it directly into your browser — do not search for it). Call that number yourself. If there was a genuine security issue, the support team will know about it.
Additional rules: never provide a 2FA code or one-time password to anyone over the phone; never install remote access software (AnyDesk, TeamViewer, AnyConnect) at the request of a caller; never transfer funds to a "secure" address provided by phone. Legitimate support teams have no need for any of this information and will never ask for it.
What to Do If You Were Vishied
If you provided a 2FA code or verification code: immediately log into your exchange account, revoke all active sessions, change your password, and regenerate your 2FA authenticator. Contact exchange support through official channels to flag the incident. If you revealed your seed phrase: move all funds to a new wallet generated on a clean device immediately — assume the seed is compromised. If funds have already been moved, record the transaction hashes and destination addresses, then contact a blockchain forensics firm as quickly as possible.
Frequently Asked Questions
How do I know if a call from 'exchange support' is a vishing attack?
Legitimate exchanges (Binance, Coinbase, Kraken) do not proactively call users. If you receive an unsolicited call from 'exchange support', it is almost certainly a scam. Hang up, call the exchange's official number independently, and report the call.
What information do vishers try to steal?
In crypto attacks: 2FA codes (TOTP or SMS), email verification codes, exchange passwords, seed phrases or private keys. They also try to get you to install remote access software (AnyDesk, TeamViewer) under the guise of 'security assistance'.
Can caller ID be spoofed in vishing attacks?
Yes — easily. Attackers use VoIP services to display any number, including official exchange support lines. Never trust a phone number displayed on your screen as proof that a call is legitimate. Verify by calling back on the number listed on the official website.
What is the connection between vishing and SIM swap?
Often the same attack chain: attackers SIM swap your number first (gaining control of your SMS), then call pretending to be 'verifying the security incident'. With both your phone number and your voice confirmation, they can reset account access completely.
What should I do if I gave information to a visher?
If you revealed a 2FA code: immediately revoke all sessions in your exchange account and change your password. If you revealed your seed phrase: transfer all funds to a new wallet on a clean device immediately. Contact a blockchain forensics firm to trace funds if they've already moved.