Key Takeaways
- Think you are being scammed? Hang up, then contact us through the app or official website, never a number the caller gives you.
- CoinJar does call customers, but never to ask for a code or seed phrase. Caller ID can be spoofed and proves nothing.
- "Move your funds to a safe wallet" is always a scam. Whoever generates a recovery phrase controls the wallet.

Would you recognise a fake support call? How do you verify who is really contacting you?
The answer: hang up on any unexpected call, then verify it yourself in writing via your platform’s official channel on their website or in-app. For your bank, hang up and call the number on the back of your card. Genuine support teams, banks and police will never ask you for a password, a two factor code, remote access to your device, a wallet recovery phrase, or a transfer of your money to a "safe" account or wallet.
A scammer who says "call us back on this number to check" is handing you a line they control.
How CoinJar handles phone contact
CoinJar Support does not provide inbound telephone customer support. A contact number is published for regulatory and corporate purposes, but it is not monitored, and calls placed to it will not be answered.
Customer enquiries are handled in writing, through email and in-app support. Written channels allow us to verify identity, keep a complete record of the request, and involve the right specialist team without transferring you between operators. Most investigations, particularly those involving transactions, account access, or payment disputes, require documentation that cannot be gathered reliably over a call.
CoinJar does make outbound calls. Our Support and Financial Crime teams may call you about an active enquiry, and if you do not answer they will leave a detailed message and attempt to reach you again at a better time and will follow up with an email. The person who rings will use the same name you have been dealing with in the email thread.
Separately, our Account Managers contact VIP customers by phone and will usually leave a detailed voicemail if the call is not answered. You can be asked to call back in these circumstances.
Because outbound calls from CoinJar are possible, the number on your screen can be spoofed and is never proof of who is calling. If you receive a call or voicemail that appears to be from CoinJar, do not use any number provided to you. Contact us through the channel published on our website and we will confirm whether the contact was genuine.
What we will never do is ring you out of the blue and ask for your password, your two-factor code, access to your screen, or a transfer to another wallet or account.
So if the call was unexpected, treat caller ID as meaningless. Hang up, email support, and wait for the written answer. If it really was us, the call can happen five minutes later at a time you choose. Nothing genuine is ever lost by taking that pause, and everything is lost by skipping it.
Voices can now be cloned from a few seconds of audio, something we covered in our guide to AI voice cloning. So the question is no longer "does this look legitimate". It is "did I initiate this contact, and can I confirm it independently".
Why impersonation is the tactic of choice
Because it skips the hard part. Nobody needs to break your two factor authentication if they can persuade you to read the code out. Impersonation was the backbone of several of the largest loss categories in the ACCC's Targeting Scams report for 2025, with phishing and remote access schemes together accounting for well over $160 million in reported losses. Those categories exist because talking to a human is cheaper than hacking one.
The three impersonations worth knowing
1. Your exchange or wallet provider
The contact usually arrives with a hook: a suspicious login, a withdrawal you did not make, an account review, an urgent verification. The goal is either your credentials or a transfer you make voluntarily.
2. Your bank's fraud team
Often the most convincing, because the caller may already know recent transaction details from a data breach or from a phishing page you visited earlier. The tell is what they ask you to do next, not what they know.
3. Police, ReportCyber or a government agency
This one tends to arrive after something has already gone wrong. Someone calls claiming to be investigating your case, or is claiming your accounts are being used for money laundering and need to be moved for your own protection. Australian police do not ask members of the public to move money to keep it safe, and they do not run investigations over WhatsApp.
We took an earlier look at the general shape of these approaches in unmasking impersonation scams, and the mechanics have barely changed. Only the polish has improved.
The instruction that gives it away every time
Almost every impersonation ends at the same place: move your money.
It might be called a safe account, a secure wallet, a quarantine address, a holding facility or a protected vault. The language sounds official because it is designed to. There is no such thing. No bank, no exchange and no law enforcement agency in Australia will ever direct you to transfer your own funds to an address they provide.
Two close cousins deserve the same instant refusal:
- "Install this app so I can help you." Remote access software hands over your screen, your session and often your accounts. Legitimate support does not need it.
- "Read me the code we just sent you." That code exists specifically to keep the caller out. Ours are sent with a warning for exactly this reason, and you can strengthen your setup with app based two factor authentication rather than SMS.
- "We'll set you up with a new secure wallet." They send you a 12 or 24 word recovery phrase, then text the last few words separately so it feels like a secret only you hold. It isn't. They generated the phrase, so they know every word of it, including the ones they pretended to hide. The moment you move funds into that wallet, they sweep it out.
That last one is worth sitting with for a second, because it is the most convincing of the lot. A recovery phrase feels like proof of ownership. Being handed one feels like being handed the keys. But whoever creates a phrase controls the wallet forever, no matter who else has a copy. A real recovery phrase is generated by you, on your device, and seen by nobody else. If someone gives you one, it is not your wallet. It's theirs, and you're funding it.
What CoinJar will never do
- Call or message you asking for your password, PIN, two factor code or wallet recovery phrase
- Provide you with a new recovery phrase
- Ask you to move funds to an external address for safekeeping, verification or "release"
- Ask you to install remote access software
- Ask you to pay a fee to unlock, unfreeze or recover your own balance
- Contact you through WhatsApp, Telegram or a personal social media account to discuss your account
If there is a hold on an account, there is a legitimate reason for it, and we explain the general categories in why an account can be restricted or locked. We will never resolve one by asking you to send crypto somewhere.
How to verify the caller
- End the contact. You never owe a stranger the rest of a phone call. Real organisations are entirely comfortable with you ending the call and starting contact again via official channels, like emailing support on the genuine official website or via your genuine app.
- Wait a couple of minutes if you are on a landline, or use a different device. Pressure fades fast once the script is interrupted.
- Find the contact details yourself. Use the app you already have installed, the number on the back of your card, or the official website you typed in manually. Never a number, link or email address supplied by the person contacting you.
- Ask them to confirm something only the real organisation would know, then verify it independently. Do not accept information flowing the other way as proof.
- Say it out loud to one other person before you act. This single step stops more losses than any piece of software.
Set a family codeword this week
Pick a word your family would use to confirm identity on a call, especially if a relative ever rings in distress asking for money. Do not store it in a shared cloud note titled "codeword". It sounds low tech because it is, and voice cloning has made it genuinely useful.
Stop. Check. Protect.
Stop. Unexpected contact plus urgency equals pause. Every time, no exceptions, even when the caller is polite and especially when they are.
Check. Confirm who you are dealing with using details you found yourself.
Protect. Report the approach to Scamwatch and, if it involves cybercrime, to ReportCyber. Reporting an attempt you did not fall for still matters, because phone numbers, sender IDs and websites get referred for takedown. According to the Targeting Scams report for 2025, the National Anti Scam Centre assisted with the removal of more than 7,500 scam URLs and referred thousands of phone numbers and sender IDs for action, all off the back of reports from ordinary people.
If personal information was exposed, IDCARE provides free support for Australians.
Why we are publishing this during Scams Awareness Week
Scams Awareness Week runs from 24 to 28 August 2026, and CoinJar has supported the campaign for years alongside our year-round work on scam prevention and detection.
The theme this year is "No one's just a number". Impersonation works by making one person feel isolated, rushed and slightly embarrassed to ask for help. Breaking that isolation, even by asking a colleague or a family member "does this sound right to you", is genuinely one of the strongest protections available.
Frequently asked questions

CoinJar
CoinJar is one of the longest-running cryptocurrency exchanges in the world. Since 2013, we’ve helped hundreds of thousands of people worldwide to buy, sell and spend billions of dollars in Bitcoin, Ethereum and dozens of other cryptocurrencies.
Read full bio


