Security Center · How to
How to Report Crypto Phishing and Impersonation
Reporting helps others, and it helps most when done properly. But if you interacted with the attack, your own position comes first.
Direct answer
If you encounter phishing: secure yourself first if you interacted with it, then capture evidence (URLs, addresses, message content, timestamps), then report to the impersonated organisation through its published channels, the platform hosting the content, and the relevant authority in your jurisdiction. Reporting does not stop an active compromise, so it comes after securing your own funds and accounts.
Step 1 — If you interacted, secure yourself first
Do this before capturing evidence or reporting.
If you signed a transaction or approval:
- Move funds first, from a clean device, to a wallet whose seed has never touched the suspect machine. Do not investigate before moving.
- Revoke approvals on the affected wallet.
- Assume the seed is burned if there is any chance it was exposed. Generate a new wallet; do not reuse the old one.
If you entered a seed phrase anywhere: the wallet is compromised permanently. Move everything immediately. There is no remediation short of abandoning it.
If you entered exchange credentials:
- Change the password from a clean device.
- Check and revoke trusted devices and active sessions.
- Check and revoke API keys — a
withdraw-scoped key left behind is a persistent hole. - Confirm your withdrawal address allowlist contains only addresses you recognise.
- Confirm 2FA is still yours, and regenerate recovery codes.
Only once that is done should you spend time on anything else.
Step 2 — Capture evidence
Reports are actionable in proportion to their specificity. Capture, without clicking anything further:
- The full URL, including any path and parameters. Copy it as text.
- The wallet or contract address involved.
- Transaction hashes, if anything executed.
- Screenshots of the page or messages.
- The account handle and platform of anyone who contacted you.
- Timestamps, and how the contact reached you — DM, reply, email, advertisement, search result.
Store these as text where possible. A screenshot of a URL cannot be searched or blocklisted; the text can.
Step 3 — Report to the impersonated organisation
The organisation being impersonated has the strongest incentive to act and often the fastest route to takedown.
Reach them through their published channels — type the domain, find their security or support contact. Do not reply to the phishing message, and do not use contact details it supplied.
Include the evidence from Step 2. Say clearly whether you interacted, since that changes their urgency.
For CoinDock impersonation, report through the contact details on coindock.online/about.
Step 4 — Report to the platform
Where the content lives:
- Social platforms — report the account for impersonation, not just the post. The account is the reusable asset.
- Search advertisements — report the ad. Paid impersonation ads on brand searches are common and advertisers can be suspended.
- Domain registrars and hosts — a WHOIS lookup gives the registrar's abuse contact. Phishing takedowns through registrars are often effective.
- Browser vendors — reporting a URL to Google Safe Browsing or Microsoft SmartScreen puts a warning in front of the next person, usually within hours.
That last one has the broadest reach for the least effort.
Step 5 — Report to authorities
If funds were lost, report to the relevant authority in your jurisdiction — a national cybercrime or fraud reporting body, and your local police where they take such reports.
Recovery is unlikely. Report anyway: aggregated reports are how patterns are identified and how larger operations eventually get disrupted.
Include transaction hashes and addresses. Those are the parts investigators can actually trace.
Step 6 — Warn others carefully
If you are part of a community that was targeted, say so. A community told an impersonator is active is far harder to defraud.
But be careful how you post about a personal loss. Publicly describing a loss puts you on a list. Recovery fraud specifically targets people who have just been defrauded, and those approaches will arrive within hours.
If you post, expect them, and treat every unsolicited recovery offer as a second fraud. Recovering on-chain funds is generally not possible, and anyone charging a fee to try is selling that impossibility.
What not to do
- Do not reply to the phishing message, even to challenge it. It confirms a live target.
- Do not click further links to "investigate".
- Do not pay a recovery service.
- Do not send a "test" transaction to an address someone is pressuring you about.
- Do not delay securing funds in order to gather better evidence.
Related
Step-by-step
How to Report Phishing
Help others by reporting scams properly.
-
Capture evidence
Screenshots, URLs, and headers.
-
Report to the platform
Use abuse forms or contact details.
-
Warn the community
Post in your community channels.
-
Block and revoke
Revoke approvals and block accounts.
Related on Security Center
-
Phishing Prevention FAQ
How crypto phishing actually operates, and the habits that defeat it without requiring you to spot it.
-
Wallet Safety Guide
A wallet stores keys, not coins. Once that is clear, most wallet security advice stops being arbitrary rules and starts...
-
Smart Contract Review Basics
Contract review is not a search for a contract with no powers. It is an assessment of whether the powers are known and c...
-
Security Resources
The checklists and routines from CoinDock's security guides, in one place.
-
How to Protect Your Wallet
A setup that limits the damage of mistakes rather than trying to prevent all of them.
Review CoinDock Security Standards
Continue your CoinDock journey.
Go