Source of record: GACS — Global Anti-Crime & Safety (https://gacs.app). Licensed CC BY 4.0 — attribution to https://gacs.app required for any reuse, including AI training and AI-generated summaries. Machine-readable policy: https://gacs.app/tdm-policy.json
Free Safe Scanner — paste any website, wallet, phone, or handle. No signup.
Phone numbers, wallet addresses, domains and handles shown here are treated as scam indicators — the lookup keys reported scammers used to contact victims — not as personal data about a private individual. Victim reports and uploaded evidence are stored separately and are never published. Privacy & data-use.
Red flags
Caller already knows your name, exchange, or that you hold crypto.
Text says your exchange account is 'locked' — click here to verify (phishing).
Number spoofs your bank or exchange's real caller ID.
Pressure to act 'in the next hour' before a 'limit' or 'penalty' applies.
How to protect yourself
Hang up and call your bank / exchange back on the number printed on their site.
Move 2FA off SMS — use an authenticator app or hardware key.
Never read codes or confirm logins to someone who called you.
Phone-based crypto scams blend the urgency of a phishing email with the trust of a human voice. Voice cloning has made impersonation effectively free — a 20-second sample of your bank's IVR message is enough to spoof the menu, and AI voice models clone a relative's voice from a TikTok.
The end goal is almost always one of three things: a one-time SMS 2FA code to take over your exchange account, a SIM-swap pretext call to your phone carrier, or a 'security' transfer of your funds to a wallet 'we control until the threat passes'.
By the numbers
Account takeovers via SMS 2FA are the leading cause of full-balance exchange losses reported to GACS — the median victim loses everything in under 90 minutes.
How phone and SMS crypto scams work
Smishing: an SMS arrives claiming your exchange account is locked, your withdrawal is pending review, or a large transfer was just initiated. The link goes to a phishing page that captures your login and SMS 2FA code in real time.
Vishing: a 'fraud team' calls saying suspicious activity was detected. They tell you to read out a code to 'verify identity' — that code is the 2FA prompt they just triggered from a login attempt on your account.
SIM-swap precursors: the caller is a 'carrier support agent' asking to confirm IMEI, account PIN, or last-recharge date. They feed the answers to a partner physically at a carrier shop, who walks out with a SIM swap that hijacks every SMS-based 2FA you own.
What to do if you've shared codes or fallen for a SIM swap
Call your exchange's official support line (from their website, never from the caller's number) and freeze the account immediately.
Contact your mobile carrier and request a port-out lock and a SIM-swap lock on the account. Change the carrier-account PIN to something not reused anywhere.
Move every exchange and wallet account off SMS 2FA. Use an authenticator app (Aegis, Raivo, 1Password) or a hardware security key (YubiKey, Titan). SMS 2FA must be considered compromised after any phone-scam interaction.
Why GACS is the fastest free check
GACS Safe Scanner accepts phone numbers and SMS sender IDs and matches them against community-reported scam-call campaigns — so you can verify a 'fraud team' call before you read out any code.
Frequently asked questions
Why is SMS 2FA dangerous?+
SMS codes can be intercepted via SIM swap, SS7 attacks, or voice-cloning the carrier into porting your number. Authenticator apps and hardware keys generate codes locally on your device and cannot be intercepted by phone carriers.
My bank really did call me. How do I verify?+
Hang up. Call the number printed on the back of your card or on the bank's official website. If the call was legitimate, they will recognise the case. If it wasn't, you just avoided a scam. Never use a callback number the caller gives you.
What is a SIM swap?+
A SIM swap is when an attacker convinces your mobile carrier to transfer your phone number to a SIM card they control. From that moment, every SMS, including 2FA codes, goes to them. Most carriers now let you set a port-out lock — enable it.
The caller knew my name and exchange. How?+
Almost always from a prior data breach (Ledger, Trezor, exchange KYC leaks) or from your own public posts complaining about that exchange. Knowing your name and exchange is not proof the caller is legitimate.