Glossary / Privacy & security
Social engineering
- Definition
- Social engineering is the craft of getting a person to do the attacker's work for them: approving a transfer, reading out a code, or bypassing a rule they were trained to enforce.
Nothing is broken in this kind of attack except a human's judgment. Attackers target staff as readily as customers: a phone campaign against Twitter employees on July 15, 2020 reached 130 accounts and collected roughly 12.86 bitcoin in a single afternoon. Because a confirmed bitcoin payment cannot be reversed, the whole con only has to work once.
How it works
Every social engineering attack assembles the same four parts, in the same order.
A pretext gives the attacker a reason to be talking to you: fraud department, exchange support, a delivery problem, a job offer, a new match on a dating app. Authority or familiarity makes the pretext stick, supplied by a spoofed caller ID, a genuine detail from a leaked database, or simply knowing your name and which exchange you use. Urgency removes your ability to check, because a compromised account or an expiring opportunity means the decision has to happen now. Finally the irreversible action: send the coins, read the code aloud, install the remote access tool, type the words.
Bitcoin sharpens the last step. Card fraud has an issuer who can reverse a charge and a bank that eats some of the loss. A confirmed on-chain payment has neither, so the attacker's payoff is final at the moment of the first confirmation, typically about ten minutes after you press send.
The most damaging campaigns skip the customer entirely and target the company's staff, where one success reaches thousands of accounts. Coinbase disclosed on May 15, 2025 that overseas customer support contractors had been bribed to hand over customer data, which was then used to run convincing "your account is compromised" calls. The company refused a 20 million dollar ransom demand and estimated remediation and reimbursement costs of 180 to 400 million dollars.
Where you see it
Six social engineering patterns cover the overwhelming majority of losses, and each has a mechanical rule that defeats it.
The safe wallet call. Someone claiming to be from your exchange or wallet vendor says your account is compromised and walks you through moving funds to a "secure address" they provide. No legitimate company will ever ask you to move coins. Any caller who does is the attack, so hang up.
Impersonated support in search and chat. Paid search ads and Telegram or Discord accounts wearing the right logo appear the moment you post a public complaint. Real support does not message first. Reach support only through a page you navigated to yourself.
Recovery scams. After a loss, a second attacker offers to trace and recover your coins for an upfront fee. Victim lists are resold precisely for this. No private service can reverse a bitcoin transaction.
Insider access. Bribed support contractors and carrier employees turn a company's normal tooling into an attack surface, as the Coinbase disclosure showed. Assume the exchange knows your holdings and your address, and keep your long-term stack somewhere the exchange has no reach.
Fake job interviews and code. Developers get sent a "take-home task" or a video call plugin that installs an information stealer, which then hunts for wallet files and seed backups on disk.
Physical coercion. Leaked customer address lists have led to home invasions targeting known holders, so treat your holdings as something you do not discuss and do not display.
Two rules cover all six. Never take an action on your coins that was prompted by an inbound contact, and always call back on a number you looked up yourself. Add a personal cooling-off period of 24 hours for any unplanned transfer, because urgency is the ingredient no attacker can do without.