Uphold Security Email Scam: How the Fake Breach Call Drains Your Crypto

An email warns that your Uphold account was accessed from a new device after a third-party data breach. The message looks like a security notice and offers a telephone hotline for immediate help.

For a crypto holder, waiting can feel reckless. Calling the number can be the action that puts the account in danger.

Realistic reconstruction of an Uphold security email scam with a fake breach hotline

Overview

The email combines a breach warning with a new login

The Uphold security email scam impersonates the cryptocurrency platform with a story about unusual account access. The subject may mention a new device, suspicious login, compromised information, or third-party security incident.

The message commonly says the account is at immediate risk and directs the reader to a “Security Hotline.” Some versions include a prominent telephone number rather than a login button, which can make the email seem safer than ordinary phishing.

The hotline is not a protective channel. It connects the recipient to an impersonator who can adapt the conversation and guide the victim through actions that expose credentials or transfer digital assets.

A real historical incident can make the lie more persuasive

Uphold disclosed that Customer.io, a third-party email provider, experienced a security incident in July 2022. Uphold said some customer names and email addresses may have been disclosed, while login credentials remained secure and customer funds were not stolen through that event.

A criminal can reuse a real, old incident as background for a false current emergency. The existence of an earlier disclosure does not prove that a new email, login warning, or hotline is genuine.

Warning signs include:

  • An unexpected breach or new-device notice
  • A telephone number presented as the only safe response
  • Pressure to call before withdrawals are enabled
  • A request to read a two-factor authentication code aloud
  • Instructions to install remote-access or screen-sharing software
  • Advice to move assets into a “safe,” “secure,” or “cold” wallet
  • A wallet address supplied by the caller

The final objective is usually account access or a crypto transfer

The fake security agent may ask for a password, code, recovery phrase, or private key. Another script avoids requesting credentials directly and instead tells the victim to move funds for protection.

Cryptocurrency sent to a scammer-controlled wallet can move again within minutes and is usually difficult to recover. The transfer may look voluntary on the blockchain even though it was induced by deception.

Uphold’s official scam guidance says the company will never call to ask a customer to move funds or ask someone to forward or read out a 2FA code. Any caller making either request should be treated as an impersonator.

How to Tell a Real Security Notice From the Scam

Do not judge the message by its logo, colors, grammar, or display name. Those elements can be copied, and a polished template costs criminals very little.

Inspect the actual sender address without replying. A lookalike domain may add words such as security, help, wallet, or support around the brand name. Even a familiar sender should not be enough to justify calling a number in the message.

Close the email and open the Uphold app normally, or type the official website address into the browser. Review account notifications, recent activity, devices, withdrawals, security settings, and support messages from inside the authenticated account.

If you need assistance, begin at Uphold’s official Help Center. Do not let the suspicious message choose the telephone number, website, wallet address, or employee you use for verification.

Crypto account owner reviewing sessions and two-factor authentication after a phishing email

How the Uphold Security Email Scam Works

Step 1: The recipient gets a realistic security alert

The campaign begins with an email that appears to come from Uphold. It may claim a login occurred from a Windows computer, foreign location, new browser, or unfamiliar IP address.

A reference to a third-party breach explains how the attacker supposedly obtained account information. That detail is designed to answer the victim’s questions before they are asked.

Step 2: A deadline creates fear of an imminent withdrawal

The email warns that funds may be moved unless the user responds immediately. It may claim that a withdrawal hold expires soon, a device will be trusted automatically, or the security team needs confirmation.

Urgency keeps the reader inside the message’s instructions. A person who pauses to open the real account may discover there is no matching alert.

Step 3: The victim calls the fake security hotline

The prominent number reaches someone who answers with a professional support greeting. The operator may ask for the case number printed in the email and then repeat the supposed device and location.

Because the criminal created the email, those details are easy to confirm. Repeating them is theater, not evidence of access to Uphold’s systems.

Step 4: The operator performs a false account verification

The caller may be asked for an email address, telephone number, account balance, recent transaction, password, or two-factor code. Questions are framed as necessary to freeze the account.

The criminal can simultaneously attempt a real login. A genuine code arriving from Uphold then appears to validate the conversation, even though sharing it may authorize the attacker.

Step 5: A “safe wallet” is introduced

Rather than stealing the login, some operators tell the victim that the account infrastructure is compromised. The assets supposedly must be moved into a protected wallet until the investigation ends.

The scammer supplies a wallet address or guides the victim through creating a transfer. A legitimate security team does not protect customer funds by directing them to an address controlled by an employee.

Step 6: Remote access removes the remaining friction

If the victim hesitates, the fake agent may suggest AnyDesk, TeamViewer, or another screen-sharing tool. The stated purpose is to help navigate security settings without asking for the password.

Remote viewing lets the operator observe balances, email, authenticator codes, and wallet activity. Full control may allow the criminal to paste a different destination address or approve actions while distracting the victim.

Step 7: The assets are moved and follow-up fraud begins

Once sent, crypto may be split among several addresses, swapped, or transferred across networks. The fake agent stops responding or claims the funds will reappear after a waiting period.

Later, a recovery service, investigator, or lawyer may contact the victim and demand an advance payment. These secondary approaches often use details collected during the original call.

What Uphold Says It Will Never Ask You to Do

Uphold’s official scam guidance states that it will never call and ask customers to move funds. It also says the company will not ask a customer to forward or read out a 2FA code.

Those two rules cut through much of the social engineering. It does not matter how urgent, polite, knowledgeable, or reassuring the caller sounds.

Never disclose a wallet recovery phrase or private key to any support representative. A recovery phrase controls the assets associated with the wallet and cannot be changed like an ordinary password.

Do not install software because an unexpected security caller recommends it. Genuine support can explain steps without taking control of a customer’s computer or watching private account activity.

What the 2022 Customer.io Incident Actually Means

In its published incident notice, Uphold said a senior engineer at Customer.io provided email addresses from several clients to a bad actor in July 2022.

Uphold stated that it was not hacked, customer funds were not stolen, and full login credentials remained secure. It believed that first names, last names, and email addresses may have been disclosed.

That information could make later phishing more personal, but it does not make every message mentioning the event authentic. A scammer can cite a real disclosure and still invent a current login, hotline, or withdrawal.

Verify a new alert based on what appears in the account today. Do not let an old incident become a reason to surrender current security controls.

Why a Telephone Phishing Email Can Bypass Your Usual Caution

Many people know not to click an unexpected login button, so some crypto phishing campaigns replace the link with a telephone number. Calling can feel like the cautious choice because no password is entered into a suspicious webpage.

The conversation is still controlled by the sender. A live operator can answer objections, create new emergencies, and give step-by-step instructions while the victim is looking at a real account.

Telephone support also hides the final destination until late in the process. The email may contain no malicious website at all, while the caller later supplies a wallet address, remote-access download, or phishing page.

Treat a callback number as a link spoken aloud. If it arrived in an unverified message, do not use it to investigate that same message.

How to Review the Account Without Exposing It

Use a trusted device and network. Open the Uphold app directly, review recent logins and transactions, and take screenshots of anything unfamiliar before changing settings.

Check the email account for password resets, forwarding rules, deleted alerts, and sessions you do not recognize. An attacker who controls email may intercept warnings even after the crypto password changes.

Use an authenticator app or another strong method supported by the service instead of relying only on text messages. Never approve a sign-in prompt unless you personally initiated the login.

If no suspicious activity appears, still report the phishing email. Reports help the platform identify telephone numbers, sender domains, and scripts being used against customers.

Company, Address, and Fulfillment Checks

The sender domain must match an official channel

Expand the sender information and examine the complete address. Added words, misspellings, unusual top-level domains, and unrelated reply addresses are reasons to stop.

The support route should begin inside your account

Open the app or official Help Center independently. A telephone number printed in the same email making the alarming claim is not independent verification.

The wallet address reveals the real destination

A “safe wallet” supplied by a caller is simply an external destination. Support staff do not need customers to transfer assets into employee-controlled addresses to investigate a login.

The account should contain matching evidence

Review devices, sessions, emails, withdrawals, and support tickets. If the claimed alert exists only in the unexpected email, treat it as unverified and report it.

What to Do if You Have Fallen Victim to This Scam

  1. End the call and stop every transfer. Do not send a test amount, network fee, recovery charge, or final verification payment. Block follow-up numbers.
  2. Contact Uphold through the official account. Report the phishing email and explain whether you shared a password, code, recovery phrase, private key, identity document, or wallet transfer.
  3. Secure the email account first. Change its password from a trusted device, sign out unknown sessions, review forwarding rules and recovery details, then secure Uphold and related financial accounts.
  4. Revoke unauthorized access. Remove unknown devices, reset exposed authentication, change API keys where relevant, and move remaining assets only according to guidance from verified account support.
  5. Document blockchain transactions. Save wallet addresses, transaction hashes, networks, amounts, timestamps, exchange receipts, and conversations. Give them to the platform and law enforcement.
  6. Disconnect remote access and scan the device. Uninstall the requested software, revoke its permissions, and run a full Malwarebytes scan for credential stealers, remote tools, and other malicious programs.
  7. Block known malicious destinations. AdGuard can help prevent visits to reported phishing domains and deceptive redirects. It cannot recover crypto already transferred.
  8. Report the theft promptly. File at IC3.gov and ReportFraud.ftc.gov, and contact local police. Notify any exchange that received the stolen assets if it can be identified.
  9. Ignore guaranteed recovery offers. Anyone demanding advance crypto, taxes, gas fees, or a private key to retrieve funds is likely attempting a second scam.

Is Your Device Infected? Run a Free Malware Scan

Slow performance, constant pop-ups, or strange behavior? These are classic signs of a malware infection. The fastest way to find out is to scan your device with Malwarebytes Anti-Malware Free — one of the most trusted malware removal tools available.

The free version detects and removes the most common threats, including:

  • Adware — the cause of those annoying pop-ups
  • Browser hijackers — unwanted redirects and changed homepages
  • Trojans and spyware — hidden programs stealing your data
  • Potentially unwanted programs (PUPs) — software you never asked for

👉 Select your device below — Windows, Mac, or Android — then follow the simple steps to download Malwarebytes, scan your system, and remove any threats it finds. The whole process takes about 5 minutes.

Malwarebytes for WindowsMalwarebytes for MacMalwarebytes for Android

Run a Malware Scan with Malwarebytes for Windows

Malwarebytes is one of the most popular and trusted anti-malware tools for Windows — and it’s completely free for removing infections. It catches threats that many antivirus programs miss, including adware, browser hijackers, and trojans. Follow the steps below to scan and clean your PC in just a few minutes.

  1. Download Malwarebytes

    Click the button below to download the latest version of Malwarebytes for Windows from the official source. The free version is all you need — it will scan your computer and remove adware, browser hijackers, and other malicious software at no cost.

    DOWNLOAD MALWAREBYTES FOR WINDOWS (FREE)

    (The link opens in a new page where your download will start)
  2. Install Malwarebytes

    When the download finishes, open your Downloads folder and double-click the MBSetup file. If Windows shows a User Account Control pop-up, click “Yes” to allow the installation.

    MBAM1
  3. Follow the On-Screen Prompts to Install Malwarebytes

    The setup wizard will walk you through a few quick screens:

    • Choose where you’re installing the program — “Personal Computer” or “Work Computer” — then click Next.

      MBAM3 1
    • Malwarebytes will now install on your device. This usually takes under a minute.

      MBAM4
    • When installation is complete, the “Welcome to Malwarebytes” screen will open automatically.

      MBAM6 1
    • On the final screen, click Open Malwarebytes to launch the program.

      MBAM5 1
  4. Enable “Scan for Rootkits”

    Before scanning, turn on rootkit detection so Malwarebytes can find even the most hidden threats. Click the Settings gear icon on the left side of the screen.

    MBAM8

    In the settings menu, find “Scan for rootkits” and click the toggle so it turns blue.

    MBAM9

    Done? Click “Dashboard” in the left pane to return to the main screen.

  5. Start the Scan

    Click the blue Scan button. Malwarebytes will automatically update its virus database and start checking your computer for malware.

    MBAM10
  6. Wait for the Scan to Finish

    The scan checks your entire system for browser hijackers and other malicious programs, so it can take several minutes. Feel free to do something else — just check back occasionally to see the progress.

    MBAM11
  7. Quarantine the Detected Threats

    When the scan is done, you’ll see a list of everything Malwarebytes found — malware, adware, and potentially unwanted programs. Click the “Quarantine” button to remove all of them at once.

    MBAM12

    Malwarebytes will now remove the malicious files and registry entries and move them safely into quarantine.

    MBAM13

  8. Restart Your Computer

    Some threats can only be fully removed after a reboot. If Malwarebytes asks you to restart, click Yes. Once you’re logged back in, your PC is clean and you can continue with the next steps in this guide.

    MBAM14

When the scan finishes, click Quarantine to remove everything Malwarebytes found. That’s it — your Windows PC is now clean of trojans, adware, and other malware, and should be back to running smoothly.

If your current antivirus allowed this malicious program on your computer, you may want to consider purchasing Malwarebytes Premium to protect against these types of threats in the future.
If you are still having problems with your computer after completing these instructions, then please follow one of the steps:

Run a Malware Scan with Malwarebytes for Mac

Malwarebytes for Mac is a free on-demand scanner that removes the malware other security software tends to miss — adware, browser hijackers, and unwanted programs included. Cleaning an infected Mac with Malwarebytes has always been completely free, and it’s our go-to recommendation. Follow the steps below to scan and clean your Mac in just a few minutes.

  1. Download Malwarebytes for Mac

    Click the button below to download the latest version of Malwarebytes for Mac.

    DOWNLOAD MALWAREBYTES FOR MAC (FREE)
    (The link opens in a new page where your download will start)
  2. Open the Malwarebytes setup file

    When the download finishes, open your Downloads folder and double-click the setup file to begin the installation.

    Double-click on setup file to install Malwarebytes

  3. Follow the On-Screen Prompts to Install Malwarebytes

    The Malwarebytes for Mac Installer will guide you through a few quick screens. Click “Continue” and keep following the prompts until the installation completes.

    Click Continue to install Malwarebytes for Mac

    Click again on Continue to install Malwarebytes for Mac

    Click Install to install Malwarebytes on Mac

    When the installation is complete, Malwarebytes opens to the Welcome to Malwarebytes screen. Click “Get started“.

  4. Select “Personal Computer” or “Work Computer”

    Malwarebytes will ask what type of computer you’re installing it on. Click either Personal Computer or Work Computer, whichever applies.
    Select Personal Computer or Work Computer mac

  5. Start the Scan

    Click the “Scan” button. Malwarebytes will automatically update its detection database and begin checking your Mac for malware.
    Click on Scan button to start a system scan Mac

  6. Wait for the Scan to Finish

    Malwarebytes will scan your Mac for adware, browser hijackers, and other malicious programs. This can take a few minutes, so feel free to do something else — just check back occasionally to see the progress.
    Wait for Malwarebytes for Mac to scan for malware

  7. Quarantine the Detected Threats

    When the scan is done, you’ll see a list of everything Malwarebytes found. Click the “Quarantine” button to remove all the threats at once.
    Review the malicious programs and click on Quarantine to remove malware

  8. Restart Your Mac

    Malwarebytes will now remove all the malicious files it found. Some threats can only be fully removed after a reboot — if Malwarebytes asks you to restart, allow it. Once you’re logged back in, your Mac is clean.
    Malwarebytes For Mac requesting to restart computer

Once the scan is done, remove every threat it detected. Your Mac is now free of adware, rogue browser extensions, and other potentially harmful software.

If your current antivirus allowed a malicious program on your computer, you might want to consider purchasing the full-featured version of Malwarebytes Anti-Malware to protect against these types of threats in the future.
If you are still experiencing problems while trying to remove a malicious program from your computer, please ask for help in our Mac Malware Removal Help & Support forum.

Run a Malware Scan with Malwarebytes for Android

Malwarebytes for Android automatically detects and removes dangerous threats like malware and ransomware so you don’t have to worry about your most-used device being compromised. Aggressive detection of adware and potentially unwanted programs keeps your Android phone or tablet running smooth.

  1. Download Malwarebytes for Android.

    You can download Malwarebytes for Android by clicking the link below.

    MALWAREBYTES FOR ANDROID DOWNLOAD LINK
    (The above link will open a new page from where you can download Malwarebytes for Android)
  2. Install Malwarebytes for Android on your phone.

    In the Google Play Store, tap “Install” to install Malwarebytes for Android on your device.

    Tap Install to install Malwarebytes for Android

    When the installation process has finished, tap “Open” to begin using Malwarebytes for Android. You can also open Malwarebytes by tapping on its icon in your phone menu or home screen.
    Malwarebytes for Android - Open App

  3. Follow the on-screen prompts to complete the setup process

    When Malwarebytes will open, you will see the Malwarebytes Setup Wizard which will guide you through a series of permissions and other setup options.
    This is the first of two screens that explain the difference between the Premium and Free versions. Swipe this screen to continue.
    Malwarebytes Setup Screen 1
    Tap on “Got it” to proceed to the next step.
    Malwarebytes Setup Screen 2
    Malwarebytes for Android will now ask for a set of permissions that are required to scan your device and protect it from malware. Tap on “Give permission” to continue.
    Malwarebytes Setup Screen 3
    Tap on “Allow” to permit Malwarebytes to access the files on your phone.
    Malwarebytes Setup Screen 4

  4. Update database and run a scan with Malwarebytes for Android

    You will now be prompted to update the Malwarebytes database and run a full system scan.

    Malwarebytes fix issue

    Click on “Update database” to update the Malwarebytes for Android definitions to the latest version, then click on “Run full scan” to perform a system scan.

    Update database and run Malwarebytes scan on phone

  5. Wait for the Malwarebytes scan to complete.

    Malwarebytes will now start scanning your phone for adware and other malicious apps. This process can take a few minutes, so we suggest you do something else and periodically check on the status of the scan to see when it is finished.
    Malwarebytes scanning Android for Vmalware

  6. Click on “Remove Selected”.

    When the scan has been completed, you will be presented with a screen showing the malware infections that Malwarebytes for Android has detected. To remove the malicious apps that Malwarebytes has found, tap on the “Remove Selected” button.
    Remove malware from your phone

  7. Restart your phone.

    Malwarebytes for Android will now remove all the malicious apps that it has found. To complete the malware removal process, Malwarebytes may ask you to restart your device.


After the scan, tap Remove Selected to delete all detected threats. Your Android phone is now clean — no more malicious apps, adware, or browser redirects.

If your current antivirus allowed a malicious app on your phone, you may want to consider purchasing the full-featured version of Malwarebytes to protect against these types of threats in the future.
If you are still having problems with your phone after completing these instructions, then please follow one of the steps:

Stay Protected: Block Ads and Malicious Sites

Now that your device is clean, keep it that way. Most infections start with a malicious ad or a fake download button — so blocking them at the source is your best defense.

We recommend AdGuard, which blocks malicious ads, phishing pages, and dangerous redirects before they can reach you.

👉 Download AdGuard and browse safely

Frequently Asked Questions

Did Uphold suffer a new breach mentioned in the email?

Do not assume so. The scam can refer to an old or invented incident. Check current notices inside the official account and on Uphold’s own website.

Was the 2022 Customer.io incident real?

Yes. Uphold disclosed exposure of some customer names and email addresses through a third party, while stating that credentials and funds were not compromised by that event.

Will Uphold call and ask me to move my crypto?

Uphold’s official guidance says it will never call to ask a customer to move funds. End any call that gives that instruction.

Can support ask for my two-factor code?

Uphold says it will not ask you to forward or read out a 2FA code. Keep the code private even if it arrived from a genuine automated sender.

What if I called the hotline but sent nothing?

Change any information you disclosed, monitor the account, and report the email. Expect follow-up phishing because the criminals now know your address and telephone number are active.

Can a cryptocurrency transfer be reversed?

Blockchain transfers generally cannot be canceled after confirmation. Report immediately because an exchange or law-enforcement agency may still be able to identify or freeze funds under its control.

The Bottom Line

The Uphold security email scam turns fear of a breach or new-device login into a telephone conversation. The fake agent then seeks a code, remote access, or a transfer to a scammer-controlled wallet.

Never call a hotline chosen by an unexpected email. Open Uphold independently, keep every 2FA code private, and remember that real support will not ask you to move funds for protection.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

Michael Williams Lotus Consults Scam Email: Fake Funding Offer Warning

Next

Capital Markets Advisory Scam: How Fake Online Experts Steal Your Money