Independent education site, not Binance / a bank / a broker We never collect passwords, codes, private keys, seed phrases or KYC documents Some outbound links are sponsored referral links

If they want an “unlock fee” before you can withdraw, it is almost always a scam

Fake support, phishing sites and shared-device risk around holding dollars

Turning your savings into dollars and parking them in some container is supposed to make your money steadier. Instead, plenty of people come unstuck at the very last step: talked into paying an “unlock fee” by a smooth script, or typing a password into a site that looks exactly like the real one. Who this is for: ordinary people about to open an offshore account, sign up for a multi-currency wallet, or buy their first stablecoin, who are worried about getting burned. Who it is not for: anyone hunting for the one platform that is “definitely safe”. Safety comes from habits, not from a name. By the end you will have a set of self-checks you can run again and again.

The conclusion first

Almost every scam around “holding dollars” ends up pointing at the same thing: getting you to send money out yourself, or to hand over control of your account. Spotting them takes very little technical knowledge. One plain rule covers most of it: a legitimate platform will never make you pay a fee before you can withdraw, and will never ask you for your password, codes, private key or seed phrase. Anything that breaks that rule, no matter how urgent or how official it sounds, deserves a full stop.

Below I unpack the most common playbooks one by one, then walk you through three checks you can do yourself: read the domain character by character, protect your device, and guard the handful of secrets that matter. If you have already been caught, there is an ordered set of steps at the end to limit the damage. This is not here to scare you, only to give you one more reflex before you act.

Burn this in: if anyone, for any reason, wants you to pay money first to “activate”, “unlock”, “upgrade”, or post a “tax deposit” before you can withdraw, it is almost always a scam. Legitimate banks, wallets and exchanges do not ask for money this way. The moment you see this signal, stop.

The common playbooks, one by one

The wrapping changes, but the skeletons are few. Learn the skeletons and you will recognise the trick even after the wording shifts.

1. The upfront “unlock fee” or deposit. This is the classic. You are told your account is frozen for “risk control”, an “anti-money-laundering review”, or “suspected anomalies”, and that you must pay a fee before you can unfreeze and withdraw. Pay once and a second and third charge tend to appear. The reality: when a legitimate platform freezes funds, it never asks you to pay to unfreeze, and certainly never asks you to transfer money privately to some personal account.

2. Impersonating platform support or staff. Someone contacts you first, claiming to be from an exchange or bank. They read back some of your details to seem credible, then guide you to “follow along”: screenshot a code, click a link, move your funds to a “safe account”. Remember that platform support does not call or message you out of the blue telling you to transfer money, and there is no such thing as a “safe account”.

3. Phishing look-alike sites. They build a page that is nearly identical to the real one, with a domain that differs by a letter or two (a look-alike character swap, an added hyphen, a different suffix), and push it to you through search ads, text links or private messages. The moment you type your username and password there, you have handed them straight over. How to read the domain character by character comes in the next section.

4. Push to private chat, remote control or “doing it for you”. They pull you off the public platform into a private chat tool, claim they will “walk you through it hand in hand”, and get you to install remote-control software or simply hand over your username and password for them to “operate on your behalf”. Once remote software is installed or your login is given away, your device and account are no longer under your control. This site never offers to register or operate on your behalf, and never pulls you into private chat.

5. Fake payees and money-mule traps. Someone promises to help you convert at a “low cost”, or to buy your dollars or stablecoins at a great price, and has you send money first to a stranger as the payee, promising to pay you back afterwards. The money goes out and that is the last you hear of it. Worse, this kind of flow can involve someone else's criminal proceeds, dragging you in without your knowing. A stranger, a private deal, and a price too good to be true: put those three together and it is almost certainly a trap.

Behind all five, the goal is either to make you send money yourself or to trick you into handing over control of your account. Hold on to those two essentials and you will recognise old wine in new bottles.

Check the official domain to beat phishing: read the address bar character by character

A phishing site's biggest weakness is always in the address bar. It can make the page look flawless, but the domain cannot lie, as long as you are willing to read it carefully.

Build one habit: before you enter any account, read the address bar from left to right, one character at a time, with your eyes locked on the main domain segment. Check for these common tricks one by one:

How to read the address bar: what really decides whose site you reach is the main domain segment, the part right before the suffix and before the last “dot”. For an address shaped like account-subdomain.maindomain.suffix, make sure that middle “maindomain” segment is the one you know. However many fancy prefixes hang in front of it, they do not count. When you cannot read it for certain, close the tab and start over rather than settle.

A safe routine: the first time you confirm it is correct, save the official address to your browser bookmarks and only ever enter through the bookmark afterwards. Before registering anywhere, check the domain accounts.binance.com and understand any referral relationship.

Using a shared or public device: better not, but if you must, do it this way

If you can avoid logging into your account on a shared computer, an internet cafe, or someone else's phone, avoid it. You do not know whether a keylogger is running, and you do not know whether the browser has kept your logged-in state. But if there is genuinely no other way, shrink the exposure as much as you can:

The core is one line: keep your secrets on a device you control, and always treat a public device as “unclean”.

Never hand over password, codes, private key or seed phrase

This is the one passage in the whole guide worth memorising. The following items are the keys to your account and your assets. No legitimate party will, or needs to, ask you for them:

Here is where I make this site's own line clear: DollarVault is an independent education site. It will never ask you for your password, codes, private key or seed phrase, and it collects no KYC documents. We do not register, operate or top up on your behalf, and we will not pull you into private chat; every platform action should be completed by you on an official page whose address you have checked. Anyone asking you for these things in this site's name is impersonating us.

When to stop immediately: the moment a conversation includes “send me the code”, “read me your private key / seed phrase”, “transfer some to a safe account first”, or “pay the fee and we will unfreeze you”, no matter how formal the title or how urgent the tone, stop, hang up or log out, and return to an official channel you have checked yourself before doing anything else.

What to do if you have been scammed: limit the damage in this order

If you have already been caught, do not panic and do not stall. Panic and delay only widen the loss. Work through it step by step in this order:

  1. Stop all transfers and actions immediately. Do not believe that “one more payment will get the earlier money back”. That is the same script continuing, and it only pulls you in deeper.
  2. Keep the evidence. Save the chat logs, transfer records, the other party's accounts, suspicious URLs and page screenshots. The sooner and more completely, the better. You will need them for reporting and for any appeal.
  3. Contact the platform first. Through a channel you have checked yourself (the support entry inside the official site or official app, not a link the other party gave you), explain the situation and see whether they can freeze, stop or intercept the relevant transactions.
  4. Report to your local police or anti-fraud authority. Bring the evidence you kept and follow the proper reporting route where you live. Channels differ by region, so go by what your local authorities publish.
  5. Change the relevant passwords and turn on two-factor authentication right away. If you typed a password on a suspicious page, or logged in on a public device, change the password on your own device as soon as possible and check the account's login and device records.
  6. Warn the people around you, so they are not scammed in turn. Scammers often strike again under the banner of “helping you recover your losses”. Anyone charging a fee to recover funds, or promising recovery, should still be treated as a scam.

Whether anything can be recovered depends on the case, and no one can promise you a result. But the sooner you stop, the fuller your evidence, and the faster you report, the better your chance of keeping the loss contained.

A red-flag checklist

Keep this checklist in your head. The instant any one of these shows up in a conversation or on a page, sound the alarm and stop to check:

Who scammers target most

Scammers have preferences. If you fall into one of the groups below, turn your guard up another notch:

Newcomers meeting dollars, stablecoins or offshore accounts for the first time. Unfamiliar with the steps, they let their guard down when “support helps you operate”, which is exactly what the playbook loves.

People in a hurry to spend or to convert. The more rushed you are, the easier it is for urgency scripts to push you along and skip the checks you should have made. The more pressing it feels, the more you should force yourself to pause for three minutes.

People in high-inflation regions anxious about their local currency. Promises like “fast value preservation” and “we buy dollars at a high price” are especially attractive to the anxious, and are the bait used most often.

People who routinely use public devices and love clicking links. Logging in at an internet cafe or on a shared computer, or casually opening links in texts and private messages, leaves the door open for phishing and malware.

Not in these groups? Do not relax either. Even the most seasoned person can slip in a moment of running hot or being distracted. Safety is not a one-time judgement; it is a fixed set of actions you run before every move.

AI face-swap and voice-cloning: when the “person” on the call is fake too

Treat a familiar face or a familiar voice as one more thing that can be faked, not as proof of identity. In 2026 the old scripts have a new coat of paint: scammers now use AI to swap faces on a video call and to clone a voice from a few seconds of audio, so the “relative” asking you to move money, or the “support agent” walking you through an “account check”, can look and sound convincing while being nobody you know.

The upgrade is only on the surface. The face and voice are new, but the ask is the same old skeleton: send money yourself, or hand over control of your account. Where a text used to say “transfer to a safe account”, now a video of your cousin says it, tears and all; where an email used to claim to be support, now a voice that sounds like the agent you spoke with last week reads you a code request. Anxiety about a “sick relative” or a “frozen account” is the lever, and a face you trust is what pushes it.

A few things still give it away. Real-time face-swaps tend to smear at the edges when the head turns sharply, when a hand passes in front of the face, or when the lighting suddenly changes; the mouth and the words can drift a little out of sync. Cloned voices handle a scripted sentence well but stumble on an unexpected question, an interruption, or a request to repeat something odd back to you. None of these is a guarantee, though, and the tells get fewer every year, so do not bet your money on spotting a glitch.

Lean on the habit instead of your eyes and ears. If a “relative” or an “official” reaches you through video or a call and the conversation turns to money, codes or moving funds, pause and verify on a separate channel you already trust: hang up and call the person back on their known number, or ask something only the real person could answer and that cannot be searched. Better still, agree a private word with close family now, before anything happens, and treat any money request that skips it as fake. The rule from the rest of this guide does not change because the impersonation got better: no legitimate party needs your codes, your seed phrase, or a “safe account” transfer, whoever appears to be asking.

Common mistakes

Mistake 1: a page that looks official is official. A page's appearance is the easiest thing to copy. The only thing that cannot lie is the address bar. Judge real from fake by the domain first, never by how good the page looks.

Mistake 2: they can read back my details, so they must be real support. Personal information may have leaked from somewhere else, and knowing a few facts does not make the identity genuine. Real support will not tell you to transfer money or ask for codes, and that test is more reliable than “they know my details”.

Mistake 3: paying a small fee to unfreeze and recover a large balance is worth it. That is exactly how the playbook is designed. Pay the first fee and a second and third follow, and not a cent of the principal comes back. Treat any “pay to unfreeze” as a scam.

Mistake 4: hire a “professional recovery service” after being scammed and you will get it back. Services that charge a fee to recover funds, or promise to get it all back, are mostly second scams. The right move is to go through the official platform and the proper reporting route where you live, not to pay another fee to a stranger.

FAQ

A legitimate platform can freeze funds for risk control, so will it make me pay to unfreeze?No. A freeze is the platform's risk-control measure, and lifting it goes through the platform's own appeal and review process. It never needs an extra payment from you, and certainly never a transfer to some personal account. The moment you see “pay to unfreeze”, you can basically call it a scam.
Someone claiming to be support contacted me first. How do I tell real from fake?The steadiest test is not “do they know my details” but “are they asking me to transfer money or read out a code”. Legitimate support does not contact you out of the blue to transfer money, does not ask for codes, and there is no such thing as a safe account. If you are unsure, hang up and start the contact yourself through the support entry in the official app or site.
I already typed my password on a suspicious site. What should I do now?Immediately change that account's password on your own device, and change any other accounts that used the same password. Turn on two-factor authentication, check the account's login and device records for anything unusual, and save the suspicious URLs and screenshots. The faster you act, the smaller the window for someone to log in.
Will this site ask me for my password or operate on my behalf?Never. DollarVault is an independent education site. It does not ask for your password, codes, private key or seed phrase, it collects no KYC documents, and it does not register, operate or top up on your behalf. Every outbound link points only to Binance's official registration page, with the action completed by you on the official side. Anyone asking for this information in this site's name is running a scam.

Sources and updates

Scam scripts change with platforms and payment rails. These primary sources are here to verify reporting channels and common patterns, not to guarantee safety. If a transfer or account takeover is in progress, stop paying, preserve chats and transaction records, then use local law-enforcement and the platform’s official reporting channel. This site cannot recover funds and will never contact readers privately to offer recovery.

This guide is meant to spread awareness of common scams and account-safety habits around holding dollars and converting currency. It is not investment, tax or legal advice, and it does not target any specific platform. For each platform's security rules, support channels and appeal processes, go by what its own official pages (security center, help center, anti-fraud notices) show at the time. For reporting and help, go by the channels your local authorities publish, and consult a local professional or law-enforcement body where needed. This site does not draw a compliance conclusion for any country.
Update note: 2026-06-20. First publication. It covers five common playbooks, how to check the domain, notes on shared devices, the steps to limit damage, and a red-flag checklist.


Q

Qiao Dai

Someone near me got caught by "pay an unfreeze fee to withdraw," so I turned these tricks into a checkable list. This is a pen name; the views are personal experience and not investment advice. About the author