What to do if you get scammed on Bybit

What to do if you get scammed on Bybit
Trading platforms like Bybit are popular because they offer advanced tools and competitive features. But scams can happen around any exchange—through fake support accounts, phishing links, impersonator websites, “investment” bots, or social engineering that convinces you to deposit money or reveal sensitive info.
If you think you’ve been scammed, don’t panic. The fastest path to damage control is to act quickly, secure your accounts, and gather evidence so you can contact support with a clear timeline.
Act immediately to limit the damage
1) Stop all transfers and access that could continue the loss
If you can still log into your Bybit account:
- Do not make additional deposits
- Do not “top up” to unlock withdrawals (this is a common scam tactic)
- Log out of any active sessions you don’t recognize
- Disconnect or revoke any third-party apps you were tricked into installing or connecting
If the scam is outside your control (for example, funds already transferred to another wallet), your priority becomes containing further exposure: secure accounts, remove access, and document what happened.
2) Secure your Bybit account right now
Even if you suspect only your email is compromised, assume the attacker may have attempted account access elsewhere.
Do this immediately:
- Change your password to a strong, unique one (not reused from other sites)
- Enable or update 2FA (two-factor authentication) using an authenticator app if possible
- Check device/session activity and remove unknown sessions (if Bybit provides a session management option)
- Verify your email address hasn’t been changed
- Review your API keys (if you created any) and revoke anything suspicious
3) Move funds if you still have control
If you still have funds in your Bybit account and you believe the attacker hasn’t already drained everything:
- Consider moving remaining assets to cold storage or to a safer account only if you’re confident it won’t trigger more scam activity
- Double-check that any “withdrawal” instructions you’re following are genuinely from official channels
Be careful: some scams involve convincing you to “confirm” withdrawals or sign transactions that drain your remaining funds.
Identify what type of scam happened
Not all scams are the same, and the right response depends on the pattern. Take a moment to categorize what happened:
Common scam types involving exchanges
Fake customer support
Someone messages you claiming there’s an “urgent issue,” then guides you to a phishing site or asks for login codes.Phishing links and fake logins
You’re sent a link that looks like Bybit but isn’t. You enter credentials and the scammer takes over.“Recovery” or “guaranteed profit” schemes
A person claims they can “double your investment” or help recover funds for a fee.Wallet-draining approvals
You approve a token/contract or connect a malicious wallet that later moves assets.Impersonator websites or fake apps
You download software or visit a site that imitates the exchange.
Quick checklist: what do you still know?
- Did you log in via a link someone sent?
- Did you share your 2FA code, password, or API key?
- Did you connect a wallet and sign something?
- Do you see withdrawals or trades you didn’t authorize?
- Did you communicate with the scammer via Telegram/Discord/WhatsApp/email?
Answering these questions helps you contact support effectively.
Contact the right people (and use evidence)
1) Use official Bybit support channels only
When you’re scammed, scammers often try to “stay in the loop” by offering a recovery service. Avoid any assistance that requires you to:
- share your password/2FA codes,
- pay more to “unlock” access,
- sign new transactions without verification,
- or send funds to a “verification wallet.”
Instead, go through Bybit’s official support routes—typically through the Bybit website/app “Help Center” or official support contact methods. If you’re unsure, navigate there directly rather than clicking links from the scammer.
2) Prepare a clear timeline
Support teams usually work faster when you can provide a structured report. Gather:
- The date/time you first noticed the issue
- The method of contact (email/DM/website link/platform)
- Exact messages (screenshots are fine)
- Any transaction IDs, wallet addresses, or order numbers involved
- The actions you took (e.g., password entered on a link, 2FA shared, API key created)
- Your account details that Bybit can verify (avoid posting secrets in public—only include what support requests)
3) Request account security review
In your report, ask for:
- verification of unauthorized access,
- reversal options if applicable,
- and guidance on what you can do to prevent recurrence.
Even if money can’t be recovered, a security review may help block further attempts and protect any remaining assets.
Stop the scammer from targeting you again
1) Change passwords across related accounts
A common issue is credential reuse. If you used the same password anywhere else (email, social media, banking apps), change those too—starting with your email account.
2) Secure your email (often the key to everything)
If the scam started via email:
- change your email password,
- check for email forwarding rules,
- review recent login activity,
- enable 2FA on your email if it isn’t already enabled.
Since email can reset passwords, protecting it is critical.
3) Watch for follow-up “recovery” attempts
Once scammers realize you’re still trying to solve the problem, they may offer:
- “chargeback” services,
- “hacked account recovery,”
- “special investigators,”
- or access to a “recovery bot.”
Treat these as high-risk until verified as legitimate. In most cases, these are scams riding on your urgency.
Guide: what to do in the first 60–90 minutes
- Stop all activity on the account (no more deposits, no more “confirmations”).
- Change your Bybit password and enable/update 2FA.
- Remove unknown sessions and revoke suspicious API keys/connected apps.
- Check for unauthorized trades or withdrawals in your activity history.
- Secure your email immediately (password + 2FA + check forwarding).
- Gather evidence: screenshots, links used, transaction IDs, timestamps, wallet addresses.
- Contact official Bybit support with a clear timeline and the evidence you collected.
If you do only a few things, do the first four and the email security. Those steps often reduce further harm the most.
Pros and cons of taking action quickly
Pros
- You reduce additional losses if the attacker still has access.
- You improve your chances with support by providing a timely, accurate timeline.
- You prevent repeat targeting, especially by securing your email and 2FA.
- You create an audit trail (transactions and activity) that’s useful for investigations.
Cons / limitations
- Scammed funds may be unrecoverable, especially if they were withdrawn to an external wallet quickly.
- Support response times vary, and not all cases result in restitution.
- Overreacting can also cause mistakes—for example, sending money to “recovery” services or approving new transactions.
- If you shared sensitive info, the attacker may have already moved quickly beyond what account security can fix.
The key is to move fast—but also verify information and only follow official guidance.
Conclusion
Getting scammed is incredibly frustrating, but your next steps can still make a real difference. If you suspect something went wrong on Bybit, focus on immediate account security, protecting your email, and gathering evidence for official support.
Most importantly: don’t trust “recovery” promises from strangers, and don’t follow links or instructions that weren’t initiated from official Bybit channels. If you act quickly and report clearly, you’ll give yourself the best possible chance to limit damage and prevent the scammer from continuing to exploit you.
If you want, tell me what kind of scam it was (fake support, phishing link, withdrawal you didn’t authorize, wallet approval, etc.)
🚀 Sign up for bybit
Register for bybit here to get 20% off trading fees
Start using bybit to trade crypto safely and efficiently.






















