Why you should never tell anyone your verification code

One six-digit message can be enough to lose an account and the wallet behind it. Here is why the code is yours alone, and how the usual tricks work.

Published September 30, 2026 · 3 min read

Why you should never tell anyone your verification code
Key takeaways
  • A code is proof of identity, so whoever has it can act as you.
  • No genuine service or support team needs you to read a code aloud or send it in a chat.
  • Scammers invent reasons such as a refund or a security check to make sharing feel routine.
  • Blockchain transfers cannot be reversed, so a leaked code can cost money that no one can bring back.

What does a verification code actually do?

A login or verification code, whether it arrives by SMS or in Telegram, is the step that proves the person entering it is really you. The service sends it to a channel you control, and you type it into the screen you opened yourself. That is the whole design: the code travels to you and stops there. If someone else learns it, the proof no longer points to you, and the service has no way to tell the difference.

Why would a real service never ask me to read the code out?

Because the code is for you to enter, not to share. A service that sent you the code already knows it, and its systems check what you type in the app or on the site. There is nothing an employee could do with your code that the service cannot do on its own side. So a request to read it aloud, send it in a chat or forward it is a warning sign in itself. This holds for every service and its support team, and it holds for Nexus Pay too.

What reasons do scammers give to get a code?

Scammers rarely say "give me your code". They build a story in which reading it out seems like a normal step, and they usually add urgency so you have less time to think. Common pretexts are a refund that supposedly needs confirming or a "security check" on your account. The message you receive is real, because the scammer has just triggered a login on your account. That makes the story feel more believable. The table below matches each pretext to what is really going on.

Common pretexts for asking for a code and how to respond
PretextWhat the scammer really wantsWhat to do
"Refund"A code that confirms a login to your accountRefuse; a refund never requires you to read out a code
"Security check"A code that lets them in while you think you are protecting the accountEnd the call or chat and open the service yourself
"Support" verifying your identityTo sound official so the request feels routineRemember that real support never needs your code
Any urgent storyTo rush you before you thinkPause, do not share anything, and check through the official app

What can happen to a crypto wallet if a code leaks?

Losing a login code can hand over the account, and from the account, the wallet. With a crypto wallet the damage is harder to undo than with many other accounts, because blockchain transfers are irreversible. If funds are sent to an address the attacker controls, nobody can bring the transfer back. That is why the code deserves the same care as a card PIN, and why it is worth keeping the amount you hold in any account proportionate to how well you protect it.

How do I protect my account from code scams?

The rules are short, and the first one covers nearly every case. Follow them even when the caller sounds informed or the pressure feels real.

  • Never read out, type into a chat or forward a code, whoever asks.
  • Enter a code only in the app or site you opened yourself, at the moment you asked for it.
  • If someone calls or writes about a "refund" or "security check", end the conversation and go to the service through its official app.
  • Turn on extra barriers where they exist: Nexus Pay, for example, offers an optional four-digit access code in the app.

If you have a card, remember that it only spends the available balance, with no credit or overdraft, and that in Nexus Pay it can be frozen and unfrozen in one tap.

What should I do if I already gave someone a code?

Act at once and stop the conversation, without giving any further codes or details. Open the service yourself, through its app rather than a link someone sent you, and check what has changed. If you use a Nexus Pay card, freeze it in the app, which takes one tap, and you can unfreeze it later. Then contact the service's support through its official channel. Be realistic about one point: a blockchain transfer that has already gone out cannot be recalled, so speed matters.

Common questions

Is it safe to share only part of the code?
No. Even part of a code helps someone who is guessing or tricking you, and no legitimate service needs any part of it. Keep the whole code to yourself.
What if the person on the phone knows my name and other details?
That proves nothing. Personal details can be gathered from other sources, and a real service still would not need your code. If you are unsure, hang up and contact the service through its app.
Does the code work the same way in Telegram as in SMS?
Yes, in the sense that matters here. It is proof that you are the one logging in, so whether it comes by SMS or in Telegram, it should never be passed on.
Can support ever ask for my code to help me?
No. Support can check things on the service's side without it. A request to read the code out is a sign the person is not who they claim to be.
Can stolen funds be returned after a wrong transfer?
Blockchain transfers are irreversible, and nobody can bring back a transfer sent to the wrong address. That is why prevention matters more than any fix afterward.

Open a wallet you control with Nexus Pay

In Telegram, in a minute, with no paperwork.

Open Nexus Pay