Why you should never tell anyone your verification code
One six-digit message can be enough to lose an account and the wallet behind it. Here is why the code is yours alone, and how the usual tricks work.
Published September 30, 2026 · 3 min read
One six-digit message can be enough to lose an account and the wallet behind it. Here is why the code is yours alone, and how the usual tricks work.
Published September 30, 2026 · 3 min read
A login or verification code, whether it arrives by SMS or in Telegram, is the step that proves the person entering it is really you. The service sends it to a channel you control, and you type it into the screen you opened yourself. That is the whole design: the code travels to you and stops there. If someone else learns it, the proof no longer points to you, and the service has no way to tell the difference.
Because the code is for you to enter, not to share. A service that sent you the code already knows it, and its systems check what you type in the app or on the site. There is nothing an employee could do with your code that the service cannot do on its own side. So a request to read it aloud, send it in a chat or forward it is a warning sign in itself. This holds for every service and its support team, and it holds for Nexus Pay too.
Scammers rarely say "give me your code". They build a story in which reading it out seems like a normal step, and they usually add urgency so you have less time to think. Common pretexts are a refund that supposedly needs confirming or a "security check" on your account. The message you receive is real, because the scammer has just triggered a login on your account. That makes the story feel more believable. The table below matches each pretext to what is really going on.
| Pretext | What the scammer really wants | What to do |
|---|---|---|
| "Refund" | A code that confirms a login to your account | Refuse; a refund never requires you to read out a code |
| "Security check" | A code that lets them in while you think you are protecting the account | End the call or chat and open the service yourself |
| "Support" verifying your identity | To sound official so the request feels routine | Remember that real support never needs your code |
| Any urgent story | To rush you before you think | Pause, do not share anything, and check through the official app |
Losing a login code can hand over the account, and from the account, the wallet. With a crypto wallet the damage is harder to undo than with many other accounts, because blockchain transfers are irreversible. If funds are sent to an address the attacker controls, nobody can bring the transfer back. That is why the code deserves the same care as a card PIN, and why it is worth keeping the amount you hold in any account proportionate to how well you protect it.
The rules are short, and the first one covers nearly every case. Follow them even when the caller sounds informed or the pressure feels real.
If you have a card, remember that it only spends the available balance, with no credit or overdraft, and that in Nexus Pay it can be frozen and unfrozen in one tap.
Act at once and stop the conversation, without giving any further codes or details. Open the service yourself, through its app rather than a link someone sent you, and check what has changed. If you use a Nexus Pay card, freeze it in the app, which takes one tap, and you can unfreeze it later. Then contact the service's support through its official channel. Be realistic about one point: a blockchain transfer that has already gone out cannot be recalled, so speed matters.
In Telegram, in a minute, with no paperwork.
Open Nexus PayOpening…