India incident response / Act without panic12 min read • Reviewed 22 Aug 2026
How to report a crypto scam in India
Speed matters after financial cyber fraud, but so does preserving evidence. Stop further loss, use official reporting channels, secure unaffected assets and avoid anyone promising guaranteed recovery.
Stop the next loss first
- Do not send another “tax,” “unlock,” “verification” or recovery payment.
- Do not share an OTP, seed phrase, private key or remote-device access.
- Contact the bank, payment service or exchange through a channel you find independently.
- Use a trusted device when changing passwords or securing accounts.
- Do not delete the chat, app, transaction history or suspicious email yet.
Call 1930 or report online immediately
India’s official cybercrime portal directs victims of online financial fraud to the national helpline 1930 and cybercrime.gov.in. Provide accurate transaction details and retain the acknowledgement number. Follow the portal’s instructions to complete the complaint after a helpline report.
Build one evidence pack
- A short timeline with dates, times and what happened
- Bank, card, UPI, exchange or wallet transaction IDs
- Wallet addresses, token, network and blockchain transaction hashes
- Order IDs, counterparty profile and payment-name details
- Original messages, email headers, phone numbers, handles and URLs
- Screenshots plus exported statements or files where available
- Amounts in INR and crypto with the time of each transfer
- Complaint, support-ticket and acknowledgement numbers
Keep originals where possible. A cropped screenshot can be useful, but an exported statement, complete email or transaction page often contains context that a crop removes.
Notify each affected service through verified channels
Contact the sending bank or payment provider, exchange, wallet provider and any receiving platform you can identify. State that the transaction is disputed or connected to suspected fraud, provide the official acknowledgement, and ask what evidence and preservation process they require. Do not rely on a support account that contacted you first.
Secure accounts without destroying evidence
From a trusted device, secure the primary email account first, then exchange accounts, cloud backups and other services that reuse the password. Review active sessions, API keys, withdrawal addresses and multi-factor methods. If a seed phrase or private key was exposed, treat that wallet as compromised and obtain careful assistance before moving remaining assets.
If a malicious token approval or signature is suspected, preserve the transaction first and review allowances using a reputable block explorer or wallet tool. Revocation itself is an on-chain transaction and cannot undo an earlier theft.
Report suspect identifiers separately when useful
The National Cybercrime Portal’s Report Suspect facility accepts suspicious URLs, WhatsApp or Telegram handles, phone numbers, email IDs and social-media URLs. This does not replace a victim complaint where loss occurred; use the route that matches what happened.
Watch for the recovery scam that follows
Fraud victims are often contacted by people claiming to be hackers, lawyers, officials or blockchain investigators. Treat guaranteed recovery, upfront crypto payments, secret contacts and requests for wallet credentials as danger signs. Verify professionals and public authorities independently.
Check the source