Skip to main content

How to Avoid Scams and Safeguard Your Account

Common account-impersonation and phishing scam patterns targeting Retired.com clients, and how to protect your account.

If you notice unauthorized activity or suspect a phishing attempt on your Retired.com account, please contact our Service team immediately by phone 1-800-738-4733 or email support@retired.com

Retired.com prioritizes the safety and security of users' digital assets. In addition to our security measures, we encourage you to read about common scams and phishing attempts and learn how to protect your information and assets from these attacks.

Scammers sometimes impersonate Retired.com, our custodian, or a crypto exchange to trick account holders into moving funds or handing over account access. This article covers the patterns to watch for and how to keep your account safe.

Avoid Scams – What to Look Out For

Scams attempt to obtain the funds of Retired.com customers (or other companies) typically by pretending to be associated with Retired.com and requesting your personal information. Here are some scams to look out for:

  • Scams that send you a fake balance and ask you to claim funds

  • Scams that ask you to download an app to cash out

  • Scams that ask you to obtain Bitcoin on a cash machine or ATM

  • Scams with a QR code that require a deposit to release funds

Impersonating a cryptocurrency exchange and providing a support number

In this scam, the perpetrator will email the target prompting users to claim funds, for example $24,000, that are claimed to be held with the exchange they are impersonating. They will then provide the Retired.com phone number, pretending it is the phone number of the exchange.

Retired.com will never send you an email telling you to call us and claim funds. If you receive an email that does not match your holdings, or you receive a suspicious email providing our contact information and are not yet a customer, it is likely a scam.

Impersonating a crypto app and providing instructions on how to cash out

In a similar attack, customers are told they have available bitcoin to claim, and to download a particular app to do so. The scam is likely designed to encourage the transfer of user assets to said app, and then to the attacker. If you are a customer, there is no way to “cash out” outside the Retired.com platform, and if you are not a customer, no external company will legitimately provide our contact information as part of a necessary process to obtain your funds.

Instructing you to obtain crypto from a Bitcoin ATM or cash machine

Retired.com is not partnered with any bitcoin or cryptocurrency ATMs or cash machines. Any communications associating user holdings with, or implying necessary use of, ATMs to obtain funds or “cash out” is more than likely fraudulent or a scam.

Impersonating Retired.com or the Service team, requiring a deposit to release funds

Retired.com allows customers to self-trade different cryptocurrencies, or return to cash, at any time via its mobile app or web portal. While there are fees, there is no significant deposit required to release funds, and we will never ask you to deposit cryptocurrency to an unknown or external wallet address to release your funds. If you’re contacted in such a manner or were provided a QR code to deposit cryptocurrency in order to release your funds from Retired.com, the attempt is likely fraudulent.

Is a DocuSign request, email, or call really from Retired.com?

Legitimate account forms — distributions, deposits, direction of investment, beneficiary updates, and similar — are often sent to you to sign electronically through DocuSign, so a DocuSign request is not automatically a scam. What tells the two apart is the context: a genuine request relates to a form or action you're expecting, comes from a Retired.com or DocuSign address, and never asks you to move funds to an unfamiliar wallet, share your password, or read back a two-factor authentication (2FA) code.

If a message, call, or signature request arrives out of the blue, doesn't match anything you initiated, or pressures you to act quickly, don't click links or call numbers from the message itself. Contact the Service team using contact information you already have to confirm whether it's genuine before you act on it.

Tips to Safeguard Your Account

  1. When in doubt, contact us: If you're ever uncertain whether a communication is genuine, contact the Service Team directly using contact information you already have — not a number or link from the suspicious message.

  2. Keep your information up-to-date: Keep your contact information (phone, email, address) current on your account, so we can reach you and verify requests with you.

  3. Create a strong password for your account: Use a strong, unique password, and consider updating it every 3–6 months.

  4. Never share your passwords: Never share your password with anyone.

  5. Beware of phishing attempts: Scrutinize emails and links that claim to come from Retired.com — check the sender address carefully before clicking anything.

  6. Don't use public Wi-Fi networks: Avoid accessing your account over public Wi-Fi.

Additionally, Retired.com staff will never:

  • Ask you for your 2-Factor Authentication code.

  • Ask you to install software on your device (except for the Retired.com mobile apps, through the official Apple App Store or Google Play store links)

  • Remotely access your device to act on your account.

  • Access or move funds held in your account.

  • Ask you to provide personal information over email like SSN or date of birth.


Need more support? Contact our Service team

Select "Start a Conversation" from the Chat menu or call us at 1-800-RETIRED

Did this answer your question?