EE / Trust & Safety

FAQ
v1.0

Disengagement flags & what to do instead.

Recovery scams evolve every week, but the tells don't. Below are the ten questions we're most often asked when a victim isn't sure whether they're talking to us or to someone pretending to be us — with the specific action to take before any more damage is done.

Ten questions, ten actions

01 / Field guide
  1. 01Flag · Unsolicited DMs on Telegram, Instagram or X

    Someone messaged me on Telegram / Instagram / X claiming to be from Elliptic Enterprises. Is that you?

    Why it's a flag

    No. We never cold-DM victims on social platforms. Impostors scrape breach forums and victim threads and reach out first — the initial contact itself is the tell.

    Do this instead

    Do not reply, do not click links, and do not share your case details. Screenshot the profile and the message, then file a report so we can pursue a takedown.

  2. 02Flag · A WhatsApp number that wasn't confirmed in writing first

    I was given a WhatsApp number and told it's my Elliptic Enterprises partner. How do I know it's real?

    Why it's a flag

    We do use WhatsApp during live engagements, but we only ever hand over a number after you've received it in writing from an @elliptic-enterprises.co.uk email. A WhatsApp number that appears out of nowhere — in a DM, on a website, from a 'referrer' — is not ours.

    Do this instead

    Reply to your original @elliptic-enterprises.co.uk thread and ask your partner to re-confirm the number. If you don't have an email thread yet, the number is not ours.

  3. 03Flag · Any email domain other than @elliptic-enterprises.co.uk

    I got an email from elliptic-enterprises.com / .net / .co / a Gmail address. Is that legitimate?

    Why it's a flag

    No. UK law mandates our .co.uk domain and we email from nothing else. Every .com, .net, .co, .support, .recovery, hyphenated variant, or free webmail (Gmail, Outlook, Proton) is an impersonator.

    Do this instead

    Do not reply and do not open attachments. Forward the full email — including headers — to intake@elliptic-enterprises.co.uk and file an impersonation report.

  4. 04Flag · Signed by "Jeffery Nimoy" or "Maximilian / Max Nimoy"

    The message is signed "Jeffery Nimoy" or "Max Nimoy". Do they work with you?

    Why it's a flag

    No. These are known impostor aliases. No one by these names works with Elliptic Enterprises in any capacity.

    Do this instead

    Disengage immediately. Preserve the message and any wallet addresses or payment details they sent, then file a report so we can add them to the public warning.

  5. 05Flag · Claims of FINRA registration in the individual's name

    They said they're personally FINRA-registered. Doesn't that make them legitimate?

    Why it's a flag

    The impostors routinely claim personal FINRA registration. They are not on the register. Our firm's specialties operate within the FINRA framework — that's a firm-level statement, not a licence anyone can wave around in a DM.

    Do this instead

    Search the name for free at brokercheck.finra.org. If the individual isn't listed, the claim is false — disengage.

  6. 06Flag · Anyone asking for your seed phrase or private keys

    They asked me to share my seed phrase / private key / to import my wallet so they can 'recover' the funds. Is that ever needed?

    Why it's a flag

    Never. No legitimate investigator, exchange, lawyer or regulator will ever ask for a seed phrase or private key. Anyone who does is trying to steal the rest of your wallet.

    Do this instead

    Stop the conversation. Move any remaining assets to a fresh wallet whose seed phrase they have never seen, then report the request.

  7. 07Flag · Screen-sharing that pivots to seed phrases or wallet approvals

    We use screen-sharing on real engagements. How do I tell a legitimate session from a scam one?

    Why it's a flag

    Screen-sharing (AnyDesk, TeamViewer, Zoom, Meet) is a normal part of our work — walking through block explorers, reviewing exchange dashboards, coordinating filings. The tell isn't the tool, it's what they ask you to do on camera: type a seed phrase, reveal a private key, or approve a wallet transaction you didn't initiate.

    Do this instead

    End the session the moment anyone asks you to type a seed phrase, expose a private key, or sign a transaction you didn't request. A real partner will pause and re-schedule — not push through.

  8. 08Flag · Upfront payment in crypto, gift cards or to a personal account

    They want an upfront fee — paid in USDT / BTC / gift cards, or to a personal bank account or wallet. Is that how you charge?

    Why it's a flag

    No. We invoice from the firm to your engagement email; we do not accept gift cards, do not accept crypto to personal wallets, and do not accept bank transfers to individuals.

    Do this instead

    Do not pay. Keep the wallet address or account number they gave you — it's evidence — and file a report.

  9. 09Flag · Fake dashboards showing your "recovered" balance

    They sent me a login to a portal that shows my recovered funds — but I need to pay a 'release fee' to withdraw. Is that yours?

    Why it's a flag

    No. This is the classic recovery-scam second stage: a fake dashboard designed to make you believe the funds exist so you'll pay a release, tax, or 'anti-money-laundering' fee. Our client portal never shows a claimable balance behind a fee gate.

    Do this instead

    Do not pay any release/tax/AML fee. Screenshot the dashboard URL and file a report — the domain is usually part of a wider takedown target.

  10. 10Flag · You're already a client and something feels off

    I'm mid-engagement with a real Elliptic Enterprises partner and I got a message that feels wrong. What do I do?

    Why it's a flag

    Impostors specifically target active clients by spoofing partner names, because the trust is already there. If a message breaks the pattern of your existing thread — new number, new email, urgent payment, new wallet — treat it as hostile until verified.

    Do this instead

    Don't reply on the new channel. Go back to your existing @elliptic-enterprises.co.uk email thread, or sign in to the client portal, and ask your partner to confirm.

02 / Next step

Still not sure? Ask us before you act.

Verify a contact

Forward the message to intake@elliptic-enterprises.co.uk from the address you originally contacted us on. We'll confirm within 24 hours whether it came from us.

Report an impostor

Have evidence of someone using our name? File a report. A partner reviews every submission within 24 hours and, where possible, files a takedown with the hosting platform.

Already a client?

Sign in to the client portal or reply on your existing @elliptic-enterprises.co.uk thread. Never verify a partner via a channel the partner themselves introduced in the suspicious message.