FAQ
v1.0
Disengagement flags & what to do instead.
Recovery scams evolve every week, but the tells don't. Below are the ten questions we're most often asked when a victim isn't sure whether they're talking to us or to someone pretending to be us — with the specific action to take before any more damage is done.
Ten questions, ten actions
01 / Field guide- 01Flag · Unsolicited DMs on Telegram, Instagram or X
Someone messaged me on Telegram / Instagram / X claiming to be from Elliptic Enterprises. Is that you?
Why it's a flagNo. We never cold-DM victims on social platforms. Impostors scrape breach forums and victim threads and reach out first — the initial contact itself is the tell.
Do this insteadDo not reply, do not click links, and do not share your case details. Screenshot the profile and the message, then file a report so we can pursue a takedown.
- 02Flag · A WhatsApp number that wasn't confirmed in writing first
I was given a WhatsApp number and told it's my Elliptic Enterprises partner. How do I know it's real?
Why it's a flagWe do use WhatsApp during live engagements, but we only ever hand over a number after you've received it in writing from an @elliptic-enterprises.co.uk email. A WhatsApp number that appears out of nowhere — in a DM, on a website, from a 'referrer' — is not ours.
Do this insteadReply to your original @elliptic-enterprises.co.uk thread and ask your partner to re-confirm the number. If you don't have an email thread yet, the number is not ours.
- 03Flag · Any email domain other than @elliptic-enterprises.co.uk
I got an email from elliptic-enterprises.com / .net / .co / a Gmail address. Is that legitimate?
Why it's a flagNo. UK law mandates our .co.uk domain and we email from nothing else. Every .com, .net, .co, .support, .recovery, hyphenated variant, or free webmail (Gmail, Outlook, Proton) is an impersonator.
Do this insteadDo not reply and do not open attachments. Forward the full email — including headers — to intake@elliptic-enterprises.co.uk and file an impersonation report.
- 04Flag · Signed by "Jeffery Nimoy" or "Maximilian / Max Nimoy"
The message is signed "Jeffery Nimoy" or "Max Nimoy". Do they work with you?
Why it's a flagNo. These are known impostor aliases. No one by these names works with Elliptic Enterprises in any capacity.
Do this insteadDisengage immediately. Preserve the message and any wallet addresses or payment details they sent, then file a report so we can add them to the public warning.
- 05Flag · Claims of FINRA registration in the individual's name
They said they're personally FINRA-registered. Doesn't that make them legitimate?
Why it's a flagThe impostors routinely claim personal FINRA registration. They are not on the register. Our firm's specialties operate within the FINRA framework — that's a firm-level statement, not a licence anyone can wave around in a DM.
Do this insteadSearch the name for free at brokercheck.finra.org. If the individual isn't listed, the claim is false — disengage.
- 06Flag · Anyone asking for your seed phrase or private keys
They asked me to share my seed phrase / private key / to import my wallet so they can 'recover' the funds. Is that ever needed?
Why it's a flagNever. No legitimate investigator, exchange, lawyer or regulator will ever ask for a seed phrase or private key. Anyone who does is trying to steal the rest of your wallet.
Do this insteadStop the conversation. Move any remaining assets to a fresh wallet whose seed phrase they have never seen, then report the request.
- 07Flag · Screen-sharing that pivots to seed phrases or wallet approvals
We use screen-sharing on real engagements. How do I tell a legitimate session from a scam one?
Why it's a flagScreen-sharing (AnyDesk, TeamViewer, Zoom, Meet) is a normal part of our work — walking through block explorers, reviewing exchange dashboards, coordinating filings. The tell isn't the tool, it's what they ask you to do on camera: type a seed phrase, reveal a private key, or approve a wallet transaction you didn't initiate.
Do this insteadEnd the session the moment anyone asks you to type a seed phrase, expose a private key, or sign a transaction you didn't request. A real partner will pause and re-schedule — not push through.
- 08Flag · Upfront payment in crypto, gift cards or to a personal account
They want an upfront fee — paid in USDT / BTC / gift cards, or to a personal bank account or wallet. Is that how you charge?
Why it's a flagNo. We invoice from the firm to your engagement email; we do not accept gift cards, do not accept crypto to personal wallets, and do not accept bank transfers to individuals.
Do this insteadDo not pay. Keep the wallet address or account number they gave you — it's evidence — and file a report.
- 09Flag · Fake dashboards showing your "recovered" balance
They sent me a login to a portal that shows my recovered funds — but I need to pay a 'release fee' to withdraw. Is that yours?
Why it's a flagNo. This is the classic recovery-scam second stage: a fake dashboard designed to make you believe the funds exist so you'll pay a release, tax, or 'anti-money-laundering' fee. Our client portal never shows a claimable balance behind a fee gate.
Do this insteadDo not pay any release/tax/AML fee. Screenshot the dashboard URL and file a report — the domain is usually part of a wider takedown target.
- 10Flag · You're already a client and something feels off
I'm mid-engagement with a real Elliptic Enterprises partner and I got a message that feels wrong. What do I do?
Why it's a flagImpostors specifically target active clients by spoofing partner names, because the trust is already there. If a message breaks the pattern of your existing thread — new number, new email, urgent payment, new wallet — treat it as hostile until verified.
Do this insteadDon't reply on the new channel. Go back to your existing @elliptic-enterprises.co.uk email thread, or sign in to the client portal, and ask your partner to confirm.
Still not sure? Ask us before you act.
Forward the message to intake@elliptic-enterprises.co.uk from the address you originally contacted us on. We'll confirm within 24 hours whether it came from us.
Have evidence of someone using our name? File a report. A partner reviews every submission within 24 hours and, where possible, files a takedown with the hosting platform.
Sign in to the client portal or reply on your existing @elliptic-enterprises.co.uk thread. Never verify a partner via a channel the partner themselves introduced in the suspicious message.