Skip to main content
Account & Security

Spotting Scams and Impersonators

Polycopy never asks for your private key outside Settings, never messages you first, and never asks you to send funds. Red flags, real support channels, and what to do if you already shared a key.

Last updated August 22, 2026

Public leaderboards make this product a target. Anyone can see who is trading well, and impersonators work that list. The whole scam industry around wallets comes down to one move: get you to reveal a key, or get you to send funds. Everything below is a variation on that.

The only real support channels

Support is help@polycopy.com and the Get Help form on the help centre. That is the entire list. We do not run support over direct messages, we have no chat help desk, and we do not phone you. If a conversation started because somebody contacted you, treat it as an attack until proven otherwise, however well they seem to know your account.

Direction matters more than platform. An account carrying our logo replying to your public post is not support. We answer where you wrote to us, from the address above.

Red flags, and what is really going on
What you seeWhat it really is

A message offering to help with a problem you posted about publicly

Somebody watching the same public feed you posted on

A request for your private key to verify or restore your account

Theft. The key is the account.

A request for your seed phrase or recovery words

Theft. Polycopy has no use for these and never asks.

A support agent asking you to screen-share while you open your wallet

They are reading your key off your screen

A site that looks like Polycopy on a slightly different domain

A phishing clone harvesting keys

A key field on any site other than polycopy.app/settings

Phishing, however perfect the page looks

An offer to recover lost or stolen funds for an upfront fee

A second theft, aimed at victims of the first

A verified trader offering to trade your funds for you

You never hand anyone funds in order to copy them

Urgency, such as your account will be locked in 30 minutes

Pressure, so you skip the check you would otherwise do

A giveaway or airdrop that needs a wallet connection first

A drainer signature request

Three checks that catch almost everything

Run these before you type anything sensitive anywhere.

Check the domain, character by character

The app lives at polycopy.app. Type it into the address bar yourself rather than following a link. Lookalike domains swap letters, add hyphens, or use a different suffix.

Check who started the conversation

We reply, we do not initiate. If they contacted you, the answer is no.

Check what is actually being asked for

A private key, a seed phrase, or a transfer of funds are never legitimate requests. There is no exception, no verification step, and no emergency that changes this.

What to do if you already shared a key

Act now and think about it afterwards. Speed is the only thing that helps here.

1

Move your funds

Log into Polymarket, sell what you can, and withdraw the cash to a wallet the exposed key does not control. Take a worse fill rather than a slower exit.

2

Disconnect the wallet in Polycopy

Settings, wallet section, Disconnect. That deletes the encrypted key from Turnkey. See How to Disconnect or Change Your Wallet.

3

Stop using that Polymarket account

You cannot rotate the key on an existing wallet, so that account stays exposed permanently. Start a fresh one.

4

Lock down 2FA on Polycopy and on your email

Your email is the recovery path for almost everything, so protect it first. See How to Set Up 2FA on Polycopy.

5

Tell us

Email help@polycopy.com from the address on your account with the affected wallet address, so we can watch for anything on our side and warn other people about the pattern.

How do I know an email is really from Polycopy?

We only ever email the address on your account, and we never ask for a key, a seed phrase, or a payment by email. When in doubt, do not click anything. Open polycopy.app yourself and check your account there.

If keys are so dangerous, why does Polycopy ask for one?

Because placing an order requires a signature. Yours is encrypted in your browser before it leaves your device and held by Turnkey, and Polycopy never sees it in readable form. That is a different thing from sending a key to a stranger in a chat. See Is My Money Safe?.

Still stuck? Send us a message and we'll reply by email.
Get help
Spotting Scams and Impersonators | Polycopy Help Center