After the 2025 cycle, the customer-support function became the highest-leverage attack surface in the sector, and operators split into two responses. Some are closing public channels — Morpho took its Discord read-only, DefiLlama moved off it — on the logic that a channel you don't run can't be turned against you. The logic fails.
Impersonation scams grew more than 1,400% in 2025 precisely because attackers pose as the support you withdrew: the channel stays open, just in your name, operated by them. Closing removes your relationship with the customer, not the attack surface. The operators holding trust keep the channel and move the risk — availability preserved for routine, high-risk actions pulled into the authenticated session. Four patterns separate re-architecture from retreat.
The retreat is a rational response to a real shift. In 2025, impersonation and AI-generated fraud overtook cyberattacks as the leading way funds are stolen. Chainalysis put crypto scam losses at roughly $17 billion for the year, with AI-enabled operations 4.5 times more profitable than traditional ones — about $3.2 million per operation. The FBI's 2025 IC3 report logged $11.4 billion in crypto losses and, for the first time, broke out AI-enabled fraud as its own category, at $893 million.
The support surface is where much of this lands. The Coinbase disclosure that bribed overseas contractors exfiltrated data on 69,461 customers, with $180–400 million in estimated remediation, was followed by a wave of impersonation fraud against those very customers. Closing the Discord is an understandable reflex. It is also the wrong move, because it cedes the channel rather than defending it.
Why closing the channel backfires
An impersonator does not need your Discord to be open. They need your customers to believe support might reach them there. When you withdraw the official presence, you do not remove that belief; you remove the only authentic voice that competes with the fake one. The customer still goes looking for help, finds the impersonator's server or DM, and has no official channel to check it against.
The attack surface did not close; your side of it did.
And the cost lands on the customer as fraud, and on you as the reputational damage of "I got scammed by someone pretending to be your support." That is the exact pattern behind the 1,400% impersonation surge.
Re-architecture starts from the opposite premise: the channel is a relationship to defend, not a liability to shed. The question is not whether the channel exists but where the risk completes. Routine interaction stays wherever the customer prefers; the actions that carry weight move to a place the operator controls.
- Retreat — close the channel. Removes your presence. The impersonator keeps theirs.
- Negligence — leave high-risk actions on open channels. The channel stays, and so does the exposure.
- Re-architecture — keep the channel, move the risk. Routine stays open on chat, email, X, Discord, Telegram, and phone. Account recovery, large transactions, KYC re-screening, and sanctions or PEP hits complete in the authenticated session — in-product, under the operator's control, with dual control.
Re-architecture, not retreat: what actually moves
1. Availability stays open; verification escalates by risk tier
Operators who hold keep every channel a customer might use — chat, email, X, Discord, Telegram, phone — open for routine interaction, and escalate verification and dual control only when the action enters higher risk: account recovery, large transactions, KYC re-screening, sanctions or PEP hits. Those actions complete inside the in-product authenticated session, not in the open channel where they began. This is the third way between the two failing options: closing the channel (retreat) and leaving high-risk actions exposed on open channels (negligence). It is the posture FCA Consumer Duty, NYDFS Part 500, DORA, and AMLA expect on the actions that carry weight.
2. The support agent surface is defended as its own attack surface
The Coinbase case established that the agent — the human with legitimate access — is a primary target, not an afterthought. Operators who hold apply hardware-key MFA aligned to NYDFS Section 500.12, dual control on privileged actions (account recovery, KYC document access, transaction reversal), behavioral anomaly detection at the workspace layer, and audit logs read as active monitoring rather than a compliance artifact filed after the fact. The re-architecture is incomplete if the channel is hardened and the agent operating it is not.
3. Third-party support vendors sit under documented ICT third-party risk management
The outsourced support layer is now inside the supervisory perimeter: NYDFS Section 500.11, DORA Articles 28–44, NIS 2 Article 21. Operators who hold contract vendor incident reporting to the operator's regulatory clock, not the vendor's, and can name the controls, the substitution plan, and the reporting timeline for each support vendor the way they would for any critical dependency. Operators who treat the vendor relationship as procurement carry a reporting gap that surfaces the moment the vendor is the breach.
4. Customer education is built into the product flow and names the current impersonation
Operators who hold place warnings at the moment of decision inside the product, send cryptographically verifiable communications so a customer can tell the real message from the fake, and onboard users against the impersonation patterns documented this year — not the generic "never share your seed phrase" the current attacks were specifically designed to defeat. Education that says "we will never DM you first, and here is how to verify any message that claims to be us" is a control; a boilerplate warning is decoration.
The four compound. Availability tiered by risk keeps the relationship while containing the risk; the hardened agent surface and the governed vendor close the operator's side; in-product education arms the customer against the impersonation the open channel invites. Strong on one and weak on three, and the retreat starts looking rational again — which is how operators end up closing channels they could have kept.
The line automation can't hold
Generalist AI and generic outsourcing handle the routine tier well: the volume that should stay open and cheap. The re-architecture is about the other tier — the account-recovery request that is really an account-takeover attempt, the "support agent" who is an impersonator, the privileged action that must complete under dual control. That is judgment under adversarial pressure, and cost-per-ticket optimization is efficient at exactly the work an attacker is counting on being cheap.
Automate the routine. The attacker is counting on you doing exactly that, and for the routine tier they are right. What they are also counting on is that cost-per-ticket will be allowed to reach the account-recovery request that is really a takeover.
That is a different job, not a cheaper ticket. Tiered on purpose: deflection for routine, a specialized operation for the actions the 2025 cycle turned into targets.
Where the line actually gets drawn
Re-architecting the support surface is a design decision, not a headcount one. A specialized operation runs the support layer with the agent surface itself under control — presence and observer detection, unauthorized-device detection, and geographic restriction at every agent desktop: the workspace-layer controls that answer the exact vector the Coinbase case exposed. The channel stays open to the customer; the risk completes where it can be defended.
Before you close a channel: five questions
Run these against your support surface, whether you operate it or a partner does.
- When a high-risk action begins on an open channel — account recovery, a large withdrawal, a KYC re-screen — does it complete in an authenticated session you control, or on the channel where it started?
- Is the support agent surface itself defended — hardware-key MFA, dual control on privileged actions, workspace-layer anomaly detection — or hardened only at the system layer?
- Can you name, for each support vendor, the controls, substitution plan, and incident-reporting timeline on your regulatory clock?
- Does your customer education name the current impersonation patterns and give a way to verify a real message, or repeat generic warnings the current attacks were built to defeat?
- If you have closed a public channel, where do your customers now go for help — and who is operating in that space in your name?
The last question is the one the retreat leaves unanswered.
Common questions
Isn't closing a public support channel the safer move after 2025?
It removes your presence, not the attack surface. Impersonation scams grew more than 1,400% in 2025 by posing as the support customers expect, so withdrawing the official channel leaves the customer with only the impersonator's version and no authentic one to check against. The safer move is to keep the channel for routine interaction and move high-risk actions into an authenticated session you control.
Why is the support agent, not just the customer, the target?
Because the agent has legitimate access. The Coinbase disclosure — bribed contractors exfiltrating data on 69,461 customers, with $180–400 million in estimated remediation — established the pattern: the cheapest way in is a person at the desk. Defending the channel without defending the agent surface leaves the primary vector open.
Where does a specialized operation fit?
As the layer that runs the re-architecture as one system: tiered availability, a defended agent surface, governed vendors, and in-product education. Toeshee operates that layer for regulated crypto, iGaming, and fintech operators under compliance discipline.
Toeshee is the specialized customer-support partner for iGaming, fintech, and digital-asset platforms, operating the support layer with risk management and compliance as the design principle of every workflow — SOC 2-compliant operations, risk-tiered escalation discipline, and Multi-Dimensional Security at every agent desktop.
We've got your back. Crypto-native.
