Risks of remote access software

Remote access software lets someone else see or control your device from anywhere in the world. It has legitimate uses — IT teams use it to fix computers without being in the room. But handing that control to the wrong person is one of the fastest ways to lose access to your accounts and your crypto.

Remote access scams are now among the most effective attacks against crypto holders, because they turn your own trusted device into the tool used against you. Kraken will never ask you to install remote access software, and no legitimate bank, exchange or government agency will contact you out of the blue to ask you to.

Remote access software ends up on your device in one of three ways: you install it deliberately for a legitimate reason, you are persuaded to install it by someone who intends to steal from you, or it is installed without your knowledge. This article covers all three.

Three different things often get grouped under the same label, and the differences matter:

Screen sharing lets another person watch your screen in real time. Tools like Zoom, Microsoft Teams and Google Meet do this. They cannot control your device, but whoever is watching can read everything you display — including passwords as you type them, one-time codes as they arrive, and a seed phrase if you open your wallet backup.

Remote control hands over your mouse and keyboard. Tools like AnyDesk, TeamViewer, LogMeIn, UltraViewer, RustDesk and Windows Quick Assist do this. Whoever is connected can open your files, install other software, change your settings and operate your accounts as though they were sitting at your desk.

A remote access trojan (RAT) does the same thing as a remote control tool, but hides. It is installed without your permission, runs silently in the background, and is designed not to appear in the places you would think to look. Attackers also install legitimate remote monitoring tools — the kind IT departments use, such as ScreenConnect, Atera or SimpleHelp — for exactly this purpose, because those tools are signed, trusted and unlikely to be blocked.

The first two are widely used, legitimate applications. That is precisely why they are attractive to malicious actors: your antivirus software may not flag them as a threat, and downloading them does not look suspicious. The danger is rarely in the software itself — it is in who ends up on the other end of the connection.

Once a malicious actor is connected to your device, they can:

  • Read anything on your screen, including your password as you type it, two-factor authentication (2FA) codes, device approval codes and recovery phrases.
  • Open, copy or delete your files — including screenshots, password manager exports and wallet backups.
  • Operate accounts you are already signed in to, without ever needing your password.
  • Install malware or leave the remote access tool running quietly, so they can return days or weeks later.
  • Disable your antivirus software or change your security settings.
  • Blank or freeze your screen so you cannot see what they are doing while they do it.

There are legitimate reasons to use these tools. You might connect to your own work computer from home, let a colleague present to you, help a family member with their device, or work with an IT technician you contacted yourself. What matters is who is on the other end, and what is visible while they are connected. If you do use it:

  • Only accept a session you arranged yourself, with a person or company you contacted.
  • Close anything sensitive first — exchange accounts, banking, email, password managers and wallet backups. Assume everything on screen can be read and copied.
  • Never sign in to Kraken, approve a withdrawal or open a wallet backup while a session is active.
  • Stay at the device, watch the session, and end it as soon as the work is done.
  • Uninstall the software when you no longer need it, or turn off unattended access so nobody can reconnect without your approval.
  • Where you can, keep it off any device you use to hold or move crypto.

Almost every version of a remote access scam follows the same four steps.

  1. A reason to install it. You are contacted out of the blue — by phone, email, text, a browser pop-up or a social media message — and told there is an urgent problem only remote help can fix.
  2. The install. You are walked step by step through downloading a remote access or screen sharing tool and granting permission. The caller stays friendly, patient and reassuring throughout.
  3. The theft. The malicious actor either takes the keyboard and moves funds while your screen is blanked, or coaches you through the transfer so that you authorize it yourself. Coaching is common because it defeats security checks that you would otherwise have to pass.
  4. The cover-up. They keep you on the call, explain away any alerts you receive, and disconnect once the funds have moved. Often the software is left installed so they can come back.
  • Fake tech support: a pop-up, call or search-engine ad warns your device is infected and offers to clean it.
  • Refund or overpayment: you are told you are owed a refund, then shown a “mistake” in which too much was paid back, and asked to return the difference in crypto.
  • Fake security team: someone claiming to be from a legitimate source (your bank, tax department, email provider, crypto exchange support) says your account is under attack and offers to secure it remotely.
  • Investment or account manager: a “broker” offers to set up your trading account or place trades for you, and needs access to do it. Legitimate brokers do not require remote access to your device.
  • Recovery scams: after you have already lost funds, someone offers to recover them for you — and asks for remote access to your device or wallet.

You do not have to be talked into installing remote access software to lose control of your device. Remote access can also be installed silently, through a single click, and there may be no person persuading you at all. In these cases the first sign of trouble is often an unauthorized withdrawal.

The most common delivery methods are:

  • Fake verification prompts. A page displays what looks like a CAPTCHA or a “verify you are human” check, then asks you to press a keyboard shortcut and paste something into a Windows Run box or a Mac Terminal window to complete the check. Pasting that command installs the malware yourself. A genuine CAPTCHA never asks you to open a command window or run anything.
  • Phishing attachments and links. An email or message — a meeting invite, an invoice, a delivery notice, QR code, a letter from a government agency — leads to a file that quietly installs a remote monitoring tool in the background. These installers are often correctly signed, so they raise no warning when they run.
  • Fake download pages and search ads. Paid ads and lookalike sites for popular software, including remote access tools and crypto wallets, can rank above the real vendor. The installer works as expected while also installing something else. Always type or bookmark the vendor’s own address rather than clicking an ad or a search result.
  • Fake browser or app updates. A pop-up on a legitimate but compromised website claims your browser, video player or wallet extension is out of date. The “update” is the malware. Update software only from within the application or from the vendor’s site.
  • Fake job offers and coding tests. Someone posing as a recruiter for a company invites you to an interview, then asks you to install their interview or assessment software, or to download and run a take-home project. This tactic often specifically targets people who work in or hold crypto.
  • Browser extensions, including ones you already trust. A fake extension impersonating a wallet, a price tracker or a security tool can sit in an official store and ask for permission to read everything you do in your browser. The subtler risk is an extension you installed years ago and have used safely ever since: extensions can be sold to a new owner or have their developer account compromised, and because they update themselves silently in the background, one you trust can turn hostile without you clicking anything. Review your installed extensions from time to time, remove anything you no longer use, and treat a request for new permissions as a reason to look closely.
  • Cracked software and activation tools. Pirated applications are a long-standing delivery route for remote access software. On a device that holds crypto, the risk is rarely worth it.

Covert remote access is designed to be hard to spot, and none of these signs is proof on its own. Treat several appearing together as a reason to investigate:

  • Your cursor moves, windows open or text is typed when you are not touching the device.
  • Your screen briefly goes black, freezes or flickers, or your device wakes from sleep by itself.
  • Programs you do not recognize appear in your installed applications or in your startup items.
  • Your antivirus software has been switched off, or its settings have changed, without you doing it.
  • Your device is slow, hot or running its fan hard while you are not using it.
  • You receive sign-in alerts, device approval requests or 2FA prompts you did not trigger.
  • There are sent emails, messages or password reset emails in your accounts that you did not send or request.

For more on how malicious software reaches your device and how to remove it, see Beware of computer malware. If you think remote access software is running on your device, follow the steps in the “If you think your device has been accessed” section below — they apply whether you granted access or not.

Treat any of the following as a reason to end the conversation immediately:

  • You did not initiate the contact.
  • You are asked to install AnyDesk, TeamViewer, Quick Assist, UltraViewer or any similar tool.
  • You are asked to share your screen while signing in to an account.
  • You are asked to read out a 2FA code, device approval code, password or seed phrase.
  • You are asked to disable 2FA, remove a Master Key or turn off your Global Settings Lock during contact you did not initiate.
  • You are told your screen will go blank “while we work”, or asked to look away.
  • You are asked to move your funds to a “safe”, “protected” or “secure” wallet or account. This is a scam script, not a real security procedure.
  • You are pressured to act immediately, told not to tell anyone, advised on how to answer legitimate support emails, or asked to stay on the line while you make a transfer.
  • You reached the “support” number through a search engine, an ad or a social media reply rather than the official website.

Kraken Support will never ask you to:

  • Install remote access or screen sharing software, or grant access to your device.
  • Provide your password, 2FA code, device approval code, Master Key or wallet seed phrase.
  • Make any security change while someone is connected to your device, or during a call or chat you did not request.
  • Move your funds to another wallet or account to keep them safe.

If you receive a call claiming to be from Kraken and you did not request it, hang up. You can verify that you are speaking to a genuine Kraken Support specialist using the in-app verification feature described in How to contact Voice Support.

These steps apply whether you granted access during a call or believe something was installed without your knowledge. Act quickly, and use a different device you trust for anything that involves signing in.

  1. Disconnect the affected device from the internet, and end the remote session if one is still active.
  2. Uninstall the remote access software completely. Check your installed applications and your startup items for anything you do not recognize — not only the tool you were asked to install.
  3. From a separate, trusted device change the password for the email address linked to your Kraken account, and for any other account that was visible during the session.
  4. Change your Kraken password and sign out of all active sessions. See Securing your Kraken account and digital life.
  5. Review your Kraken account for changes you did not make: new or removed 2FA methods, new API keys, new withdrawal addresses in your address book, and updated contact details.
  6. Run a full antivirus scan on the affected device. If full remote control was granted, the safest course is to reinstall the operating system — a scan cannot guarantee that nothing was left behind.
  7. Contact your bank if your banking was accessed or visible, and ask them to review recent activity.
  8. Report it to us using our suspicious activity form.
  9. If you held a wallet outside Kraken on that device, treat the seed phrase as compromised and move those funds to a new wallet with a newly generated seed phrase.
  • Enable Passkeys. Passkeys are phishing-resistant and cannot be read off your screen or repeated to a caller, unlike a 2FA code. See What is a Passkey?.
  • Enable a Master Key. A Master Key prevents your Kraken password from being reset even if your email is compromised. See What is a Master Key?.
  • Enable the Global Settings Lock (GSL). The GSL blocks changes to your account settings and withdrawal addresses, and hides sensitive account information. It is your last line of defense if your password and 2FA are compromised. See What is the Global Settings Lock (GSL)?.
  • Never install software at a stranger’s request. If you need technical help, contact the company yourself using a number or link you found on their official website — not one that was given to you.
  • Never paste a command you did not write. No legitimate website, verification check or support process requires you to run a command in Terminal, PowerShell or the Windows Run box.
  • Download software from the source. Type or bookmark the vendor’s address rather than clicking a search result or an ad, and install updates from within the application itself.
  • Keep your device and browser updated, and keep reputable security software switched on. Neither will stop every attack, but both raise the cost of reaching you.
  • Slow down. Urgency is the tool that makes this scam work. Ending a call costs you nothing; if it was genuine, you can always call back on a verified number.

Need more help?