Edited by H. Omer Aktas
Ready to read this guide aloud.
Opening answer
A one-time code scam happens when someone tricks you into sharing a code sent by text, email, authenticator app, bank app, shopping app, or social media account. The code may approve a login, password reset, money transfer, new device, or account recovery. The safest rule is simple: if someone asks you to read, forward, screenshot, or type a code for them, stop. The code is meant for you only. The FTC warns that anyone asking for your verification code is a scammer, and that rule is a strong beginner habit.
Simple summary
- A one-time code is a temporary key for logging in or confirming an action.
- A scammer may already have your password and only needs the code.
- They may pretend to be a bank, buyer, friend, support worker, or family member.
- AI-written messages can make the request sound calm and believable.
- Never share the code with another person, even if the story sounds harmless.
Try this prompt
Use this prompt if you are unsure about a request. Do not paste the actual code into the AI tool. You can describe the situation without sharing the number.
Prompt:
Someone is asking me for a verification code that was sent to my phone. Explain why this could be dangerous. Give me a safe reply and steps to protect my account without sharing the code.
Plain-English explanation
A one-time code is like a temporary key. It may last only a few minutes, but during that time it can let someone pass a security check. The scam often begins before you see the code. The scammer may enter your email, phone number, or username on a login page. Then the real service sends a real code to you. The scammer contacts you and invents a reason you should share it.
The request may sound innocent: “I sent a code to you by mistake,” “I need to verify you are the seller,” “I am from support,” or “Your account is being protected.” The danger is that the code may give access to your account, not theirs. The FTC’s consumer alert says verification codes are only for you to log into your account and should not be shared with someone else: FTC verification code warning.
How people can use AI safely with this problem
AI can help you write a safe refusal, understand the scammer’s story, and prepare next steps. It should not receive the actual code, password, recovery phrase, or private account details. A safe AI task is: “Write a short message saying I cannot share verification codes.” Another safe task is: “Make a checklist for securing my account after a suspicious code request.”
Step-by-step guidance
- Do not share the code, screenshot, or notification.
- Stop the conversation if the person keeps pressuring you.
- Open the account app or website directly, not through their link.
- Change the password if you think they may know it.
- Turn on stronger multi-factor authentication where available, such as an authenticator app or passkey.
- Check account recovery email, phone number, and recent login activity.
- Report the scam through the platform, bank, or consumer-protection authority.
Safety and privacy notes
Never share one-time codes, login approvals, authenticator numbers, recovery codes, password reset links, passkeys, or bank confirmation numbers. A real support worker should not need your code. If you already shared one, act quickly: change passwords, sign out of other devices, contact the provider, and watch financial accounts.
Common mistakes to avoid
- Thinking it is safe because the code expires soon.
- Believing the person because they know your name, phone number, or email.
- Sharing a code to “prove” you are real in a marketplace sale.
- Reading a bank code to someone who called you first.
- Approving a login notification just to make it disappear.
- Pasting the actual code into AI while asking for advice.
Examples
Buyer scam: A buyer says they need a code to prove you are not fake. The code may let them register your number or enter your account.
Bank scam: A caller says fraud is happening and asks you to read the code for cancellation. The code may approve the fraud.
Friend scam: A hacked friend account asks for a code to recover their account. The code may actually be for your account.
Code request patterns
| Story | What may really be happening | Safe response |
|---|---|---|
| “I sent it by mistake” | They are trying to register or recover an account using your number | Do not send it |
| “I am from your bank” | They may be approving login or transfer access | Hang up and call the bank directly |
| “I need it to verify you” | They may be taking over a marketplace or messaging account | Refuse and report |
| “Read the number to cancel fraud” | The code may approve the action they claim to stop | Do not read it |
| “Tap approve” | They may be logging in from another device | Deny the request and change password |
What is a one-time code scam?
It is a trick where someone asks for a temporary login or verification code that belongs only to you. The scammer may use the code to enter an account, reset a password, link a device, move a phone number, or approve a transaction.
Is a code safe if I did not request it?
No. An unexpected code can mean someone is trying to log in, reset a password, or test your account. Do not share it. Open the account directly and check security settings if you are worried.
What should older adults know about codes?
A code is not a customer-service number and not proof that a caller is real. It is a key. If another person asks for it, the conversation should stop until a trusted person or official channel is involved.
Where to verify changing facts
Security settings differ by account. Check the official help pages for your bank, email provider, phone carrier, social platform, or shopping account. For general phishing advice, CISA’s guidance on recognizing and reporting phishing is useful: CISA phishing guidance.
FAQ
Can I share a code with my bank?
Do not share a code with someone who called or messaged you first. Call the bank using the number on your card or official app.
What if the person says they work for support?
Real support should not need your one-time code. Use the official app or website to contact support separately.
What if I shared the code?
Change your password, sign out other devices, check recovery settings, and contact the provider quickly.
Are authenticator app codes safer than text codes?
They can be stronger, but you still should not share them with another person.
Can AI tell if a code request is fake?
AI can explain warning signs, but you should treat any request for your code as unsafe.
Should I delete the code message?
You can keep a screenshot for reporting if needed, but do not send the code to anyone.
Final takeaway
A one-time code is a key, not a conversation detail. Keep it private, verify through official channels, and act quickly if you shared it. When in doubt, the safest answer is: “I cannot share verification codes.”