A caller or texter says you've won, then adds a twist: "To confirm you're a real person, we just sent a 6-digit code to your phone — read it back to us." A second later a code lands in your messages. It looks official, it feels like a harmless identity check, and that is exactly why it works. What actually happened is that the scammer typed your phone number into a login or password-reset screen, and the code your carrier just delivered is the key to your account. Say it out loud and you've handed it over.
Why the code is never a "verification" of you
Real one-time passwords (OTPs) exist to prove you are logging in — not to prove anything to a stranger. When a legitimate service sends a code, the message itself almost always says so: "Your code is 481902. Don't share it with anyone — no one from our team will ever ask for it." Read that line before you read the digits. Google, Apple, Amazon, PayPal, your bank, and every major platform put that warning in the text precisely because this scam is so common.
A giveaway sponsor has zero reason to trigger a code to your phone. There is nothing on your device they need to "verify," and no legitimate prize claim requires you to relay numbers a machine just texted you. If someone generated a code by entering your number, they're standing at the login door to one of your accounts — email, a bank, a crypto app, an Amazon login — waiting for you to speak the only thing keeping them out. The request to "read it back" is the whole scam in five words.
The account takeover playbook, step by step
Here's the sequence in real time. The scammer opens the login page for your email or a payment app, enters your phone number or address, and clicks "Forgot password" or "Text me a code." The service dutifully sends you the OTP. On the phone with you, they fill dead air — "This just confirms you're not a bot" — while the clock runs, because most codes expire in 5 to 10 minutes. The moment you recite the digits, they type them in, reset the password, and lock you out. From there they drain stored balances, hit saved cards, or use your inbox to reset every other account tied to it.
Watch for the pressure tells that ride along with the ask: a code that arrives unrequested, a stranger who needs it read back "in the next couple of minutes," or a script that reframes the code as a "claim number," "release code," or "verification PIN." Same trick, different label. If any of that is happening, hang up. Then go open the account yourself — not through a link they sent — and change the password. If a code you didn't ask for shows up on its own, someone already has your number in a login box; treat it as an early warning, not a nuisance.
The one rule that shuts it down
You don't need to identify the scam, the platform, or the story behind it. Just apply a single flat rule: a code texted to your phone is for your eyes only, and no honest person will ever ask you to share it. Not a sponsor, not "account security," not a support agent, not a fellow winner. The instant anyone asks you to read back digits, you already know it's a scam — no other detail matters.
If you slip and relay a code, move fast: change that account's password, enable an authenticator app instead of SMS, and check recent-activity and password-reset logs. In the US you can report it at reportfraud.ftc.gov.
Codes are yours alone — if someone asks you to read one back, they're breaking into your account, not verifying you.