Spot Fake ‘Buyer Verification’ Prompts on Marketplaces Designed to Capture Your OTPs

Fraudsters are weaponizing trust on local and peer-to-peer marketplaces by pretending to be eager buyers who just need you to complete a “quick verification” before they proceed. The trap: they send you to a fake verification page or an automated bot that prompts you for a one-time passcode (OTP). That code is the last key they need to break into your accounts, reroute payments, or lock you out. This guide shows you how to spot these scams instantly, safely test suspicious requests, and protect your identity and money.

What this scam looks like in the wild

Here’s a typical pattern across Facebook Marketplace, Craigslist, OfferUp, Nextdoor, Poshmark, and similar platforms:

  • “I’m very interested — but we use Buyer Verification for safety.” The person pressures you to click a link or message a “verification bot” on WhatsApp, Telegram, or SMS.
  • You receive an OTP via SMS or email. The fraudster says “enter the code to confirm you’re real.” In reality, they just attempted to log in to one of your accounts using your phone or email — and your OTP is the final step they need.
  • They claim the marketplace now requires it. They drop fake policy language (“Trust & Safety requires ID code,” “merchant secure badge,” “Zelle buyer protection code”). None of this exists.
  • They escalate urgency. “I’ll buy now if you verify in 2 minutes,” “I can’t meet unless you complete this step.” The rush is intentional so you don’t think.

Why they want your OTP

Most major platforms and banks protect logins with two-step verification. If a criminal already has your username and password from a data breach or password reuse, your OTP is the only thing stopping them from getting in. They trigger a login to your account (or password reset), the site sends you a code, and they trick you into sharing it under the disguise of “verification.”

Once they have that OTP, they can:

  • Take over your marketplace account and impersonate you to scam others.
  • Access your email and reset passwords everywhere else.
  • Enter your bank or payment apps and attempt transfers, change contact info, or add new devices.
  • Lock you out by changing recovery options or enabling their own security tools first.

Common variations and wording they use

  • “Google Voice verification”: They ask for a code “to confirm you’re real.” They’re actually registering a Google Voice number using your phone, letting them spoof calls under your identity.
  • “Zelle/PayPal/Cash App buyer protection code”: No such thing. Payment apps do not require buyer-to-seller OTP checks via third-party links.
  • “Meta/Trust & Safety ID check”: If it’s not within the official app or domain, it’s fake.
  • “Verification bot” on WhatsApp/Telegram: Real marketplaces don’t use off-platform bots to verify you.
  • MFA fatigue calls: Repeated OTP or push prompts to wear you down so you approve one “just to stop the alerts.”

Legit verification versus a scam: quick test

Use these fast checks before you click or share any code:

  • Location: Real checks happen inside your account on the official app or website domain. If you’re pushed to a random site, a messaging app, or a QR code, it’s fake.
  • Direction of request: If a stranger needs you to complete an OTP to transact with them, it’s almost certainly a scam. Buyers don’t need your OTP for anything.
  • Who initiated the OTP? If you didn’t just try to log in or change a setting, an incoming OTP means someone else triggered it. Do not share it with anyone.
  • Domain check: Verify the URL is the exact official domain, with no lookalike spelling or extra words.
  • Support claims: If they say “support requires it,” ask them to point you to the exact policy page on the official site. It won’t exist.

Red flags you can trust every time

  • Any OTP or code request arriving during a chat with a stranger.
  • Off-platform verification steps (WhatsApp, Telegram, SMS short codes, or third-party links).
  • QR code scans to “prove identity.” QR links simply route you to phishing pages.
  • Pressure tactics (“I’m driving now, need code in 2 minutes”).
  • Grammar oddities or memorized scripts that ignore your answers.
  • Payment app “guarantees” or “escrow” claims outside the platform’s built-in system.

Protective habits that shut this down

  • Never share OTPs, recovery codes, or push approvals. No buyer, seller, or support rep needs them.
  • Keep all negotiation inside the marketplace app. If they push you to WhatsApp or SMS, decline.
  • Use passkeys or an authenticator app instead of SMS for 2FA where possible. Authenticator codes are harder to intercept and reduce SIM-swap risk.
  • Use unique passwords for every account with a password manager. This prevents a single leaked password from opening multiple doors.
  • Lock down recovery options: Update email and phone numbers, add strong backup codes, and remove old devices or phone numbers you no longer use.
  • Set purchase and payout alerts on payment apps and banks so you see surprises instantly.

How to respond in the moment

  1. Stop and don’t enter or share any code. If an OTP just arrived and you didn’t initiate a login, assume someone else did.
  2. End the conversation with a simple “I only transact within the app” and block the user.
  3. Change the password on the related account(s) immediately, especially your email. If possible, upgrade to passkeys or an authenticator.
  4. Review recent logins/devices in account security settings. Sign out everywhere and re-login on your own devices.
  5. Turn on alerts for new logins, password changes, and transactions.
  6. If money moved or a listing account was hijacked, contact the platform and your bank or payment provider right away.

If you already gave them a code

Act quickly to contain damage:

  • Reset passwords immediately for the affected service and your primary email. Use a strong, unique password.
  • Revoke sessions/devices in the account’s security panel and regenerate backup codes.
  • Check and correct account details (display name, recovery email/phone, payout methods, shipping address).
  • Scan for forwarding rules in email (fraudsters often add silent forwarding to catch password resets).
  • Review financial accounts for unauthorized charges, payout changes, or linked devices.
  • File support tickets with the marketplace and payment app, documenting the conversation and any URLs the scammer sent.

Real-world examples you can practice spotting

  • Fake buyer: “I sent you a code from Zelle to confirm you’re registered. Please send the code so I can transfer.” — Reality: There is no Zelle verification code needed from the buyer. They triggered a login or reset flow tied to your number.
  • Google Voice trap: “Text the code to prove you’re legit.” — Reality: They’re trying to attach a Google Voice number to your phone to impersonate you.
  • Phishing page: “Go to seller-verify-marketplace[dot]com to pass buyer protection.” — Reality: Off-domain, designed to harvest codes and credentials.

Extra defenses against OTP theft

  • Swap SMS for app-based 2FA wherever possible. Use an authenticator app or passkeys. Avoid using your phone number as a universal key.
  • Enable number lock with your mobile carrier. A port-out or SIM swap can expose your SMS codes. Add a carrier PIN and ask about port freezes.
  • Quarantine marketplace email. Consider a unique email alias for buying/selling so marketplace messages can’t be mixed with bank or work messages.
  • Separate financial from social logins. Don’t use “Sign in with Facebook/Google” for payment apps. Keep them isolated.
  • Check breach exposure. If your email appears in breach lists, assume criminals have at least some of your old credentials and are testing OTP prompts to bypass 2FA.

How data exposure fuels these scams

Scammers succeed faster when they know your phone number, email, or where you list items for sale. Public profiles, previous listings, and data broker sites often expose this information. With it, criminals can:

  • Personalize scripts so their messages feel credible.
  • Trigger targeted OTPs that match services you actually use.
  • Bypass basic identity checks on payment and marketplace platforms.

Reducing your exposed contact info, removing data broker listings, and using unique emails per service make you a less attractive target.

When monitoring helps

OTP theft is often one step in a broader identity attack. If you’ve noticed surprise OTPs, password reset emails you didn’t request, or logins from new locations, it’s smart to increase monitoring of your financial identity for a while. Credit and identity monitoring can alert you to new accounts, inquiries, or changes that follow OTP and account-takeover attempts. If you want a consolidated place to watch for these signals and set up action alerts, consider a dedicated privacy, credit monitoring, and identity-protection resource such as SmartCredit.

Marketplace-specific safety checklist

  • Stay on-platform: Use the platform’s messaging and payment protections. Decline off-platform links.
  • Meet safely: Prefer public meet-up spots with staff or cameras (many police departments offer “exchange zones”).
  • Never prepay for verification or shipping labels from the buyer.
  • Ignore “priority buyer” badges sent as images or links. Real badges appear in the app, not as files a stranger sends.
  • Report and block any user who requests OTPs, QR scans, or external “verification.”

Build your personal “no-code” policy

Decide in advance: you will never share a one-time code, push approval, recovery code, or backup code with anyone, under any circumstance. This personal rule removes on-the-spot decision pressure. If a stranger asks for a code, the conversation ends. If you receive an unexpected OTP, you change your password and review sessions. This single habit prevents many account takeovers.

Frequently asked questions

What if the buyer insists this is platform policy?

Ask them to point to the official policy page on the platform’s domain, not a screenshot or a pasted paragraph. They can’t, because legitimate platforms don’t require off-platform OTP sharing.

Is a photo ID request always a scam?

Some platforms offer optional in-app ID verification, but it happens within your account settings, not through a stranger’s link or chat. Never upload your ID to a third-party site sent by a buyer or seller.

I got an OTP but didn’t share it. Am I safe?

Safer, yes. Still change the related account password, review devices, and enable stronger 2FA. The OTP attempt means someone is testing your defenses.

What about QR codes for shipping labels or payments?

Use only the platform’s own shipping and payment features. Do not scan a QR code a stranger sends; it can lead to phishing pages or login tricks.

Conclusion

Fake marketplace “buyer verification” prompts exist for one reason: to capture your one-time passcodes and defeat your account protections. The quickest defenses are simple — keep conversations on-platform, never share codes, verify URLs, and lock down your authentication. If you slip and share a code, move fast: change passwords, revoke sessions, and review financial and recovery settings. Strengthening your privacy practices and monitoring your identity for suspicious changes will make you far harder to victimize and much quicker to recover if a criminal tries again.

Good to Know

Legitimate marketplaces almost never require a buyer or seller to “verify by code” through a third-party link or bot. If someone insists on a code, they usually need your OTP to break into an account they already partially compromised.