I got a text saying my Chime account is locked and I need to verify it - is this real?
Almost certainly not. Chime is a real company, but messages like this are sent in bulk by people impersonating it, and the link or phone number in them leads to a copy of the real thing. Do not tap it. Open the app yourself and check there.
Last reviewed: 19 July 2026
Explanation
These texts and emails go out in bulk to numbers that may or may not belong to actual customers. The sender is guessing, and the people who happen to be waiting on a transfer or who recently saw a declined payment are the ones who react. The message usually says the account is locked, a payment was flagged, or your details need reverifying, and it offers a link to a page that copies the familiar colors and login screen. Anything typed there goes to whoever built the page, including your password and any one-time code you pass along. Other versions skip the link and give a number to call, where a calm, professional voice walks you through moving your balance to a so-called safe account. Nothing about the message can be trusted, because every detail in it was chosen by the sender. The one check that settles it: close the message, open the app already on your phone, and see whether the same alert appears inside it.
Common red flags
- A link in the message rather than an instruction to open the app yourself
- Urgency about your account being locked, frozen, or closed within hours
- A request for your password, PIN, card number, or a code that was texted to you
- The sender asks you to move your balance to a different account for safekeeping
- The sender address or number looks slightly off, or changes between messages
- You are told not to hang up, or not to discuss the call with anyone
What to do now
- Do not tap any link in the message and do not call the number it gives you
- Open the app directly from your phone, or type the official website address yourself, and look for the same alert there
- If you already entered your details, change your password immediately and turn on two-factor authentication
- Report the issue through the support option inside the app so there is a record of it
- If you sent money or shared a code, contact support through the app straight away and ask what recovery options exist in your case
- Forward the text to your mobile carrier's spam reporting shortcode and then delete it
Frequently asked questions
I already clicked the link but did not type anything in. Am I in trouble?
Opening a page is far less serious than entering details on it. If you did not type your login, card number, or a security code, the most likely outcome is nothing at all. Still, change your password from inside the app as a precaution, turn on two-factor authentication if it is off, and watch your transactions for the next couple of weeks. If anything appears that you did not authorize, report it through the app right away.
The caller knew my name and the last four digits of my card. Doesn't that prove it was really them?
No. Details like a name, an email address, or the last digits of a card circulate widely after data breaches and can be bought or pieced together. Someone opening with accurate information is using it to buy your trust in the first few seconds. Genuine support will not need you to prove yourself by reading out a one-time code or moving money. Treat knowledge of your details as neutral, not as proof of who is calling.