7 Signs Your eSewa or Khalti Account Has Been Compromised
Fraud on Nepal's digital wallets rarely announces itself with a dramatic hack. It shows up as small, easy-to-dismiss signals — a strange notification, an OTP you didn't request. Here's exactly what to watch for and what to do the moment you spot it.
Digital wallets have become the default way Nepal pays — bills, transfers, mobile top-ups, online shopping. That convenience has made eSewa and Khalti accounts an attractive target, and the numbers back it up: Nepal Police's Cyber Bureau has already logged over 13,000 cybercrime complaints in the current fiscal year alone, with wallet and bank-related fraud among the fastest-growing categories. Scammers now impersonate wallet support staff convincingly enough to fool even government officials and police officers — this isn't a problem limited to people who are "bad with technology."
The good news is that account compromise almost always leaves a trail before real money disappears. Knowing these seven signs — and reacting to the first one instead of waiting for the seventh — is the difference between a close call and a drained wallet.
Fig. 1 — The seven zones of a wallet app where compromise shows up first.
Sign 1: Unrecognized Login Notifications
A "new login" alert from a device or city you don't recognize
Both eSewa and Khalti send a notification (in-app, SMS, or email) whenever your account is accessed from a new device or location. If you get one for a login you didn't make — especially from a different city than where you actually are — treat it as an active compromise, not a false alarm. This is often the very first signal, arriving before any money moves.
Sign 2: Unexpected OTP Requests
An OTP arrives when you haven't initiated any transaction
A one-time password only exists because someone — hopefully you — just entered your correct login credentials or PIN and triggered the next step. If an OTP lands on your phone out of nowhere, someone already has enough of your information to get to that step. This is also the exact moment scammers call, posing as "customer support," and ask you to read the code back to them. Never share an OTP with anyone, under any circumstance — neither eSewa nor Khalti staff will ever ask for it.
Sign 3: Balance Discrepancies
Your balance doesn't match what you expect, even by a small amount
Fraudsters frequently test stolen credentials with a small transaction first — a mobile top-up, a tiny transfer — before attempting a larger withdrawal. A missing few hundred rupees is easy to shrug off as a forgotten purchase; don't. Check your statement in the app the moment a number looks even slightly off.
Sign 4: Password Reset Emails You Didn't Request
A "reset your password" email or SMS shows up unprompted
This means someone entered your registered phone number or email into the login screen and clicked "Forgot password." It's a clear sign your account is actively being targeted, even if the attacker hasn't gotten in yet. Do not click the reset link inside the message — open the official app directly instead, and change your password and PIN from there.
Sign 5: Unfamiliar Linked Devices
A device you don't own appears in your account's active sessions
Both apps let you view currently logged-in devices under account or security settings. If you see a device model, city, or session you don't recognize, someone else has live access to your account right now — not just your credentials, but an active, working session.
Sign 6: Transactions You Didn't Make
A payment, transfer, or QR scan appears in your history that wasn't you
This is the sign most people notice first, but by this point money has usually already moved. Watch specifically for payments to merchants you've never used, round-number transfers to unfamiliar wallet IDs, or "received" notifications tied to a QR code you never scanned yourself — scammers sometimes send fake "scan to receive" QR codes that actually authorize a payment out of your account.
Sign 7: Account Locked Without Reason
You're suddenly locked out, with no failed-login attempts of your own
A common tactic is entering your password incorrectly enough times to trigger a temporary lock, then calling you pretending to be wallet support, claiming they can "help unlock it" — in exchange for your OTP or PIN. If you're locked out and haven't tried logging in yourself, assume someone else has been trying, and never accept "unlock help" from an inbound caller.
What to Do Immediately If You Spot Any of These
Speed matters more than anything else here. Work through this order the moment you notice even one warning sign:
Open the official app directly (never a link from SMS/email) and change your password and MPIN immediately.
Check your recent transaction and login history for anything unfamiliar, and screenshot everything suspicious before it disappears.
Log out of all other devices/sessions from the security settings menu, if the option is available.
Call official support directly — eSewa: 01-5970016, or Khalti's in-app support line — using a number you look up yourself, not one texted to you. Report the unauthorized activity and ask them to flag the receiving account.
File a complaint with the Nepal Police Cyber Bureau at nepalpolice.gov.np — the sooner you report, the higher the chance of recovering funds or freezing the destination account.
Check your linked bank account too, since wallet compromise often traces back to (or spreads to) the bank account funding it.
How to Strengthen Account Security Going Forward
Prevention costs a few minutes today; recovery can cost weeks and doesn't always succeed. These habits close the gaps scammers rely on most:
Enable two-factor authentication
Turn on every additional verification layer both apps offer — it stops a stolen password alone from being enough to get in.
Use biometric login where possible
Fingerprint or face unlock removes the password entirely from day-to-day access, shrinking what a phishing attempt can capture.
Never share OTP, PIN, or password
Not with callers claiming to be support, not with "verification" links, not with anyone — no legitimate wallet staff will ever ask.
Verify calls independently
If someone calls claiming to be from eSewa or Khalti, hang up and call the number listed on the official app or website yourself.
Only install from official app stores
Counterfeit apps on unofficial sites or APK links are a common credential-stealing trap — download only from Google Play or the App Store.
Keep your wallet balance lean
NRB caps wallet balances at NPR 50,000 for a reason — keeping only what you need for near-term spending limits what's ever at risk.
Review linked devices periodically
Make it a monthly habit to check active sessions and remove anything you don't immediately recognize.
Be skeptical of unsolicited "rewards"
Fake prize, refund, and cashback messages are the most common lure used to extract an OTP — legitimate rewards never require you to send one.
None of these signs are proof on their own that something catastrophic has happened — but each one is your account telling you to look closer. Nepal's wallets are, on the whole, secure systems built with real fraud controls; the weak point almost always turns out to be a shared OTP or a trusted-looking phone call, not the platform itself. Stay skeptical of urgency, verify before you click or share anything, and you remove the one ingredient every one of these scams actually needs from you.
This article is for general awareness and informational purposes only and does not constitute security, legal, or financial advice. Fraud tactics and platform security features change over time — always refer to eSewa's and Khalti's official in-app help centers, and report suspected fraud to the Nepal Police Cyber Bureau, for current guidance.
Discussion