TL;DR
- A stranger builds a warm relationship over weeks, then introduces a trading or staking platform showing spectacular fake profits. Withdrawing triggers endless fees. The tell: you cannot get money out without paying more in.
- Someone claiming to be your exchange, wallet provider, bank or a government agency contacts you about a security problem and guides you into moving funds, sharing codes or granting remote access. The tell: they contacted you, and they want to keep you on the line.
- After you lose money to any scam, a helpful investigator, law firm or even fake FBI agent appears, claiming your funds were located and asking for an upfront fee or your wallet details to release them. The tell: guaranteed recovery for money paid in advance.
- A fake website that imitates a real crypto service tricks you into connecting a wallet and signing a transaction that hands spending power to the attacker. The tell: the site arrived via an advert, message or reply, and it is rushing you to claim, verify or migrate something.
In one block
A crypto scam is a fraud that manipulates a person into authorising the loss of their own cryptocurrency, whether by sending funds to a criminal, revealing a seed phrase or login code, or signing a transaction that hands over spending power. Scams attack judgement rather than cryptography, which is why the defences are habits rather than software.
1. Fake investment platforms, also called pig butchering
Quick answer
A stranger builds a warm relationship over weeks, then introduces a trading or staking platform showing spectacular fake profits. Withdrawing triggers endless fees. The tell: you cannot get money out without paying more in.
This is the most expensive scam in crypto by a wide margin: crypto investment fraud produced 61,559 complaints and 7.23 billion dollars in reported US losses in 2025, the largest cryptocurrency-linked category in the FBI data. It starts anywhere a conversation can start: a wrong-number text, a dating app match, a professional networking message, an investment group invite. The fraudster is patient, consistent and genuinely charming, often for weeks before money is ever mentioned. The platform they eventually share looks professional and may even allow a small early withdrawal to build trust. Its displayed balance proves nothing: your deposits went straight to the criminal, and the profits are numbers in their database.
The decisive moment arrives when you try to withdraw. Suddenly there is a tax, a compliance deposit, an account unlock fee. Paying one creates the next. A legitimate platform may withhold tax where the law requires it; what it will never do is demand a fresh crypto deposit to an external wallet before releasing your own balance.
One-line test: any platform demanding a new deposit to release money it says is already yours is running the classic investment fraud playbook. Stop there.
2. Impersonation and fake support
Quick answer
Someone claiming to be your exchange, wallet provider, bank or a government agency contacts you about a security problem and guides you into moving funds, sharing codes or granting remote access. The tell: they contacted you, and they want to keep you on the line.
Clusters that Chainalysis classifies as impersonation scams grew more than 1,400 percent year on year in its on-chain dataset, a tracker-specific growth measure rather than a count of every complaint, and the direction of travel is unmistakable. The fuel is stolen data: breaches give callers real details about you, and caller-ID spoofing makes the number look official. Knowing your name, email or last transaction proves only that the criminal bought a database. The script always converges on the same actions: read out a one-time code, approve a login, install remote-access software, or move funds to a safe wallet the caller kindly provides. The safe wallet is theirs.
One-line test: hang up, then contact the organisation through the app or website you find yourself. A genuine security team will never object to that.
3. Recovery scams
Quick answer
After you lose money to any scam, a helpful investigator, law firm or even fake FBI agent appears, claiming your funds were located and asking for an upfront fee or your wallet details to release them. The tell: guaranteed recovery for money paid in advance.
The FBI logged 10,516 recovery-scam complaints in 2025 with 1.4 billion dollars in associated losses (a figure the IC3 notes may include losses from the earlier scam that triggered the recovery approach), and fraudsters have impersonated the FBI's own complaint centre to run them. Victim lists are traded between criminal groups, so being scammed once puts you on a shopping list. Legitimate law enforcement never charges a release fee, and no private firm can guarantee the return of crypto, because nobody can reverse a confirmed transaction on demand.
One-line test: anyone who guarantees recovery or wants payment before recovering anything is running the second act of the first scam.
4. Phishing sites and wallet drainers
Quick answer
A fake website that imitates a real crypto service tricks you into connecting a wallet and signing a transaction that hands spending power to the attacker. The tell: the site arrived via an advert, message or reply, and it is rushing you to claim, verify or migrate something.
Wallet drainers are rented criminal software: the operator clones a real project's website, buys search adverts or hijacks social accounts to spread the link, and the kit does the rest. Connecting a wallet alone grants no spending power; the theft needs your signature, and one signature on the wrong prompt can authorise broad token, NFT or account authority. ScamSniffer, which tracks EVM phishing specifically, recorded roughly 494 million dollars in drainer losses across some 332,000 addresses in 2024, falling to 83.85 million dollars across 106,106 victims in 2025 as defences improved and criminals shifted tactics. Its largest single 2025 theft took 6.5 million dollars with one signed permit.
One-line test: never sign anything you cannot explain, and reach crypto sites only through your own bookmarks. For the full mechanics, our advanced guide on wallet-draining and approval attacks takes this apart piece by piece.
5. Giveaway and doubling scams, now with deepfakes
Quick answer
A celebrity, executive or brand appears to promise that any crypto you send will be returned doubled, often in a convincing live video. The tell: there is no exception to this rule, every doubling giveaway is fake.
AI has industrialised an old trick. Fabricated videos of public figures now run on hijacked channels during live events, and the production quality defeats casual inspection. It does not matter how real the face looks or how official the account badge appears: no legitimate person or company returns crypto doubled. The FBI received 22,364 complaints referencing AI across all fraud types in 2025, with 893 million dollars in losses, and giveaway fraud is one of its most visible uses.
One-line test: send one, receive two is always a scam, spoken by anyone, on any platform, in any year.
6. Rug pulls and honeypot tokens
Quick answer
A new token launches with professional marketing and a rising chart; then insiders drain the value, or the contract quietly blocks everyone except the creator from selling. The tell: you cannot find independent evidence of who controls the token and its liquidity.
Rug pulls dress up as real projects: polished sites, paid influencers, active chats. The exit comes through draining liquidity, dumping insider allocations or abusing hidden contract powers. Honeypots are the same fraud in miniature, malicious code that lets you buy and never sell, which is why the chart only rises. Be careful with the word, though: a price collapse alone proves nothing about intent, and plenty of honest projects simply fail. What you can check in ten minutes: whether the contract is verified, who holds the supply, whether liquidity is locked, and whether a small test sale works. Treat these as combined risk signals rather than a checklist that certifies safety; verification only publishes the code, locks can be narrow or temporary, and a test sale cannot guarantee the rules will not change.
One-line test: if the only people vouching for a token are people paid by the token, walk away.
7. Address poisoning and clipboard hijacking
Quick answer
Criminals plant a lookalike address in your transaction history, or malware swaps the address you copied, so your next transfer goes to them. The tell: you only ever check the first and last few characters of an address.
Peer-reviewed research from Carnegie Mellon, presented at the USENIX Security Symposium, measured about 270 million poisoning attempts across two years on Ethereum and BNB Smart Chain, with 6,633 successful thefts taking at least 83.8 million dollars over the study period. Separately, security firms reported a trader losing nearly 50 million dollars in USDT to a single lookalike address in December 2025. The attack works because human eyes skim long strings, and the fake is engineered to match at both ends.
One-line test: never copy a recipient from transaction history; use a saved address book entry established through an independent channel, and compare the trusted screen against that record before approving. A past test transfer protects nothing if the address you copy today came from poisoned history.
8. Crypto ATM payment demands
Quick answer
A caller impersonating the tax office, police, a utility or a grandchild in trouble insists you pay immediately in cash through a crypto ATM. The tell: in this scenario no genuine authority or company settles debts through a machine in a petrol station.
This scam targets people who have never touched crypto, which is exactly the point: the machine converts your cash into an irreversible transfer to the criminal's wallet. US losses through crypto ATMs and kiosks reached 389 million dollars in 2025, up 58 percent in a year, and victims over sixty carried a heavy share of it. The pressure is always emotional: arrest warrants, disconnection notices, a relative in danger.
One-line test: an unexpected caller directing you to a crypto ATM and a supplied wallet address to settle a bill, tax, fine or bail is running a scam. No genuine authority or business collects payment that way.
9. Fake wallet apps and malicious downloads
Quick answer
A counterfeit wallet or exchange app, spread through search adverts, app-store lookalikes or direct messages, captures your seed phrase or credentials the moment you type them. The tell: the download came from a link somebody gave you.
A wallet is only as trustworthy as its source. Fake apps and extensions imitate real brands down to the reviews, and a seed phrase typed into one gives the operator everything needed to recreate your wallet, instantly and permanently. No support agent, airdrop, website or security check ever needs your recovery words. There is exactly one legitimate reason to enter a seed phrase: deliberately restoring your own wallet in software or hardware you obtained from a source you independently verified, after confirming the restoration is actually necessary.
One-line test: seed phrases go into wallets you installed from the official source, and nowhere else, ever.
10. SIM swaps and account takeovers
Quick answer
A criminal moves your phone number to their SIM or breaks into your email, then uses password resets and text-message codes to walk into your exchange account. The tell for prevention: your crypto security is only as strong as your phone number and inbox.
This is the quiet one, and it needs no message to you at all. With your number hijacked through a manipulated telecom employee, or your email opened with a reused password, the attacker resets your exchange login and drains the account, intercepting every code sent by text. The defences are structural: a unique password from a password manager for the exchange and the email behind it, app-based or hardware-key authentication instead of text messages, and withdrawal allowlists with time delays where your exchange offers them.
One-line test: if losing your phone number would let someone into your exchange account, fix that today, before anyone tests it for you.
All ten at a glance
| Scam | The tell | The one-line test |
|---|---|---|
| Fake investment platform | Withdrawals trigger fees | More money to release your money means scam |
| Impersonation and fake support | They contacted you, urgently | Hang up; verify through an official route you find |
| Recovery scam | Guaranteed recovery, upfront fee | Prepaid recovery is the scam's second act |
| Phishing site or drainer | Claim, verify or migrate, fast | Never sign what you cannot explain |
| Giveaway or deepfake doubling | Send one, receive two | Always fake, regardless of the face |
| Rug pull or honeypot | Only paid voices vouch for it | Check control, liquidity and a test sale |
| Address poisoning | Lookalike address in history | Address book entries, never history |
| Crypto ATM demand | Pay a bill through a machine | No authority collects debts by crypto ATM |
| Fake wallet app | Download link supplied to you | Seed phrases only into officially sourced wallets |
| SIM swap or takeover | Security rests on texts and email | Phone number access must not equal account access |
Frequently asked questions
What is the most common crypto scam?
It depends on the measure. By reported losses, fake investment platforms, often called pig butchering, dominate: 7.23 billion dollars of the 11.37 billion in US cryptocurrency-linked losses reported to the FBI for 2025. By sheer contact volume, phishing and impersonation reach the most people, though those complaint counts span all internet crime rather than crypto alone.
How can I tell if a crypto platform is legitimate?
Identify the exact legal entity and check the relevant official regulator register, remembering that registration alone is not proof of safety or endorsement. Confirm you found the platform independently rather than through someone who contacted you, and be aware that a small successful withdrawal does not prove a platform is legitimate, because these schemes often allow early withdrawals to build trust. A displayed balance is never proof that assets exist.
Can I get my money back after a crypto scam?
Sometimes funds can be frozen at a regulated exchange or later seized by law enforcement, but recovery is never guaranteed and depends on speed, jurisdiction and where the assets move. Report immediately with transaction details, and treat anyone who promises recovery for an upfront fee as the next scammer.
Why do smart people fall for crypto scams?
Because the scams attack emotion, trust and time pressure rather than intelligence. Fraudsters manufacture urgency so you act before you think, and AI now makes the messages, voices and videos genuinely convincing. Process beats cleverness: slow down and verify through your own channel.
Does a hardware wallet protect me from scams?
It is designed to keep private keys off the connected computer and to show transaction details on a separate display. It cannot stop you approving a malicious request, typing a seed phrase into a fake interface, or trusting a screen you never actually read. The protection is real, and it only covers what you independently verify on the device itself.
Sources and further reading
Key references for this article, current as of July 2026. Volatile figures are re-checked at each quarterly review.
- FBI Internet Crime Complaint Center, 2025 Annual Report. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
- FBI press release on 2025 cryptocurrency and AI fraud losses. https://www.fbi.gov/news/press-releases/cryptocurrency-and-ai-scams-bilk-americans-of-billions
- Chainalysis, 2026 Crypto Crime Report: scams chapter. https://www.chainalysis.com/blog/crypto-scams-2026/
- ScamSniffer, 2025 Crypto Phishing Report. https://drops.scamsniffer.io/scam-sniffer-2025-crypto-phishing-losses-fall-83-to-84-million/
- Tsuchiya, Dong, Soska and Christin, Blockchain Address Poisoning, 34th USENIX Security Symposium, 2025. https://www.usenix.org/conference/usenixsecurity25/presentation/tsuchiya
- Reporting: FBI Internet Crime Complaint Center at https://www.ic3.gov (US) and Report Fraud (which replaced Action Fraud in December 2025) at https://www.reportfraud.police.uk (England, Wales and Northern Ireland; in Scotland, call Police Scotland on 101).
Quick quiz: did it stick?
Five questions, one honest self-check. Answers below.
You have completed a quiz on “10 Most Common Crypto Scams and How to Spot Them”! Share your achievement on social media.




