TL;DR
- Crypto scams work because transactions are irreversible, self-custody has no safety net, and scammers exploit universal psychology: urgency, fear, greed, trust in authority, and loneliness.
- A hack breaks into a system through a technical vulnerability. A scam manipulates a person into authorising the loss. In the FBI's 2025 complaint data, fraud accounted for the large majority of reported individual crypto losses, and security researchers report that many major thefts now begin with social engineering rather than a technical exploit.
- Social engineering is the manipulation of people rather than technology. In crypto it appears as fake support agents, impersonated executives, urgent security warnings, and any contact designed to panic or excite you into acting without verifying.
- A wallet drainer is a malicious toolkit that empties your wallet after tricking you into signing a transaction that authorises the theft. It exploits the legitimate token approval mechanism, so the blockchain executes the theft as a valid, victim-signed action.
In one block
Chainalysis identified at least 14 billion US dollars of 2025 on-chain inflows to addresses classified as scams or fraud according to on-chain analysis, with the full total projected to exceed 17 billion as more illicit addresses are identified.
Where things stand in mid 2026
The numbers deserve a moment of attention, because they explain why this topic matters more now than at any point in crypto's history. Chainalysis, the blockchain analytics firm whose annual Crypto Crime Report is the industry's reference dataset, identified at least 14 billion US dollars received by known scam and fraud addresses in 2025, and projects the true total will exceed 17 billion as further illicit addresses are classified. Its recalculated figure for 2024 is roughly 12 billion dollars, and that pattern of upward revision is worth remembering whenever a fresh headline number appears. Illicit cryptocurrency addresses of all kinds received at least 154 billion dollars in 2025, a 162 percent increase year on year, although much of that surge relates to sanctions evasion by state actors rather than consumer fraud.
Two shifts stand out for ordinary users. First, scammers have moved from volume to precision. The average scam payment jumped from 782 dollars in 2024 to 2,764 dollars in 2025, a 253 percent increase, as criminal groups abandoned spray-and-pray tactics in favour of fewer, better-researched, higher-value targets. Second, artificial intelligence has industrialised deception. Chainalysis found that AI-assisted scams are around 4.5 times more profitable than traditional ones, and impersonation scams alone grew more than 1,400 percent year on year. The FBI's Internet Crime Complaint Center recorded 11.37 billion dollars in reported crypto fraud losses for 2025 across 181,565 complaints, with investment fraud accounting for 7.23 billion dollars of the total. A further 10,516 complaints concerned recovery scams, frauds that target people who have already been scammed, with 1.4 billion dollars in associated losses. These datasets measure different things: on-chain analytics count flows to classified addresses, while complaint data count what victims report, so the figures indicate scale without adding up to one audited total.
Meanwhile the technical attack surface has shifted too. Chainalysis estimated about 3.4 billion dollars stolen through hacks in 2025 across services and personal wallets, and the year's defining incidents came through compromised credentials, deceived operators and manipulated interfaces rather than smart-contract bugs. Even the largest theft in crypto history, the 1.5 billion dollar Bybit exchange breach of February 2025, worked this way. Forensic investigations by Sygnia and Verichains, later confirmed by Safe, traced it to a compromised Safe{Wallet} developer machine: attackers injected malicious code into the wallet interface so that Bybit signers approved a disguised transaction they believed was a routine cold-wallet transfer. No key was stolen and no contract was broken. The lesson of the current era is blunt: criminals have concluded that people and the software around them are softer targets than the protocol itself.

Why do crypto scams work so well?
Quick answer
Crypto scams work because transactions are irreversible, self-custody has no safety net, and scammers exploit universal psychology: urgency, fear, greed, trust in authority, and loneliness.
Understanding the structural reasons is the foundation of every defence that follows. When a fraudulent card payment goes through, your bank can claw it back. When a signed blockchain transaction confirms, in the normal case no institution can reverse it. That property is what makes crypto censorship resistant, and it is also what makes it the perfect payment rail for fraud. For this class of scam the scammer's problem is therefore usually persuasive rather than technical: how to get you to press the button yourself. Other attacks pair that persuasion with malware, malicious approvals, credential theft or compromised infrastructure, which later sections cover.
The persuasion toolkit has changed little in a century of confidence tricks. Scammers manufacture urgency so you act before you think, invoke authority so you comply without checking, dangle guaranteed returns so greed overrides scepticism, and build emotional relationships so loyalty overrides doubt. What has changed is the delivery mechanism. Generative AI now writes fluent messages in any language, clones voices from seconds of audio, and produces convincing live video of people who do not exist. The classic advice to watch for bad grammar or to ask for a video call no longer offers reliable protection.
Scams versus hacks: what is the difference?
Quick answer
A hack breaks into a system through a technical vulnerability. A scam manipulates a person into authorising the loss. In the FBI's 2025 complaint data, fraud accounted for the large majority of reported individual crypto losses, and security researchers report that many major thefts now begin with social engineering rather than a technical exploit.
The distinction matters because the defences are different. You cannot patch yourself against a protocol exploit; you can only limit exposure to risky platforms. But you absolutely can train yourself against manipulation, and doing so protects you from the far larger loss category.
| Scam | Hack | |
|---|---|---|
| What is attacked | The person: their trust, fear, greed or attention | The system: code, infrastructure or credentials |
| Who authorises the loss | The victim, by signing, sending or sharing | The attacker, by exploiting a vulnerability |
| Typical examples | Pig butchering, drainers, impersonation, address poisoning | Smart contract exploits, bridge attacks, exchange breaches |
| 2025 scale | About 17 billion dollars (Chainalysis estimate) | About 3.4 billion dollars stolen from services |
| Primary defence | Verification habits, signing discipline, scepticism | Platform diversification, hardware isolation, audits |
| Trend | Growing fast, AI-accelerated | Shifting towards social engineering entry points |
What is social engineering in crypto?
Quick answer
Social engineering is the manipulation of people rather than technology. In crypto it appears as fake support agents, impersonated executives, urgent security warnings, and any contact designed to panic or excite you into acting without verifying.
Social engineering is the master category that powers almost everything else in this article. Wallet drainers need a lure. Pig butchering needs a relationship. Deepfakes need a believable identity. Strip away the technology and every one of these attacks is a persuasion exercise.
Impersonation: the fastest growing attack of 2025 and 2026
Impersonation scams grew more than 1,400 percent year on year according to Chainalysis, and average payments to impersonators rose over 600 percent. The pattern is consistent. You receive a call, email or message from someone claiming to be your exchange's fraud team, a wallet vendor's support desk, a government agency, or a well-known founder. They know things about you, often sourced from data breaches, which makes them credible. They tell you your funds are at risk and that you must act immediately: move assets to a 'safe' wallet they control, read out a verification code, or confirm your seed phrase.
Real cases show how devastating this has become. In December 2025, Brooklyn prosecutors indicted a 23-year-old accused of stealing nearly 16 million dollars by impersonating Coinbase customer service, aided by a bribed support contractor who supplied stolen customer data. Consider how this plays out: a caller poses as a hardware wallet support agent and walks the target through a fake verification process until they reveal their recovery seed. The hardware is never compromised. The person is.
The psychology to watch for
- Manufactured urgency. Deadlines measured in minutes exist to switch off your critical thinking. Legitimate institutions never require irreversible action within the hour.
- Fear framing. 'Your account has been compromised' is the single most effective opening line in modern crypto fraud, because it makes the scammer feel like the rescuer.
- Authority borrowing. Logos, spoofed phone numbers, cloned websites and leaked personal data all rent credibility the attacker has not earned.
- Secrecy instructions. Being told to keep the situation confidential, or to stay on the line while you act, isolates you from anyone who might spot the fraud.
The universal counter-move is channel switching. Whatever the incoming message says, close it, and contact the organisation through its official website or app, using details you found yourself. No legitimate support team will ever object to that, and no scammer can survive it.
What are wallet drainers and approval phishing?
Quick answer
A wallet drainer is a malicious toolkit that empties your wallet after tricking you into signing a transaction that authorises the theft. It exploits the legitimate token approval mechanism, so the blockchain executes the theft as a valid, victim-signed action.
Drainers deserve the closest technical attention of any threat in this guide, because they attack the exact moment where self-custody users feel safest: their own wallet interface. Understanding the mechanism requires one piece of background. Token standards such as ERC-20 include an approval function that lets a smart contract move tokens on your behalf. Every decentralised exchange and lending protocol relies on it. When you sign an approval, you are granting spending power, and the blockchain does not distinguish between granting it to a legitimate protocol and granting it to a thief.
A drainer attack chains five steps together. First comes the lure: a fake airdrop, a poisoned search ad, a hijacked social media account, or a direct message about a prize or a job. Second, the victim lands on a convincing clone of a real dApp or a plausible new one. Third, they connect their wallet, which is harmless in itself but lets the site read balances and select the most valuable assets to target. Fourth comes the decisive moment: the site requests a signature. It may be an unlimited token approval, an off-chain permit signature, or a bundled transaction disguised behind a friendly button reading 'claim' or 'verify'. Fifth, once signed, the drainer sweeps the approved assets, often within seconds, and routes them through laundering infrastructure.

Drainers as a service
Almost nobody who steals with a drainer wrote the code. Drainer kits are rented through drainer-as-a-service operations that supply the malware, host the phishing pages, and take a commission of the stolen assets. ScamSniffer's analysis of EVM chains attributed roughly 494 million dollars of losses to wallet drainers in 2024 across some 332,000 affected addresses. Its 2025 report then recorded a striking reversal: losses fell 83 percent to 83.85 million dollars across about 106,000 victims, with the largest single theft at 6.5 million dollars via a malicious permit signature. Part of that decline reflects better wallet warnings and user education, and part reflects criminals migrating to harder-to-track vectors such as social engineering and infostealer malware. The permit signature remained the dominant technique, and malicious EIP-7702 signatures emerged as a new vector after Ethereum's Pectra upgrade. A quiet year in one dataset is no reason to relax at the signing screen.
Approval phishing meets romance fraud
Law enforcement now treats approval phishing as the technical endgame of relationship scams. Cross-border law-enforcement operations have increasingly targeted these networks, tracing victim wallet addresses across many countries and freezing a portion of stolen funds. The pattern such operations document is important: instead of persuading a victim to send crypto to a fake platform, the scammer persuades them to sign a wallet permission. The drain can then happen weeks later, long after the victim has forgotten the interaction.
Defences that actually work
- Read every signature. If your wallet cannot show you in plain language what a transaction does, do not sign it. Signing what you cannot independently verify is what let the Bybit signers approve a disguised transaction, and it remains a leading enabler of drainer losses. Verify transaction details on a trusted display, not only in the interface that requested them.
- Reject unlimited approvals. Where a dApp requests token approval, set a spending cap that matches your immediate transaction rather than the default unlimited amount.
- Audit and revoke old approvals. Use an approval checker such as the one built into Etherscan or Revoke.cash monthly. Old permissions to abandoned or upgraded contracts are standing invitations.
- Segment your wallets. Keep a small hot wallet for experiments and interactions, and never connect the wallet holding your savings to a new site. A drainer cannot sweep assets it was never approved to touch.
- Never navigate from a message. Type URLs yourself or use your own bookmarks. Search ads, DMs and even verified social accounts are all established drainer delivery channels.
What is pig butchering?
Quick answer
Pig butchering is long-form investment fraud in which scammers build a weeks-long emotional or professional relationship, guide the victim onto a fake trading platform showing fabricated profits, and extract deposits until the victim has nothing left.
The name translates the Chinese term sha zhu pan: the victim is fattened before slaughter. It is the most financially devastating scam category in the world. The FBI attributes 7.23 billion dollars of 2025 crypto fraud losses to investment fraud, a category that prominently includes this pattern, and researchers have traced tens of billions of dollars of victim funds flowing through these networks since 2020. The human cost extends to the perpetrators' side too: the United Nations estimates that hundreds of thousands of trafficked workers are held in scam compounds across Southeast Asia, forced to run these operations under threat of violence.
The playbook has three acts. The approach begins with a wrong-number text, a dating app match, or a LinkedIn connection, followed by weeks of warm, patient, everyday conversation with no mention of money. The fattening introduces a trading platform, often a polished app with live-looking charts and responsive support, on which the victim sees rapid gains and is usually allowed to withdraw a small amount early to build trust. The slaughter arrives when the victim, now heavily invested, tries to withdraw. The platform invents taxes, compliance fees and account upgrades that must be paid first, extracting further deposits until the victim is exhausted, at which point the scammer vanishes.
Two developments define the 2026 version of this scam. Artificial intelligence has loosened the labour constraint: AI personas can hold many fluent, personalised conversations at once, and deepfake video undermines the old advice of asking for a live call. At the same time, enforcement has escalated, with multiple cross-border operations and prosecutions targeting large pig butchering networks and freezing significant sums, including US action in late 2025 against figures linked to Cambodia's Prince Group. INTERPOL has identified trafficking victims from more than 60 countries inside such compounds, which is worth remembering: the person messaging you may be a captive as well as a criminal.
The tell-tale sequence
Every pig butchering operation, however sophisticated, must pass through the same choke points: a stranger initiates contact, the relationship moves to an investment conversation, the platform is one you have never heard of and were introduced to by the contact, early small withdrawals succeed, and eventually withdrawing requires paying money in. That final step is the unambiguous alarm. No legitimate exchange anywhere requires an upfront fee, tax payment or deposit to release your own funds. If you ever reach that point, stop paying immediately, preserve the evidence, and report it.
What is address poisoning?
Quick answer
Address poisoning plants lookalike addresses in your transaction history, betting that you will copy the wrong one when sending funds. The fake address matches the first and last characters of a real contact, which is exactly the part most people check.
This is the lowest-tech attack in the modern arsenal and one of the most effective against active traders. Attackers generate vanity addresses whose opening and closing characters mimic an address you genuinely use, then send you a dust transaction, a tiny transfer, sometimes of worthless tokens, so the lookalike appears in your history. Later, when you copy an address from that history instead of from a verified source, the funds go to the attacker. Researchers at Carnegie Mellon University, in a peer-reviewed study presented at the USENIX Security Symposium, measured around 270 million poisoning attempts on Ethereum and BNB Smart Chain over two years, targeting some 17 million addresses, with 6,633 successful incidents causing at least 83.8 million dollars in confirmed losses. The technique has also claimed spectacular single losses, including a trader who sent 50 million dollars in USDT to a poisoned address in December 2025.
The related malware variant is the clipboard hijacker: software that silently replaces any wallet address you copy with the attacker's. Torg Grabber, an infostealer analysed by Gen Digital in early 2026 across 334 samples, targeted 728 cryptocurrency wallet extensions and used clipboard-hijacking delivery to reach victims' machines. The defence against both is identical and simple to state: verify the entire address, every time, before signing, and use address books or name services for repeat recipients rather than transaction history. For large transfers, send a small test amount first and confirm receipt through a second channel.
How are deepfakes and AI changing crypto scams?
Quick answer
AI supplies scammers with fluent multilingual messaging, cloned voices, fabricated identity documents, and real-time fake video. It makes every other scam cheaper, more convincing and more scalable, and it has ended the era when a video call proved someone was real.
The FBI's IC3 received 22,364 complaints referencing AI use in 2025, with 893 million dollars in associated losses; that figure spans every internet crime category rather than crypto alone, but crypto fraud is one of its heaviest components. Chainalysis expects nearly all scams to incorporate AI to some degree within a few years. The applications criminals have found are worth understanding individually, because each one breaks a verification habit people still rely on.
- Celebrity giveaway deepfakes. Fabricated videos of public figures promising to double any crypto sent to an address, often broadcast through hijacked channels during major live events. The rule is absolute: every doubling giveaway is fake, without exception, regardless of the speaker, the platform badge or the production quality.
- Live video impersonation. Real-time face and voice swapping during video calls now lets scammers impersonate financial advisers, executives and romantic partners convincingly. A live call is no longer proof of identity.
- Synthetic identity attacks. AI-generated documents and deepfaked verification videos are used to pass know-your-customer checks and hijack accounts. In one documented case, attackers combined breached personal data with a deepfake video to take over an exchange account and extract more than 2 million dollars within a day, without any malware at all.
- Voice cloning of people you know. Seconds of audio scraped from social media are enough to clone a family member or colleague asking for an urgent transfer. Agree an offline code word with close contacts and treat any urgent payment request by voice as unverified until confirmed on a separate channel.
What are rug pulls, honeypots and fake platforms?
Quick answer
A rug pull is a project whose insiders drain the funds and disappear. A honeypot is a token you can buy but never sell. A fake platform is a trading interface whose numbers are simply invented. All three simulate a legitimate investment until the moment of exit.
These threats target the investing instinct rather than the wallet directly. Rug pulls dress themselves in the full costume of a genuine project: professional websites, active social channels, paid influencer promotion and rising charts. One caution before the examples: a price collapse alone proves nothing about intent. The Mantra (OM) token collapse of early 2025 erased billions in value within hours and is widely studied for how concentrated allocations and leverage can destroy a market, yet it was never established as a rug pull, and reserving that word for cases with evidence of deliberate extraction keeps your own analysis sharp. Honeypots are less ambiguous: malicious contract code permits buying while blocking every seller except the creator, which is why the chart only ever goes up. Fake platforms complete the set: polished dashboards whose balances are fiction, frequently paired with pig butchering relationships to supply the traffic.
Due diligence that takes ten minutes defeats most of these. Check whether the token contract is verified and audited, whether liquidity is locked, how concentrated the holder distribution is, whether the team is identifiable, and how old the domain is. A platform claiming years of operation with a website registered last month has answered your question. Above all, treat any platform you were introduced to by an unsolicited contact as fraudulent until proven otherwise, because that introduction path is itself the strongest red flag in crypto.
What are wrench attacks and physical threats?
Quick answer
A wrench attack uses physical coercion, from robbery to kidnapping, to force a victim to hand over crypto. Verified incidents rose 41 percent year on year in early 2026, with Europe, and France in particular, as the epicentre.
The name comes from an old joke: why break encryption when a five dollar wrench persuades faster? In 2026 the joke has become a documented criminal industry. Security firm CertiK verified 34 physical attacks on crypto holders between January and April 2026, up 41 percent from the same period in 2025, with estimated losses of roughly 101 million dollars, and projects around 130 incidents by year end if the pace holds. Europe accounted for the large majority of early 2026 cases, and France has become the global hotspot. Attackers increasingly target family members rather than holders themselves, as in the January 2026 kidnapping of a prominent US journalist's mother in a 6 million dollar Bitcoin ransom attempt.

The targeting pipeline matters for prevention. Investigators link attack waves to data breaches at crypto firms and to open-source intelligence: social media posts about holdings, conference appearances, luxury purchases and leaked customer databases together build the victim list. The practical implications follow directly. Never disclose holdings publicly or semi-publicly, treat KYC data breaches involving your accounts as a physical security event, and be conscious that home addresses connected to crypto wealth are the key data point criminals seek. For significant holders, custody design is itself physical security: multi-signature and multi-party arrangements that make it technically impossible for one coerced person to move funds remove the incentive for coercion, and telling the truth about that limitation is a recognised deterrent.
The 2026 threat landscape at a glance
The table below compresses this guide into a reference you can return to. Each threat is paired with its primary target, the red flag that most reliably exposes it, and the single most effective defence.
| Threat | Primary target | Most reliable red flag | Strongest defence |
|---|---|---|---|
| Impersonation | Exchange and wallet users | Unsolicited contact plus urgency | Hang up; verify via official channel you find yourself |
| Wallet drainers | Self-custody users | Signature request from a site reached via link or ad | Read signatures; cap approvals; segment wallets |
| Pig butchering | Anyone lonely or ambitious | Stranger introduces an unknown trading platform | Never invest via a platform a contact introduced |
| Address poisoning | Active traders | Copying addresses from transaction history | Verify full address; use address book; test transfers |
| Deepfake fraud | Everyone | Celebrity giveaways; urgent voice or video requests | Treat all doubling offers as fake; use code words |
| Rug pulls and honeypots | Token investors | Anonymous team; unlocked liquidity; sell-side silence | Check contract, liquidity lock, holder concentration |
| Clipboard hijackers | Anyone copying addresses | Pasted address differs from copied one | Verify entire address before every signature |
| Wrench attacks | Known large holders | Public visibility of holdings | Privacy discipline; coercion-resistant custody |
How do you spot a crypto scam? Universal red flags
Quick answer
Guaranteed returns, urgency, unsolicited contact, requests for seed phrases or remote access, upfront fees to release funds, and platforms you did not find yourself. Any one of these justifies stopping to verify before a single further step.
Individual scams evolve constantly, so the durable skill is recognising the invariants that appear across all of them. These six survive every technological shift because they reflect what a scam must do to function.
- Guaranteed or fixed returns. Crypto markets are volatile by nature. Anyone promising risk-free profit is describing something that does not exist.
- Pressure to act now. Every legitimate opportunity survives a day of reflection. Deadlines exist to prevent verification.
- They contacted you. Unsolicited investment opportunities, support outreach and prize notifications are scams at rates approaching certainty. Legitimate support never initiates contact.
- Any request for your seed phrase. No company, support agent, wallet vendor or government body ever needs it. The request itself is the scam, complete and entire.
- Paying to withdraw. Taxes, unlock fees and compliance charges demanded before releasing your own money define fraud. Real platforms deduct fees from balances.
- You cannot explain what you are signing. If a transaction's effect is unclear to you, the safe answer is always to decline and investigate. Nothing genuine is lost by waiting.
How do you protect your crypto? A layered defence
Quick answer
Layer your defences: strong account hygiene, hardware-backed keys, wallet segmentation, signing discipline, approval audits, and privacy about your holdings. No single measure is sufficient, and the layers are designed so that one mistake does not become a total loss.
Security professionals think in layers precisely because humans make mistakes. The goal is an arrangement where a single lapse, one bad click, one convincing phone call, one careless signature, costs you something recoverable rather than everything.
Layer 1: account and device hygiene
Use a unique password and app-based or hardware two-factor authentication on every exchange account, never SMS codes, which fall to SIM swapping. Keep wallet software, browsers and operating systems updated, since several major 2026 loss events traced back to unpatched vulnerabilities. Install browser extensions sparingly and audit them: the clipboard hijacker you never installed cannot rob you.
Layer 2: key management
How you hold keys determines what a single mistake can cost. A hardware wallet keeps keys off internet-connected devices and greatly reduces remote key extraction under safe setup and verification, though it cannot make a deceptive signature safe, and as support-impersonation cases have demonstrated, it cannot protect a seed phrase its owner reads out to a stranger. The seed phrase itself remains the classic single point of failure: anyone who obtains those words owns the funds, and anyone who loses them loses access. This is why the industry has been moving towards architectures without that single point, including multi-signature setups that require several devices to approve a transaction, and multi-party computation wallets that split key material so no complete key ever exists in one place. Whatever you choose, the principle is the same: arrange your custody so that no single secret, device or moment of misplaced trust can cost you everything.
Layer 3: transaction discipline
Slow down at the point of signature, because that is the main control point for approval and transfer-authority attacks, because a malicious signature is what turns access into loss. Verify complete addresses. Send test amounts before large transfers. Read what each approval grants and cap it. Bookmark the dApps you use and reach them only through those bookmarks. Review and revoke stale approvals monthly. None of these habits takes more than a minute, and together they substantially reduce the drainer, poisoning and hijacker attack surfaces, though no checklist removes them entirely.
Layer 4: information discipline
Treat knowledge of your holdings as a secret in its own right. Publicity converts you from a random target into a selected one, for phishing at minimum and physical coercion at worst. Avoid discussing amounts on social media, in usernames, or with new acquaintances, and assume that data you give to any platform may eventually leak.
What should you do if you have been scammed?
Quick answer
Act in this order: stop all further payments, revoke wallet approvals, move remaining funds to a fresh wallet, preserve evidence, report to law enforcement and the platforms involved, and treat every recovery offer as a second scam.
The first move is diagnosis, because the correct action depends entirely on what was compromised. Revoking a token approval stops further use of that approval, and does nothing after a seed phrase has leaked. Moving assets to a new wallet is essential after key compromise, and unnecessary after a one-off transfer to a fraudster. A password reset achieves little if the attacker also holds your email account or active sessions. Match the response to the failure.
| What happened | First action | What not to assume |
|---|---|---|
| You signed a malicious approval or permit | Revoke that specific permission with a trusted checker; move exposed assets if the attacker is active | Revocation does not repair a leaked seed phrase |
| You entered or shared a seed phrase | Treat the wallet as fully compromised; from a clean device, create a new wallet with fresh recovery material and move everything | Changing an app password or revoking approvals is not enough |
| Your exchange account or email was accessed | From a clean device, lock the account, revoke sessions and API keys, secure email and phone recovery routes | A password change alone can leave live sessions open |
| Malware or a clipboard hijacker is suspected | Disconnect the device from anything sensitive; rebuild or professionally clean it before reuse | An address is not safe just because you copied it correctly |
| You sent funds to a fake platform or address | Stop all payments, preserve hashes and messages, notify the receiving exchange if known, report immediately | No private service can reverse a confirmed transaction |
Speed matters most in the first hours. Preserve everything: addresses, transaction hashes, chat logs, URLs, usernames and phone numbers, because blockchain forensics has become genuinely effective and rapid reporting improves the odds of funds being frozen at an exchange. If anyone is in physical danger, personal safety comes before asset preservation: contact emergency services first.
Report to your national cybercrime channel: the Internet Crime Complaint Center at ic3.gov in the United States, Report Fraud in the United Kingdom (which replaced Action Fraud in December 2025; Scotland uses Police Scotland on 101), or your local police cyber unit elsewhere in Europe. Coordinated operations have frozen and returned meaningful sums, and programmes such as the FBI's Operation Level Up now identify and warn victims of ongoing pig butchering before the final losses land.
Finally, expect the second wave. Scam victims are systematically re-targeted by fake recovery services claiming, for a fee, to retrieve stolen funds. Legitimate recovery of crypto happens through law enforcement and the courts. Anyone who contacts you promising recovery in exchange for an upfront payment is running the same play on you twice.
Frequently asked questions
What is the most common crypto scam in 2026?
Investment fraud, dominated by pig butchering, is the most damaging category, accounting for 7.23 billion dollars of reported US losses in 2025. Impersonation is the fastest growing, up more than 1,400 percent year on year.
Can a scammer steal crypto just from my wallet address?
No. A public address alone lets someone view your balance and send you tokens, and nothing more. Theft requires your private key, your seed phrase, or a transaction you sign. This is also why address poisoning works through your mistake rather than any power the attacker has over your wallet.
Are hardware wallets enough to stop scams?
No. A hardware wallet greatly reduces remote key theft because signing happens on the device, though it does not make you immune to malware, malicious transactions you approve, or device and firmware flaws, and it is strongly recommended. It cannot stop you approving a malicious transaction on its screen or reading your seed phrase to a fake support agent, which is how some of the largest 2026 losses occurred.
Can stolen crypto be recovered?
Sometimes, but rarely and never guaranteed. Recovery happens when law enforcement freezes funds at exchanges or seizes them from criminal infrastructure, which is why fast reporting with full evidence matters. Any private service guaranteeing recovery for an upfront fee is itself a scam.
How do I check if a wallet approval is dangerous?
Use an approval checker such as Etherscan's token approval tool or Revoke.cash to list every permission your address has granted. Revoke anything you do not recognise, anything unlimited that no longer needs to be, and anything belonging to a project you have stopped using.
Is a video call proof that someone is real?
No longer. Real-time deepfake tools can convincingly fake faces and voices on live calls as of 2026. Verify identity through independent channels you initiate, and agree code words with people close to you for any request involving money.
Does connecting my wallet to a website give it access to my funds?
Not by itself. A normal connection exposes your public address and lets the site propose actions; spending authority only arises when you sign a transfer, approval, permit or order. The connection is the reconnaissance step, and the signature is the theft, which is why the signing screen deserves all of your attention.
What should I do if I typed my seed phrase into a website?
Treat the wallet as fully compromised, immediately. From a clean device, create a brand new wallet with entirely new recovery words and transfer every remaining asset to it. Do not reuse the old phrase anywhere, and do not assume revoking approvals or changing passwords helps: whoever holds those words holds the keys.
Do scammers really target ordinary people with small amounts?
Yes, though the balance has shifted towards larger targets. Automated drainers and phishing operate at industrial scale where every wallet is worth sweeping, while relationship scams and impersonation increasingly research higher-value victims. Nobody is too small to be targeted and nobody is too clever: documented victims include finance executives and a bank chief executive.
Key takeaways
Sources and further reading
The statistics in this article are drawn from the following primary sources, current as of July 2026. Volatile figures are re-checked at each quarterly review.
- Chainalysis, 2026 Crypto Crime Report: scams chapter and introduction. https://www.chainalysis.com/blog/crypto-scams-2026/ and https://www.chainalysis.com/blog/2026-crypto-crime-report-introduction/
- FBI Internet Crime Complaint Center, 2025 Annual Report. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
- FBI press release on 2025 cryptocurrency and AI fraud losses. https://www.fbi.gov/news/press-releases/cryptocurrency-and-ai-scams-bilk-americans-of-billions
- ScamSniffer, 2025 Crypto Phishing Report on wallet drainer losses. https://drops.scamsniffer.io/scam-sniffer-2025-crypto-phishing-losses-fall-83-to-84-million/
- Tsuchiya, Dong, Soska and Christin, Blockchain Address Poisoning, 34th USENIX Security Symposium, 2025. https://www.usenix.org/conference/usenixsecurity25/presentation/tsuchiya
- CertiK, 2026 Wrench Attacks Overview. https://www.certik.com/blog/2026-wrench-attacks-overview
- Reporting: FBI Internet Crime Complaint Center at https://www.ic3.gov (US) and Report Fraud (which replaced Action Fraud in December 2025) at https://www.reportfraud.police.uk (England, Wales and Northern Ireland; in Scotland, call Police Scotland on 101).
Quick quiz: did it stick?
A quick check on whether your scam radar is now properly calibrated. Answers with explanations follow. No pressure, but a perfect score is the only acceptable outcome when the exam fee is your savings.
You have completed a quiz on “Crypto Scams and Threats: How to Spot and Avoid Them”! Share your achievement on social media.




