The five most common crypto scams are phishing links, fake giveaways, DEX rug pulls, Ponzi platforms, and imposter apps.
Every crypto scam exploits one of two vulnerabilities: technical confusion or emotional urgency. A 2024 Chainalysis report revealed that first-time investors lose an average of $4,500 during their first scam encounter. Once you understand the specific attack vectors, you can spot and defuse them within seconds. Bookmark legitimate URLs, never type your 24-word seed phrase into any website, and sign transactions only after verifying the destination address on a hardware display.
Quick Picks
Not sure where to start? Tap a category - we'll show you the winner and why.
1. Phishing Links and Spoofed Domains
Lookalike websites and urgency-driven emails designed to harvest seed phrases and private keys.
Phishing remains the single largest entry point for wallet drains. Attackers mimic Binance, Ledger Live, or MetaMask interfaces to trick users into typing their recovery seed.
Phishing attacks rely on visual deception. An attacker registers a domain that differs from the official site by a single character (such as replacing an 'l' with a '1' or using a '.io' extension instead of '.com'). They send urgent security alerts via email, Telegram, or Discord claiming your account is suspended or a transaction requires re-authorization.
When you click through, the website looks identical to the real platform. You are prompted to 'verify your wallet' by entering your 12 or 24-word recovery phrase. The moment those words are submitted, automated drainer scripts sweep every token, NFT, and staked asset into an attacker address within seconds.
According to CertiK, crypto phishing attacks rose by 40% year-over-year. The defense is absolute: legitimate platforms will never ask for your recovery phrase via web forms, email, or customer support. Bookmark verified exchange and wallet addresses in your browser, navigate to them directly, and never click links in unexpected security emails.
2. Fake Giveaways and Social Media Impersonation
Hijacked verified accounts promising to double your Bitcoin or Ethereum if you send funds first.
Real crypto projects and founders never ask you to send crypto to receive a giveaway. Any promotion requiring an upfront deposit is an outright theft scam.
In a typical giveaway scam, attackers compromise high-profile verified accounts on X (formerly Twitter) or broadcast hijacked YouTube live streams featuring recorded footage of prominent figures like Vitalik Buterin or Elon Musk. The stream includes a QR code and a promise: 'Send 1 ETH to verify your address, and receive 2 ETH back immediately.'
The collection wallet is a one-way black hole. The Federal Trade Commission reported that over $130 million was stolen via cryptocurrency giveaway scams targeting video platforms in a single year. Attackers use automated bot swarms in the comment sections to post fake testimonials claiming they received their payout.
The mathematical principle is simple: legitimate promotional rewards and airdrops are deposited directly into user wallets based on snapshot activity. They never require an advance deposit. If a post or live stream requires sending cryptocurrency to receive free funds, report the channel and exit immediately.
3. Liquidity Pool Rug Pulls and Honeypot Tokens
Hyped decentralized tokens where creators disable the sell function or remove liquidity reserves.
Rug pulls exploit decentralized exchanges like Uniswap and Raydium. Developers build malicious functions into the token code that allow them to drain investor capital without warning.
In decentralized finance, anyone can create a new token and pair it with ETH or SOL in a liquidity pool. Malicious actors generate social media hype around a new meme coin or protocol, causing early buyers to flood in and drive the price up. When the pool reaches maximum value, the creators execute their trap.
In a liquidity drain, the creators withdraw the underlying ETH or SOL backing the token, leaving investors holding worthless digital tokens. In a honeypot scam, developers embed code into the smart contract that permits buying but blocks all sell transactions for non-whitelisted addresses. The 2021 Squid Game token is a notorious example: it surged 75,000% before creators pulled $3.38 million and vanished.
To protect your capital, verify whether the liquidity pool is locked for at least one year using verified locker services like Team Finance or Unicrypt. Check if the smart contract has been audited by firms such as CertiK or OpenZeppelin, and run the token address through scanner tools like TokenSniffer before approving any swaps.
4. High-Yield Ponzi Platforms Disguised as AI Arbitrage
Investment platforms promising 1% to 3% daily guaranteed returns through fictitious automated bots.
No trading algorithm delivers guaranteed daily returns without market drawdown. Platforms advertising 200%+ annual APY pay early depositors using fresh deposits until the scheme collapses.
Ponzi platforms present polished dashboards claiming to use proprietary 'AI arbitrage algorithms' or 'institutional staking pipelines' that yield consistent profits (typically 1% to 2% daily). In the initial weeks, the platform allows small withdrawals to build trust and encourage users to deposit larger balances.
They incorporate aggressive multi-tier affiliate structures, paying 10% to 20% referral bonuses to turn users into recruiters. However, no actual trading takes place. All returns are paid directly from newer investor capital. When incoming deposits slow down, the operators disable withdrawal requests citing 'regulatory audits' or 'technical maintenance', before taking down the website entirely.
The FBI's Internet Crime Complaint Center documented over $3.9 billion in cryptocurrency investment fraud. The litmus test: ask for verifiable on-chain wallet addresses showing real trading transactions. If an operator cannot provide auditable trade receipts, or claims their strategy is too proprietary to disclose, assume total loss risk.
5. Imposter Exchanges and Cloned Mobile Apps
Fake trading applications distributed via paid search ads and spoofed app store developer accounts.
Cybercriminals publish lookalike apps with logos mimicking Coinbase or Bybit. When you attempt to withdraw funds, the app demands an advance tax fee or locks your deposit.
Attackers buy sponsored Google Ads targeting keywords like 'download crypto exchange' or 'secure bitcoin wallet'. The ad links to a clone site that directs visitors to download a malicious APK or enterprise iOS profile. In some cases, rogue apps bypass app store filters by disguising themselves as utility tools before activating a crypto scam interface after download.
Once installed, the fake app simulates a legitimate exchange interface. When you deposit crypto, the balance appears to credit. However, when you attempt to withdraw, the app displays an error message stating your account is under review and demands a 20% 'tax verification fee' or 'AML compliance deposit'. Paying this additional fee yields no result, and the funds are permanently lost.
Security researchers at Sophos identified over 250 fake crypto applications across official and third-party app stores. Always access official exchanges by navigating directly to their verified domain or following official links on CoinGecko or CoinMarketCap. Check the app publisher name, review count, and release date in the App Store before installing.
Tell us about you. We'll tell you which one.
Click whichever line sounds like you. We'll show our pick and why.
Never share your 24-word recovery phrase, and verify every domain independently.
Scammers rely on manufactured urgency, unreal yield promises, and interface cloning. By securing your primary holdings in an offline hardware wallet, bookmarking official exchange domains, and refusing to sign unknown smart contract approvals, you eliminate more than 95% of all crypto attack vectors.
Frequently asked questions
Attackers buy data from historical breaches, monitor beginner subreddits and Telegram groups, and buy Google Ads on high-intent search terms like 'how to buy crypto'. Always verify domains independently.
On-chain transactions are mathematically irreversible. While law enforcement occasionally seizes mixer endpoints, recovery rates for individual victims are below 3%. Beware of unsolicited 'recovery experts' who contact you; virtually all recovery services on social media are secondary scams.
A hardware wallet like Ledger or Trezor prevents remote hackers and malware from accessing your private keys. However, if you manually enter your 24 words into a phishing site or sign a malicious contract approval, funds can still be taken. Hardware wallets secure your keys; your vigilance secures your approvals.
Never type your 24-word recovery phrase into any phone, website, or software application. Your seed phrase belongs solely on physical metal or paper and inside your hardware wallet device.