Not financial, legal, or tax advice. This article describes common scam patterns for educational purposes and isn't a substitute for your own judgment or professional advice.
Crypto scams follow a small number of repeating patterns, such as fake support, fake giveaways, and promises of guaranteed returns, dressed up in different branding each time. Learning the pattern matters more than memorizing any one scam, because new versions appear constantly. The US Federal Trade Commission keeps a current list of the tactics it sees most often.
Common scam types
- Phishing. Fake emails, texts, or websites designed to capture your password or seed phrase.
- Fake giveaways. "Send 1 ETH, get 2 back," a classic that only ever takes money, never returns it.
- Impersonation. Scammers posing as exchange support, a celebrity, or even someone you know whose account was hacked.
- Rug pulls. A new token or project that gains hype, takes investor money, and disappears.
- Guaranteed-return schemes. Any offer promising fixed, risk-free profits from crypto "trading" or "staking."
Three more belong on that list, because they account for a large share of modern losses and are less widely recognized.
- Malicious approvals. A site asks you to connect your wallet and sign something. You are not sending funds; you are granting a contract standing permission to take a token whenever it likes. Your keys were never exposed, and the theft is, mechanically, something you authorized.
- Address poisoning. A scammer sends you a tiny transaction from an address that closely resembles one you use, so that it appears in your history. Later, you copy the address from that history instead of the real one.
- Long-con romance and investment fraud. Weeks or months of genuine-seeming conversation, then an introduction to a trading platform that shows your balance growing beautifully and cannot be withdrawn from. This is the pattern behind the largest individual losses by a wide margin.
Red flags to watch for
Urgency ("act in the next 10 minutes"), unsolicited contact from "support," requests for your seed phrase or a screen-share session, and returns that sound too good to be true are the common threads across almost every scam. Legitimate platforms never ask for your seed phrase, and no investment can guarantee profit.
Underneath every one of those is the same structure, and recognizing it generalizes better than any list. A scam needs you to act before you think, so it manufactures a reason for speed: a closing window, an expiring allocation, an account about to be locked. It needs to be the one that contacted you, because a target who went looking might have checked. And it needs an emotion strong enough to override caution, whether that is fear, greed, affection, or the particular panic of being told your funds are at risk.
Which yields a rule that costs nothing and catches most of it: nothing legitimate in crypto ever requires you to act within the next ten minutes. Not support, not an opportunity, not a security alert. The urgency is the tell, and it is present in essentially every case.
How to verify before you act
Go directly to a company's official website or app rather than clicking a link you were sent. Check a project's history, team, and audits independently rather than trusting a single social media post. If someone claiming to be "support" contacts you first, assume it's a scam until proven otherwise. Our checklist for judging a token before you buy it covers what to look at.
A few habits make verification automatic rather than effortful. Bookmark the venues you use and navigate from the bookmark, since search advertisements for fake front-ends are a standing business and the fake looks identical to the real thing. Verify token contract addresses against the project's own documentation, never a search result, because anyone can create a token with any name. And read what you sign on your hardware wallet's own screen, which exists precisely so malware on your computer cannot show you one thing while sending another.
The strongest structural defense is separation. Keep a wallet with a small balance for anything experimental, and keep savings in cold storage that never connects to an application. Then the worst realistic outcome of a bad click is bounded, rather than total, and almost every catastrophic loss in this industry happened to someone whose entire holdings were in the wallet they happened to be experimenting with.
What to do if you're targeted
Stop responding, don't click any links, and don't send anything else. If you've already shared a seed phrase or private key, move any remaining funds to a new wallet immediately. If it has already gone wrong, follow the steps for a compromised wallet immediately.
Be very careful about what comes next, because a second wave targets people who have just been robbed. Recovery services promising to retrieve stolen crypto are, essentially without exception, a scam preying on desperation, and they frequently find victims by watching public complaints. Funds moved on-chain cannot be reversed by anyone, and no fee changes that.
One last thing worth saying plainly: being scammed is not a character flaw. These operations are professional, well-resourced, and specifically designed to work on intelligent people having a normal day, and shame is precisely what keeps victims quiet and lets the same scheme run again. Report it, warn people, and move on.
The rules that catch almost everything
Scam branding changes constantly and the structure does not, so a short list of rules generalizes better than any catalog of current schemes:
- Nobody legitimate will ever ask for your seed phrase. Not support, not a developer, not a wallet, not an exchange. There is no error, no migration, and no recovery process that requires it. Anyone who asks is robbing you, with no exceptions to check for.
- If they contacted you first, assume it is a scam. Real support does not DM you. Real opportunities do not arrive unsolicited. This single rule ends most attacks at the first message.
- Guaranteed returns do not exist. Not in crypto, not anywhere. A fixed, risk-free yield is a description of who is being paid with whose money.
- Urgency is the tell. Nothing legitimate expires in ten minutes. The countdown exists to prevent the research that would end the conversation.
- A request you do not understand is a request to decline. There is no cost to walking away and no recovery if you are wrong.
Notice that none of these require technical knowledge, and none depend on recognizing a particular scam. They work because every version of this needs the same few things from you: speed, secrecy, and a reason not to check. Refuse those three and the specific story stops mattering.
The one addition worth making for the current era is that the production values are no longer a signal. Scam sites are pixel-perfect, the English is flawless, the documentation is thorough, and video and voice can now be convincingly faked, so a call from someone who sounds exactly like a person you know is not evidence of anything. The old advice to watch for typos and clumsy design is obsolete, and judging legitimacy by polish now actively works against you, since the professional operations are the dangerous ones.
What has not changed is the structure underneath. However convincing the surface, the request is still for speed, secrecy, or access, and it still arrives from someone you did not go looking for. Verify through a channel you chose yourself, and the quality of the impersonation stops being relevant.