Common crypto scams — and how to avoid them
Crypto's best feature for users — fast, final, irreversible payments — is also its best feature for thieves. Once your coins are sent, there's no bank to call and no chargeback to file. The good news: almost every scam is a variation on a handful of patterns. Learn the patterns and the red flags, and you can spot the vast majority before they cost you anything.
Reviewed by Robert · Updated August 2026
Why scammers love crypto
Crypto transactions are irreversible, often pseudonymous, and global — there's no central authority to reverse a payment or freeze a thief's account. Add a fast-moving market, fear of missing out, and a steady stream of newcomers, and you get an environment where scams thrive. Understanding that backdrop is the first defense: if something is pressuring you to send crypto right now, that urgency is the tell.
Scams that lure you into "investing"
- Fake giveaways & "send 1, get 2 back." Impersonated celebrities, companies, or "official" accounts promise to double any crypto you send. You'll never get anything back. No legitimate giveaway asks you to send funds first.
- Romance & "pig-butchering" scams. A friendly stranger builds trust over weeks, then introduces a "can't-miss" investment on a slick fake platform. Early "gains" look real to keep you depositing — until you try to withdraw and it all vanishes.
- Guaranteed-return & fake-yield platforms. Sites or "trading bots" promising fixed daily/weekly profits are classic Ponzi structures: early withdrawals are paid with later victims' money until it collapses.
- Rug pulls & honeypot tokens. A new token is hyped, you buy in, and the creators drain the liquidity and disappear — or the token is coded so you can buy but never sell.
- Pump-and-dump groups. Coordinated hype inflates a thin coin so insiders can sell into the buying. The people who "got the tip" are the exit liquidity.
Scams that steal access to what you already own
- Phishing sites & fake apps. Look-alike exchange or wallet pages (and fake app-store apps) capture your login or, worse, your recovery phrase. A single character off in the URL is the whole trap.
- Fake "support." Scammers pose as wallet or exchange customer service in chats, email, or search ads, then ask you to "verify" your seed phrase or share your screen. Real support never needs your seed phrase.
- Wallet drainers & malicious approvals. A site asks you to "connect" and sign a transaction that actually grants permission to spend your tokens, or signs away your assets. Read what you're approving — a signature can be a blank check.
- Address-swapping malware. Clipboard hijackers silently replace a copied wallet address with the attacker's, so your send goes to them. Always double-check the first and last characters.
- SIM-swaps & account takeover. By hijacking your phone number, a thief defeats SMS codes and password resets on custodial accounts. Use an authenticator app, not SMS, for two-factor.
- Fake airdrops & "claim" sites. Surprise tokens appear in your wallet to bait you to a malicious site to "claim" them — which drains the wallet you connect.
The red flags that show up again and again
Different scams, same warning signs. Treat any of these as a hard stop:
- Guaranteed or unusually high returns — real investing never promises a fixed profit.
- Pressure and urgency — "act now," limited-time, "the price moves at midnight."
- Anyone asking for your seed phrase or private keys — always a scam, no exceptions.
- Unsolicited contact — DMs, texts, or calls about an opportunity you didn't seek out.
- "Pay a fee to withdraw" — a fake platform demanding taxes/fees before releasing "your" funds.
- Requests to move to another app or platform — off to WhatsApp/Telegram and a custom "exchange."
How to protect yourself
- Never share your recovery phrase or enter it on any website. Store the bulk of your crypto in cold storage. (See our companion guide, hot wallet vs. cold wallet.)
- Reach sites through your own bookmarks, not search ads or links in messages, and verify the URL exactly.
- Use an authenticator app for 2FA, not SMS, and a unique password per account.
- Slow down and verify independently. Look up the project, the team, and the contract; if you can't, don't.
- Review and revoke token approvals periodically, and read every transaction before you sign it.
- Send a tiny test amount first when using a new address, and assume unsolicited offers are fake until proven otherwise.
If you think you've been scammed
Move fast: transfer any remaining funds to a wallet the scammer can't touch, revoke any approvals you granted, and change passwords on affected accounts. Report it to your exchange and to the authorities — in the U.S., the FTC and the FBI's Internet Crime Complaint Center (IC3). Finally, beware the recovery scam: people who "guarantee" they can get your lost crypto back for an upfront fee are almost always the same kind of fraudster, hitting victims a second time. (More from the FTC: cryptocurrency and scams.)
CapitalCalcs provides educational information, not financial or security advice, and never holds, custodies, or has any access to your crypto. Scam tactics change constantly — when in doubt, slow down and verify. See how we calculate.