Crypto moves value the way the internet moves email: quickly, globally, and without a central authority that can reverse a mistake. That design is powerful, but it also means fraud in crypto tends to be final. Once a transaction is confirmed on a blockchain, no support desk can claw it back. Scammers know this, which is why almost every crypto scam is really a social engineering problem — a trick designed to get you to click, sign, or send voluntarily.
One of the oldest patterns is the giveaway scam. A post, video, or livestream claims that if you send coins to a listed address, you will get a larger amount back. Sometimes the account impersonates a well-known figure or a company; sometimes a hijacked account with real followers is used to add credibility. The mechanics never change: money flows one direction only. No legitimate entity requires you to send crypto first in order to receive crypto. Treat any offer with that structure as fraudulent by definition, regardless of how polished the branding looks.
Impersonation scams extend this into direct contact. Someone posing as customer support, a wallet developer, or an exchange employee reaches out after you post about a problem publicly. They ask for your seed phrase or recovery words, or ask you to enter them into a "validation" or "sync" tool. A seed phrase is the master key to a self-custody wallet — anyone holding it controls every asset in that wallet, permanently. Legitimate support staff never need it, never ask for it, and cannot use it to help you. The same applies to private keys and to screen-sharing sessions where someone asks to watch you unlock a wallet.
Investment schemes, sometimes called pig butchering, are slower and more damaging. Contact often begins on a dating app, a messaging platform, or a wrong-number text that turns into friendly conversation over weeks. Eventually the contact mentions a trading platform, a mining pool, or an arbitrage bot with steady returns. The platform is fake: it shows fabricated balances that grow on a dashboard while the deposited funds are already gone. Victims are usually allowed to withdraw a small amount early, which builds trust, then blocked with demands for taxes or fees when they try to withdraw more. The warning signs are consistency of returns, pressure to deposit more, and the fact that the introduction came from an unsolicited stranger.
On-chain scams work differently because they exploit how smart contracts operate. When you interact with a decentralized application, you sign a transaction granting the contract permission to move certain tokens on your behalf. A malicious contract can request unlimited spending approval, then drain the approved tokens later, long after you have forgotten the interaction. Related tricks include signature phishing, where the request is not a normal transfer but a message that authorizes someone to take your assets or transfer an NFT. Reading what your wallet is asking you to approve, rejecting requests you do not understand, and periodically revoking old approvals through a token-approval checker all reduce this exposure.
Phishing sites tie everything together. Attackers buy search ads for common wallet and exchange names, register domains with a swapped character, or post fake links in community chats after a real announcement. The cloned site looks correct and asks you to connect a wallet or log in. Bookmarking the sites you use, typing addresses manually, and being skeptical of sponsored search results are simple defenses. Hardware wallets help here too, because they display transaction details on a separate screen that malware on your computer cannot alter.
A few habits cover most cases. Slow down when anything is urgent, since urgency is manufactured on purpose. Verify claims through a second, independent channel rather than a link you were sent. Keep seed phrases offline and never typed into any website. Enable app-based two-factor authentication rather than SMS where possible. Send a small test transaction before a large transfer to a new address. And assume that any opportunity arriving unsolicited in your inbox, DMs, or comments is a solicitation, not a discovery.
This article is for general education only — not financial advice, and nothing here is a recommendation to buy, sell, or hold any asset. Cryptocurrency carries real risk of loss; always do your own research before making a financial decision.