Beginner · 10 min read

How to Spot and Avoid Common Crypto Scams

Most crypto scams follow a handful of predictable scripts — fake support, phishing links, and rug pulls — and each one has a tell if you know where to look.

Selin AydinSelin AydinSecurity Editor · Crypto security, custody, exploits and smart-contract risk
How to Spot and Avoid Common Crypto Scams
The short answer

Most crypto scams run a handful of scripts: fake support that contacts you first, phishing links on lookalike domains, rug pulls where the exit was always the plan, and impersonation backed by artificial urgency. Each has a tell. The single rule that defeats nearly all of them is to initiate contact yourself, through a bookmark, and never from a message, an advertisement or a search result.

Chainalysis puts illicit crypto transaction volume in the tens of billions of dollars annually, and a meaningful share of that isn't hacking in the technical sense — it's ordinary social engineering aimed at ordinary users. Avoiding crypto scams doesn't require a security background. It requires recognising a short list of scripts that get reused constantly, because they work.

The uncomfortable truth is that crypto's core feature — irreversible, permissionless transactions — is also what makes it a magnet for fraud. There's no chargeback, no fraud department to call, no bank to freeze the transfer. That single design choice shapes everything about how you need to defend yourself.

The fake support scam

This is one of the most common vectors, and it works because it exploits the exact moment you're already frustrated. You post in a Discord or Telegram group asking why your withdrawal is stuck. Within minutes — sometimes seconds — someone with an official-looking username and a support badge in their profile messages you directly, offering to help. They ask you to "verify your wallet" by sharing your seed phrase, or to run a "diagnostic" by connecting your wallet to a link they provide.

No legitimate exchange or protocol support team will ever ask for your seed phrase or private key. Full stop. That's not a rule with exceptions for urgent-sounding situations — it's the single clearest tell in the entire category, because there is no technical reason support staff would ever need it. If someone asks, the conversation is over and you should report and block, not negotiate.

The fix is procedural: real support responds in the platform's official channel, not via unsolicited DMs, and legitimate companies almost universally disable direct messages from strangers in their official Discord servers specifically because of this scam. If you can DM someone claiming to be support, treat that as a warning sign rather than a convenience.

Phishing in crypto usually arrives as a link — in a tweet reply, a Google ad, an email, or a QR code at a conference booth — pointing to a site that looks identical to a real exchange or wallet interface but sits on a lookalike domain. Common tricks include swapping a lowercase L for a capital I, adding a hyphen, or using a different top-level domain entirely (.io instead of .com, for instance).

Google ads have been a particularly persistent problem: scammers have paid to have phishing sites rank above the genuine site for searches like "Uniswap" or "MetaMask download," because sponsored results look almost identical to organic ones at a glance. The safest habit is boring but effective — never click a search ad for a wallet or exchange, and instead navigate by typing the URL you already know, or use a bookmark you saved the first time you verified the site was genuine.

Once you land on a phishing site, the trap is usually a "Connect Wallet" button that, instead of a harmless connection, requests a token approval — permission for a contract to move your assets. People sign this because it looks like the standard wallet popup they've seen a hundred times. Read what you're signing. If a transaction request mentions "approve," "setApprovalForAll," or an unlimited spending allowance for a site you didn't intend to interact with, reject it.

Rug pulls — when the exit is the whole plan

A rug pull is when a project's creators drain the liquidity pool or dump their own token holdings, collapsing the price to near zero, usually within hours or days of launch. The Squid Game token in late 2021 is the textbook case: the price rose over 300,000% in a week before the creators pulled liquidity and the token became worthless within minutes, and — pointedly — the token's smart contract had been built so holders couldn't sell it in the first place, only the creators could.

That detail points to the most useful defence: check whether a token's contract has been through an independent audit, and check whether you can actually sell a small test amount before committing real money. Tools that scan a contract for functions like blacklisting, unlimited minting, or sell restrictions exist for exactly this reason, and running a new token through one takes under a minute.

Liquidity locks are another signal worth checking. Legitimate projects often lock their liquidity pool tokens in a time-locked contract, visible on-chain, so the team physically cannot pull the pool overnight. If a project's liquidity is unlocked and concentrated in one or two wallets, that's not proof of a scam, but it's a red flag that raises the burden of proof for everything else about the project.

Impersonation and the urgency trick

A pattern that cuts across all of the above: scams manufacture urgency. "Your account will be suspended in 24 hours." "This airdrop closes in 10 minutes." "Limited slots remaining for early access." Urgency is a tool for shutting down the part of your judgement that would otherwise notice something's off, and it appears in almost every successful scam regardless of the specific mechanism.

Giveaway scams follow the same logic with a twist — impersonated accounts of well-known figures in crypto, sometimes using hijacked verified accounts, promise to double any crypto sent to a specific address within minutes. There is no legitimate version of this offer. None. The mechanism of "send X to receive 2X" has never once been real, and its persistence over a decade is purely a function of how cheap it is to run against a large enough audience.

A practical checklist before you act

Before sending funds, connecting a wallet, or sharing any information, run through this: has anyone asked for my seed phrase or private key, in any form — that's an automatic stop. Did I navigate to this site myself, or did I click a link from a DM, ad, or comment — unsolicited links deserve extra scrutiny regardless of source. Is there artificial urgency pushing me to skip verification steps? Does the return being promised sound disconnected from any real, explainable source of yield? And for tokens specifically: has the contract been audited, and can I verify the liquidity situation on a block explorer before buying in.

What to do if it's already happened

If you've shared a seed phrase or approved a malicious contract, speed matters more than anything else. Move remaining funds to a new wallet immediately, using a different device if you suspect the original one is compromised. Revoke any token approvals you don't recognise using a reputable revocation tool tied to the relevant block explorer. Report the incident to the platform involved and, where the amount justifies it, to your local financial crime authority — recovery is rare, but the reporting helps flag addresses and patterns for others.

None of this is about becoming paranoid toward the entire industry. It's about recognising that the attack surface in crypto is narrower than people assume — almost everything comes down to seed phrase requests, lookalike links, or manufactured urgency. Learn those three shapes and you'll recognise the vast majority of what's actually out there.

FAQ

Will crypto support ever message me first?
No. Legitimate support responds to requests you open yourself and never sends unsolicited direct messages. Any inbound offer of help about a wallet or account is an attack.
How do I check a link is the real site?
Navigate from your own bookmark rather than a search result, advertisement or message. Lookalike domains substitute characters that read correctly at a glance, so inspecting the URL is less reliable than never following one.
What is a rug pull?
A project whose exit is the plan: liquidity is withdrawn or the supply is dumped once enough buyers have arrived. Locked or burned liquidity and a distributed holder base are what distinguish a real launch.
Can I recover money lost to a crypto scam?
On-chain transfers are final. Report the destination address to the receiving exchange quickly, since funds that reach a custodial platform can sometimes be frozen, and ignore anyone offering paid recovery — that is a second scam aimed at victims.