How to Spot and Avoid Common Crypto Scams
Most crypto scams follow a handful of predictable scripts — fake support, phishing links, and rug pulls — and each one has a tell if you know where to look.
Most crypto scams follow a handful of predictable scripts — fake support, phishing links, and rug pulls — and each one has a tell if you know where to look.

Most crypto scams run a handful of scripts: fake support that contacts you first, phishing links on lookalike domains, rug pulls where the exit was always the plan, and impersonation backed by artificial urgency. Each has a tell. The single rule that defeats nearly all of them is to initiate contact yourself, through a bookmark, and never from a message, an advertisement or a search result.
Chainalysis puts illicit crypto transaction volume in the tens of billions of dollars annually, and a meaningful share of that isn't hacking in the technical sense — it's ordinary social engineering aimed at ordinary users. Avoiding crypto scams doesn't require a security background. It requires recognising a short list of scripts that get reused constantly, because they work.
The uncomfortable truth is that crypto's core feature — irreversible, permissionless transactions — is also what makes it a magnet for fraud. There's no chargeback, no fraud department to call, no bank to freeze the transfer. That single design choice shapes everything about how you need to defend yourself.
This is one of the most common vectors, and it works because it exploits the exact moment you're already frustrated. You post in a Discord or Telegram group asking why your withdrawal is stuck. Within minutes — sometimes seconds — someone with an official-looking username and a support badge in their profile messages you directly, offering to help. They ask you to "verify your wallet" by sharing your seed phrase, or to run a "diagnostic" by connecting your wallet to a link they provide.
No legitimate exchange or protocol support team will ever ask for your seed phrase or private key. Full stop. That's not a rule with exceptions for urgent-sounding situations — it's the single clearest tell in the entire category, because there is no technical reason support staff would ever need it. If someone asks, the conversation is over and you should report and block, not negotiate.
The fix is procedural: real support responds in the platform's official channel, not via unsolicited DMs, and legitimate companies almost universally disable direct messages from strangers in their official Discord servers specifically because of this scam. If you can DM someone claiming to be support, treat that as a warning sign rather than a convenience.
Phishing in crypto usually arrives as a link — in a tweet reply, a Google ad, an email, or a QR code at a conference booth — pointing to a site that looks identical to a real exchange or wallet interface but sits on a lookalike domain. Common tricks include swapping a lowercase L for a capital I, adding a hyphen, or using a different top-level domain entirely (.io instead of .com, for instance).
Google ads have been a particularly persistent problem: scammers have paid to have phishing sites rank above the genuine site for searches like "Uniswap" or "MetaMask download," because sponsored results look almost identical to organic ones at a glance. The safest habit is boring but effective — never click a search ad for a wallet or exchange, and instead navigate by typing the URL you already know, or use a bookmark you saved the first time you verified the site was genuine.
Once you land on a phishing site, the trap is usually a "Connect Wallet" button that, instead of a harmless connection, requests a token approval — permission for a contract to move your assets. People sign this because it looks like the standard wallet popup they've seen a hundred times. Read what you're signing. If a transaction request mentions "approve," "setApprovalForAll," or an unlimited spending allowance for a site you didn't intend to interact with, reject it.
A rug pull is when a project's creators drain the liquidity pool or dump their own token holdings, collapsing the price to near zero, usually within hours or days of launch. The Squid Game token in late 2021 is the textbook case: the price rose over 300,000% in a week before the creators pulled liquidity and the token became worthless within minutes, and — pointedly — the token's smart contract had been built so holders couldn't sell it in the first place, only the creators could.
That detail points to the most useful defence: check whether a token's contract has been through an independent audit, and check whether you can actually sell a small test amount before committing real money. Tools that scan a contract for functions like blacklisting, unlimited minting, or sell restrictions exist for exactly this reason, and running a new token through one takes under a minute.
Liquidity locks are another signal worth checking. Legitimate projects often lock their liquidity pool tokens in a time-locked contract, visible on-chain, so the team physically cannot pull the pool overnight. If a project's liquidity is unlocked and concentrated in one or two wallets, that's not proof of a scam, but it's a red flag that raises the burden of proof for everything else about the project.
A pattern that cuts across all of the above: scams manufacture urgency. "Your account will be suspended in 24 hours." "This airdrop closes in 10 minutes." "Limited slots remaining for early access." Urgency is a tool for shutting down the part of your judgement that would otherwise notice something's off, and it appears in almost every successful scam regardless of the specific mechanism.
Giveaway scams follow the same logic with a twist — impersonated accounts of well-known figures in crypto, sometimes using hijacked verified accounts, promise to double any crypto sent to a specific address within minutes. There is no legitimate version of this offer. None. The mechanism of "send X to receive 2X" has never once been real, and its persistence over a decade is purely a function of how cheap it is to run against a large enough audience.
Before sending funds, connecting a wallet, or sharing any information, run through this: has anyone asked for my seed phrase or private key, in any form — that's an automatic stop. Did I navigate to this site myself, or did I click a link from a DM, ad, or comment — unsolicited links deserve extra scrutiny regardless of source. Is there artificial urgency pushing me to skip verification steps? Does the return being promised sound disconnected from any real, explainable source of yield? And for tokens specifically: has the contract been audited, and can I verify the liquidity situation on a block explorer before buying in.
If you've shared a seed phrase or approved a malicious contract, speed matters more than anything else. Move remaining funds to a new wallet immediately, using a different device if you suspect the original one is compromised. Revoke any token approvals you don't recognise using a reputable revocation tool tied to the relevant block explorer. Report the incident to the platform involved and, where the amount justifies it, to your local financial crime authority — recovery is rare, but the reporting helps flag addresses and patterns for others.
None of this is about becoming paranoid toward the entire industry. It's about recognising that the attack surface in crypto is narrower than people assume — almost everything comes down to seed phrase requests, lookalike links, or manufactured urgency. Learn those three shapes and you'll recognise the vast majority of what's actually out there.

Price tells you what the market thinks. On-chain metrics tell you what's actually happening underneath it. Here's a starter toolkit for reading network health directly from the ledger.

A myth-busting look at the difference between letting an exchange hold your keys and holding them yourself, with the real-world collapses that made the distinction matter.

Moving funds off an exchange and into cold storage for the first time is simpler than it looks — provided you follow the sequence in the right order and don't skip the verification steps.