Crypto scams have become more sophisticated as the cryptocurrency industry has grown, with attackers increasingly relying on social engineering rather than technical exploits alone. Modern scams range from phishing websites and fake wallet apps to wallet drainers, address poisoning, AI-generated deepfakes, and elaborate investment schemes that impersonate trusted companies or individuals.

According to Chainalysis, scammers stole an estimated $17 billion through crypto scams and fraud in 2025, making it the most profitable year on record. The report also found that AI-enabled scams generated 4.5 times more revenue than traditional operations, while impersonation scams surged by 1,400% year over year, highlighting how quickly cybercriminals are adapting to new technologies.

Understanding how these scams work is one of the most effective ways to protect your cryptocurrency. From wallet drainers and phishing attacks to rug pulls, fake airdrops, AI-powered impersonation scams, and fraudulent investment platforms, recognizing the warning signs before connecting your wallet, signing a transaction, or sending funds can prevent irreversible losses.

1. Pig Butchering Investment Scams

What it is

Pig butchering is a long-term investment scam in which scammers build trust before directing victims to fake cryptocurrency trading platforms that display fabricated profits. Victims are persuaded to invest increasing amounts of money before withdrawals are blocked or additional payments are demanded to release their funds.

How the scam works

  • Initial contact through dating apps, social media, WhatsApp, Telegram, or LinkedIn.
  • The scammer builds trust over days or weeks.
  • The victim is introduced to a fake cryptocurrency investment platform.
  • Small withdrawals may be allowed to build confidence.
  • Larger withdrawals are blocked, or the victim is asked to pay fake taxes, fees, or verification charges.

How to avoid it

  • Ignore unsolicited investment offers.
  • Verify trading platforms independently.
  • Never pay fees or taxes to unlock withdrawals.
  • Be skeptical of guaranteed returns or unusually high profits.

2. Phishing Scams

Phishing scams trick users into revealing sensitive information or approving malicious transactions by impersonating trusted cryptocurrency companies, wallet providers, exchanges, or customer support teams. Modern phishing campaigns extend beyond email and commonly use fake websites, social media accounts, messaging apps, QR codes, and AI-generated messages or voice calls to appear legitimate. Phishing remains one of the most common ways cryptocurrency users lose access to their funds.

How the scam works

  • Victims receive an email, message, or phone call claiming to be from a trusted crypto platform.
  • They are directed to a fake website or asked to connect their wallet, enter their seed phrase, or approve a malicious transaction.
  • The scammers use the stolen credentials or wallet permissions to transfer cryptocurrencies or other digital assets.
  • Some phishing campaigns impersonate customer support and ask users to install remote access software or "verify" their wallet.

How to avoid it

  • Never share your seed phrase or private keys with anyone.
  • Access exchanges and wallets by typing the official website address instead of clicking links in emails or messages.
  • Verify customer support through official channels, as legitimate companies do not request sensitive information through direct messages.
  • Enable two-factor authentication (2FA) and carefully review every wallet signature or approval request before confirming it.

3. Wallet Drainer Scams

A wallet drainer is a phishing scam that tricks users into connecting their crypto wallet to a malicious website and approving a transaction that gives attackers permission to transfer their assets. These scams do not require attackers to steal private keys or seed phrases. Instead, they exploit wallet approvals that users unknowingly authorize. Wallet drainers have become one of the most common Web3 attack methods, often spread through fake airdrops, NFT mints, compromised social media accounts, and fraudulent websites.

How the scam works

  • Victims are lured to a fake website through social media, ads, Discord, Telegram, or phishing emails.
  • The site prompts the user to connect their wallet and sign or approve a transaction.
  • The approval grants the attacker permission to access specific assets or token allowances.
  • The attacker transfers cryptocurrencies, NFTs, or other digital assets from the wallet, often within seconds.

How to avoid it

  • Connect your wallet only to trusted websites and verify the URL before signing any transaction.
  • Read wallet approval requests carefully instead of approving them automatically.
  • Use a separate wallet for testing new dApps and keep long-term holdings in a different wallet or a hardware wallet.
  • Regularly review and revoke unnecessary token approvals using trusted permission management tools.

4. Fake Wallet Apps

Fake wallet apps imitate legitimate cryptocurrency wallets to steal seed phrases, private keys, passwords, or transaction approvals. They may appear in app stores, browser-extension marketplaces, search ads, or cloned wallet websites with copied branding, fabricated reviews, and similar developer names. In 2025, researchers identified more than 40 fraudulent Firefox extensions impersonating popular crypto wallets, while Ledger continued warning users about counterfeit Ledger Wallet applications designed to capture recovery phrases or trigger unauthorized transactions.

How the scam works

  • The victim downloads a fake mobile app, desktop program, or browser extension.
  • The app asks the user to import an existing wallet using a seed phrase or private key.
  • Some versions display false security warnings or claim that the wallet must be restored, synchronized, or verified.
  • The scammers use the stolen recovery phrase to recreate the wallet and transfer its assets. Other fake apps initiate transactions that the victim is prompted to approve.

How to avoid it

  • Download wallet software through links on the provider’s official website.
  • Verify the developer name, extension publisher, download history, and permissions before installation.
  • Never enter a hardware wallet recovery phrase into a computer, phone, website, or support form.
  • Treat urgent requests to restore, synchronize, migrate, or verify a wallet as suspicious.
  • Remove unfamiliar wallet extensions and confirm software updates through the wallet provider’s official channels.

5. Fake Customer Support Scams

Fake customer support scams involve criminals impersonating support agents from cryptocurrency exchanges, wallet providers, or hardware wallet companies to steal funds or sensitive information. They often monitor social media for users seeking help, then contact them through direct messages, Telegram, Discord, WhatsApp, or phone calls while posing as official support. These scams have become increasingly common following high-profile data breaches and phishing campaigns that expose customer information.

How the scam works

  • A victim posts about a wallet or exchange issue on social media or contacts what appears to be an official support account.
  • The scammer initiates a private conversation, claiming they can resolve the problem.
  • The victim is asked to share their seed phrase, private keys, one-time verification codes, or install remote access software. Some scammers instead direct victims to fake wallet verification pages or ask them to sign a malicious transaction.
  • Once they obtain access or wallet permissions, the scammers transfer the victim's cryptocurrency.

How to avoid it

  • Contact customer support only through the company's official website or app.
  • Never share your seed phrase, private keys, passwords, or two-factor authentication codes with anyone.
  • Ignore unsolicited direct messages from accounts claiming to be customer support.
  • Legitimate support teams will never ask you to transfer funds, verify your wallet by entering your recovery phrase, or install remote access software.

6. Honeypot Token Scams

A honeypot token is a malicious cryptocurrency that allows investors to buy tokens but prevents them from selling or transferring them. The restriction is hidden within the token's smart contract, making the project appear legitimate until investors attempt to cash out. Honeypot scams are especially common on decentralized exchanges (DEXs), where anyone can launch a token with little oversight, and security researchers continue to identify thousands of malicious contracts each year.

How the scam works

  • Scammers launch a new token and promote it through social media, influencers, or messaging apps.
  • Investors can buy the token normally, creating the illusion of a legitimate project.
  • Hidden smart contract functions block sell transactions, blacklist wallets, or impose restrictions that prevent most holders from exiting their positions.
  • The scammers sell their own holdings or remove liquidity while investors remain unable to sell their tokens.

How to avoid it

  • Research the token and its team before investing.
  • Verify that the smart contract has been audited or reviewed by reputable security firms.
  • Check whether other investors can successfully sell the token and review recent transaction activity on a blockchain explorer.
  • Be cautious of newly launched tokens promoted with unrealistic returns, aggressive marketing, or fear of missing out (FOMO).

7. Rug Pull Scams

A rug pull is a scam in which a project's developers or insiders abandon a cryptocurrency project after attracting investor funds, causing the token's value to collapse. In most cases, the attackers drain liquidity, sell large amounts of tokens, or exploit privileged smart contract functions that allow them to manipulate the token after launch. Rug pulls are most commonly associated with newly launched tokens, memecoins, and decentralized finance (DeFi) projects.

How the scam works

  • A new token is launched and heavily promoted through social media, influencers, or online communities.
  • Investors buy the token, increasing its price and liquidity.
  • The developers remove liquidity, dump their token holdings, or use hidden smart contract functions to inflate the token supply or restrict trading.
  • The token's price crashes, leaving investors with assets that are difficult or impossible to sell.

How to avoid it

  • Research the project's team, roadmap, and real-world utility before investing.
  • Check whether liquidity is locked and whether the smart contract has been audited.
  • Review the contract for privileged functions, such as the ability to mint new tokens, pause trading, or blacklist wallets.
  • Be cautious of anonymous teams, aggressive marketing campaigns, and projects that promise unrealistic returns or rely solely on hype.

8. Address Poisoning Scams

Address poisoning tricks users into sending cryptocurrency to a lookalike wallet address controlled by a scammer. Using specialized software, the attacker repeatedly generates wallet addresses until one closely matches the beginning and ending characters of a legitimate address, then inserts it into the victim's transaction history through a small or zero-value transfer. The wallet itself is not compromised; funds are lost when the victim copies the fake address instead of the legitimate one.

How the scam works

  • The attacker reviews a wallet’s public transaction history and identifies an address it regularly sends funds to.
  • A lookalike address is generated with matching characters at the beginning and end.
  • The attacker sends a small transaction, zero-value transfer, NFT, or fake token so the address appears in the victim’s activity history.
  • The victim later copies the poisoned address instead of the legitimate one and sends funds directly to the attacker.

How to avoid it

  • Never copy a destination address from transaction history.
  • Compare the entire address, not only the first and last characters.
  • Save trusted recipients in an address book or allowlist.
  • Send a small test transaction before making a large transfer.
  • Treat unexpected deposits, NFTs, and zero-value transactions as suspicious, and use wallet warnings when available.

9. Fake Airdrops and NFT Claim Scams

Fake airdrop and NFT claim scams promise free tokens, rewards, or exclusive mints to lure users to malicious websites. The offer may arrive through a social media post, direct message, search ad, compromised project account, or an unsolicited token or NFT sent directly to the victim’s wallet. The site then attempts to steal the user’s recovery phrase or obtain a wallet signature that authorizes asset transfers.

How the scam works

  • The scammer promotes a limited-time airdrop, NFT mint, refund, or loyalty reward.
  • Victims are directed to a cloned project website and asked to connect their wallet.
  • The claim process requests a malicious token approval, NFT permission, or signature whose real effect is difficult to recognize.
  • Once approved, a wallet drainer transfers the authorized tokens or NFTs. Some sites instead ask users to enter their seed phrase.
  • Unsolicited NFTs may include a website address in their image or description to lead recipients to the phishing page.

How to avoid it

  • Confirm airdrops and mints through the project’s official website and independently verified social accounts.
  • Do not follow links or QR codes contained in unsolicited tokens, NFTs, direct messages, or replies.
  • Never enter a seed phrase to claim an airdrop or NFT.
  • Review every signature and approval request, including the assets and spending permissions involved.
  • Use a separate wallet with limited funds for new mints and claims, and hide or report unsolicited NFTs instead of interacting with them.

10. Fake Crypto Presale Scams

Fake crypto presales offer early access to a new token at a discounted price but provide little or nothing of value in return. Scammers create polished websites, whitepapers, staged fundraising counters, and social media campaigns to make the sale appear legitimate. They may invent team members, audits, partnerships, or planned exchange listings before disappearing with buyers’ funds, issuing a worthless token, or using the claim process to drain connected wallets. MetaMask also warns that scammers clone genuine presale websites and substitute their own payment address.

How the scam works

  • The project is promoted through search ads, social media, influencers, messaging groups, or paid articles.
  • Buyers are offered lower prices, bonuses, or limited presale stages designed to create urgency.
  • Payments are sent to a project wallet or made after connecting a wallet to the presale website.
  • The team may fabricate fundraising totals, audits, partnerships, endorsements, or exchange-listing agreements.
  • The token is never delivered, cannot be claimed or sold, collapses after launch, or requires a malicious signature that gives a wallet drainer access to the buyer’s assets.

How to avoid it

  • Verify the presale through the project’s official channels and check that the website address and payment contract match.
  • Confirm audits, partnerships, and planned listings directly with the companies named rather than relying on project announcements.
  • Research the team, token allocation, vesting schedule, contract permissions, and intended use of presale funds.
  • Treat countdown timers, guaranteed returns, rapidly increasing prices, and pressure to buy before the next stage as warning signs.
  • Do not connect a wallet holding valuable assets to an unfamiliar presale site, and never enter a seed phrase to buy or claim tokens.

11. AI Deepfake Scams

AI deepfake scams use artificial intelligence to generate realistic videos, voice recordings, or images that imitate crypto founders, company executives, celebrities, family members, or friends. Scammers use this fabricated content to promote fake investments, giveaways, token sales, or urgent payment requests. Deepfakes are usually part of a broader impersonation scam rather than a separate method of stealing cryptocurrency.

How the scam works

  • Scammers publish fake videos or livestreams showing a recognizable person promoting an investment, giveaway, or token.
  • AI-generated voices may be used in phone calls, voice notes, or video meetings to impersonate executives, colleagues, friends, or relatives.
  • Victims are directed to a fake trading platform, presale page, wallet-connection site, or cryptocurrency payment address.
  • Some campaigns use AI-generated profiles and personalized messages over time before introducing the fraudulent investment.
  • Any profits, account balances, endorsements, or live interactions shown to the victim may be fabricated.

How to avoid it

  • Verify investment claims through the person’s or company’s official website and independently confirmed accounts.
  • Do not trust a video, livestream, or voice call as proof of identity.
  • Contact the person through a separate, previously verified channel before sending cryptocurrency or sharing sensitive information.
  • Ignore giveaways or investments that require an upfront crypto payment to receive larger returns.
  • Look for altered lip movement, unnatural speech, visual glitches, or inconsistent details, but do not rely on these signs alone because high-quality deepfakes may appear convincing.

12. Giveaway and Impersonation Scams

Giveaway and impersonation scams use the identity of a crypto company, founder, celebrity, investor, or government agency to promote a fraudulent reward or request. Scammers may copy verified profiles, hijack genuine accounts, spoof phone numbers, or create fake livestreams and websites. Victims are then told to send cryptocurrency to verify their wallet, unlock a prize, or receive a larger payment in return.

How the scam works

  • A fake or compromised account announces a token giveaway, promotion, reimbursement, or investment opportunity.
  • Forged screenshots, copied branding, fake comments, and coordinated accounts make the offer appear genuine.
  • Victims are asked to send crypto to a wallet address, connect their wallet to a claim page, or provide login and security information.
  • Once cryptocurrency is sent, no reward is issued. A connected wallet may instead be exposed to phishing or a wallet drainer.

How to avoid it

  • Never send cryptocurrency to verify an address or receive a larger amount in return.
  • Confirm promotions through the company’s official website and independently verified accounts.
  • Do not rely on profile photos, verification badges, caller ID, livestreams, screenshots, or supportive comments as proof of identity.
  • Check the username, website address, account history, and announcement channels carefully.
  • Ignore urgent giveaways that require an upfront payment, wallet connection, seed phrase, or one-time security code.

What to Do If You Get Scammed

Act as soon as you discover a crypto scam. Confirmed blockchain transactions are generally irreversible, but a rapid response may protect remaining assets and give exchanges or investigators a better chance of tracing the funds.

  • Stop all contact and payments. Do not send additional cryptocurrency for withdrawal fees, taxes, account verification, or fund recovery.
  • Secure a compromised wallet. Revoke malicious token approvals and transfer remaining assets to a new wallet. Disconnecting a wallet from a website alone does not cancel existing approvals.
  • Abandon the wallet if its recovery phrase or private key was exposed. Create a new wallet on a trusted, malware-free device and move any assets that remain. Do not reuse the compromised recovery phrase.
  • Lock affected exchange accounts. Contact the exchange through its official website or app, change your password, end unfamiliar sessions, and reset two-factor authentication. Ask the exchange to flag the recipient account or address; it may be able to freeze funds that have not yet been withdrawn.
  • Secure related accounts and devices. Change the password for the connected email account, check for unknown forwarding rules, contact your mobile carrier if SIM swapping is possible, and scan devices for malware or remote-access software. Notify your bank or card provider if financial details were shared.
  • Preserve evidence. Save transaction hashes, wallet addresses, payment receipts, website addresses, emails, messages, phone numbers, account names, screenshots, and a written timeline of events. Do not delete conversations or reset devices before preserving relevant records.
  • Report the incident. Notify the exchange, wallet provider, social platform, or website involved and file a report with the appropriate police, cybercrime, financial, or consumer-protection authority in your country. U.S. victims can report cryptocurrency fraud to the FBI’s Internet Crime Complaint Center, the FTC, the CFTC, or the SEC.
  • Watch for recovery scams. Scammers may impersonate investigators, lawyers, blockchain analysts, or government agencies and claim they can retrieve the funds for an upfront fee. No legitimate service can guarantee the recovery of stolen cryptocurrency.

Reporting quickly does not guarantee recovery, but transaction records and recipient addresses can help exchanges and law-enforcement agencies trace funds, connect related cases, and identify accounts that may still hold the stolen assets.