Avoiding Crypto Scams
Crypto scams work because the technology is genuinely confusing and the stakes are high. When someone does not fully understand how a wallet or a token works, bad actors have room to operate — and they exploit that room ruthlessly. Unlike a fraudulent bank charge, a crypto transa
Avoiding Crypto Scams
Crypto scams work because the technology is genuinely confusing and the stakes are high. When someone does not fully understand how a wallet or a token works, bad actors have room to operate — and they exploit that room ruthlessly. Unlike a fraudulent bank charge, a crypto transaction that sends your funds to a scammer cannot be reversed. There is no dispute process, no chargeback, no customer service line. What leaves your wallet is gone.
The good news is that almost every common scam follows a recognizable pattern. Once you know what those patterns look like, you can spot them before any damage is done. This guide walks through the most frequent scams targeting crypto users, explains exactly how each one works, and tells you what to do — and what never to do.
How Phishing Attacks Work
Phishing is the practice of impersonating a trusted source to steal your credentials or private keys. In crypto, this usually targets your wallet's seed phrase (the 12 or 24 words that can fully restore your wallet and give complete access to your funds).
The attack arrives through many channels: a fake email from "MetaMask Support," a Google ad that looks identical to a real exchange but leads to a cloned website, a Discord message from someone pretending to be a project moderator, or a pop-up inside a browser extension. The message typically creates urgency — your wallet is at risk, your account will be suspended, you must verify immediately.
The request always leads to the same place: a form asking for your seed phrase, or a fake wallet connection that requests unlimited spending approval (a permission that lets a smart contract move any of your tokens without further confirmation).
What to do instead:
- Never type your seed phrase anywhere except into the physical device or official software you use to restore a wallet from scratch. No website, support agent, or automated tool should ever ask for it.
- Before connecting your wallet to any site, triple-check the URL. Bookmark legitimate sites and navigate from the bookmark, not from search results or links in messages.
- In your wallet, review token approvals regularly and revoke any you do not recognize. Tools built into block explorers let you see and cancel these permissions.
Rug Pulls: When the Project Disappears
A rug pull occurs when the creators of a crypto project — usually a new token or a decentralized finance (DeFi) protocol — abandon it and take the funds that users deposited. DeFi refers to financial applications built on blockchains that operate without a central company running them, typically through smart contracts.
Rug pulls follow a familiar script. A team launches a token with professional branding, a white paper (a document explaining the project's goals and mechanics), and a social media presence. They generate excitement, often paying for promotion. Early buyers see the price rise as more people join. Then the team either withdraws the liquidity (the pool of funds that allows the token to be traded), sells their enormous pre-allocated holdings all at once, or simply stops developing the project and goes silent. The token price collapses to near zero.
Some rug pulls are obvious in retrospect but feel legitimate in the moment. Red flags to watch for:
- Anonymous teams with no verifiable history. Pseudonymity is common in crypto, but legitimate projects usually have at least some members with traceable professional backgrounds or prior work you can inspect.
- No audit. A smart contract audit is an independent technical review of a protocol's code. The absence of one from a reputable firm is a serious warning sign, though an audit alone does not guarantee safety.
- Locked vs. unlocked liquidity. If the team controls the liquidity and has not locked it through a time-lock contract (code that prevents withdrawal for a set period), they can drain it at any moment.
- Promises that sound disconnected from any real mechanism. "Guaranteed 1,000% APY" with no explanation of where the yield comes from is a promise no honest project can make.
Fake Airdrops and Free Token Traps
An airdrop is when a project distributes free tokens to wallet addresses, usually to build an audience or reward early users. Fake airdrops mimic this to do the opposite: drain your wallet.
You receive a message — through email, Twitter, Telegram, or simply by finding tokens appear in your wallet that you never requested — telling you that you have unclaimed tokens. To claim them, you must visit a website and connect your wallet. The site then asks you to sign a transaction. What you are actually signing is a malicious approval that gives the attacker permission to transfer your assets. You receive nothing of value. Your real holdings disappear.
The most insidious version of this is the "dust attack," where tiny amounts of a token are sent to your wallet address. The tokens themselves may be worthless, but they are designed to lure you to a phishing site when you try to find out what they are.
The rule is simple: do not interact with tokens you did not choose to receive. Do not visit the websites they advertise. Do not try to swap them. Many wallets let you hide unknown tokens; use that feature.
Investment Scams and Impersonation
These range from "pig butchering" schemes — where a scammer builds a relationship with you over weeks before steering you toward a fake investment platform — to celebrity impersonation scams where a verified-looking account promises to double any crypto you send to a given address. The doubling never happens.
No legitimate investment ever requires you to send funds to a stranger's wallet as a prerequisite to receiving more back. No celebrity is running a giveaway this way. No exchange will send you extra crypto for depositing. These are structurally impossible honest offers.
Risks and Common Mistakes
Trusting urgency. Scammers manufacture time pressure precisely because careful thinking is their enemy. A real protocol does not need you to act within ten minutes. Slow down.
Assuming a verified social media account is safe. Accounts get hacked, and verification badges can be faked or purchased. Always verify announcements through multiple official channels before acting.
Keeping funds on exchanges longer than necessary. An exchange holds your crypto in its own wallets, meaning you do not control the private keys. If the exchange is hacked or becomes insolvent, your funds are at risk. Storing meaningful amounts in a self-custody wallet — where you hold your own seed phrase — reduces this exposure significantly.
Skipping research because of social proof. A large follower count, an enthusiastic Telegram community, or a celebrity endorsement is not due diligence. Many of these signals are purchased or manufactured. Read the actual code if you can, or find independent technical analysis before putting real money in.
Reusing seed phrases or storing them digitally. Your seed phrase written in a notes app or email is one data breach away from being stolen. Write it on paper, store it securely offline, and never photograph it.
For a deeper foundation in wallet security and how self-custody works, the BCA Academy has structured courses that build this knowledge systematically.
Frequently Asked Questions
How Do I Know If a Crypto Website Is Legitimate?
Check the exact URL character by character against the official domain you find through the project's verified social channels, not through search results. Look for the padlock icon (HTTPS), but know that scam sites can have it too. When in doubt, navigate to the site from a bookmark you set yourself on a previous safe visit.
Can I Get My Money Back If I Am Scammed?
In almost all cases, no. Blockchain transactions are irreversible by design. You can report the scam to relevant authorities and to the platform where you encountered the scammer, but recovering funds is rare. This is why prevention is the only reliable strategy.
What Is the Safest Way to Store Crypto?
A hardware wallet (a physical device that keeps your private keys offline and requires physical confirmation of transactions) is the most secure option for significant holdings. At minimum, use a non-custodial software wallet where you control your own seed phrase rather than keeping funds on an exchange indefinitely.
Are All Airdrops Dangerous?
No. Airdrops from projects you actively use and have registered for are generally legitimate. The risk comes from unsolicited tokens or messages telling you that you have something to claim when you never signed up for anything. If an airdrop requires you to connect your wallet and approve a transaction to claim it, treat that as a red flag and verify carefully before proceeding.