watifsol.xyz

Types of crypto scam

Every week, people lose millions of dollars in cryptocurrency to scams. The mechanisms vary widely - from fake emails that steal login credentials to sophisticated smart contract exploits that drain wallets in a single transaction - but the patterns repeat. Understanding how each type of scam actually works is the only reliable defense. This page catalogues the major scam mechanics so you can recognize one in progress, whether you are checking a token on Uniswap, responding to a message on Discord, or reviewing a transaction in MetaMask.

Wallet and credential theft

The most direct scams aim to steal your private keys, seed phrase, or wallet access. These attacks exploit trust in familiar platforms and urgency in communication.

Phishing link delivery via email or DM is the entry point for many losses. A message that appears to come from MetaMask, OpenSea, or CoinMarketCap asks you to "verify your account" or "claim an airdrop." The link leads to a page that looks identical to the real site but captures everything you type. The page How to Spot a Crypto Phishing Link in Emails and DMs walks through the specific telltales - mismatched domains, generic greetings, and the pressure to act immediately.

Seed phrase solicitation by impersonation targets the one thing that should never be shared. A scammer poses as wallet support on Discord, Telegram, or X/Twitter and claims they need your seed phrase to "fix a problem" or "recover funds." The rule is absolute: no legitimate service ever asks for your seed phrase. The spoke page Seed Phrase Solicitation by Impersonation Scams explains the common impersonation scripts and the single rule that prevents all of them.

Fake customer support DM on Discord or Telegram follows the same logic. After you post a question in a project's public channel, a scammer DMs you pretending to be an admin. They direct you to a fake support site or ask for remote access to your computer. The pattern is consistent: legitimate support teams do not initiate DMs with unsolicited help.

SIM swap intercepting two-factor authentication bypasses SMS-based security on exchanges. A scammer convinces your mobile carrier to transfer your phone number to a SIM they control. Now all SMS-based 2FA codes arrive on their device. The page SIM Swap Attack Bypassing Crypto Two-Factor Authentication details the carrier social engineering and explains why an authenticator app or hardware security key prevents this attack entirely.

Clipboard hijacking replacing copied wallet addresses is a malware technique that monitors your clipboard. When you copy a wallet address to send funds, the malware replaces it with the scammer's address. You paste, you verify the first few and last few characters, you send - and the funds go to the scammer. The spoke page Clipboard Hijacking Replacing Your Copied Crypto Wallet Address describes the verification step that catches this every time.

Address poisoning tainting your transaction history does not steal from you immediately. A scammer sends a tiny amount of crypto - often 0.000001 ETH - from an address that looks similar to one you have used before. That address now appears in your wallet's transaction history. Later, when you copy an address from your own history, you may accidentally copy the poisoned lookalike. The page Address Poisoning Scam Tainting Your Crypto Transaction History shows how scammers generate these addresses and how to avoid copying them.

Token and defi scams

The second major category involves malicious smart contracts and token designs that manipulate what you see, what you can trade, and what approvals you have granted.

Fake token approvals draining wallets is the mechanism behind most DeFi wallet drains. You connect your wallet to a dApp, and the site asks you to sign a transaction that sets approval for the scammer's contract to spend your tokens. Once signed, the scammer can transfer any amount of that token from your wallet. The spoke page Fake Token Approvals That Drain Your Crypto Wallet explains exactly what the permit or approve function does, how to recognize the signature request, and how tools like Revoke.cash let you check and revoke active approvals.

Counterfeit token ticker impersonation on DEX causes confusion on Uniswap, PancakeSwap, and Jupiter. A scammer deploys a token with the same ticker and name as a legitimate project but with a different contract address. Unsuspecting buyers swap for the fake, which may be a honeypot or have an infinite mint function. The page Counterfeit Token Ticker Impersonation on Uniswap and DEXs shows how to verify contract addresses on Etherscan, BscScan, or CoinGecko before trading.

Honeypot token with un-sellable contract lets you buy but not sell. The contract includes a condition - often a whitelist, a minimum token balance, or a function that reverts for all but the deployer - that blocks sells. You are left holding a token with no exit. The spoke page Honeypot Token Scam With an Unsellable Smart Contract explains how to check for the trap using Honeypot.is, Token Sniffer, and by simulating a sell transaction with a tool like Pocket Universe.

Rug pull liquidity removal by devs is the classic DeFi scam. The developers create a token, pair it with ETH or BNB on a DEX, and lock some liquidity to inspire confidence. Then they call a function that removes the liquidity pool entirely, leaving token holders with worthless assets. The page Rug Pull Scams and Liquidity Removal Explained describes the on-chain signals - liquidity lock duration, contract ownership not renounced, and sudden large transfers from the deployer address.

Fake staking rewards displayed in dApp UI tricks you into depositing real tokens for a return that never materializes. The dApp shows a balance of "rewards" that grows over time, but when you try to withdraw, the transaction fails or the site disappears. The interface is the product; the actual smart contract either lacks a withdraw function or routes deposits to the scammer.

Fake airdrop claim contract interaction baits you with the promise of free tokens. You visit a site claiming to distribute an airdrop for a project you hold. To "claim," you must connect your wallet and approve a transaction. That approval drains eligible tokens from your wallet instead. The rule: if an airdrop requires you to pay gas to claim, verify through the project's official channels first.

Fake NFT mint site draining on connect works identically. The site shows an upcoming NFT collection with low mint prices. You connect your wallet, sign a "set approval for all" transaction (visible on OpenSea-style signature requests), and the scammer immediately transfers your existing NFTs. The spoke page Fake NFT Mint Sites That Drain Your Wallet on Connection shows what a legitimate mint signature request looks like versus a malicious one.

Ice phishing prompting blind transaction signing is a more subtle variant. The scammer creates a legitimate-looking transaction request but hides the actual function call. If you use a hardware wallet and blindly confirm without reviewing the transaction data, you may approve a token transfer or a contract interaction you did not intend. Hardware wallets with transaction preview - like the Ledger with Ethereum contracts - can reveal what you are actually signing.

Market manipulation and social engineering

These scams do not exploit smart contract bugs. They exploit psychology, coordination, and the illusion of legitimacy.

Pump and dump coordinated price inflation happens when a group artificially drives up a token's price through coordinated buying, social media hype, and fake volume. The organizers sell at the peak, leaving late buyers with losses. The page Pump and Dump Crypto Scams and Coordinated Price Inflation details the signals: sudden chart spikes on low-liquidity tokens, coordinated posts from anonymous accounts, and volume that comes from a small number of wallets.

Pig butchering long-con romance grooming is the most financially destructive scam in crypto. A scammer builds a romantic relationship over weeks or months, then introduces a "trading opportunity" or "investment platform." They encourage the victim to deposit increasing amounts, often showing fake profits in a UI the scammer controls. When the victim tries to withdraw, the platform demands fees or simply disappears. The spoke page Romance Scam Directing to Fake Exchange under this broader topic covers the escalation pattern.

Ponzi structure paying old investors with new money relies on unsustainable mathematics. A platform promises fixed returns from trading, staking, or mining, but in reality it pays earlier depositors with the deposits of newer ones. The returns are not generated by any actual activity. The page Crypto Ponzi Schemes Paying Old Investors With New Money explains how to identify the structure: consistent returns regardless of market conditions, referral bonuses that reward recruitment, and withdrawal delays that increase over time.

Fake mining pool requiring upfront deposit promises daily returns from crypto mining. You pay a "setup fee" or "first deposit" to start earning. The dashboard shows accumulating rewards, but withdrawals are blocked by a "minimum threshold" or "maintenance fee." The mining never happens; the deposit is the scam.

Celebrity deepfake video endorsement scam uses AI-generated video of Elon Musk, Vitalik Buterin, or other figures to promote a fake token or exchange. The video appears live or recently recorded. The scam runs on YouTube streams, Telegram channels, and social media. No celebrity endorses random crypto projects. The page Celebrity Deepfake Video Endorsement Scam under the broader topic of social engineering scams covers detection.

Fake job offer requiring crypto deposit targets job seekers. A "recruiter" offers a remote crypto-related position, then requires a deposit for "training," "background check," or "wallet setup." Once paid, the recruiter disappears. The spoke page Fake Crypto Job Offers Requiring an Upfront Deposit explains why legitimate employers never ask employees to deposit cryptocurrency.

Recovery scam targeting prior victims for fee is a second scam layered on the first. After losing funds, a victim searches for recovery services. A "hacker," "funds recovery expert," or "law firm" claims they can retrieve the stolen crypto for an upfront fee. They cannot. The page Recovery Scams Targeting Previous Crypto Scam Victims explains why on-chain recovery is not possible without the scammer's cooperation and why paying any fee for recovery is always a second loss.

Exit scam exchange or platform shutdown occurs when a centralized platform stops allowing withdrawals and disappears with user funds. The warning signs include sudden changes to withdrawal policies, vague announcements about "maintenance," and the departure of key team members. The spoke page Exit Scam Exchange and Platform Shutdown Warning Signs lists the behavioral patterns that precede a shutdown.

Technical exploits and infrastructure attacks

These attacks target the blockchain's mechanics, the infrastructure that connects users to dApps, and the tools people use to interact with crypto.

Smart contract allowlist bypass exploits find ways around contract protections. A project may use an allowlist to restrict who can trade or mint, but a flaw in the allowlist logic - or the use of a public allowlist - lets scammers bypass it. These are less common but catastrophic when they occur.

Flash loan price oracle manipulation attacks use uncollateralized loans that must be repaid in one transaction. A scammer borrows a large amount, swaps it on a DEX to manipulate the token price, then uses that manipulated price to trigger a liquidation or collateral valuation in a lending protocol. The price oracle did not update in time. These attacks do not target individual users directly but can drain liquidity pools that users hold.

MEV sandwich attack front-running trades happens when a bot or validator sees your pending transaction, places a buy order before it and a sell order after it, capturing the price difference. You get a worse execution price. This is not a scam in the legal sense but is a form of value extraction that mainly affects large swaps on low-liquidity pairs.

Governance attack via flash-loaned voting power uses flash loans to temporarily acquire enough tokens to vote on a governance proposal. The attacker passes a proposal that drains the treasury. This requires a large capital base and specific protocol vulnerabilities, but it has happened to major DeFi projects.

DNS hijacking redirecting legitimate dApp frontend takes over the domain registration of a popular dApp like Uniswap or PancakeSwap. Users who type the correct URL land on a phishing clone that asks them to connect their wallet and sign a malicious transaction. The spoke page DNS Hijacking Redirecting Legitimate Crypto dApp Frontends explains how to verify you are on the real site by checking the contract address directly on Etherscan rather than trusting the frontend.

Dusting attack deanonymizing wallet holder sends tiny amounts of crypto - dust - to thousands of wallets. The scammer analyzes the transaction history of those wallets to identify which ones belong to the same person, then attempts to link wallets to real identities through exchange KYC data. The page Dusting Attack Linking Your Crypto Wallet to Real Identity covers how to handle dust tokens (do not interact with them) and how this attack works in practice.

Telegram bot fake verification gate appears in trading groups. A bot asks you to "verify you are human" by connecting your wallet and signing a message. That message is actually a token approval transaction. The verification is the trap.

WalletConnect session expired phishing popup appears when a fake site displays a popup that mimics a legitimate WalletConnect session expiration, asking you to reconnect. Reconnecting signs a new approval for the scammer's contract.

Recognizing Scams in Progress: Errors, Warnings, and Decisions

Many scams announce themselves through the errors and warnings they generate. Understanding what these messages mean can stop you from completing a harmful transaction.

The page Crypto Scam Error Messages and What They Really Mean catalogues the specific error texts you might encounter during a scam and explains what the scammer's contract is doing to your funds. For example, "Gas estimation failed" on a token you are trying to sell often indicates a honeypot that is blocking the transaction. "This transaction is expected to fail" from MetaMask is a warning that the contract will revert your transaction - a common pattern on malicious approval requests. "TransferFrom failed: insufficient balance" after you have already approved a token means the scammer has already drained it.

The tools listed in the entity inventory - Revoke.cash, Token Sniffer, Honeypot.is, Pocket Universe, Wallet Guard, and ScamSniffer - exist specifically to detect these patterns. They are not optional accessories; they are the basic toolkit for interacting with DeFi. Using a hardware wallet does not make you immune to signing a malicious approval. Using a verified contract address on Etherscan does not mean the contract is safe. Using a DEX does not mean the token has been vetted.

The one rule that covers most scams

Across all these mechanisms, one rule prevents the majority of losses: never sign a transaction or share a seed phrase without knowing exactly what it does. Every scam in the wallet theft category, every token approval drain, every fake airdrop claim, and every phishing site depends on you signing or sharing something you should not. If you are unsure, disconnect, verify through official channels, and use a transaction simulator before signing. The spokes listed above each address a specific variant of this problem. If you recognize yourself in any of them - if you have received a suspicious DM, if you are trying to sell a token that will not sell, if you see a strange address in your transaction history - read the relevant spoke page before you do anything else.

Not financial advice. watifsol.xyz publishes market data and general information about digital assets. Crypto assets are volatile and you can lose everything you put in. Nothing here is a recommendation to buy, sell or hold, and we make no price predictions.

Prices are sourced from third parties and may be delayed or wrong. Verify anything you intend to act on against a primary source.

Back to crypto scams