This space is available Advertise with CryptoOverlook → 160 × 600
This space is available Advertise with CryptoOverlook → 160 × 600
This space is available Advertise with CryptoOverlook → 728 × 90

Risk & Psychology

Common Crypto Scams and How They Actually Work

Specific, mechanism-level breakdowns of phishing, fake giveaways, rug pulls, pig butchering, and fake support scams, so you can recognize the pattern rather than just 'be careful.'

Why “just be careful” isn’t enough

Generic warnings don’t help much because these scams aren’t careless mistakes; they’re specifically engineered to look legitimate to a careful person in a hurry, a stressed moment, or a moment of excitement about a good opportunity. Knowing the actual mechanism behind each pattern is a far better defense than a vague sense of caution, because it lets you recognize the shape of an attack before you’re deep enough into it to have already made the mistake.

Phishing: fake login pages and fake wallet-connect prompts

Phishing means being led to a fake version of a real interface, designed to capture either your exchange login credentials or your wallet’s connection approval. Two common forms:

  • Fake exchange login pages, usually reached through a link in a phishing email, a fake ad, or a search result for an exchange’s name that’s actually a paid impersonator ad ranked above the real site. The page looks identical to the real login screen; anything typed there goes straight to the attacker.
  • Fake wallet-connect prompts, common on fake DeFi or NFT sites, where “connecting” your wallet is followed by a signature request that isn’t what it appears to be: instead of a harmless login-style signature, it’s a request to approve the site’s contract to move funds or NFTs out of your wallet, sometimes disguised in transaction data that looks routine to anyone not reading it closely.

The defense that actually works is boring but effective: type exchange URLs directly or use a saved bookmark rather than clicking links or search ads, and read exactly what a wallet signature request is asking for rather than clicking “confirm” out of habit, a point also covered from the DEX side in What DeFi and a DEX Actually Are.

Fake giveaways and impersonation scams

A very well-worn pattern: a social media account impersonating a public figure, a celebrity, or an exchange’s own official account, posting or replying with some version of “send crypto to this address and receive double back.” The accounts often use a real person’s name, photo, and a slightly altered handle, sometimes bought verification badges, and sometimes hijacked real accounts with a large existing follower count, all to look authentic to someone scrolling quickly. No legitimate giveaway, exchange promotion, or public figure asks you to send crypto first in order to receive more back; that specific mechanic (send first, receive double) is close to a universal marker of this scam category, not an unusual detail.

Rug pulls: the mechanism, specifically

A rug pull happens when the team behind a new token or project abandons it and drains the funds backing it, leaving remaining holders with a token that’s suddenly worth close to nothing. The most common version works through a liquidity pool: a new token is paired with a real asset (often ETH or a stablecoin) in a pool on a DEX, and its early price is entirely a function of that pool’s ratio, described in What DeFi and a DEX Actually Are. If the developers hold a large share of both the token supply and control over the liquidity pool itself, they can, at any point, withdraw the real asset side of the pool and leave buyers holding a token with no liquidity to sell into, crashing its price to near zero almost instantly. A newer variant that became more common through 2025 involves memecoins launched with no real project behind them at all, sometimes pumped through coordinated social media hype for a short window before the same liquidity-drain mechanism plays out. Warning signs include: liquidity that isn’t locked or time-locked, a small number of wallets holding a large share of total supply, an anonymous team with no verifiable track record, and pressure to buy quickly before “missing out.”

Pig butchering and romance scams

This is one of the most financially damaging patterns in crypto, and it deserves to be taken seriously rather than treated as an obvious con only careless people fall for. It typically begins with an unsolicited but low-pressure contact: a “wrong number” text, a dating app match, or a LinkedIn connection, followed by weeks or months of consistent, genuinely warm conversation with no ask attached, building real trust and often real emotional connection. Only after that foundation is established does the scammer introduce a crypto investment “opportunity,” usually a platform they claim personal success with. The victim is guided to deposit a small amount first, sees fabricated but convincing profits on a fake dashboard, and is encouraged to deposit more, sometimes over an extended period, before discovering at withdrawal time that the platform and the relationship were never real. Losses attributed to this pattern have run into the billions of dollars annually, and a large share of victims report not realizing they were being scammed until very late in the process, precisely because the emotional relationship was built deliberately and patiently before any financial ask appeared. The clearest, most reliable red flag is the sequence itself: an online-only relationship that gradually and specifically steers toward a crypto investment platform is worth treating with serious skepticism regardless of how genuine the relationship feels, and no legitimate investment opportunity depends on a personal relationship to justify skipping independent research.

Fake support scams

An attacker impersonates official support for an exchange or wallet, reaching out (or responding to a public post asking for help) and offering to resolve an issue, but the “fix” always eventually requires either your seed phrase, remote access to your device, or a “verification” transaction. As covered in Wallets and Custody, no legitimate support agent, from an exchange or a wallet provider, ever needs your seed phrase to help you; there is no genuine troubleshooting step that requires it, because a seed phrase isn’t an account credential a company holds a copy of, it’s the cryptographic key itself. Any contact asking for it, however official it looks or however plausible the stated reason, is a scam by definition, not a judgment call.

A general pattern worth internalizing

Almost every scam on this page shares a structural feature: urgency paired with a request that bypasses your own independent verification, whether that’s “act now before this offer expires,” “verify your wallet immediately or lose access,” or a relationship engineered to make skepticism feel rude. Slowing down and independently verifying (typing a URL directly, calling an exchange through a number from its real website rather than one given to you, asking whether any legitimate process actually requires what’s being asked) defeats a large share of these patterns regardless of how convincing the specific approach is.

Frequently asked questions

If I’ve already sent crypto to a scammer, can it be recovered? Almost never through the blockchain itself; transactions are final and there’s no institution that can reverse one. Law enforcement recovery efforts do exist and have returned some funds in specific cases, but industry-wide recovery rates remain low, generally a small fraction of what’s actually lost each year, so treat the possibility of recovery as unlikely rather than a rescue plan.

Are hardware wallets immune to these scams? A hardware wallet protects your private key from remote theft, but it can’t stop you from approving a malicious transaction or handing over a seed phrase voluntarily; most of the scams on this page work by getting you to authorize the theft yourself, which a hardware wallet doesn’t prevent on its own.

Is it safe to click a link an exchange sends me directly? Treat any unsolicited link with skepticism even if it appears to come from a real exchange, since sender addresses and domains can be spoofed or closely imitated. When in doubt, navigate to the exchange directly through a bookmark or by typing the URL rather than clicking through.

Where can I look up scam-related terms I don’t recognize? The Glossary covers common terms used across this site’s guides.

Risk

Nothing on this page is financial advice, and it is not a complete or current list of every crypto scam pattern; new variations appear regularly. Losses from crypto scams are, in the large majority of cases, permanent and unrecoverable. Do your own research before making any decisions based on this page.

This space is available Advertise with CryptoOverlook → 728 × 90