⚠️ Introduction: The Growing Threat of Crypto Scams
Cryptocurrency offers incredible opportunities — but it also attracts scammers. With over $10 billion lost to crypto scams annually, understanding the threat landscape is essential for anyone using digital assets.
The crypto ecosystem is still relatively new, and many users are unfamiliar with the risks. Scammers exploit this by using increasingly sophisticated tactics to steal funds. The good news is that most scams are preventable with awareness and basic security practices.
This guide covers the 10 most common crypto payment scams and provides actionable steps to avoid them.
Trust, but verify. Scammers rely on trust and urgency. If something seems too good to be true, it probably is. Take your time, verify everything, and never share your private keys.
🔴 The 10 Most Common Crypto Payment Scams
Fake websites, emails, or messages impersonating legitimate platforms to steal your login credentials or private keys. Always verify URLs.
Developers create a seemingly legitimate project, attract investment, then disappear with the funds. Research before investing.
Malicious apps that steal your private keys. Only download from official sources and verify developer credentials.
Attackers send small amounts from a similar-looking address, hoping you'll copy it by mistake for your next transfer.
Counterfeit exchange platforms that steal deposits or credentials. Always verify exchange legitimacy.
Scammers posing as customer support, celebrities, or trusted contacts to gain your trust and steal funds.
Payments to early investors come from new investors' funds, not from profits. Collapses when new investors stop coming.
Scammers promise free tokens but require you to connect your wallet to a malicious site, draining your funds.
Malware that detects crypto addresses in your clipboard and replaces them with the attacker's address.
Malicious contracts that exploit approvals to drain funds. Always verify contract addresses and revoke unused approvals.
☐ "Guaranteed" returns or high-yield promises
☐ Unsolicited messages from "support"
☐ Pressure to act quickly ("limited time")
☐ Requests for private keys or seed phrases
☐ Unverified URLs or app stores
☐ Too-good-to-be-true offers
🎣 Phishing: The #1 Crypto Scam
Phishing is the most common crypto scam, accounting for over 50% of all crypto-related fraud. It involves tricking users into visiting fake websites or clicking malicious links that steal credentials or private keys.
How Phishing Works
- Fake Websites: Scammers create exact replicas of legitimate exchanges or wallet sites (e.g., binance.com vs binance-secure.com).
- Email Phishing: Emails that appear to be from platforms you use, asking you to "verify" your account or "secure" your wallet.
- Social Media Phishing: Fake accounts impersonating support teams, offering "help" with your account.
- DNS Hijacking: Attackers redirect traffic from legitimate sites to fake ones.
How to Avoid Phishing
- Always verify URLs — Check the address bar carefully. Look for "https://" and the correct domain name.
- Use bookmarks — Save trusted sites in your browser bookmarks instead of clicking links from emails.
- Never share private keys — No legitimate service will ever ask for your private key or seed phrase.
- Enable 2FA — Two-factor authentication prevents access even if your password is stolen.
- Check email senders — Verify the email address, not just the display name.
In 2025, a major phishing campaign targeted Trust Wallet users with fake "security alerts" directing them to a malicious site. Users who connected their wallets lost funds immediately. Always verify — never click links in unsolicited messages.
🔄 Rug Pulls & Investment Scams
Rug pulls are scams where developers create a seemingly legitimate crypto project, attract investment, then suddenly withdraw all funds and disappear, leaving investors with worthless tokens.
Signs of a Potential Rug Pull
- Anonymous team — No publicly identifiable team members.
- Unrealistic promises — Guaranteed high returns or "get rich quick" claims.
- Poor or copied code — The smart contract may be copied from another project.
- No audit — No reputable third-party security audit.
- Sudden marketing push — Aggressive marketing to attract quick investment.
- Liquidity not locked — The team can withdraw liquidity at any time.
☐ Research the team (are they real and known?)
☐ Check for third-party security audits
☐ Verify liquidity is locked
☐ Read the whitepaper carefully
☐ Look for red flags in community discussions
☐ Never invest more than you can afford to lose
🎯 Address Poisoning
Address poisoning is one of the fastest-growing crypto scams. Attackers send small amounts (often 0 USDT or a tiny dust amount) to your wallet from an address that looks similar to one you frequently transact with.
How It Works
- You regularly send USDT to a specific address (e.g., your family member's wallet).
- A scammer sends a tiny amount to your wallet from an address with a similar first and last few characters.
- When you go to send funds, you scroll through your transaction history and accidentally copy the poisoned address instead of the real one.
- You send funds to the scammer's address, and they are gone forever.
How to Prevent Address Poisoning
- Check the full address — Don't rely on just the first and last few characters. Compare the full address.
- Use an address book — Save trusted addresses in your wallet's address book to avoid copying from history.
- Send a test transaction — For large amounts, send a small test first and confirm with the recipient.
- Ignore small unknown transactions — If you receive a tiny, unexpected amount, ignore it. Don't use it as a reference.
- Use ENS/UD names — Human-readable names are much harder to spoof.
In most wallets, you can long-press or tap on the address to see the full address. Always verify the full address before sending. A few extra seconds can save you from losing everything.
📱 Fake Wallets & Apps
Scammers create fake wallet apps that look identical to legitimate ones but are designed to steal your private keys or seed phrases. These apps are often distributed through unofficial app stores or phishing links.
How to Avoid Fake Wallets
- Download from official stores — Only use Google Play (Android) or Apple App Store (iOS). Verify the developer name.
- Check reviews — Look at app reviews. Legitimate apps have thousands of reviews; fake ones often have few or suspicious reviews.
- Verify website links — Go to the official website and use the download link there.
- Check developer name — Ensure the developer matches the official company (e.g., "Trust Wallet" vs "TrustWallet_Official").
- Never install APKs from unknown sources — Avoid downloading APK files from websites.
☐ Downloaded from official app store
☐ Verified developer name
☐ Read reviews before installing
☐ Checked official website for links
☐ Never clicked suspicious download links
🚨 What to Do If You've Been Scammed
- Act immediately — Time is critical. Move any remaining funds to a new, secure wallet.
- Revoke token approvals — If you approved a malicious contract, revoke approvals using tools like Revoke.cash.
- Change passwords — Update passwords on all related accounts and enable 2FA if not already active.
- Contact the platform — If the scam involved an exchange or payment platform, contact their support team.
- Report the incident — File a report with local authorities and crypto tracking services.
- Learn and share — Understand how the scam happened to prevent future incidents, and share your experience to help others.
Recovery of stolen crypto is extremely difficult — less than 1-2% of stolen funds are ever recovered. Prevention is your best protection. Take security seriously.