
How to spot a crypto scam before you lose funds
The recurring patterns behind phishing, fake apps, and impersonation — and how to shut them down
The mental image of a crypto theft — a hooded genius cracking encryption — is almost always wrong. The overwhelming majority of losses are ordinary people, on ordinary days, tricked into approving a transaction or typing their recovery phrase into the wrong box. That's good news, because human tricks repeat. Once you can recognise the handful of patterns scammers reuse, most of them stop working on you.
The one rule that catches the most scams
If you learn nothing else, learn this: no legitimate service ever needs your 12- or 24-word recovery phrase. Not support, not a wallet "validator," not an airdrop, not a migration tool. The phrase is the master key to your entire wallet — anyone who has it can drain everything, instantly and irreversibly, and there's no one to reverse it. We explain the full mechanics in why you should never share your seed phrase.
Anyone asking for those words, in any channel, for any reason, is trying to rob you. Treat the request itself as conclusive proof of a scam and stop there. Almost every seed-phrase theft depends on the victim making an exception "just this once."

Guaranteed returns and "free money"
"Double your ETH." "Risk-free staking at 40%." "Send 1, get 2 back." "You've been selected for an exclusive airdrop." These pitches all lean on the same lie: that someone will hand you value for nothing, or multiply your money with no risk. In real markets, return comes with risk, and nobody gives away free crypto to strangers.
The send-to-receive variant is especially common — you're told that sending coins to an address will return double. It never does; the address is a one-way trip. Whenever a promise of profit arrives with urgency attached, you're looking at the oldest scam pattern there is, dressed in new vocabulary.
Lookalike domains and fake apps
A huge share of thefts begin with you landing somewhere that looks right but isn't. Scammers register domains a single character off — metamask-wallet.app, atexhub-support.com, a capital "I" impersonating a lowercase "l" — and buy the search-ad slot that sits above the real result. Fake wallet apps appear in app stores under familiar names, and fake "support" pages rank for phrases like "wallet help" or "recover funds."
Two habits neutralise almost all of it: bookmark the real sites and reach them only through your bookmarks, and stop clicking search-engine ads for anything crypto-related. When you do land on a URL, read it character by character, and be extra wary of anything that grafts "support," "claim," "wallet," or "airdrop" onto a real brand's name.
Unsolicited "support" and DMs
Genuine support does not slide into your Telegram, Discord, or X messages offering to help — especially not seconds after you post a question in a public channel. Scammers monitor those channels precisely to pounce on confused users. The friendly stranger who contacts you first to "help fix your transaction" is running a script, and it ends with a request for your phrase or a link to a draining site.
The rule of thumb: you reach out to support through official, bookmarked channels — support never reaches out to you. Any inbound offer of help with a wallet or transaction should be treated as hostile by default.
Pressure, urgency, and countdown timers
"Only 10 spots left." "Your account will be frozen in 15 minutes." "Claim now — offer expires." Manufactured urgency is not a coincidence; it's the mechanism. Pressure exists to short-circuit the pause where you'd otherwise notice something is wrong. A legitimate service is perfectly happy for you to take your time, sleep on it, and verify independently. If something is engineered to make you act right now, that engineering is the tell.
Transaction approvals you didn't initiate

Not every theft asks for your phrase. Some ask for your signature. A wallet pop-up requesting approval to spend a token — especially unlimited spending, or on a token you never interacted with — can hand an attacker standing permission to move your funds later. Because you clicked "approve," it feels like your decision, which is exactly what makes it effective.
Slow down on every signing request. Ask what action it is, what it grants and to whom, and whether you actually initiated it. If anything is unexpected or asks for more than the task needs, reject it. And periodically revoke old approvals you no longer use with a reputable approval-checker, so a forgotten permission can't be abused down the line.
Deposits you can't withdraw
A whole category of scams — often called "pig butchering" — builds trust slowly. A platform (or a persuasive new online friend) shows your balance climbing with impressive "profits." Then, when you try to withdraw, the money is stuck: you're told to pay a "tax," a "fee," or a "verification deposit" first. Each payment unlocks another demand. The growing balance was always fictional, and the withdrawal was never going to happen. If a platform blocks withdrawals or charges a fee to release your own funds, it's an exit scam.
Common mistakes that let scams land
- Making a "just this once" exception to the never-share-your-phrase rule under pressure.
- Clicking the top search result for a wallet or exchange instead of a saved bookmark — the top slot is often a paid phishing ad.
- Trusting a green padlock or professional design as proof of legitimacy. Scam sites have valid certificates and polished branding too.
- Using your main wallet everywhere. Connecting large holdings to every new site maximises what a single bad approval can cost. Keep a low-balance "clean" wallet for anything unproven.
- Acting while rushed or emotional. Nearly every successful scam depends on the victim not pausing. The pause is the defence.
Quick answers
Can someone drain my wallet if they only have my public address? No. Your address is safe to share to receive funds. Theft requires your recovery phrase or your signature on a transaction — never the address alone.
A "support agent" messaged me offering to fix a stuck transaction. Legit? No. Real support never messages you first. Assume any inbound offer of wallet help is a scam and disengage.
How do I know a swap or wallet site is the real one? Reach it through a bookmark you saved earlier, not a search ad or a link someone sent you, and read the URL character by character. When in doubt, don't connect.
I sent crypto to a scam address — can I get it back? On-chain transfers are final; there's no reversal. This is precisely why verifying addresses and refusing pressure before you send matters so much.
The takeaway
Crypto scams aren't clever technically — they're clever psychologically, and they recycle the same moves: a request for your phrase, a promise of free money, a lookalike site, an unsolicited helper, a ticking clock, a surprise approval, a withdrawal you can't make. Learn the shapes and they lose their power. Keep your recovery phrase offline and never typed, verify every address, revoke stale approvals, and treat urgency as a warning rather than a reason. When you use non-custodial tools like the swap page, your funds move directly between chains with no account for anyone to hold hostage — removing an entire category of risk. If something feels rushed, it almost certainly is; slowing down is the whole defence.