Crypto scams usually exploit authority, urgency, romance, greed, or confusion before they exploit software. The payment then becomes difficult to reverse. A useful defense recognizes the requested action: reveal a secret, install remote-control software, send crypto, connect a wallet, or approve token spending.
CryptoStart is supported by display advertising. Ads do not select threats or products in this guide. If funds or credentials are at immediate risk, use independently verified provider and law-enforcement channels.
Phishing: the copied doorway
A phishing message may claim that an exchange account is locked, a wallet needs an urgent upgrade, or a transaction requires verification. The link opens a copied login or wallet page. The FTC advises checking unexpected messages through a known website or phone number rather than using the supplied link.
Navigate through a bookmark or manually verified app. Check the entire domain, not the logo. Password managers can help because they will not automatically fill credentials on an unrelated domain, though users should still inspect the page. A request for a recovery phrase or private key is decisive evidence to stop: those secrets grant wallet control.
Fake support: the helpful intruder
Fake agents appear in search ads, social replies, direct messages, and unsolicited calls. They may ask the user to install screen-sharing software, read a one-time code, “synchronize” a wallet, or transfer funds to safety. Ethereum.org states that there is no official Ethereum support contacting users and that legitimate services do not need recovery phrases.
Close the conversation. Open the provider’s bookmarked support page on a clean device. Never call a number from a pop-up. A real support process can use a transaction hash or account case number; it cannot require the keys to a self-custody wallet.
Investment and relationship scams
The FTC warns that crypto investment fraud often starts through social media or dating apps. The scammer builds trust, displays fabricated profits on a convincing site, and allows or simulates a small withdrawal. Larger deposits later become locked behind invented taxes or fees.
- Guaranteed profit or a low-risk high return is a stop signal.
- An online contact who dictates a platform, wallet, or transaction should not control the process.
- A balance displayed on a private website is not proof that assets exist.
- Paying an extra “release,” “tax,” or “verification” charge rarely recovers the first transfer.
Approval traps
On smart-contract networks, a malicious site may request permission to spend tokens. The wallet prompt might say Approve rather than Send. An unlimited allowance can let a contract transfer more than the immediate amount later. Ethereum security guidance recommends limiting contract spending to the amount required.
Read the action, contract, asset, amount, network, and estimated fee. If the wallet cannot explain the request, reject it. Disconnecting a website from the wallet interface does not necessarily cancel an on-chain token allowance. Review and revoke permissions through a trusted ecosystem tool, understanding that revocation itself can require a network fee.
Address and clipboard substitution
Malware can replace a copied address. Address poisoning can place a lookalike transaction in history so a user later copies the attacker’s address. Compare multiple characters at the beginning and end, preferably the full address, on a second trusted display. Use a small test and a carefully configured allowlist.
Do not copy a destination from transaction history merely because it resembles a familiar one. Label trusted addresses after an independently verified first transfer.
Token and stablecoin impersonation
Names and ticker symbols are easy to copy. A wallet can display a worthless token that uses a familiar symbol. Confirm the contract address through the issuer’s official documentation and match the network. An unsolicited token may carry a link in its name; ignore it rather than visiting or attempting to sell it.
Fake stablecoins often borrow the appearance of a known issuer. A price shown on an obscure exchange is not proof of redeemability or reserves.
Recovery scams
After a theft, another scammer may promise to recover funds for an upfront crypto payment, wallet connection, or phrase. The FTC warns that legitimate organizations do not contact victims out of the blue to return exchange losses. Public blockchains can trace movement, but tracing does not give a private person authority to reverse transfers.
Stop-and-check table
| Request | Immediate response | Safe verification |
|---|---|---|
| Share seed phrase/private key | Refuse and close | No legitimate counterparty needs it |
| Send funds to “protect” them | Do not send | Contact institution independently |
| Install remote access | Decline | Use official support without screen control |
| Approve unlimited token spend | Reject | Identify contract and set exact allowance |
| Pay fee to recover stolen crypto | Do not pay | Report through official channels |
If credentials were exposed
From a clean device, secure the email account and exchange password, revoke active sessions, strengthen multi-factor authentication, and activate withdrawal locks. Contact the exchange through its official site. If a self-custody recovery phrase was exposed, assume the wallet is compromised; create a new wallet securely and move remaining assets only after checking for malicious approvals and fees. Never reuse the old phrase.
If a suspicious approval was signed, review allowances and transfer remaining assets with care. Preserve messages, domains, addresses, transaction hashes, receipts, and timestamps. Report fraud to the platform and relevant authorities; in the United States, the FTC points users to ReportFraud, the FBI’s IC3, the CFTC, and the SEC as applicable.
The durable rule
Pressure shortens verification. A safe process slows it down: leave the message, navigate independently, identify the exact requested blockchain action, and ask whether the counterparty needs authority it should never possess. Security tools help, but a deliberate refusal to reveal secrets or send under pressure blocks the widest range of scams.