We use technologies like cookies to store and/or access device information. We do this to improve browsing experience and to show (non-) personalized ads. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Техническое хранение или доступ необходимы для законной цели хранения предпочтений, которые не запрошены подписчиком или пользователем.
The technical storage or access that is used exclusively for statistical purposes.
Техническое хранилище или доступ, который используется исключительно для анонимных статистических целей. Без повестки в суд, добровольного согласия со стороны вашего интернет-провайдера или дополнительных записей от третьей стороны информация, хранящаяся или полученная только для этой цели, обычно не может быть использована для вашей идентификации.
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
How to Avoid Crypto Scams: 10 Fraud Schemes That Work in 2026
From “trust, but verify” to “do not trust — verify”.
$14 billion. That is how much crypto scammers received in 2025 according to confirmed on-chain data from Chainalysis. The real figure is higher: analysts expect the total to exceed $17 billion as new wallets that were not previously flagged as fraudulent continue to be identified each year. For comparison, the revised estimate for 2024 reached approximately $12 billion.
The average amount sent by a single victim in one payment increased from $782 to $2,764 — roughly 3.5 times higher in one year. Scammers have become more precise: fewer mass messages sent at random, more targeted attacks aimed at specific people with specific balances.
Below are 10 schemes we see most often, along with practical rules on how to avoid crypto scams in 2026. Only the scams that are working right now, with real cases and practical recommendations.
1. Pig butchering: the “long fattening” scam
By total losses, this is one of the most expensive fraud schemes of 2025–2026. Both law-enforcement agencies and analysts rank it among the main categories of investment fraud. The name comes from Chinese scammer slang: the victim is “fattened up” before the money is taken. A person is groomed for weeks or months, an emotional connection is built, and only then are investments introduced.
How it works
A stranger contacts you through Telegram, WhatsApp, Instagram, or a dating platform. They may present themselves as an investor, entrepreneur, or simply an interesting person. During the first few weeks, there is no mention of money: just normal conversation, questions about your life, photo exchanges, and sometimes video calls using a deepfake or a real person following a script.
The investment topic appears gradually and casually. “I made good money on one platform,” or “look, it works.” You are directed to a website that looks like a professional exchange: charts, orders, and 24/7 support. You deposit a small amount, see apparent “growth,” and add more. When you try to withdraw, new barriers appear: a “profit tax,” an “unlocking fee,” or “identity verification.” Every new requirement is another payment to the scammers.
Scale
In February 2026, the U.S. Scam Center Strike Force reported that the volume of cryptocurrency frozen, seized, and forfeited in connection with scam centers in Southeast Asia had exceeded $580 million. According to the U.S. Department of Justice, such centers use investment and confidence schemes to extract money from victims, while workers inside the compounds are often victims of human trafficking themselves.
This is a separate and disturbing side of the scheme. Many pig-butchering operators are not voluntary scammers. People from Cambodia, Myanmar, Laos, and other Southeast Asian countries are lured with job offers, have their documents taken away, and are forced to work in scam centers. There are victims on both sides: the people targeted and the people made to carry out the scams.
How to recognize it
2. Address poisoning: contaminating transaction history
One of the most technical attacks on this list is also one of the easiest to fall for: all it takes is copying an address from the wrong place. The scheme works on any blockchain with long addresses. Historically, Tron with USDT-TRC20 was one of the main targets because tiny dust transfers cost almost nothing. After the Ethereum Fusaka upgrade in December 2025, mass attacks also became significantly more profitable on Ethereum: fees dropped sharply, making microtransactions cheaper to send at scale.
How it works
A bot constantly monitors the blockchain and identifies addresses to which you regularly send funds. It then generates a so-called vanity address — a lookalike address whose first and last characters match the original. Wallets and blockchain explorers typically display those characters while hiding the middle behind an ellipsis.
The bot then sends a microtransaction from the fake address to your wallet. It appears in the history and looks like an ordinary transfer from the “correct” address. The next time you need to send funds to the same recipient, you copy the address from your history — and the money goes to the scammer. Irreversibly.
Why Fusaka made mass attacks more profitable
Before the upgrade, sending dust transfers at scale was less profitable because fees consumed the economics of the attack. After Fusaka, gas became roughly six times cheaper. According to research by Andrey Sergeenkov, the average number of dust transactions increased from around 30,000 to 167,000 per day, with a peak of approximately 510,000 transactions in a single day in January 2026.
During the 73 days after the upgrade, confirmed losses reached around $63.3 million — 13 times higher than during a comparable period before Fusaka. A single $50 million transaction accounted for a significant share of that amount, but even without it, losses increased by approximately 2.7 times.
Real cases
In December 2025, a trader lost almost $50 million in USDT due to a poisoned address. The worst part is that the trader first made a small test transfer, then copied the address from the transaction history again and sent the main payment there. The funds were quickly converted and began moving through Tornado Cash. In March 2026, a crypto influencer known as sillytuna lost around $24 million in a similar incident after copying a lookalike address from the transaction history.
3. Deepfakes and AI-powered fraud
According to Chainalysis, AI-powered scams were approximately 4.5 times more profitable than traditional schemes in 2025. What previously required a team of designers, copywriters, and actors can now be done by one person with a laptop.
Deepfake videos
The most common scenario is a video using the face and voice of a well-known person: Vitalik Buterin, Binance founder CZ, Elon Musk, or a local influencer. The video promotes a fake airdrop, an investment platform, or the classic crypto “doubling” scam: send 1 ETH and receive 2 ETH back. Deepfake quality is now good enough that many viewers will not notice the forgery in a short 30–60 second clip.
Voice cloning
A separate and more dangerous attack vector. AI services can clone a voice using a short audio sample: a podcast excerpt, a voice message, or a social-media video is enough. A “friend,” “business partner,” or “exchange support agent” calls you using a familiar voice and asks for an urgent transfer. In a stressful situation, this works.
AI phishing
Phishing messages can now be grammatically correct and personalized to the context: your name, a recent transaction, or the name of your wallet. The old rule that “scammers write with mistakes” no longer works in 2026. AI can write cleanly in any language and adapt its tone to the situation.
How to protect yourself
4. Phishing impersonating government agencies and services
Impersonation of official organizations is the fastest-growing scam category. According to Chainalysis, the number of impersonation schemes increased by more than 1,400% in 2025, while the average victim payment rose by more than 600%. People trust messages from a “bank” or “tax authority” and react automatically without checking the source.
How it works
You receive an SMS, messenger message, or email allegedly from a tax authority, bank, postal service, or payment provider. The wording is typical: “outstanding account balance,” “suspicious activity,” or “verification required.” The link leads to a clone website that visually copies the original. You enter a login, password, seed phrase, or card number, and the data goes directly to the scammers.
A large-scale example from the United States is the E-ZPass campaign. A Chinese-speaking group known as Darcula, or the Smishing Triad, sent messages imitating toll-road services and postal notifications. In November 2025, Google filed a lawsuit against the operators of Lighthouse, a Phishing-as-a-Service platform used for such attacks. According to Google, Lighthouse affected more than 1 million victims in over 120 countries, and between 12.7 million and 115 million bank cards may have been compromised in the United States alone.
In Ukraine, the scheme looks the same but uses local brands. The most common impersonations include:
The logic is always the same: a familiar brand, urgency, and a link you click without thinking.
How to recognize it
5. Fake exchange support
A separate type of impersonation. Unlike mass phishing, these scams are targeted and the attackers often know more about the victim than expected.
How it works
You receive a call or message from “Coinbase support,” “Binance support,” or the “Kraken security team.” They report suspicious activity and possible unauthorized account access. To “protect your funds,” they ask you to transfer crypto to a “safe wallet” or disclose your seed phrase “to restore access.” Both scenarios end the same way: the entire balance is lost.
The particular danger of this scheme is that scammers may actually possess real personal data. In May 2025, Coinbase disclosed an incident in which attackers bribed overseas support staff and contractors to obtain customer data. The leak included names, contact details, partially masked bank details, document images, account-balance snapshots, and transaction histories. In its SEC filing, Coinbase estimated that remediation costs and voluntary reimbursements could range from $180 million to $400 million.
One example of how the calling operation works: in December 2025, Brooklyn prosecutors charged 23-year-old Ronald Spektor with stealing almost $16 million from approximately 100 Coinbase users. According to investigators, he posed as an exchange employee, persuaded victims to move assets to a “new wallet,” and then withdrew the funds.
6. Rug pulls involving memecoins and new tokens
This scheme has existed for as long as tokens have, but it is experiencing another peak in 2025–2026. The reason is simple: launching a token on Solana, Base, and other low-cost networks costs very little, while token-creation tools are available to almost anyone.
How it works
A team, often anonymous, creates a token with a catchy name and meme-style branding. Hype is generated through X, Telegram channels, paid influencers, and bots. The price rises because of artificial excitement and limited liquidity: a relatively small amount of buying is enough to make the chart look like a rocket.
Once enough real buyers have arrived and liquidity in the pool has increased, the developers remove it in a single move. The price collapses to zero within seconds. The website disappears, the Telegram chat is deleted, and the social-media accounts vanish as well. Identifying those responsible is nearly impossible because everything was anonymous from the beginning.
Red flags
7. Fake airdrops and malicious approvals
One of the most deceptive schemes because the victim initiates and confirms the transaction. Technically, nobody “hacked” you: you voluntarily granted access. That is why recovering funds is especially difficult.
How it works
A fake airdrop is usually promoted through social media: posts on X, Telegram channels, comments under trending topics, and fake project accounts. At the same time, an unknown token or NFT may appear in your wallet with text such as “Claim your airdrop at xyz-site.com” or “You won 10,000 USDT, claim now.”
You open the site, connect your wallet, and sign a transaction believing you are claiming tokens. Instead, you sign an approve request that authorizes a smart contract to move tokens from your wallet. Often it is setApprovalForAll, which grants unlimited access to all tokens of a particular type. The scammer can then drain the balance immediately or wait until more assets accumulate.
Another variation is a phishing clone of a well-known DeFi protocol such as Uniswap, 1inch, or Aave. The reason given for connecting the wallet may be a “protocol update,” “liquidity migration,” or “new contract version.” The site looks authentic; the only difference is the URL.
How to protect yourself
8. Phishing-as-a-Service: scams as a business
This section is not about one specific scheme. It explains why all the previous scams scale so quickly. Modern fraud is an organized industry with suppliers, clients, and its own “technical support.”
How it is structured
Telegram groups with thousands of members sell everything needed for fraud: phishing kits with ready-made clone websites, databases of potential victims with emails and phone numbers, bulk-SMS services, proxies, and money-laundering services. Payments are made in stablecoins.
A specific example is Lighthouse, a Chinese-language service used in the Darcula and E-ZPass campaigns. According to Chainalysis citing Cisco Talos, individual service fees included $50 for development, $30 for proxies, and $20 for updates and support. Over three years, Lighthouse received more than 7,000 deposits and collected over $1.5 million in crypto.
Lighthouse is only one example. Analysts track large Chinese-language Crime-as-a-Service groups on Telegram with separate providers for phishing, messaging campaigns, and money laundering. Payments between them are made in stablecoins.
Why this matters
The barrier to entry for scammers is now minimal. They do not need to know how to code, build infrastructure, or understand crypto in depth. Buying a ready-made kit, paying for a messaging campaign, and launching an operation is enough. As a result, the number of attacks will increase, and their quality will improve as suppliers compete with one another.
9. Fake exchanges and investment platforms
This scam often works together with pig butchering: the victim is sent to exactly this kind of website. But it can also operate independently through search ads, social media, or messaging apps.
How it works
Scammers create a website that looks like a professional exchange or investment platform: an attractive interface, real-time charts, “24/7 support,” and sometimes even a mobile app. You register, deposit funds, and watch the balance apparently “grow.” Everything looks convincing.
Problems begin when you attempt to withdraw. First, you are told to pay a “profit tax.” Next comes a paid “identity verification.” Then there is an “insurance deposit for large amounts.” Every new requirement means another payment to the scammers. Some victims go through several rounds before realizing that no withdrawal will ever happen.
Another variation is a clone of a real exchange website. The domain may be binnance.com with a double n or coinbаse.com using a Cyrillic “а” instead of the Latin character, while the interface copies the original. You enter your login and password, and the data immediately goes to the scammers.
How to recognize it
10. Recovery scams: targeting people who have already lost money
A separate level of cynicism. This scheme preys on people who have already lost money and are in a state of panic.
How it works
You have fallen victim to one of the schemes above and lost crypto. You look for help by posting on forums, Reddit, X, or in comments under fraud-related posts. Soon, you find a “blockchain recovery expert” or a “crypto-asset recovery specialist.” They have a professional website, reviews, and sometimes even a supposed “law firm” behind them.
They promise to recover the money for a fixed upfront payment or a percentage of the amount recovered. You pay and receive nothing. Or worse, you are asked to “connect your wallet to trace the funds,” and the remaining assets are taken.
These “specialists” deliberately monitor victims of other scams: comments under fraud-related posts, complaints on X, and Reddit threads such as “I lost my crypto, what do I do?” They know that the person is panicking, feels guilty, and is ready to pay for any hope.
How to avoid crypto scams: protection checklist
Most schemes on this list do not rely on a technical exploit. They rely on urgency, trust, and inattention. To understand how to avoid crypto scams in practice, start with a few simple habits. These are the specific actions that reduce the risk:
To better understand how to avoid crypto scams when selling assets through an exchange or P2P, also review the rules for safely withdrawing crypto to a card.
Conclusion
To understand how to avoid crypto scams, look at all 10 schemes together. They share one common denominator. Almost none of them break cryptography or compromise a hardware wallet directly. The weak point is the same every time: a person who is in a hurry, trusts a familiar brand or voice, and acts automatically. In some cases, scammers build relationships for months; in others, they exploit the authority of an exchange or rely on an address copied without checking. The underlying principle is the same.
Protection therefore comes down to a few simple habits: keep your keys on a hardware wallet, check the full address, revoke unnecessary permissions, never make financial decisions under pressure, and use a security key instead of SMS wherever possible. Each habit closes a specific attack vector described above.
A hardware wallet will not make you immune to social engineering, but it removes an entire class of risks: insider leaks at exchanges, compromised hot wallets, and platform bankruptcies.
Scammers become more technologically advanced every year, but most losses still happen not because of a hack, but because of a second of inattention. You control that second yourself: take a pause whenever someone insists that you hurry.
Related Posts
How Coldcard Was Hacked — and Why a Firmware Update Won’t Fix Your Seed
On July 30 at 01:10 UTC, the Coldcard hack began: in just 41 minutes, someone completely drained 1,196 Bitcoin addresses. No phishing, no physical access to the devices, and no transactions signed by users. The cause came down to a single line in Coldcard’s firmware configuration, which caused the wallet to generate seeds with a …
Firmware Update for a Hardware Wallet: When to Update and When to Wait
A hardware wallet firmware update often feels like a minor thing: people buy a hardware wallet so it can sit in a drawer and not cause problems. Most of the time, that is exactly what happens — until the app suddenly says that a firmware update is available. That is where users tend to split …
What Is Shamir Backup and SLIP39?
Welcome! In this article, we will explain how Shamir Backup works. We will look at why it is one of the best ways to protect your crypto investments, compare the SLIP39 and BIP39 standards, and answer the question: “How can you protect your cryptocurrency from theft and sleep better at night?” I will try to …
Physical attacks on crypto holders: how to protect yourself from a wrench attack
Wrench attack is a physical attack on a cryptocurrency holder intended to force them to hand over access to a wallet. In crypto, people usually talk about hackers, phishing, and smart-contract vulnerabilities. But there is a threat that a standard wallet setup cannot stop: a person with a wrench standing at your door. Protection is …