Key concepts
- No legitimate person or service ever needs your recovery phrase or private key, so every request for one is theft attempted in plain sight.
- Blockchain payments are final, which removes the chargeback safety net people rely on elsewhere and makes prevention the only real protection.
- Manufactured urgency, guaranteed returns and unsolicited contact are the three red flags shared by nearly every crypto scam.
- Approving a token permission can be as damaging as sending funds, so read what a wallet is asking you to sign before confirming.
Start with the rule that prevents more losses than everything else combined. Nobody legitimate will ever need your recovery phrase or your private key. Not an exchange, not a wallet developer, not a support agent, not a validator, not a giveaway, not us. There is no situation — no migration, no verification, no rescue, no upgrade — where handing those words to another person is the correct move.
If you remember nothing else from this lesson, remember that. Anyone who asks is a thief, without exception and regardless of how convincing, official or urgent they appear.
Why crypto attracts fraud
Fraud follows the money that cannot be clawed back. A card payment can be disputed and a bank transfer can sometimes be recalled, but a signed blockchain transaction settles in minutes and stays settled. There is no chargeback, no arbitration and no central operator with a reverse button.
Add a subject many people find intimidating, a culture of rapid decisions, and pseudonymous wallet addresses, and you have close to ideal conditions for a confidence trick. None of this makes crypto uniquely dangerous. It does mean the burden of caution sits with you.
The schemes you will actually meet
- Fake support. You post a problem publicly and are contacted privately within minutes by "support". They will eventually ask you to enter your recovery phrase into a validation tool. Real support never initiates contact and never asks.
- Giveaways and free-token drops. A message says you have qualified for tokens and must connect a wallet or send a small amount to unlock a larger one. Money only ever flows in one direction here.
- Long-game investment fraud. A friendly stranger builds rapport over weeks, then introduces a platform showing steady gains. Small withdrawals succeed to earn trust; the large one triggers surprise "fees" or "taxes" that never end.
- Cloned apps and lookalike sites. A search advertisement or a near-identical domain leads to a wallet that hands your keys straight to the operator.
- Token exits. A new coin rises on coordinated hype, then insiders sell into it or drain its liquidity — a rug pull or a pump and dump.
- Malicious signature requests. A site asks you to approve a transaction whose real effect is granting open-ended permission to move your tokens. The wallet is emptied later, at the attacker's convenience.
Red flags that cut across all of them
The schemes vary, but the pressure tactics rarely do. Manufactured urgency is the clearest tell: a window closing, a slot expiring, an account about to be locked. Legitimate opportunities do not evaporate while you check.
Watch for guaranteed or fixed returns, since real market returns are never guaranteed. Watch for unsolicited contact of any kind, for requests to move the conversation to a private channel, and for anyone discouraging you from telling family or doing your own research. Watch for payments demanded in crypto specifically, and for a story that requires you to act before understanding.
Screenshots of profits prove nothing. Neither does a verified-looking account, a slick interface, or a name you recognise attached to a message you did not expect.
Habits that make you a hard target
Security here is mostly procedural rather than technical. Keep your recovery phrase offline and never type it into anything except your own wallet during a deliberate restore. Reach services by typing the address or using your own bookmark, never by clicking a link in a message or an advertisement.
Slow down before signing anything, and read what the wallet is actually asking you to approve. Review and revoke old token permissions periodically. Send a small test transaction before a large one. And put a deliberate pause between excitement and action — most people who lose money can point to the moment they decided not to wait.
If you hold meaningful amounts, a hardware wallet and a clear split between custodial and self-custodied funds limit how much any single mistake can cost you.
Our standing promise
The CoinCrafty editorial desk will never message you first. We will never ask for your keys, your recovery phrase, your passwords or a payment. We do not run giveaways, we do not manage funds, and we will never contact you about your account, because you do not have one with us. Any message claiming otherwise is an impersonation, whatever name or logo it carries. If you want to check something with us, come to us through our contact page.
For the worked, click-by-click version of this material — including what a malicious approval screen looks like and how to withdraw safely — read how to spot crypto scams in the Toolkit. If you have already lost funds, stop engaging, move any remaining balances to a fresh wallet with a new recovery phrase, and report it locally. Anyone promising to recover stolen crypto for an upfront fee is running the second scam.
Frequently asked questions
Someone from support messaged me first. Could it ever be genuine?
Treat it as fraudulent. Reputable exchanges and wallet providers answer tickets you opened; they do not reach out privately after you post a problem in public, and they do not conduct support over direct messages on social platforms. If you think a real issue exists, close the conversation and contact the provider yourself through the address you already use.
I connected my wallet to a site I now think was fake. What should I do?
Act quickly. Move remaining assets to a wallet with a completely new recovery phrase, since the old one may be compromised. Then review the token permissions granted from the old address and revoke anything you do not recognise. If you entered your recovery phrase anywhere, assume that wallet is permanently unsafe and never reuse it.
Are scams only a problem with small, unknown coins?
No. Impersonation, fake support and malicious signature requests target holders of the largest assets precisely because that is where the money is. Project quality and personal security are separate questions. A well-run network cannot protect you from a transaction you were persuaded to sign yourself.