Skip to content
Sat, Jul 25 UTC 22:21:48 MKT CAP $1.99T
BitcoinBTC $64,394.35 +0.37% EthereumETH $1,874.17 +0.77% TetherUSDT $1.00 +0.00% BNBBNB $569.14 +0.87% XRPXRP $1.10 +0.85% USD CoinUSDC $1.00 +0.01% SolanaSOL $74.42 +0.80% TRONTRX $0.3312 +0.24% DogecoinDOGE $0.0722 +4.40% XMR $362.66 -0.12% CardanoADA $0.1649 +0.67% ToncoinTON $1.60 +0.95% StellarXLM $0.1787 +0.96% ChainlinkLINK $8.38 +0.69% DaiDAI $1.00 +0.00% Bitcoin CashBCH $209.60 +0.00%

HomeThe Crafty Toolkit › How to Spot and Avoid Crypto Scams

How-to

How to Spot and Avoid Crypto Scams

Nearly every crypto theft relies on one of a small number of scripts. Learn the scripts and almost all of them stop working on you.

Difficulty: Beginner Time: 20 minutes 7 steps

By the CoinCrafty editorial desk · Updated 25 Jul 2026

Educational content, not financial advice. Follow the steps carefully and never share your seed phrase or private keys with anyone. CoinCrafty will never ask for them.

What you will need

  • A healthy suspicion of unsolicited contact
  • Bookmarks for the sites you actually use, so you never reach them by search
  • A wallet you use for experimenting, separate from where you store savings

Step by step

Learn the one rule that stops most theft

Nobody legitimate ever needs your recovery phrase or your private keys. Not a wallet vendor, not an exchange, not a support agent, not a developer helping you debug, not a friend, and not us. There is no situation — no migration, no validation, no "wallet sync", no airdrop claim — where handing them over is correct. Internalise this one rule and the majority of scams simply fail.

Safety: CoinCrafty will never ask for your seed phrase, private keys or a wallet connection, and will never direct-message you first.

Treat unsolicited contact as hostile by default

Support impersonation is the workhorse of crypto theft. You post a problem publicly, and within minutes several accounts message you offering help. All of them are attackers. Real support does not proactively message you, does not use direct messages, and does not move the conversation to another platform. Close the message and go to the official site you bookmarked yourself.

Reach sites by bookmark, never by search advert

Attackers buy search adverts for wallet and exchange names, producing a pixel-perfect copy at a lookalike domain. Everything works normally until you enter your phrase or approve a transaction. Type addresses by hand once, bookmark them, and use only the bookmark thereafter.

Understand what you are approving

On smart-contract networks, connecting a wallet to a site can grant that site standing permission to move specific tokens. Wallet-drainer sites rely on people approving without reading. Read what a signature request actually says, be extremely wary of requests for unlimited approval, and periodically review and revoke permissions you no longer need.

Safety: If a signature request is confusing, that is a reason to reject it, not to approve it and find out.

Apply the returns test

Guaranteed returns do not exist in crypto, and any promise of them is a confession. Doubling schemes, "arbitrage bots" with fixed daily percentages, celebrity giveaways asking you to send first, and recovery services promising to retrieve stolen funds for an upfront fee are all the same scam wearing different clothes. So is a romantic or friendly acquaintance who eventually mentions an investment platform.

Compartmentalise your wallets

Keep a separate wallet with a small balance for experimenting with new sites and applications, and keep your savings in a wallet that never connects to anything. This single habit converts most catastrophic losses into small, survivable ones.

Know what to do if it goes wrong

If you believe a phrase has been exposed, immediately create a new wallet with a fresh phrase and move everything you can. If you approved a malicious contract, revoke the approval. Report the incident to the platform involved and to your national fraud reporting service. Then ignore absolutely everyone who contacts you offering to recover the funds, because that is the follow-up scam and it targets people who have just been robbed.

Safety: Recovery services that ask for an upfront payment are always a second theft. There is no legitimate paid service that reverses a blockchain transaction.

Common mistakes

Tools for this guide

Frequently asked questions

Someone is impersonating CoinCrafty. What should I do?

Please tell us via our contact page. We will never direct-message you first, never ask for keys or a phrase, and never run a giveaway that requires you to send funds. Anything claiming otherwise is not us.

Is an airdrop always a scam?

No, but the claim process is a favourite attack surface. A genuine airdrop never requires your recovery phrase, and you should be extremely cautious about any claim page that asks for broad token approvals.

Are hardware wallets immune to scams?

No. They protect your keys from malware brilliantly, but they cannot stop you from approving a malicious transaction or typing your phrase into a fake site. The device removes one category of risk, not all of them.

I sent funds to a scammer. Can I get them back?

Almost certainly not — blockchain transactions are final. Report it, protect whatever remains, and be very sceptical of anyone who contacts you promising recovery.

Sources

More from the Toolkit