Home › The Crafty Toolkit › How to Spot and Avoid Crypto Scams
How to Spot and Avoid Crypto Scams
Nearly every crypto theft relies on one of a small number of scripts. Learn the scripts and almost all of them stop working on you.
By the CoinCrafty editorial desk · Updated 25 Jul 2026
What you will need
- A healthy suspicion of unsolicited contact
- Bookmarks for the sites you actually use, so you never reach them by search
- A wallet you use for experimenting, separate from where you store savings
Step by step
Learn the one rule that stops most theft
Nobody legitimate ever needs your recovery phrase or your private keys. Not a wallet vendor, not an exchange, not a support agent, not a developer helping you debug, not a friend, and not us. There is no situation — no migration, no validation, no "wallet sync", no airdrop claim — where handing them over is correct. Internalise this one rule and the majority of scams simply fail.
Treat unsolicited contact as hostile by default
Support impersonation is the workhorse of crypto theft. You post a problem publicly, and within minutes several accounts message you offering help. All of them are attackers. Real support does not proactively message you, does not use direct messages, and does not move the conversation to another platform. Close the message and go to the official site you bookmarked yourself.
Reach sites by bookmark, never by search advert
Attackers buy search adverts for wallet and exchange names, producing a pixel-perfect copy at a lookalike domain. Everything works normally until you enter your phrase or approve a transaction. Type addresses by hand once, bookmark them, and use only the bookmark thereafter.
Understand what you are approving
On smart-contract networks, connecting a wallet to a site can grant that site standing permission to move specific tokens. Wallet-drainer sites rely on people approving without reading. Read what a signature request actually says, be extremely wary of requests for unlimited approval, and periodically review and revoke permissions you no longer need.
Apply the returns test
Guaranteed returns do not exist in crypto, and any promise of them is a confession. Doubling schemes, "arbitrage bots" with fixed daily percentages, celebrity giveaways asking you to send first, and recovery services promising to retrieve stolen funds for an upfront fee are all the same scam wearing different clothes. So is a romantic or friendly acquaintance who eventually mentions an investment platform.
Compartmentalise your wallets
Keep a separate wallet with a small balance for experimenting with new sites and applications, and keep your savings in a wallet that never connects to anything. This single habit converts most catastrophic losses into small, survivable ones.
Know what to do if it goes wrong
If you believe a phrase has been exposed, immediately create a new wallet with a fresh phrase and move everything you can. If you approved a malicious contract, revoke the approval. Report the incident to the platform involved and to your national fraud reporting service. Then ignore absolutely everyone who contacts you offering to recover the funds, because that is the follow-up scam and it targets people who have just been robbed.
Common mistakes
- Replying to a direct message from anyone claiming to be support.
- Reaching an exchange or wallet through a search advert rather than a bookmark.
- Approving a wallet signature request without reading what permission it grants.
- Using one wallet for both savings and experimenting with unfamiliar applications.
- Believing that a large follower count or a verified badge means an account is genuine.
- Paying an upfront fee to a "recovery expert" after a theft.
Tools for this guide
Frequently asked questions
Someone is impersonating CoinCrafty. What should I do?
Please tell us via our contact page. We will never direct-message you first, never ask for keys or a phrase, and never run a giveaway that requires you to send funds. Anything claiming otherwise is not us.
Is an airdrop always a scam?
No, but the claim process is a favourite attack surface. A genuine airdrop never requires your recovery phrase, and you should be extremely cautious about any claim page that asks for broad token approvals.
Are hardware wallets immune to scams?
No. They protect your keys from malware brilliantly, but they cannot stop you from approving a malicious transaction or typing your phrase into a fake site. The device removes one category of risk, not all of them.
I sent funds to a scammer. Can I get them back?
Almost certainly not — blockchain transactions are final. Report it, protect whatever remains, and be very sceptical of anyone who contacts you promising recovery.