Temple of FortuneDE
Menu

Security

How to spot the 7 most common crypto scams of 2026

Crypto fraud is an industry now — with call centers, AI and off-the-shelf toolkits. These seven patterns are behind most of the losses. Knowing them is how you stop falling for them.

By Femi Adler · Temple of Fortune · Updated:

Quick answer

Most crypto losses in 2026 trace back to a few recurring patterns: investment fraud built on a cultivated relationship ("pig butchering"), fake support asking for your seed phrase, wallet drainers via malicious approvals, fake platforms and apps, impersonation and giveaway schemes, address poisoning, and rug pulls. The common thread: time pressure, unrealistic returns, and a request to hand over keys or approvals.

Fraud is no longer the exception — it is infrastructure

Anyone who still pictures crypto fraud as a lone hacker in a hoodie underestimates the problem. In 2026, scamming is an organized business: call centers, teams with divided roles, “as a service” toolkits and increasingly AI. The numbers are uncomfortable. According to the FBI IC3 2025 Internet Crime Report, reported US losses to internet crime came to nearly $21 billion in total; within that total, cases involving cryptocurrency accounted for more than $11 billion. Two caveats keep the numbers honest. First, the figures are worth keeping apart: $21 billion is all internet crime combined, $11 billion is the crypto-related share of it. Second, these are reported cases — IC3 itself notes that many victims never file, so actual losses are almost certainly higher. Investment fraud remains the biggest reported driver, and much of it runs through cryptocurrency.

In parallel, the FTC reports that people have lost billions to scams that started on social media — and within that social-media data, fake investment opportunities stand out as the costliest pattern. And Chainalysis describes in its crime reporting how AI and phishing toolkits lower the barrier to entry and make schemes scalable.

The good news: almost all losses run through a few recurring patterns. Learn them and you recognize them — usually before money moves. Here are the seven that matter most.

1. Pig butchering — investment fraud built on a relationship

“Pig butchering” is the dominant and costliest scheme. The playbook: a stranger contacts you seemingly by chance — via dating apps, social media, or a “wrong number” message. Over weeks, trust or romance builds. Then comes the investment tip: a “brilliant” platform where the new acquaintance is supposedly getting rich. Early on you may even be allowed to “withdraw” small amounts — that is part of the bait. Once you deposit larger sums, the money is gone.

The FBI frequently traces crypto investment fraud to exactly this blend of romance and investment scam. Warning signs: unexpected contact, quickly growing closeness, an investment “secret”, a platform only your new acquaintance has shown you, and withdrawals that suddenly fail over “taxes” or “fees”.

2. Fake support & seed-phrase phishing

A supposed agent from your exchange or wallet maker gets in touch — by email, chat, phone or in a forum. There is a “security issue”, a “verification” is needed. It always ends with the same request: reveal your seed phrase or type it into a website.

The rule against it is absolute: no legitimate support ever asks for your seed phrase. The FBI’s fraud warnings make the same point, and every major hardware-wallet maker and exchange states it in its own official security documentation — if in doubt, look it up in your provider’s help center rather than taking our (or anyone’s) word for it. Real support has no reason to ever see your recovery words. They belong only in your own device — never in a chat window, never on a linked page. Whoever asks is the attack, however real the logo looks.

3. Wallet drainers — theft by signature

With a wallet drainer, no one steals your seed phrase. Instead, a fake website or app gets you to sign a transaction or approval that gives the attacker access to your tokens. One click on “Connect Wallet” and “Approve” — and a contract is allowed to clear out your holdings. Chainalysis and security firms now describe drainers as ready-made toolkits that attackers rent.

Defense: read signature requests carefully before confirming — an unlimited token approval or a setApprovalForAll request (which hands over an entire NFT collection at once) should always make you pause. Do not connect your wallet to unknown sites, and regularly review and revoke old approvals using tools such as Revoke.cash or the token-approval checker built into your chain’s block explorer. One caveat applies even here: revocation tools themselves require you to connect your wallet and sign transactions, and phishing clones of exactly these tools exist. Type the URL yourself, verify the domain character by character, and read every signature request there with the same care as anywhere else. The warning signs, in CISA’s logic, are the same as any phishing: an unexpected prompt, time pressure, an offer that sounds too good.

4. Fake exchanges, apps and investment platforms

Some platforms exist only to collect deposits. They show you pretty price charts and rising “gains” in the dashboard — but every withdrawal fails on new conditions: first pay “tax”, then an “unlock fee”, then a “compliance check”. There is nothing to withdraw because nothing was ever invested.

Defense: use regulated providers only, verify app names and domains exactly (fraudsters copy real brands pixel for pixel), and grow suspicious the moment getting money out is harder than putting it in. The FTC’s social-media scam data names fake investment platforms and social-media-promoted “trading groups” as a recurring — and particularly costly — pattern.

5. Impersonation & giveaway scams (including deepfakes)

“Send 1 ETH to this address and get 2 back” — the giveaway scheme is old but keeps working because it hides behind real names: cloned celebrity accounts, fake corporate streams, and now AI deepfakes of well-known faces and voices. The IC3 2025 report devotes a dedicated section to AI-enabled fraud for the first time.

Rule: no one doubles your money. Any request to send crypto first in order to get more back is fraud — no exceptions.

6. Address poisoning — the tainted address

This scheme exploits convenience. The attacker plants an address in your transaction history that closely resembles one you use often (same start, same end). The variants: a tiny dust transfer, a zero-value transfer (which costs the attacker nothing but still shows up in your history), or a transfer of a worthless fake token made to look like a real payment. If you thoughtlessly copy from your history on your next send, your money lands with the fraudster.

Defense: verify recipient addresses in full, not just the start and end; never copy addresses from your transaction history; use an address book for recurring recipients; when in doubt, send a test amount first.

7. Rug pulls & fake tokens

In a rug pull, developers promote a new token or project, pump the price with hype — then pull the liquidity or dump their entire holdings at once. What remains is a worthless token. A variant is fake tokens: the same name as a real project, but a different, fraudulent contract.

Defense: always verify contract addresses via official sources, read extreme return promises as a warning sign, and accept that the survival rate of small, hyped projects is low.

The common thread — and what cuts it

Seven schemes, one core: the lever is not technology but psychology. Build trust, create urgency, then ask for money, keys or an approval. That is exactly why three simple habits defeat almost all of it:

  • Slow down. No genuine offer expires in five minutes. Time pressure is a tool of fraud.
  • Protect keys and approvals. Your seed phrase belongs to no one; read signatures before you grant them.
  • Verify independently. Addresses, domains, contracts via official sources — never via the link someone sent you.

And if something did happen: stop any further payments at once, preserve evidence (chats, addresses, transaction IDs), and report it — in the US to your local police and the FBI’s Internet Crime Complaint Center (ic3.gov), plus the FTC for consumer fraud; elsewhere, to your national police and financial-fraud reporting office. There is no guarantee of recovery — but silence only helps the perpetrators.

FAQ

What is the fastest way to spot a scam?
Three signals that almost always appear together: a return that sounds too good to be true; artificial time pressure ("today only", "last spots"); and a request to send money, grant an approval, or hand over keys/codes. If two of them apply, caution is mandatory.
I already sent money — is it gone?
Crypto transactions are generally irreversible, and there is no guarantee of recovery. Still: stop any further payment immediately, preserve evidence (chats, addresses, transaction IDs), and report the case. In the US, that means your local police and the FBI's Internet Crime Complaint Center (ic3.gov); fraud can also be reported to the FTC. In some cases investigators do manage to freeze funds.
Is AI-enabled fraud really a new problem?
The IC3 2025 report includes, for the first time, a dedicated section on AI-enabled fraud — deepfakes, cloned voices, automated chats. The technology lowers attackers' costs and makes fakes more convincing. The defensive rules stay the same.

Sources

This article is for general information only.

Comments

Argue hard on substance, fair in tone. No financial "tips" with profit promises, no ads, no links to scams — that gets removed, and repeat offenders lose their account. Otherwise: welcome to the temple.