A practical guide to crypto giveaways, phishing, pig-butchering schemes, deepfakes, fake apps, and pump-and-dumps, plus early warning signs to watch
Crypto is easy to move, hard to reverse, and traded through systems that many users still don’t fully understand. That combination gives scammers plenty to work with.
Some scams are old formats with a crypto wrapper: Ponzi schemes, fake giveaways, impersonation, and phishing. Others rely on newer tools, including AI-generated video and voice. The delivery changes, but the pressure tactics rarely do.
Never send crypto to “verify” a wallet or receive a larger payment in return.
No legitimate support agent needs your seed phrase, private key, or account password.
Verify people, apps, and websites through an independent official channel.
Guaranteed returns, forced urgency, and withdrawal fees demanded in advance are strong warning signs.
Giveaway scams are common on X, Instagram, YouTube, Telegram, and other social platforms. A scammer creates or compromises an account that looks like it belongs to a company, exchange, or public figure. The account then promises to return more crypto to anyone who sends funds first.
Replies under the post may appear to confirm that the promotion is real. Those accounts, screenshots, and transaction claims can all be fabricated.
The rule is simple: a legitimate giveaway won’t require you to send crypto before receiving a reward.
Fake airdrops use a similar approach. Instead of asking for a direct transfer, they send victims to a malicious site. The site may request a wallet connection or ask the user to sign a transaction that grants access to tokens.
Read every wallet request before signing. A “claim” transaction can carry permissions that have nothing to do with receiving an airdrop.
A pig-butchering scam starts with trust, not a sales pitch.
The scammer makes contact through a dating app, social network, or messaging service. They may spend weeks building a relationship before mentioning crypto. Eventually, they recommend an investment platform and offer to help the victim get started.
The platform is fake, even if it looks convincing. Deposits may appear as a growing balance, complete with profitable trades and account statements. None of those figures prove that real trading occurred.
Problems begin when the victim requests a withdrawal. The platform may demand a tax, verification deposit, liquidity charge, or processing fee. Paying it doesn’t release the balance. It gives the scammer another payment.
Common warning signs include:
Unsolicited contact that quickly becomes personal
A sudden shift toward investing or trading
Pressure to use an unfamiliar platform
Profits that can be reinvested but not withdrawn
Requests for additional payments before a withdrawal
Don’t judge a platform by its interface. Check its real domain, operating company, regulatory claims, and independent history before sending funds.
AI has made impersonation cheaper and more convincing. Scammers can imitate the face or voice of an exchange executive, celebrity, support agent, friend, or relative.
A familiar voice is no longer enough to confirm identity.
These scams often arrive as fake video announcements, urgent voice messages, or direct messages from accounts posing as customer support. The request usually involves sending crypto, visiting a website, sharing account information, or acting before there is time to verify the story.
Ignore the contact details provided in the message. Open the company’s official website yourself and use the support channel listed there. If the message appears to come from someone you know, contact that person separately.
Ponzi schemes pay earlier participants with money from newer investors. There may be no real trading strategy or productive business behind the reported returns.
Pyramid schemes depend on recruitment. Participants pay to join and earn by bringing in more people, with part of the money flowing upward through the structure.
Both models fail when new deposits slow down.
Watch for fixed or “guaranteed” returns, vague explanations of how profits are generated, referral-heavy compensation, and restrictions on withdrawals. A dashboard showing daily earnings is not proof of revenue. Neither is an on-chain payment to an early participant.
If the product makes little sense without continuous recruitment, the recruitment is probably the product.
A malicious app can copy the branding and interface of a real wallet or exchange. Some appear in official app stores, where users may assume the listing has already been thoroughly vetted.
The app might steal credentials, replace a deposit address, expose a seed phrase, or direct funds to a wallet controlled by the attacker.
Use the download link published on the project’s official website. Check the publisher name and compare the listing with the company’s verified channels. Reviews and download counts can help, but neither is conclusive on its own.
Be especially careful when an app asks you to import a seed phrase. Entering it into a fake wallet gives the attacker control over every asset protected by that phrase.
Phishing messages imitate exchanges, wallets, DeFi protocols, and support teams. They often claim that an account is locked, an API key has expired, or a withdrawal requires urgent confirmation.
The link leads to a cloned login page. Anything entered there goes to the attacker.
Check the full domain before entering credentials. Small changes are easy to miss: an extra letter, a different domain ending, or a character that looks nearly identical to the original. Search ads can also lead to imitation sites, so bookmarking frequently used exchange and wallet pages is safer than searching for them each time.
No legitimate service will ask for your seed phrase or private key. Support agents also don’t need your account password.
If a message claims there is a problem with your account, close it. Open the official site directly and check the account from there.
Some scams manipulate price rather than stealing through a fake login page.
Promoters build interest around a thinly traded token, often through exaggerated claims, coordinated social posts, or paid endorsements that aren’t disclosed. Once outside buyers push the price higher, insiders sell into the demand. Late buyers are left holding an asset with little liquidity.
A rug pull is a related risk. Developers attract deposits or buyers, then remove liquidity, abandon the project, mint more tokens, or use hidden contract controls against holders.
Before buying an unfamiliar token, check:
How the supply is distributed
Whether a few wallets control most of it
Who controls liquidity and whether it can be removed
Whether the contract can mint, blacklist, pause, or change transfer rules
Whether the team and claimed product can be independently verified
If the contract has been audited, what the audit covered
An audit reduces some technical uncertainty. It doesn’t prove that the team is honest or that the token has economic value.
Slow the process down whenever money, credentials, or wallet permissions are involved.
Open websites from a bookmark or a verified official account. Confirm unusual requests through a second channel. Read wallet transactions before signing them. Keep seed phrases offline, and never paste one into a website sent through a message.
Treat urgency as a reason to stop. Scammers want the transfer completed before the claim can be checked.
The same applies to withdrawals. If a platform asks for another payment to release your balance, don’t send it. A legitimate fee can normally be deducted from funds already held in the account. Repeated demands for taxes, deposits, or “unlock” charges usually mean the displayed balance was never withdrawable.