Security Intermediate 9 min read

How to Spot Crypto Scams - 6 most common types and a defense checklist

There are six core scam patterns in crypto. Once you know them, you stop falling for them. This guide walks through each one with real examples from the field, the red flags that give them away, and a checklist for what to do if you already clicked. The hero below has the playbook for all six in one place.

Scam playbook · 6 patterns
CLICK A TYPE TO INSPECT
Honeypot tokens
What it looks like
A new token with a chart that only goes up. You buy easily. When you try to sell, MetaMask throws an error every time. The contract is coded so buys go through but sells revert.
Red flags
Fix: paste the contract into Honeypot.is or DexTools. Honeypot field must be No. Buy and sell tax both under 10%. Liquidity locked. Anything yellow is a skip.

The pattern, the cost, the rule

The pattern
Every crypto scam works by creating urgency or trust and pointing you at one wrong action: buy this token, sign this transaction, paste this seed. Slow down and 90% of the trick falls apart.
The cost
Losses come in three sizes. Small: one bad token swap, $20-200 gone. Medium: wallet drained from a fake site signature, $1k-50k. Total: seed phrase compromised, every wallet on that phrase forever lost.
The rule
Nothing in crypto comes free. Nobody DMs strangers with a profitable arbitrage. Nobody runs a Twitter giveaway by asking for your seed. The moment something feels too generous, it is the scam.

6 scam types in detail

Almost every crypto scam in the wild fits into one of these six. Once you can name them, you can spot them in seconds.

01 / TOKEN CONTRACT
Honeypot tokens
Smart contract lets you buy but reverts every sell. Chart looks like a perfect uptrend because nobody is allowed to sell. Promoted via insider tips: "this coin is listing on Binance tomorrow, 100x guaranteed". You buy, watch it pump, try to take profit, and find your sell button is broken. The owner pulls liquidity and exits with everything.
Check on Honeypot.is
02 / WEB
Phishing clone sites
Pixel-perfect copy of a real protocol with a slightly different URL: uniswap-app.com, alt-layer-claim.io, trustpad-com.net. The dash is the giveaway: real project domains almost never use them. Connect your wallet, sign a transaction, and a malicious contract drains every approval-eligible token in your wallet.
Check the URL exactly
03 / SOCIAL
DM and group spam
Random Telegram DM offering an "arbitrage strategy", a "private signal group", or a "guaranteed bridge bug". Most lead to a fake exchange where deposits are real and withdrawals are blocked. Same pattern in groups: you are added to a chat with hundreds of fake members all praising the same scam project.
Mute and report
04 / SEARCH
Fake Google ads
Search "uniswap" or "metamask" or "chainlist" and the first result is a paid ad for a phishing clone above the real site. People skim and click the top result. Once Google catches them they buy a new ad under another domain and the cycle restarts. Treat the entire ads section in crypto search results as hostile.
Always scroll past ads
05 / MALWARE
Cracked software and clipboard hijack
Pirated apps, especially Excel files from torrents, often ship with a clipboard hijacker. You copy your wallet address, paste it into Telegram, and the pasted address is silently swapped to the attacker's. You only notice when the receiver says "that is not your address". By then the test transfer is gone.
Verify pasted addresses
06 / SEED
Seed phrase theft
The worst one. Malware scans your filesystem for 12, 18, or 24-word patterns and ships any matches to the attacker. The wallet is now permanently compromised: a bot watches the address and sweeps any future deposit within seconds. Even funds you send after finding out are stolen instantly. Treat the wallet as dead.
Never store seed in plain text

The 3-month warm-up: how a $100k+ scam group worked

The most polished scam I watched go down in person was not a quick rug. It was patient, professional, and ran for months before anyone got robbed.

Field report · early 2023
A new "crypto signals" channel appeared and started buying ads everywhere
They bought ads from every mid-tier crypto Telegram channel they could reach. Within a few weeks they had over 100,000 subscribers. The content was sharp: real project breakdowns, real chart analysis, occasional good calls. People you know follow people like that all the time. It looked completely legit.

After three months of careful brand-building they posted one message: "insider tip, this token is listing on Binance, buy now". Their audience piled in. The token was a honeypot. Buys went through, sells reverted. The owner pulled liquidity within hours and walked away with over $100k from a single post. Channel went dark the next day.

~3 mo
Trust build-up
100k+
Subscribers
1 post
Trigger event
$100k+
Stolen

The lesson: a channel with months of good content is not proof of safety. The exit is the point. Anyone large enough to scam at this scale is patient enough to wait three months for the setup. Always verify a token contract independently no matter who recommends it.

7-step defense checklist

Stick this on a sticky note next to your monitor. Every step here costs nothing and removes one entire scam category from your life.

1
Type URLs by hand for anything that touches your wallet
Never click a wallet-connect link from a Twitter reply, Telegram message, or Google ad. Always type the domain into the bar yourself or use a bookmark. This single habit kills phishing scams entirely.
2
Verify every new token contract on Honeypot.is or DexTools
Before any swap of a small-cap or new token, paste the contract address into a honeypot scanner. Honeypot: No. Buy tax: under 10%. Sell tax: under 10%. Liquidity: locked. If any field is yellow or red, walk away.
3
Never DM strangers offering "schemes" or "arbitrage"
Real traders do not message strangers with profitable strategies. If someone could earn $10k a day from a private trick, they would not be sharing it with you. Block, mute, move on.
4
Scroll past Google ads for any crypto search
For terms like "uniswap", "metamask", "chainlist", "phantom wallet", the first paid result is often a phishing clone. Always scroll to the first organic (non-ad) result and double-check the domain.
5
Verify the pasted address every time you send
Clipboard hijackers swap addresses silently. Check the first 4 and last 4 characters of the pasted address before signing. If they do not match what you copied, your machine has malware. Stop, scan, swap to a clean device.
6
Keep your seed phrase off the internet, period
Never type, paste, or photograph the 12-24 word seed. Not in a password manager, not in a cloud note, not in a screenshot. Paper or hardware wallet only. Once a seed touches a connected device it should be considered compromised.
7
Use a separate machine for serious crypto
If you hold real money, dedicate one device to crypto only. No torrents, no random downloads, no cracked software. A clean Mac or a fresh Linux install costs less than one drained wallet.

What to do if you already connected to a scam site

Caught it within minutes? You can usually save the wallet. Run both steps below in the next 5-10 minutes. The fast version: revoke approvals, then disconnect every site.

STEP 1 / 5 MIN
Revoke approvals on Revoke.cash
Open revoke.cash, connect the affected wallet, and revoke every approval that does not match a protocol you actively use. Token approvals are how scam contracts drain wallets later: a malicious approval lets them transfer your tokens at any time, even days after you closed the tab. Also check every chain (Ethereum, BSC, Polygon, Arbitrum, Base) - approvals are per-chain.
STEP 2 / 2 MIN
Disconnect every site from MetaMask
Open MetaMask, click the three dots top-right, then Connected sites. Hit disconnect on every single entry, even ones you trust. You can always reconnect to real sites later. Do this on every wallet (MetaMask, Phantom, Rabby) you use across the same browser.

If you signed a malicious approval and watched tokens move out within seconds, the funds are gone. Move whatever is left to a fresh wallet on a clean device immediately. The compromised wallet should be considered burned. If your seed phrase was ever typed or stored on the affected machine, the entire phrase plus every wallet on it is dead - move everything to a brand new seed today.

Stuck on a term? Every crypto term explained simply in our glossary. Open the glossary