Scam types
Types of crypto scams and how each one is built
English version for the United Kingdom.
Schemes look different and work the same. Each one has a first contact, a moment when the money leaves, and a single step without which the whole thing collapses. Naming that step is more useful than memorising the stories.
01Schemes that need you to send
The largest category never touches your wallet. It persuades you to send, and the transfer is genuine, authorised and final.
Fake investment platforms show a rising balance that exists only in their own interface. Giveaway schemes promise to return a multiple of what you send. Romance and long contact schemes spend weeks building trust before the first deposit. Recovery services target people who have already lost money and take a second payment for a return that does not happen.
The common step is the outgoing transfer. The defence is structural: no legitimate operation requires you to send first to receive later.
02Schemes that need your key
The second category goes for the key or the phrase, because the key is the asset.
Fake wallet applications, cloned support chats, and pages that ask you to restore a wallet to fix an error all collect the same twelve words. Malicious signature requests do it differently: the site asks for a signature that grants permission to move tokens, and the victim approves it believing it is a login.
The common step is a request to type the phrase or approve an unclear permission. No genuine service ever needs either.
| Category | How it reaches you | Step it depends on |
|---|---|---|
| Fake investment platform | Advertising, messenger, referral | You send a deposit |
| Giveaway or multiplier | Video stream, social post | You send first to receive |
| Recovery service | Contact after a loss | You pay in advance |
| Fake wallet or support | Search result, chat | You type the recovery phrase |
| Malicious signature | Site that asks you to connect | You approve an unclear permission |
| Address substitution | Clipboard, message, invoice | You trust a pasted address |
03Schemes that need the address
The third category leaves everything alone except the destination.
Clipboard malware swaps a copied address. A lookalike address is generated to match the first and last characters. An invoice in a business thread arrives with new details from a genuine address after correspondence has been read.
The common step is trusting an address that came through a message. The defence is to take it from the system of record and to verify it in full.
04Questions and answers
What do all crypto scams have in common?
Each depends on a single step performed by the owner: an outgoing transfer, a typed recovery phrase, an approved permission, or a trusted address. Remove that step and the scheme has nothing left.
Is a professional website evidence that a project is real?
No. A site, a whitepaper, an active community and a rising chart can all be purchased. Verification moves to properties that cannot be bought, such as contract behaviour and register entries.
Can stolen cryptocurrency be recovered?
Tracing is real work and produces accurate reports, and it does not change who controls the funds. Any advance payment for a promised return is a second loss on top of the first.