Crypto scams often succeed by making an ordinary action feel urgent: reset an account, claim a token, help a friend or release a withdrawal. Before sending funds or signing anything, identify who is asking and what authority the action grants.

A familiar logo, paid advertisement or message from a known account is not sufficient evidence. Accounts and websites can be impersonated or compromised.

Recognize the request behind the story

Fake support agents may offer to repair a wallet by asking for its recovery phrase or remote access. Investment scams may display invented profits and demand another payment before allowing withdrawal. An unsolicited “tax” or “unlock fee” sent to a stranger's wallet is a major warning sign.

Romance and relationship scams can develop slowly. A small successful withdrawal can be part of the persuasion, not proof of legitimacy. The FTC's crypto scam guidance describes common payment and investment deception.

Verify the organization through a route you obtain independently. Do not use contact details supplied by the person whose claim you are checking.

Treat signatures as decisions

Connecting a wallet normally exposes an address; signing can authorize much more. A token approval may allow a specified contract to move a permitted amount later. Some message signatures grant spending authority without an immediate visible transfer.

Read the network, asset, recipient, spender and amount. If the wallet cannot explain the request clearly, cancel and investigate. A hardware wallet cannot protect you from every instruction you deliberately approve.

Disconnecting from a website does not itself revoke on-chain permissions. Use your wallet's official guidance to review and remove unnecessary approvals.

Avoid copied-address traps

Address poisoning places lookalike addresses in transaction history to encourage a later mistake. Clipboard malware can replace a copied address.

Take receiving details from the intended recipient's current trusted screen. Compare the complete address after pasting. A small test reduces some routing errors but does not establish that an investment or service is genuine.

Unsolicited tokens can advertise malicious websites. You do not need to trade, claim or “remove” them through a stranger's link.

Respond according to what was exposed

If an exchange account is compromised, use the official recovery channel from a clean device. Secure the associated email, reset credentials, revoke unauthorized sessions or API keys and ask about withdrawal restrictions.

If a malicious approval is involved, a verified revocation may stop future use of that permission. It cannot undo a completed theft, and it does not solve a stolen private key.

If the recovery phrase or key is exposed, a new password is insufficient. A new wallet needs a fresh secret created on a trusted device. Beware of automated sweepers before adding fee funds to the compromised address; obtain help through independently verified channels.

Preserve evidence and avoid a second loss

Save transaction IDs, addresses, timestamps, messages, URLs and payment records. Notify relevant platforms and the appropriate local reporting authority promptly. Recovery is uncertain.

The FTC also warns about recovery scams. Someone promising guaranteed retrieval for an upfront payment may be targeting you because you already lost money. Do not share recovery secrets with anyone offering assistance.

Guides