How to Spot a Crypto Scam
By the PickACrypto Team · Updated Jul 19, 2026
Crypto's irreversibility makes it the scammer's favourite payment rail: no chargebacks, no fraud department, no undo. The encouraging news, after years of watching this space, is that the scams barely innovate. The same half-dozen patterns recycle endlessly with new logos, and a short set of rules defeats nearly all of them. This guide is the catalogue and the rules. Read it once properly and you're better defended than the average holder. The people who lose funds are rarely stupid, just unbriefed and rushed at the wrong moment. Rushing you is the entire craft.
Step 1: Internalise the three absolute rules
Before the catalogue, the rules that outrank everything. One: nobody legitimate ever asks for your seed phrase. Not wallet support, not an exchange, not a claim site. The words are the wallet, and every request for them, without exception in the history of the industry, is theft. Two: nobody legitimate asks you to send funds to "verify", "unlock", or "release" anything. Money that flows toward the helper is the scam's whole mechanism. Three: guaranteed returns don't exist here. This market's volatility is public knowledge; anyone promising fixed daily profits is quoting the bait, not an investment. Ninety percent of what follows is these three rules wearing costumes.
Step 2: Learn the phishing-and-drainer pattern
The most common technical scam: a site or message gets you to sign something malicious in your wallet. Delivery varies (fake airdrop claims, cloned DEX front-ends bought as search ads, urgent DMs about your "compromised" account, fake mint pages) and the payload is always a signature: an unlimited token approval or a drainer transaction that empties the wallet in one click. The defences are mechanical. Type or bookmark URLs instead of clicking ads and DMs (our DEX guide's standing rule), read every signature prompt before approving, treat unlimited approvals to unknown contracts as alarms, and periodically revoke stale approvals. Urgency is the tell: countdown timers, "claim in the next hour", "your funds are at risk, act now". Real protocols don't operate at gunpoint.
Step 3: Recognise the human-contact scams
Fake support lurks wherever you ask for help: post a question in any crypto forum and DMs arrive from "admins" offering assistance that ends with your seed phrase or a remote-desktop session. Real support never DMs first. File that as a law of nature. Romance and "pig butchering" is the costliest scam running: a warm contact builds rapport over weeks, introduces a trading platform showing fabulous fake gains, and the platform (wholly fictional, balances included) swallows every deposit, with a final "pay the tax to withdraw" insult on the way out. Any new relationship that steers toward an investment platform you've never heard of is the pattern, full stop. Impersonation giveaways, where a famous person "doubles" whatever you send, still work, still empty wallets, still violate rule two.
Step 4: Vet the tokens themselves
Some scams are the asset. Rug pulls: a token launches, hype builds, insiders holding the supply and the liquidity pull both, price goes to zero. Tokenomics reading (who holds what, whether liquidity is locked) catches most in advance. Honeypots: contracts coded so you can buy but never sell. A buy-only chart and failed sell transactions on the explorer are the signature, and verifying contract addresses avoids the counterfeit-token variant. Yield frauds: platforms paying "guaranteed" returns from new deposits until they don't, which is rule three industrialised. Where does the yield come from is the question that unravels them; "trading bot" and "AI arbitrage" are not answers, and our research guide turns the vetting into a process.
Step 5: Run the sixty-second gauntlet before anything gets your money or signature
Our habit, and the summary of everything above. Who contacted whom first? (Inbound offers are guilty until proven otherwise.) Is there urgency? (Manufactured deadlines are the scammer's oxygen.) What exactly am I signing or sending, and could I explain it to someone else? Where does the promised return actually come from? And would this offer survive me taking a day to check it? Scams fail these questions loudly; legitimate things pass them boringly. If it's already too late and something got through: revoke approvals immediately, move remaining funds to a fresh wallet with a fresh phrase, and report the addresses. Recovery is rare, and honesty about that beats the "fund recovery services" that circle victims, which are, with grim reliability, the same scammers back for seconds.
Frequently asked questions
Can you get scammed just by connecting your wallet to a website?
Connecting alone reveals your address and balances but can't move funds. The theft happens at the next step, when you sign a malicious transaction or approval. Connect cautiously, but reserve the real scrutiny for anything that asks you to sign.
How do I get my money back after a crypto scam?
Usually you don't, and anyone promising recovery for an upfront fee is running the follow-up scam. What's left is containment (revoke approvals, move remaining funds to a fresh wallet) and reporting the addresses to exchanges and police, which occasionally freezes funds at the off-ramp.
What are the biggest red flags of a crypto scam?
Anyone asking for your seed phrase, anyone asking you to send funds to receive funds, guaranteed returns, unsolicited contact, and manufactured urgency. One of those is a warning; two or more together is the answer.