Scam Guide
Learn to spot common crypto scams and protect your assets — recovery phrase security, phishing detection, Rug Pull red flags and Ponzi warnings.
The crypto world offers incredible opportunities, but it’s also full of scams. According to Chainalysis, global crypto scam losses exceeded $12 billion in 2025. This section helps you identify common scams and protect your digital assets.
Scam Identification
- Common Crypto Scams 2026: Complete Guide — From phishing, fake support, pig butchering to Ponzi schemes
- How to Identify Rug Pulls & Scam Coins — Learn to evaluate contract code, liquidity pools, and team backgrounds
- How to Identify Fake Exchanges & Phishing Sites — Practical tips for spotting legitimate exchanges
Wallet & Private Key Security
- Seed Phrase & Private Key Security Guide — Secure generation, storage, and backup methods
DeFi Safety
- Revoke Guide: Remove DeFi Contract Approvals — Regularly check and revoke unnecessary token approvals
Frequently Asked Questions (FAQ)
What are the most common crypto scams?
Per the 2025 Chainalysis report (global losses over $12 billion), common scams include: ① Phishing (fake websites/emails/DMs stealing credentials); ② Pig butchering (building trust on social platforms then luring investments); ③ Fake support (impersonating platform support to direct transfers); ④ Ponzi/high-yield schemes (promising guaranteed fixed returns); ⑤ Rug pulls (scam token teams vanishing with funds). Key to identify: anything promising “guaranteed profit” or “pay first, earn later” is very likely a scam. See the common scams guide.
What is a rug pull? How do I spot scam coins?
A rug pull happens when a project team disappears or dumps after accumulating large funds, usually the moment liquidity is drained — the token price collapses to zero instantly. How to spot: ① check if the contract is open-source and time-locked; ② check whether liquidity is locked; ③ assess whether the team is anonymous and lacks real background; ④ beware overly concentrated token distribution. See the rug pull identification guide.
How do I identify fake exchanges and phishing sites?
Key points: ① Verify the official URL — phishing sites use lookalike domains (e.g. binance.com vs binance-secure.com); ② Check the SSL certificate and registration; ③ Enter via the official app or a bookmarked site, not links in SMS/emails; ④ Test a small withdrawal — legitimate platforms withdraw normally. Messages claiming “account anomaly, transfer to verify” are almost always scams. See how to identify fake exchanges.
My seed phrase or private key leaked — what do I do?
Act immediately: ① Move all assets to a new secure wallet (the old address is compromised); ② Check for contract approvals given on malicious sites and revoke them (with Revoke tools); ③ Notify relevant platforms to freeze accounts (if an exchange is involved); ④ Figure out how the leak happened to prevent recurrence. Note: any “official recovery of your seed phrase” service is a scam — once a private key leaks, moving assets is the only self-help.
What are contract approvals and why revoke them?
When you use a DApp or DEX, you sign a token approval allowing that contract to spend your tokens up to a limit. If the project is malicious or gets hacked, the attacker can drain assets within your approval range. So regularly check and revoke unneeded approvals (tools like revoke.cash) to reduce theft risk. See the Revoke approval guide.
How do I avoid being scammed on Telegram/Discord?
① Never click links from strangers — verify domains first; ② Beware “support” DMs — real projects don’t proactively DM you; ③ Treat “claim airdrop,” “verification bot,” “free coins” with high suspicion; ④ Check if the group is muted/only admins post — such groups are often scam groups; ⑤ Any request to “activate” or pay “fees” first is a scam. See social media scam prevention.
No matching articles found