Types of Crypto Scams: Complete 2026 List and Red Flags

Types of crypto scams: complete 2026 list and red flags
As of january 2026, the safest way to read a list of crypto scams is not by novelty. It is by victim path, loss severity, and reversibility. This guide ranks the main crypto scam types by how victims are contacted, how funds move, what warning appears before the transaction, and whether recovery is realistic after settlement.
How we ranked this list of crypto scam types
This ranking uses a dated 2026 review of law-enforcement reports, consumer complaint patterns, blockchain analytics research, and on-chain attack mechanics. The core data layer is recombined from public sources rather than anonymous anecdotes. The severity anchor is the fbi ic3 report, 2023, which recorded more than $5.6 billion in cryptocurrency-related losses and a 45% year-over-year increase from 2022.

We used an original scoring model called the 4R victim-risk matrix: reach, revenue, recognition difficulty, and reversibility. Reach asks how often the scam appears. Revenue asks how large losses become. Recognition difficulty asks whether a careful user can spot the trap before signing or sending. Reversibility asks whether an exchange freeze, police report, or forensic trail can realistically lead to recovery.
The contrarian point is simple: red flags are needed, but they are not enough in 2026. AI impersonation, fake dashboards, and wallet-drainer kits now build trust before the victim sees an obvious warning. That is why each scam below connects the red flag to the exact step in the victim journey where the decision still matters.
Selection criteria: frequency, losses, sophistication, and reversibility
High-loss social engineering ranks above smaller technical tricks because the average victim is often moved through weeks of grooming before the first large transfer. Wallet-drainer attacks rank high because one signature can approve asset movement without handing over a seed phrase. Market scams rank lower when losses are smaller per victim or when pre-trade checks can expose the risk.
Attribution also matters. Andreas Antonopoulos, author and educator, has spent years teaching self-custody and key-control basics. Vitalik Buterin, co-founder of Ethereum, is relevant to the wallet-permission problem because account design, signatures, and smart-contract approvals sit at the center of many on-chain losses. Neither point makes crypto unsafe by default; it means the user action before settlement is the control point.
How to read this list
Each entry explains how the scam works, who it targets, why it ranks where it does, a useful metric, and the first prevention step. Blockchain forensics can trace many transactions, especially when funds reach a regulated exchange. It cannot reverse a settled transfer by itself. The best outcome usually comes from prevention, fast documentation, and immediate reporting.
Quick comparison: 20 types of crypto scams in 2026
Types of crypto scams are deceptive schemes that steal digital assets, private keys, seed phrases, exchange logins, or fiat funds intended for crypto. In 2026, the highest-risk scams combine trust-building, fake interfaces, and irreversible settlement, so the safest response is to verify before sending or signing.
At-a-glance scam comparison table
Rank | Scam type | How it works | Main red flag | First safety step |
|---|---|---|---|---|
1 | Pig butchering | Relationship builds trust, then pushes fake investing. | Unsolicited contact plus guaranteed returns. | Stop contact and report quickly. |
2 | Fake investment platform | Dashboard shows profits but blocks withdrawals. | Fee required before withdrawal. | Never pay release fees. |
3 | Romance transfer fraud | Emotional bond becomes direct crypto request. | Online partner needs urgent funds. | Refuse crypto requests from strangers. |
4 | Ponzi or referral scheme | New deposits pay old investors. | Fixed daily yield and bonuses. | Verify yield source on-chain. |
5 | AI impersonation | Voice or video fakes a trusted person. | Urgent action from unexpected call. | Verify through bookmarked channels. |
6 | Seed phrase phishing | Fake support asks for recovery words. | 12 or 24 words requested. | Close the page immediately. |
7 | Wallet drainer | Malicious approval grants token access. | Unlimited approval prompt. | Reject and review approvals. |
8 | Address poisoning | Lookalike address appears in history. | Tiny unknown transfer appears. | Verify full address from source. |
9 | Fake airdrop | Claim page drains after wallet connection. | Countdown claim link. | Check official channels first. |
10 | Rug pull | Team removes liquidity or mints supply. | Anonymous team and short lock. | Check contract and liquidity. |
11 | Honeypot token | Contract allows buys but blocks sells. | No successful sells visible. | Test sell logic before buying. |
12 | Fake yield farm | High APY hides withdrawal trap. | Huge APY with no audit. | Verify contract and withdrawal code. |
13 | Fake exchange | Deposits work, withdrawals stall. | Tax or compliance fee demand. | Check regulator and domain age. |
14 | Pump and dump | Insiders hype token, then sell. | Low-cap spike without news. | Check holder concentration. |
15 | Fraudulent presale | Token sale raises funds without delivery. | Copied whitepaper and vague team. | Verify contract before funding. |
16 | Fake mining | Dashboard shows fake hardware income. | No verifiable pool address. | Ask for pool proof. |
17 | SIM swap | Phone number takeover beats SMS codes. | Sudden loss of signal. | Call carrier and lock accounts. |
18 | Payment instruction scam | Caller demands crypto ATM or QR payment. | Government or utility pressure. | Hang up and call official number. |
19 | Ransomware or sextortion | Threat demands crypto payment. | Pay-now threat with wallet address. | Preserve evidence and report. |
20 | Recovery scam | Fake investigator targets prior victims. | Guaranteed recovery for upfront fee. | Do not pay recovery agents. |
The table is ranked by loss potential, not search popularity. Investment fraud sits at the top because the fbi ic3 report, 2023 attributed about $3.96 billion in reported losses to crypto investment fraud. Lower-ranked scams still matter, but more of them have visible checks before funds move.
1-5. High-loss social engineering and investment scams
These are the highest-risk crypto scam types because they target trust before they target wallets. The attacker usually spends days or weeks making the victim comfortable, then uses a fake platform, emergency request, or authority signal to push a transfer.
1. Pig butchering scams: most damaging long-con investment fraud
Pig butchering starts with a harmless message, dating profile, social account, or professional contact. The scammer builds familiarity, then introduces a supposed low-risk crypto investment. The victim is sent to a fake exchange or trading app where small gains appear on screen. Bigger deposits follow once the dashboard seems believable.
This ranks first because it combines emotional trust, fake profit evidence, and irreversible settlement. Chainalysis estimated at least $75.7 billion in illicit revenue connected to pig-butchering activity from 2020 through 2024 (Chainalysis, february 2024). The first safety step is refusing investment advice from anyone you have not met and verified independently. If funds already moved, document addresses and report immediately.
2. Fake crypto investment platforms: best-looking scam dashboards
Fake platforms imitate exchanges, brokerages, and mobile trading apps. Deposits appear instantly. Balances rise. Support chats respond politely. The trap appears at withdrawal, when the platform demands a tax, compliance deposit, insurance payment, or account activation fee before releasing funds.
This ranks second because the interface itself becomes the evidence victims trust. A useful metric is domain age: many scam sites are only weeks or months old, while claiming years of trading history. Before depositing, check the legal entity, regulator database, app developer name, and withdrawal reviews from independent sources. A real platform does not require a new payment to release your existing balance.
3. Romance and relationship crypto scams: trust-based transfer fraud
Romance crypto scams may overlap with pig butchering, but some skip the investment dashboard entirely. The attacker builds intimacy, then asks for crypto to solve an emergency, complete a business deal, or bypass a frozen bank transfer. The payment story changes, but the pressure is always personal.
This ranks third because emotional manipulation defeats normal financial caution. The ftc reported $1.14 billion in romance scam losses in 2023 and said crypto was the payment method tied to the highest reported losses (ftc romance scam guidance, 2024). Treat any online-only relationship that becomes financial as a hard stop. Video calls, reverse image checks, and third-party verification should happen before any payment discussion.
4. Ponzi, pyramid, and referral schemes: yield funded by new deposits
Ponzi-style crypto schemes advertise fixed daily returns, AI trading bots, mining packages, or private arbitrage systems. Early users may receive small payouts funded by later deposits. Referral rewards speed up growth and make victims recruit friends before the collapse.
This ranks fourth because the pitch sounds mathematical while the revenue source is hidden. Use the 3-source yield test: identify the yield source, verify it on-chain, and compare it with realistic market conditions. If a product promises 1% per day, the implied annualized return is far beyond normal staking or lending markets. If the operator cannot explain fees, validator rewards, or trading revenue with public evidence, leave.
5. AI deepfake impersonation scams: fastest-growing trust exploit
AI scams use cloned voices, face-swapped videos, synthetic livestreams, and automated chat to impersonate founders, support teams, celebrities, or coworkers. The victim hears or sees a familiar person and is pushed to send funds, connect a wallet, or join a token sale quickly.
This ranks fifth because visual proof is weaker than it used to be. In one widely reported case, a finance worker at a hong kong company transferred about $25 million after a deepfake video meeting (cnn, february 2024). Crypto versions use the same tactic for fake token endorsements and support calls. Verify any urgent request through a separate channel you choose, not the channel the caller provides.
6-12. Wallet, DeFi, NFT, and on-chain scam types
These scams target the signature layer. The attacker does not always need your seed phrase. A malicious approval, wrong address, or fake claim page can move assets once you confirm the action.
6. Seed phrase phishing: classic wallet takeover scam
Seed phrase phishing asks for the 12 or 24 recovery words that control a wallet. Attackers use fake support pages, sponsored search results, browser extensions, chatbots, and direct messages that claim your wallet must be restored, verified, or synchronized.
This ranks sixth because the loss is usually total and immediate. The key statistic is simple: a standard wallet recovery phrase is enough to recreate the wallet on another device. No legitimate wallet, exchange, or protocol needs those words. If a form asks for them, close it. Bookmark official wallet pages and never store the phrase in email, cloud notes, screenshots, or messaging apps.
7. Wallet drainers and approval phishing: one signature can empty assets
Wallet drainers trick users into signing approvals that give a malicious contract permission to move tokens or NFTs. Common prompts include unlimited ERC-20 approvals and NFT collection-wide permissions. The page may look like a mint, governance vote, token migration, or airdrop claim.
This ranks seventh because victims often think they only connected a wallet. Chainalysis has tracked approval-phishing losses in the hundreds of millions, including an estimated $374 million in 2023 (Chainalysis, 2024). Hardware wallets help with key storage, but they can still sign a bad approval. Review approval text, use transaction simulation, and check allowances with Revoke.cash.
8. Address poisoning and clipboard malware: wrong-address transfer traps
Address poisoning sends tiny transactions from lookalike wallet addresses so the attacker appears in your history. Clipboard malware silently replaces a copied address with the attacker’s address. QR-code swaps use the same idea in visual form.
This ranks eighth because the victim signs a real transfer to the wrong recipient. CoinDesk reported $1.2 million in address-poisoning losses in a single week in january 2024 (CoinDesk, january 2024). Use the three-point address rule: verify the first six characters, last six characters, and total address length from the original trusted source. For large transfers, send a small test first.
9. Fake airdrops and NFT mints: free-token traps
Fake airdrops promise free tokens or exclusive mints. The claim page asks for a wallet connection, a signature, or a small fee. Spam NFTs in a wallet may also point to malicious claim pages through metadata or description links.
This ranks ninth because the journey can finish in under 90 seconds: see post, click link, connect wallet, sign, lose funds. The best first step is checking the project’s official website and verified social channel before connecting. For a deeper checklist, use our fake airdrop scam checklist, which covers domain checks, contract confirmation, and safe burner-wallet use.
10. Rug pulls and exit scams: token teams vanish with liquidity
A rug pull launches a token, attracts buyers, then removes liquidity, mints new supply, changes sell rules, or abandons the project. Hype often comes from paid promotion, vague roadmaps, and claims that liquidity is locked.
This ranks tenth because many checks are visible before buying, but retail traders skip them during hype. One practical metric is wallet concentration: if the top 10 wallets control more than 40% of supply and several trace to the same funding source, risk is high. Also check whether liquidity is locked for meaningful time. Our rug pull warning signs guide explains contract-level checks before buying a new token.
11. Honeypots and malicious smart contracts: you can buy but cannot sell
A honeypot token allows buys but blocks sells. The contract may blacklist buyers, apply a 99% sell tax, or let the owner disable trading. The chart rises because buyers can enter, but exits fail or route value back to the deployer.
This ranks eleventh because it looks like ordinary volatility until you try to exit. The key test is sell history. If the block explorer shows many buys and no successful sells from normal wallets, assume the token is hostile. Run tiny test transactions only if you understand the risk, and avoid unverified contracts with hidden owner controls.
12. Fake staking, liquidity mining, and yield farms: APY used as bait
Fake yield products clone the look of real DeFi protocols and advertise extreme APY. The user approves token spending or deposits into a contract controlled by the attacker. Withdrawals may work briefly to build trust, then fail.
This ranks twelfth because high APY is not always fake, but unverifiable APY is dangerous. Real yield should map to protocol fees, validator rewards, lending demand, or token incentives visible in code and documentation. Andreas Antonopoulos, author and educator, is often cited for the key-control lesson that users must understand what they sign. If you cannot verify withdrawal logic and audit scope, the yield is not worth the custody risk.
13-16. Market, exchange, and token launch scams
These scams imitate legitimate market infrastructure: exchanges, launches, trading groups, and mining dashboards. They work because the interface looks normal until the victim tries to withdraw or sell.
13. Fake exchanges and trading apps: deposits go in, withdrawals never leave
Fake exchanges copy real trading screens, price charts, support widgets, and app layouts. Deposits clear quickly. A small withdrawal may even work. The block comes later, when larger balances require a tax payment, identity fee, or compliance deposit.
This ranks thirteenth because it is preventable with boring checks, but costly when skipped. The fbi ic3 report, 2023 tied crypto investment fraud to about $3.96 billion in reported losses. Before depositing, confirm the domain, legal entity, regulator status, app publisher, and withdrawal history. Do not trust a link sent by the person who introduced the platform.
14. Pump-and-dump groups: coordinated hype, then exit selling
Pump groups use chat channels and social posts to drive buying into thinly traded tokens. Insiders accumulate first, hype a countdown or listing rumor, then sell into late buyers as price spikes.
This ranks fourteenth because the red flag is public, but greed compresses decision time. Watch for 200% to 400% moves with no credible news, no product change, and no liquidity depth. Check holder distribution and recent funding links before buying. If a small group controls the float, you are likely providing exit liquidity rather than discovering an opportunity.
15. Fraudulent ICOs, IDOs, presales, and meme coin launches: fundraising without substance
Fraudulent token launches raise funds before a product exists. Warning signs include copied whitepapers, fake partnership logos, anonymous teams, vague roadmaps, and token contracts published at the last minute.
This ranks fifteenth because a presale can collect large sums before any trading market exposes the project. Use the three-layer token check: verify the sale contract before sending funds, confirm vesting terms in the contract rather than a PDF, and check whether treasury controls use a public multi-signature setup. If any layer fails, skip the sale.
16. Fake cloud mining and validator node schemes: hardware you never control
Fake mining sites sell hashrate contracts, validator licenses, or node packages backed by a dashboard that shows daily earnings. The operator does not provide verifiable pool addresses, hardware details, electricity assumptions, or validator identifiers.
This ranks sixteenth because it borrows language from real mining while hiding the asset. A practical metric is pool proof: a legitimate mining product should point to public pool activity or validator records. If the operator cannot show where blocks, rewards, or validator income originate, the dashboard is only a promise. Treat indefinite maintenance freezes as a major scam signal.
17-20. Account takeover, payment, extortion, and recovery scams
In this group, crypto is usually the payment rail rather than the original bait. The victim is pressured through account compromise, authority claims, threats, or a false promise of getting stolen funds back.
17. SIM swap and exchange account takeover: phone numbers as attack vectors
A SIM swap moves your phone number to a device controlled by the attacker. That gives the attacker SMS codes, reset links, and time to drain exchange accounts before the victim regains service.
This ranks seventeenth because it is common, fast, and preventable. The fbi has warned about SIM swap losses above $48 million in a single year (fbi ic3 public reporting portal, 2024). Use authenticator apps or hardware security keys instead of SMS, add a carrier passphrase, and enable exchange withdrawal allowlists. For larger holdings, MPC wallet security can reduce single-key failure risk.
18. QR code, crypto ATM, and payment instruction scams: urgency at the point of payment
Payment-instruction scams use fake authority. A caller may claim to represent tax staff, police, a utility, a bank, or tech support, then demand crypto by QR code, wallet address, or ATM.
This ranks eighteenth because the victim may not be interested in crypto at all. The ftc reported more than $110 million in crypto ATM fraud losses in 2023 and noted steep growth from earlier years (ftc data spotlight, september 2024). No legitimate agency or utility demands crypto ATM payment. Hang up and call the organization using a number from its official website.
19. Ransomware and sextortion: coercion using crypto payment demands
Ransomware encrypts files and demands payment for a decryption key. Sextortion emails claim to hold compromising footage and demand crypto to stay silent. Ransomware may involve real access; most sextortion emails are mass-sent bluffs.
This ranks nineteenth because panic causes rushed payment. The first metric to check is evidence quality: generic passwords, old breach data, or no sample file usually point to bluffing. For ransomware, isolate systems and contact incident-response help before paying. For sextortion, do not engage. Preserve emails, wallet addresses, and headers, then report to the relevant cybercrime portal.
20. Crypto recovery scams: victims targeted a second time
Recovery scammers contact victims after a wallet drain, rug pull, or fake platform loss. They pose as investigators, lawyers, hackers, or exchange insiders and promise guaranteed recovery for an upfront fee.
This ranks twentieth because it exploits a victim when judgment is already strained. The red flag is the guarantee. Blockchain tracing is real, but no private stranger can force a foreign exchange, mixer, or wallet holder to return funds. Legitimate investigators document flows and support law-enforcement work. They do not demand secret fees through direct messages or promise full recovery on a deadline.
Red flags, prevention checklist, and what to do if scammed
The repeated lesson across this list of crypto scams is that the best decision happens before signing or sending. Scammers try to make verification feel rude, slow, or unnecessary. Treat that pressure itself as evidence.

Common red flags across nearly every crypto scam
- Guaranteed returns, especially fixed daily or monthly profit claims.
- Seed phrase request, including any form asking for 12 or 24 recovery words.
- Withdrawal fee demand, tax payment, open up fee, or insurance deposit.
- Urgent deadline pressure, countdown timer, or limited-window claim.
- Unsolicited contact, especially from dating apps, chat groups, or fake support.
- Secret strategy claim, private bot, insider listing, or VIP pool.
- Wallet approval prompt, especially unlimited token or NFT permissions.
- Off-platform pressure, moving from a regulated channel to a private wallet.
- Unverified contract, hidden owner controls, or missing withdrawal logic.
- Guaranteed recovery, especially after you have already lost funds.
How to protect yourself before sending funds or signing transactions
Start with custody. Understanding self-custody wallet rules helps you know who controls keys, approvals, and withdrawal paths. For larger balances, compare hardware wallet vs exchange security and review our Ledger vs Trezor hardware wallet comparison before choosing storage.
- Keep long-term holdings in cold storage, not a daily-use hot wallet.
- Use a separate wallet with limited funds for new DeFi or NFT interactions.
- Simulate transactions when the wallet or tool supports it.
- Review active approvals monthly and revoke permissions you do not recognize.
- Use app-based or hardware-key two-factor authentication, not SMS.
- Enable withdrawal allowlists on every exchange account.
- Send a small test transfer before moving a large amount.
- Verify contract addresses from official sources, not from forwarded messages.
Vitalik Buterin, co-founder of Ethereum, is often associated with public discussions about safer wallet design and account abstraction. The practical user takeaway is plain: better wallet design helps, but users still need to slow down at the signing screen and understand what permission is being granted.
What to do if you think you have been scammed
- Stop sending funds. Do not pay another tax, open up fee, gas fee, or recovery deposit.
- Secure accounts. Change exchange passwords, rotate two-factor authentication, and contact your carrier if a phone takeover is possible.
- Revoke approvals. If you used a suspicious dApp, review token and NFT permissions before more assets move.
- Move remaining funds. Transfer unaffected assets to a clean wallet, ideally hardware-backed.
- Document evidence. Save transaction hashes, wallet addresses, URLs, chat handles, emails, screenshots, and timestamps.
- Contact exchanges. If funds touched a custodial platform, ask support to flag recipient addresses quickly.
- Report the incident. File with Chainabuse, fbi ic3, and your local consumer or cybercrime authority.
- Monitor addresses. Watch known scam addresses and update reports if funds move to an exchange.
It is also worth checking crypto insurance coverage limits before any incident. Most retail policies do not cover self-custody mistakes, but some custodial platforms carry limited coverage for defined platform failures.
How blockchain forensics helps, and where it has limits
Blockchain forensics can trace fund flows through addresses, clusters, bridges, and exchange deposits. This is the process described in our guide to how crypto tracking works. It helps investigators build evidence and helps exchanges flag suspicious deposits.
The best-case recovery path occurs when stolen funds reach a regulated exchange that can identify an account and respond to lawful requests. That can happen. The justice department seized about $3.6 billion in bitcoin linked to the 2016 Bitfinex hack (justice department, february 2022), showing that old trails can still matter.
The limit is equally important. Mixers, cross-chain routes, privacy coins, fake identity documents, and overseas exchanges can make tracing probabilistic or slow. Forensics is evidence, not a chargeback. Prevention and rapid response remain stronger than waiting for a post-loss rescue.
Frequently Asked Questions
- How can you tell if someone is a crypto scammer?
- Watch for urgency, guaranteed returns, secrecy, and unsolicited messages pushing you off-platform. Fake credentials and pressure to act fast are classic warning signs. Anyone requesting your seed phrase, private key, an upfront tax, an unlock fee, or an extra deposit before you can withdraw should be treated as a scammer immediately.
- What are 5 of the most current crypto scams?
- The five highest-priority scams in 2026 are pig butchering, AI deepfake impersonation, wallet drainer phishing, fake investment platforms, and fraudulent airdrops or NFT mints. Each one combines social engineering with convincing interfaces and exploits the fact that blockchain transactions are largely irreversible once confirmed.
- Can you get your money back if you get scammed on crypto?
- Crypto transactions generally cannot be reversed by the sender. Recovery is possible if stolen funds reach a compliant exchange that can freeze them, or if law enforcement acts quickly. Preserve all evidence immediately — transaction hashes, wallet addresses, and screenshots — then report to authorities and the platform involved.
- Can you get scammed if someone sends you crypto?
- Receiving crypto is not automatically dangerous, but it can be part of a scam. Risks include fake overpayment schemes, address poisoning dust transactions, malicious token links, spam NFTs with harmful smart contracts, and requests to return funds to a different address than the one that originally sent them.
- What is a common red flag of a crypto phishing scam?
- The biggest red flags are requests for your seed phrase, private key, wallet connection approvals, or urgent signature prompts you did not initiate. Also watch for fake support accounts, lookalike URLs, sponsored search ads, Discord DMs, Telegram admins messaging first, and airdrop or token migration claim pages.
- How does a cryptocurrency scam work?
- Scammers first build trust or create urgency, then direct victims to a fake platform or malicious wallet prompt. Once you deposit funds or sign an approval, they block withdrawals or drain your assets entirely. Most scams look completely legitimate right up until the exit stage, which is what makes them so effective.
- What are the most common crypto scams?
- The main categories include pig butchering, phishing, wallet drainers, fake exchanges, rug pulls, Ponzi schemes, fake airdrops, pump-and-dumps, SIM swaps, ransomware, and recovery scams targeting previous victims. Delivery channels vary widely — social media, email, search ads — but the end goal is always asset theft or credential theft.
- Are there any cryptocurrency scams in 2026?
- Yes, crypto scams remain highly active in 2026. AI impersonation, fake investment apps, approval phishing, and pig butchering are among the most significant threats right now. Improved blockchain analytics has made investigations more effective, but it does not eliminate the user-level risks that most scams continue to exploit successfully.
Sources
Author

Crypto analyst and blockchain educator with over 8 years of experience in the digital asset space. Former fintech consultant at a major Wall Street firm turned full-time crypto journalist. Specializes in DeFi, tokenomics, and blockchain technology. His writing breaks down complex cryptocurrency concepts into actionable insights for both beginners and seasoned investors.


