What Is a Crypto Scam?
A crypto scam is a deceptive scheme that manipulates a target into voluntarily sending cryptocurrency, revealing wallet credentials, or signing a malicious transaction. Technical attacks such as hacks or smart contract exploits take assets by breaking into a system (opens in new tab). Crypto scams succeed through brand impersonation and persuasion, with the victim authorizing the transfer.
How crypto scams work
Nearly every major crypto scam category runs on impersonation. The attacker borrows a trusted identity, whether an exchange's support team, a well-known executive, a token project, or a government agency, to establish credibility, then steers the target onto infrastructure the attacker controls: a fake trading platform, a lookalike domain, a counterfeit app, or a spoofed support line.
A common sequence appears across variants. Contact begins on social media, dating apps, SMS, paid ads, or community channels like Discord and Telegram. The attacker builds trust and moves the conversation to a private and unmonitored channel (opens in new tab). The victim is then directed to a fraudulent platform showing fabricated returns (opens in new tab).
When the victim tries to withdraw, the platform denies the request and demands additional taxes or fees (opens in new tab). Drainer variants compress this into minutes: a fake airdrop or mint page prompts the victim to connect a wallet and sign a routine approval (opens in new tab), which quietly grants the attacker permission to sweep the assets.
In a common variation, a scammer watches a project's public Discord or Telegram channel for users asking for help, then sends a direct message posing as a support rep or community leader. They share a lookalike domain and ask the victim to "verify" their wallet (opens in new tab), which captures the seed phrase.
Why crypto scams are hard to stop
Many crypto scams operate outside the targeted company's infrastructure. A fake support line, a spoofed token launch, or a scam ad bypasses the brand's own systems, so traditional security tools (opens in new tab) in the SOC rarely generate an alert. Customers whose funds are taken still associate the incident with the impersonated brand, then flood its real support channels with cases it cannot resolve. In 2024, cyber-enabled fraud accounted for nearly 83% (opens in new tab) of all losses reported to IC3.
Drainer-as-a-Service (opens in new tab) and phishing-as-a-service kits have industrialized the supply side, bundling fake websites, malicious scripts, and operator dashboards so attackers can run large campaigns without coding skills (opens in new tab).
Crypto scammers register lookalike domains in bulk and hide behind bulletproof hosting (opens in new tab) that ignores abuse complaints. After a takedown, they rebuild on fresh infrastructure as fast as the old domains come down.
Types of crypto scams
The major categories share the impersonation core but differ in lure and extraction mechanics:
- Pig butchering (investment fraud). Organized scam compounds (opens in new tab) in Southeast Asia run long-con relationship scams, grooming victims for weeks before steering them to fake trading platforms. Investment fraud is the most reported crypto scheme (opens in new tab) by reported losses.
- Fake exchange support. Scammers pose as exchange employees on unsolicited calls and messages, manufacture an account emergency, and use it to harvest login credentials, a recurring exchange-support scam pattern (opens in new tab).
- Wallet drainers. Lookalike airdrop, mint, or DeFi sites trick users into signing token approvals (opens in new tab) that let the attacker transfer assets within seconds.
- Rug pulls. Developers hype tokens, DeFi protocols, or NFT projects, then withdraw liquidity or dump their holdings. Rug pulls sit alongside investment scams in federal fraud guidance (opens in new tab), because deliberate deception is the operative mechanism.
- Giveaway and deepfake scams. Hijacked, often verified, social accounts run looping deepfake videos of executives promising to multiply any crypto sent to a displayed address. In a Gartner survey (opens in new tab) of security leaders, 62% of organizations experienced a deepfake attack involving social engineering or the exploitation of automated processes in the prior year.
- Ponzi schemes. Operators pay existing investors with funds collected from new ones; the structure constitutes investment fraud (opens in new tab) under US securities law. Crypto versions show steady returns in an app dashboard until operators freeze withdrawals (opens in new tab) citing technical issues.
- Address poisoning. Attackers generate lookalike wallet addresses (opens in new tab) and seed them into a victim's transaction history. A later copy-paste then sends funds to the attacker.
- Recovery scams. Advance-fee fraud (opens in new tab) that re-victimizes prior scam victims through fake law firms and recovery services charging upfront fees.
How to defend against crypto scams
Crypto scams target a brand's trust, which sits outside the network perimeter, so defense must reach outside it too. Four controls matter most:
- Monitor beyond the perimeter. Watch domain registries (opens in new tab) for typosquats and bulk registration clusters, monitor certificate transparency logs for unauthorized certificates, and scan social platforms, app stores, paid ads, and messaging channels for unauthorized use of brand names and logos. Include executive likenesses in that monitoring.
- Run coordinated takedowns at campaign level. A single campaign pairs a lookalike domain with scam ads, fake profiles, and counterfeit apps, and pulling one asset down leaves the rest earning. Coordinate requests across registrars, hosts, ad networks, and platform trust and safety teams so linked infrastructure comes down together.
- Give customers a reporting channel. Add a simple form for reporting suspicious sites and messages, and state plainly how official support (opens in new tab) does and does not contact customers.
- Train employees on crypto-themed social engineering. Pig butchering works through emotional manipulation and trust. Teach staff to recognize grooming tactics and escalating investment conversations, and require multi-person authorization and verification for changes to payment instructions.
Because that infrastructure rotates after every takedown, these controls only hold when they run continuously, not case by case.
How Doppel helps
Doppel is the AI-native Social Engineering Defense (SED) platform that unifies Digital Risk Protection and Human Risk Management to detect and dismantle crypto impersonation across domains, social media, paid ads, app stores, and crypto channels. The Doppel Threat Graph connects lookalike domains, fake support profiles, scam ads, counterfeit apps, and crypto-channel signals into a campaign-level view.
The platform's agentic AI prioritizes and executes takedowns across registrars, hosts, social platforms, and ad networks, dismantling linked scam campaigns at machine speed. Teams can convert detected campaigns into Simulation exercises with one click, so live lures strengthen employee training. Coordinated enforcement across every channel makes the campaign too costly to rebuild. A guided demo shows the impersonation campaigns targeting your brand and the takedowns that dismantled them. Request a demo to get started.
Frequently asked questions about crypto scams
What is a crypto scam?
A crypto scam is a deceptive scheme that manipulates a person into voluntarily sending cryptocurrency, revealing wallet credentials, or authorizing a malicious transaction. It uses impersonation and social engineering to gain trust; attackers pose as exchanges, executives, token projects, or government agencies. Common forms include fake investment platforms, wallet drainers, giveaway scams, and fraudulent exchange support. Blockchain networks treat transactions as final (opens in new tab), which leaves victims with limited recourse once funds move.
What is a crypto scam in cybersecurity?
In a security program, a crypto scam is a brand-impersonation attack that runs on infrastructure the attacker owns: registered lookalike domains, fake support profiles, purchased scam ads, and counterfeit apps. Many off-platform campaigns bypass the enterprise network, leaving few logs or endpoint events and little internal telemetry (opens in new tab) for a security operations center (SOC). The financial loss lands on customers, while the reputational damage and inbound support volume land on the impersonated company. Countering it takes external monitoring of registries, certificate transparency logs, social platforms, and app stores, paired with coordinated takedowns of linked assets across a campaign.
What is the difference between a crypto scam and a crypto hack?
A crypto scam extracts assets through deception: the attacker persuades the victim to authorize a transfer, sign an approval, or hand over credentials. A crypto hack takes assets without the victim's participation, through technical exploitation (opens in new tab) of a vulnerability in an exchange, protocol, or smart contract. Deliberate deception of investors makes rug pulls a form of fraud (opens in new tab) under US enforcement standards, even when they use smart contract mechanisms. The distinction matters for defense, since scams bypass technical controls by targeting human trust.
What is an example of a crypto scam?
Pig butchering is one of today's most prevalent (opens in new tab) and damaging schemes. A scammer makes contact through a dating app, a social platform, or a "wrong number" text, builds a relationship over weeks, then introduces a cryptocurrency investment opportunity. The victim deposits funds into a fake trading platform that displays fabricated profits (opens in new tab), and some operators even permit a small early withdrawal (opens in new tab) to build confidence. When the victim attempts a larger withdrawal, the platform blocks it and demands additional payments framed as taxes or fees.
How do you report a crypto scam?
File a complaint with the Internet Crime Complaint Center (opens in new tab) at ic3.gov. Include wallet addresses, transaction hashes, amounts and dates, the domains and platforms involved, and how contact began. Reports can also go to the Federal Trade Commission (opens in new tab) at ReportFraud.ftc.gov. Scammers actively impersonate the IC3 (opens in new tab) itself, so confirm the URL ends in .gov and avoid sponsored search results when looking for official reporting sites. Be wary of any recovery service charging an up-front fee.


