Explainer · Security
How to spot a crypto scam
October 21, 2026
Crypto's most consistent product isn't a coin, a chain, or an app — it's new ways to separate people from their money. The mechanisms vary, but the underlying patterns repeat across almost every scam, regardless of what the current trend is called. Here is what those patterns actually look like, and what to check before a wallet connects, a signature gets signed, or a transfer goes out.
Rug pulls and honeypots
A rug pull is the most common outcome for a bad project, not one scam type among many. A team launches a token, builds hype, then either drains the liquidity pool it controls or dumps its own concentrated token allocation, and the price collapses toward zero within minutes. The warning signs are usually visible ahead of time: an anonymous team with no verifiable history, a token allocation heavily concentrated in team or insider wallets, and no independent smart-contract audit that anyone can actually read.
A honeypot is a narrower, nastier version of the same idea. The contract is written so a buy order goes through but a sell order never does — capital goes in, and there is no way out. The protection here is mechanical rather than analytical: a small test buy followed by an immediate small test sell exposes a honeypot before real size is ever committed, because the contract reveals itself the moment an exit is attempted.
Approval drainers and wallet risk
Connecting a wallet is not, by itself, risk-free. A malicious site can prompt a signature that looks like a routine permission but is actually unlimited authorization — letting that contract move tokens out of the wallet whenever it chooses, not just once. The theft often happens later, sometimes days after the original signature, specifically so the loss doesn't get connected back to the site that caused it.
This is why revoking old token approvals periodically, and reading what a signature request actually authorizes rather than clicking through it, matters as much as avoiding obviously fake sites in the first place.
Social engineering does most of the damage
A large share of losses in this industry has nothing to do with smart contracts at all. Fake customer-support accounts reply within minutes of a public complaint, offering to "help" over direct message. Giveaways promising to double any crypto sent in impersonate real exchanges or public figures. Long-running romance scams eventually pivot into a fake investment platform — a pattern now commonly called pig butchering, run patiently over weeks before the ask ever appears.
The mechanisms differ, but they all run on the same two levers: manufactured urgency, and borrowed trust from a familiar name or a real relationship. Recognizing those two levers matters more than memorizing any specific scam format, because the format changes constantly and the levers don't.
A short, concrete checklist
- No legitimate support asks for a seed phrase. A seed phrase should never be shared with anyone, under any circumstance — not support, not an exchange, not a "verification" step.
- Verify independently, not through a supplied link. A contract address or website should be checked against an independent source before a wallet connects to it, rather than trusted because someone sent the link directly.
- Test a new contract before committing size. A small buy followed by a small sell reveals a honeypot before real capital is at risk.
- Guaranteed returns are the tell, not the opportunity. Any unsolicited message promising doubled or guaranteed returns is a red flag on its face, regardless of who it appears to be from.
- Urgency is a signal, not a coincidence. Pressure to act immediately, before there's time to check anything, is close to a universal feature of these schemes — the pressure itself is the warning.
The read
Almost none of these scams require sophisticated hacking. They require moving fast and skipping a check that would normally happen. The single best defense across all of them is the same: thirty seconds of delay before signing, clicking, or sending. That's a habit, not a credential — it doesn't require special technical expertise, just a consistent pause at the exact moment something is pushing for speed.
This is general-circulation educational content, not investment or legal advice. No security checklist eliminates risk; new scam formats appear constantly and none of the above is exhaustive.