Short answer: nearly all crypto theft comes from a small set of scripts — fake support, phishing sites, malicious signatures, guaranteed-return "investments", and address poisoning. All of them require you to take an action. Slowing down for sixty seconds before any irreversible step defeats most of them.
The seven patterns
1. Fake support
You post a problem in a public channel; within minutes someone messages you privately offering help, then asks for your seed phrase, a "validation" signature, or a small payment to unlock funds. Real support never initiates a direct message and never asks for a seed phrase. Contact support only through the link on the official site.
2. Phishing clones
A pixel-perfect copy of a wallet or exchange, reached through a search advertisement or a shortened link. You connect your wallet, sign what looks like a login, and the wallet empties. Bookmark the real domains and use only the bookmarks.
3. Wallet drainers
A "mint", "claim" or "airdrop" page asks you to sign a message. The signature grants unlimited spending permission on your tokens or transfers ownership of an asset. Read what your wallet displays: if a signature mentions approval, permit, or setApprovalForAll on a site you do not fully trust, reject it.
4. Guaranteed-return investments
A platform promises fixed daily percentages, shows a rising balance, and permits small withdrawals early on. The withdrawal that fails is the large one, usually accompanied by a demand for a "tax" or "unlock fee". No legitimate operation guarantees returns; the ability to withdraw a little proves nothing.
5. Long-con relationship fraud
Weeks of friendly conversation lead to a trading tip on a professional-looking platform. The relationship is manufactured to make the platform credible. The tell is simple: the introduction of any investment opportunity by someone you have never met in person.
6. Address poisoning
An attacker sends a dust transaction from an address whose first and last characters match one you use, so it appears in your history. Later you copy the address from history instead of the source and send funds to the attacker. Never copy addresses from transaction history.
7. Fake tokens and rug pulls
A new token pumps, buyers arrive, liquidity is removed, price goes to zero. Some contracts also block selling outright. Check whether liquidity is locked and whether the contract has been audited — and treat any token you learned about from an unsolicited message as hostile.
The sixty-second checklist
- Read the domain character by character. Look for extra hyphens and swapped letters.
- Confirm what you are signing. Approvals and permits are not logins.
- Copy the address from its source, then verify the first and last four characters.
- Ask who benefits if you act quickly. Urgency is the universal ingredient.
- Send a small test transaction on anything new.
If it already happened
- Move remaining funds to a fresh wallet on a clean device, most valuable assets first.
- Revoke approvals afterwards — moving funds is more urgent than tidying permissions.
- Record transaction hashes and addresses; they are what any investigator or exchange will need.
- Report to the relevant service and to local law enforcement. Blacklisting is occasionally possible for centralised tokens.
- Ignore "recovery experts" who contact you afterwards. That is a second scam aimed at the same victim.
Key takeaways
- Scams need your action — that is where the defence lives.
- No legitimate party ever asks for a seed phrase.
- Signatures can be as dangerous as transfers.
- Urgency is a red flag in every single script.
When you exchange, use bookmarked services and check the domain before creating an order — our guide to choosing an exchange service covers what else to verify.
Frequently asked questions
Can stolen crypto be recovered?
Rarely. If funds reach a centralised exchange quickly and you report it, an account can sometimes be frozen. On-chain transfers themselves cannot be reversed, which is why prevention is the entire strategy.
Is it dangerous just to connect a wallet to a website?
Connecting alone only shares your address. The risk starts when you sign something. Damage requires a signature, so read every signing prompt carefully.
Why did I receive tokens I never bought?
Usually a dust or spam airdrop meant to lure you to a site to "claim" them, or to poison your address history. Do not interact with unexpected tokens; hide them instead.