Security field guide / 2026 edition

Your assets move fast.
So do the scams.

A practical, no-hype guide to recognizing crypto fraud, protecting keys, and building habits that hold up when a message, app, or market move feels urgent.

Confirmed blockchain transfers are generally irreversible. Pause before every signature.

Paused
Start with the signal, not the promise.
00Read first

Crypto safety is a system of small, deliberate decisions.

Crypto is portable, global, and fast. Those same qualities make it attractive to fraudsters. The strongest defense is not a single setting; it is a repeatable process for checking people, websites, apps, wallet requests, and withdrawal destinations before you act.

Timeline illustration of major cryptocurrency milestones from 2008 to 2023

Common crypto scams and how to stop them early

Most crypto scams begin with urgency, authority, or an offer that is unusually generous. The details change, but the manipulation remains familiar: get you isolated, get you to bypass a check, then get you to transfer or sign.

01

Social media giveaway scams

Fake or hijacked X, Instagram, and YouTube accounts imitate a public figure or major company. They promise to return more crypto after you send a small amount first, while fake replies claim the reward arrived. A real giveaway never requires an upfront transfer. The same rule applies to airdrops that ask you to connect a wallet or sign a transaction to claim "free" tokens.

Advance payment
02

Pig butchering investment scams

An unsolicited contact on a dating app, social platform, or messenger spends days building rapport, then introduces an investment opportunity. Victims are guided to a polished but fake trading site that displays invented profits. When they try to withdraw, the site demands a fee or tax payment. That extra payment is stolen too. Never pay to unlock your own withdrawal.

Trust grooming
03

AI deepfake and impersonation

Convincing cloned video or audio can now imitate exchange executives, celebrities, or even relatives. Common versions include fake support agents replying to your public complaint, a fabricated investment announcement, or a WhatsApp message from a "family member" in need of crypto. Verify every unsolicited opportunity through a separately sourced official channel.

False authority
04

Ponzi, pyramid, and pump schemes

Guaranteed returns and exceptionally high yields are danger signs, especially when the revenue model is unclear. Ponzi schemes use new deposits to pay older participants; pyramid schemes pay for recruitment. In crypto, projects such as OneCoin, Bitconnect, and PlusToken showed how quickly such systems can grow before collapsing. Hype-driven pump-and-dumps and liquidity rug pulls use a similar information gap.

Guaranteed yield
05

Fake mobile apps

Malicious apps can closely mimic established wallets and exchanges, including inside official app stores. Deposits sent to an address shown by a fake app go straight to the attacker. Start from the service's official website, use its store link, and check the publisher name, recent reviews, release history, and download count before installing.

Look-alike app
06

Phishing and fake support

Phishing imitates a legitimate service to collect login credentials, identity details, or a recovery phrase. Watch for near-miss domains, urgent account emails, and Telegram or Discord "support" messages. No legitimate exchange, wallet, or support team will request your seed phrase, private key, account password, or one-time 2FA code.

Credential theft
07

Undisclosed interests and exit scams

Not every scam steals directly. Promoters can inflate a token while insiders prepare to sell, or developers can abandon a project after pulling liquidity. Before committing funds, inspect token distribution, team history, the project's actual problem, competitors, documentation, and independent smart contract audits. Treat paid promotion and anonymous teams as risks to investigate, not proof of credibility.

Hype over proof

The one rule that catches most fraud

When a stranger creates urgency around an unfamiliar platform, a wallet signature, an up-front payment, or a secret recovery phrase, stop. Close the message and independently locate the official support channel.

Illustration of a Bitcoin beside rising market candles

Free tokens are not free when the claim asks for your keys.

Airdrops are used by legitimate projects to distribute tokens and attract users. Scammers exploit this familiar marketing pattern with convincing phishing pages, impersonated accounts, and tokens or NFTs dropped into your wallet without permission.

Fake campaign pages

A polished site advertises a reward, then requests a wallet connection, private information, or a signature whose real effect is to approve asset access.

Brand impersonation

A compromised or look-alike account borrows the credibility of a well-known exchange, wallet, creator, or project to push a fraudulent claim window.

Unexpected wallet assets

Tokens and NFTs can be sent to you to advertise a malicious website. Do not visit a URL in the asset name, image, or explorer note. Do not try to sell or move a suspicious token.

Impossible rewards

Rewards that promise significant value for no effort, no eligibility rules, and no verifiable project history are designed to trigger impulsive action.

A safer claim process

Four independent checks
01

Find the source

Use the project's established website and official channels, not a sponsored post, direct message, or search result alone.

02

Inspect the project

Look for clear documentation, identifiable contributors, a coherent purpose, and community discussion beyond its own feed.

03

Isolate risk

Use a burner wallet with only a small amount for experimental, one-time interactions. Keep primary holdings separate.

04

Read the signature

Reject requests for seed phrases and scrutinize approvals, recipient addresses, network, and transaction values before signing.

Illustration of hands exchanging Bitcoin and Ethereum tokens

Five controls that materially improve exchange and wallet security

Decentralized systems give end users greater control, but that control comes with operational responsibility. These controls reduce the chance that one stolen credential or one bad click turns into a full loss.

Use RSA for trading APIs

For exchange API access, an RSA key pair can be stronger than a shared secret. Register only the public key and sign requests with the private key you keep protected.

Restrict API IP addresses

Allowlist the approved IP addresses for every API key. Attempts from unknown locations should fail automatically, even if a key is exposed.

Allowlist withdrawal addresses

Pre-approve trusted destinations. This reduces losses from copy-paste mistakes and creates friction before funds can leave for a new address.

Use a hardware security key

YubiKey-style hardware 2FA requires a physical device or NFC presence. It is less exposed to password theft and SIM swap attacks than SMS codes.

Keep withdrawal limits low

Set a realistic limit for the amount that can leave in a time period. A limit buys time to detect suspicious activity before a full balance is lost.

Use unique credentials

A password manager lets every exchange and email account have a long, unique password, limiting credential-stuffing damage after a breach elsewhere.

Five-minute safety check

Use this checklist to review the accounts and wallets you use most often.

0 / 6Controls reviewed
Illustration of a vault protecting Bitcoin, Ethereum, and XRP tokens

Your phone is a wallet interface. Treat it like one.

Mobile devices concentrate identity, authentication, messaging, and wallet access in one place. That makes them a high-value target for fake apps, hidden miners, address-replacing malware, SIM swaps, and unsafe public Wi-Fi.

Install with intent

  • Begin at the official site and follow its app-store link instead of searching by name.
  • Confirm the developer name, support domain, release history, downloads, and recent reviews.
  • For a wallet, confirm that a new address is generated and that you control the exported private key or seed phrase.
  • Prefer reputable, maintained software. Open source code can provide additional scrutiny, but is not a guarantee by itself.

Watch device behavior

  • Unexpected overheating, battery drain, or slow performance can indicate cryptojacking or other unwanted background activity.
  • Remove untrusted apps and keep the operating system and browser updated.
  • Avoid pirated apps and unofficial installers, which are more likely to contain mining scripts or credential theft tools.
  • On any transfer, recheck the pasted destination. Clipper malware can replace a copied address with an attacker-controlled look-alike.

Make SMS a fallback, not your strongest factor

With a SIM swap, an attacker who takes control of your phone number may intercept text codes and reset accounts. Use an authenticator app or hardware key for critical accounts, minimize public personal details, and ask your mobile carrier to lock account changes behind a separate passcode.

Illustration of a city skyline with Ethereum symbols

Private keys, keyloggers, and multisig: reduce single points of failure.

Private keys are proof of control. A single-key wallet is simple, but it also means one stolen or lost secret can end access to all funds. For material balances or shared funds, consider splitting responsibility rather than concentrating it.

RiskWhat it looks likeYour move
Software keyloggerA program records keystrokes, clipboard contents, or screenshots after arriving through a bad link, attachment, or compromised download.Patch systems, use reputable security software, avoid unknown downloads, and consider a clean device for large transactions.
Hardware keyloggerA physical device sits between a keyboard and a computer, usually a concern on unfamiliar or public hardware.Never enter recovery phrases on public computers. Inspect physical ports and use trusted personal devices for sensitive actions.
Single-key custodyOne secret controls all funds. Convenience is high, but theft, loss, malware, or coercion can be catastrophic.Segment holdings. Consider a hardware wallet and stored, offline backup procedures for long-term holdings.
Multisig custodyA transaction needs multiple independent signatures, such as two out of three keys, before it can move funds.Keep keys on separate devices or in separate locations. For teams, set a threshold matching real approval responsibilities.

Why a 2-of-3 multisig can help

Resilience, not complexity for its own sake
A

Separate locations

Hold each key on a separate device or offline backup. One stolen device does not automatically mean a stolen wallet.

B

Loss tolerance

With two of three keys, one lost key does not make the funds inaccessible, unlike a strict two-of-two setup.

C

Shared approval

Businesses and families can require a majority decision, making unilateral misuse substantially harder.

D

Use tested tooling

Multisig has setup and recovery complexity. Document roles, test recovery with small amounts, and understand the wallet's model first.

Ransomware uses crypto for payment, but prevention begins before the demand.

Ransomware encrypts files or locks systems and demands payment, often in cryptocurrency. It commonly reaches victims through phishing attachments, fake links, exploit kits that target unpatched software, or malicious advertising. Paying does not guarantee recovery and may fund further attacks.

Reduce the blast radius

  • Keep regular backups on an external or isolated device, and test that restoration actually works.
  • Install operating system, browser, wallet, and security updates promptly.
  • Show file extensions in your operating system and treat executable attachments such as .exe, .vbs, and .scr with extreme caution.

Know the delivery paths

  • Emails that imitate invoices or account notices often deliver the initial malicious link or attachment.
  • Fake software updates, including old Flash-style prompts, are a recurring route to infection.
  • HTTPS alone does not prove a site is trustworthy. Attackers can use encrypted websites too.

Think you signed, installed, or sent something unsafe?

Speed matters, but panic leads to more loss. Move through a short, documented response plan. Take screenshots of messages and transaction details before reporting, but do not keep interacting with the suspected attacker.

Act in the first hour.

For a suspected wallet or account compromise, use a known-clean device where possible. Do not rely on a browser or phone that may be infected to secure the same accounts.

01 / ContainDisconnect suspicious sites, revoke risky permissions where appropriate, and move remaining funds to a secure wallet you control.
02 / SecureChange passwords from a clean device, reset 2FA, remove unknown API keys, and freeze or disable withdrawals through official support.
03 / ReportContact the official service through its published site. Report impostors to the relevant platform and local cybercrime authorities.

Questions worth answering before the next message arrives.

How can I tell whether a social media giveaway is a scam?

Any giveaway that asks you to send crypto first is a scam. Check the account handle character by character, do not trust comments as proof, and independently verify announcements through the company's official website or established channels.

What should I do if someone asks for my seed phrase?

Do not reply and do not enter the phrase anywhere. A real exchange, wallet provider, or support team will never request it. Disconnect from the site or contact, then report the account through an official channel. If you already exposed the phrase, move assets to a newly created wallet as soon as possible.

How do I verify a crypto app before installing it?

Visit the intended service's official website first and use its store link. Compare the developer identity with the site, inspect recent reviews and download history, and be wary of a recently listed app claiming to represent a major platform.

What are the strongest warning signs of pig butchering?

Unsolicited contact that quickly turns to investment, pressure to use an unknown platform, staged gains that encourage reinvestment, and demands for fees or taxes before withdrawal are all serious warning signs. Stop the conversation and report it.

Can a public Wi-Fi network compromise my crypto?

Public Wi-Fi increases exposure to interception and malicious network behavior. Avoid sensitive transactions on it. Use a trusted network, keep software updated, and do not let convenience override verification of the website, device, and recipient address.

A safer default

Security is not paranoia. It is a habit of verification.

Slow down before transferring, signing, connecting, or sharing. A few seconds of independent verification can protect years of accumulated value.