← Back to Blog

Crypto Security Glossary — 60+ Terms Explained (2026)

Crypto security glossary 60 terms explained

This glossary covers the key terms used in cryptocurrency security, fraud investigation, blockchain forensics, and money laundering analysis. Each entry includes a plain-language definition, how it works in practice, and how investigators or victims can detect it. Updated for 2026.

Scam / Fraud Forensics Laundering DeFi / Exploit Technical

Scam & Fraud Types

Pig Butchering (Sha Zhu Pan)
Scam / Fraud

A long-con investment fraud where scammers build a romantic or friendship relationship with a victim over weeks or months before introducing a fake crypto investment platform. The victim is gradually encouraged to deposit increasing amounts — the "fattening" — before the platform disappears and all funds are stolen. The name comes from the Chinese term for "slaughtering the pig."

How It Works

Scammer initiates contact via dating app, social media, or wrong-number text. Relationship builds over weeks. Fake investment platform is introduced casually. Victim deposits small amounts and sees fake "profits." Larger deposits follow. When the scammer decides, the platform freezes withdrawals and disappears.

How to Detect

Unsolicited contact from an attractive stranger. Investment platform not listed on major exchanges. Withdrawals require "tax payments" or "fees." Profits that seem too consistent. Pressure to invest more before a "deadline."

Romance Scam
Scam / Fraud

A fraud where the scammer builds a romantic relationship with the victim entirely for financial exploitation. Unlike pig butchering (which uses romance as a vehicle to an investment scam), romance scams may involve direct requests for money, gift cards, or crypto for fabricated emergencies — medical crises, travel problems, business failures.

How It Works

Fake profile on dating apps or social media. Relationship develops quickly with excessive affection ("love bombing"). Crisis emerges requiring money. Requests escalate. When victim stops paying, contact ends.

How to Detect

Person claims to be overseas (military, oil rig, doctor abroad). Refuses video calls or calls are brief and scripted. Profile photos are stolen (reverse image search reveals this). Money requests always involve crypto or gift cards.

Rug Pull
Scam / Fraud

A DeFi scam where project developers drain investor funds by removing liquidity, abandoning the project, or exploiting a backdoor in the smart contract after enough investor capital has been deposited. Common in token launches and NFT projects.

How It Works

Project launches with hype and marketing. Investors buy in, liquidity grows. Developers either pull liquidity directly, dump reserved tokens, or trigger a hidden smart contract function that transfers funds to their wallet.

How to Detect

Anonymous team with no verifiable history. Liquidity not locked. Smart contract not audited. Concentrated token ownership (few wallets hold most supply). Unrealistic APY promises.

Recovery Scam
Scam / Fraud

A second-wave fraud targeting people who have already been scammed. Recovery scammers pose as investigators, law enforcement, or recovery specialists and promise to retrieve stolen funds for an upfront fee. They specifically target people who have recently filed fraud reports or posted about being scammed.

How It Works

Scammer monitors IC3 reports, victim forums, and social media for people who've reported crypto fraud. Contacts them unsolicited with promises of recovery. Charges upfront fees, then disappears or escalates with more fees.

How to Detect

Unsolicited contact. Guarantees recovery — no legitimate investigator can guarantee this. Upfront fees before any work. Claims to work with FBI or Interpol. Accepts payment in crypto only.

Pump and Dump
Scam / Fraud

A market manipulation scheme where organizers accumulate a low-cap token, then artificially inflate its price through coordinated buying, social media hype, and fake volume — then sell ("dump") their holdings at the peak, crashing the price and leaving other investors with losses.

How It Works

Organizers accumulate token quietly. Coordinated Telegram/Discord groups buy simultaneously. Social media hype amplifies price spike. Organizers sell at peak. Price collapses. Latecomers hold worthless tokens.

How to Detect

Sudden price spike on low-volume token. Heavy promotion in Telegram/Discord groups. Anonymous promoters. No fundamental use case. Trading volume concentrated in short timeframe.

Fake Exchange / Investment Platform
Scam / Fraud

A fraudulent website or app designed to look like a legitimate cryptocurrency exchange or investment platform. Victims deposit funds and see fake balances showing profits. When they attempt to withdraw, they're told they owe taxes, fees, or other charges — which are just additional theft mechanisms.

How It Works

Platform clones legitimate exchange branding or creates convincing original UI. Victim deposits crypto, sees fake profits displayed. Withdrawal attempts trigger fee demands. Platform eventually disappears entirely.

How to Detect

Platform not listed on CoinGecko or CoinMarketCap. Domain registered recently. Withdrawal requires additional payment. No verifiable company registration. Only accessible via link from scammer.

Phishing
Scam / Fraud

A social engineering attack where victims are tricked into revealing seed phrases, private keys, or login credentials through fake websites, emails, or messages impersonating legitimate services — exchanges, wallets, or support teams.

How It Works

Victim receives urgent email or message about account problem. Link leads to fake website mimicking legitimate service. Victim enters credentials or seed phrase. Attacker drains wallet immediately.

How to Detect

Urgency and fear tactics. URL slightly different from legitimate domain. Requests for seed phrase — no legitimate service ever needs this. Unsolicited contact claiming account issues.

Wallet Approval / Drainer Scam
Scam / Fraud

A smart contract attack where a victim is tricked into signing a transaction that grants unlimited approval for a malicious contract to spend their tokens. Common in fake NFT mints, fake airdrop claims, and malicious DeFi sites.

How It Works

Victim connects wallet to malicious site. Site requests token approval transaction. Victim signs without checking what they're approving. Attacker immediately calls the approval to drain all approved tokens.

How to Detect

Always read what a wallet approval transaction is granting. Use revoke.cash to check and revoke existing approvals. Never sign approvals on unfamiliar sites. Unlimited approval requests are almost always malicious.

SIM Swap Attack
Scam / Fraud

An attack where a criminal convinces a mobile carrier to transfer a victim's phone number to a SIM card the attacker controls. This allows them to intercept SMS-based two-factor authentication codes and gain access to exchange accounts and wallets.

How It Works

Attacker uses personal info from data breaches or social engineering to impersonate victim at mobile carrier. Carrier transfers number to attacker's SIM. Attacker uses SMS 2FA codes to access crypto accounts and initiates withdrawals.

How to Detect

Sudden loss of mobile service. Exchanges or accounts sending unexpected 2FA codes. Use authenticator apps (not SMS) for 2FA. Set a carrier PIN to prevent unauthorized SIM transfers.

Blockchain Forensics Terms

Transaction Graph Analysis
Forensics

A forensic technique that maps the complete flow of funds across the blockchain — tracking every transaction from origin through intermediate wallets to final destination. The resulting graph shows exactly how money moved, how it was split or consolidated, and where it ultimately ended up.

How It Works

Starting from a known transaction hash, investigators trace every output to subsequent transactions, building a directed graph of fund flows. Each node is a wallet address; each edge is a transaction. The graph is followed until funds reach an identifiable endpoint.

Application

Used to trace stolen funds from victim wallet to exchange deposit, document the complete chain of custody for court submission, and identify all wallets involved in a fraud operation.

Wallet Clustering
Forensics

The process of grouping multiple wallet addresses that are likely controlled by the same entity, based on behavioral patterns, transaction inputs, timing analysis, and address reuse. Clustering reduces a sprawling network of hundreds of wallets to a manageable set of actors.

How It Works

Common input ownership heuristic: if two addresses are inputs to the same transaction, they're likely controlled by the same entity. Change address analysis, timing patterns, and cross-transaction behavior reinforce cluster assignments.

Application

Identifies that 50 wallets involved in a fraud are all controlled by one actor. Establishes the full scope of criminal activity and supports entity-level attribution rather than address-level tracing.

Entity Attribution
Forensics

The process of linking a wallet cluster to a known real-world entity — an exchange, a darknet market, a sanctioned address, or a previously identified criminal organization. Attribution converts an anonymous address into a named actor.

How It Works

Clusters are matched against databases of known entity addresses (exchanges, services, sanctioned wallets). OSINT correlation links behavioral patterns to off-chain identifiers. Exchange KYC data obtained through legal process completes the attribution.

Application

Tells investigators whether stolen funds went to Binance, a known fraud operation, or a previously identified criminal wallet. Determines the subpoena target and the strength of the legal case.

Chain of Custody (Digital)
Forensics

The documented record of how digital evidence was collected, preserved, analyzed, and reported — establishing that evidence has not been tampered with and is admissible in legal proceedings. In blockchain forensics, chain of custody includes documentation of every transaction hash, wallet address, timestamp, and methodology step.

How It Works

Every finding is documented with its source (blockchain explorer URL, transaction ID), timestamp, and the analytical step that produced it. Methodology is documented so conclusions can be independently reproduced from public blockchain data.

Application

Required for blockchain evidence to be admissible in court. A forensic report without documented methodology cannot survive cross-examination and may be excluded as evidence.

OSINT (Open Source Intelligence)
Forensics

The collection and analysis of publicly available information to support an investigation. In blockchain forensics, OSINT bridges the gap between on-chain wallet addresses and real-world identities — using social media, domain records, forum posts, and other public sources.

How It Works

Wallet addresses found in public forum posts, social media, or scam databases are linked to usernames. Usernames are cross-referenced across platforms. Email addresses from domain registrations, IP addresses from platform records, and social media metadata all contribute to identity resolution.

Application

Connects an anonymous blockchain address to a real person or organization. Most effective when combined with exchange KYC data obtained through legal process.

Blockchain Intelligence
Forensics

The systematic analysis of on-chain transaction data to identify illicit activity, map criminal networks, and produce actionable intelligence. Broader than forensics — includes proactive monitoring, threat actor profiling, and pattern recognition across multiple cases.

How It Works

Combines transaction graph analysis, wallet clustering, entity attribution, and OSINT to build comprehensive profiles of criminal actors and operations. Used by law enforcement, compliance teams, and private investigators.

Application

Powers law enforcement investigations, exchange AML compliance, sanctions screening, and private fraud investigations. See our full guide: What is Blockchain Intelligence?

Money Laundering & Obfuscation

Crypto Mixer / Tumbler
Laundering

A service that pools cryptocurrency from multiple users and redistributes equivalent amounts to different addresses, breaking the direct transaction link between sender and receiver. Used by criminals to obscure the origin of illicit funds.

How It Works

User deposits funds to mixer. Mixer pools with other deposits and sends different coins from the pool to the specified output address. The on-chain link between input and output is broken. Bitcoin mixers use CoinJoin; ETH mixers include Tornado Cash (OFAC sanctioned).

How Investigators Trace It

Timing analysis, amount correlation, and graph heuristics can probabilistically link mixer inputs to outputs. Not impossible — just harder than direct tracing. Tornado Cash usage is also flagged by exchange compliance systems.

Chain Hopping
Laundering

Moving funds across multiple blockchains via bridges or cross-chain swaps to complicate forensic tracing. A common laundering pattern in large crypto fraud operations — funds may move from Bitcoin to Ethereum to Tron across multiple hops.

How It Works

Funds converted using a cross-chain bridge (e.g., Wormhole, Stargate) or a centralized exchange used as a bridge. Each chain transition creates a new transaction graph requiring separate analysis tools.

How Investigators Trace It

Bridge transactions leave records on both source and destination chains. Investigators match the bridge deposit on one chain to the corresponding output on the destination chain, continuing the trace.

Wallet Fan-Out
Laundering

A laundering technique where stolen funds are immediately split across many wallets after receipt to reduce traceability and complicate investigation. A single theft may fan out to 50 or 100 wallets within minutes.

How It Works

Immediately after receiving stolen funds, the scammer sends small amounts to dozens of new wallets. These sub-wallets may fan out further before eventually consolidating to an exchange deposit address.

How Investigators Trace It

Despite appearing complex, fan-out patterns typically reconsolidate. Following all branches of the fan-out usually leads to a limited number of exchange deposit addresses — the actual endpoints.

Layering
Laundering

The second stage of money laundering — moving funds through multiple transactions, conversions, and accounts to obscure their origin. In crypto, layering involves combinations of mixing, chain hopping, DEX swaps, and wallet fan-out.

How It Works

After placement (receiving stolen funds), criminals add multiple layers of transactions to distance the funds from their origin. More layers = more investigative work required, but the blockchain record remains for each step.

How Investigators Trace It

Each layer leaves a permanent on-chain record. Systematic tracing follows every layer until funds reach an identifiable endpoint. Complex layering takes more time but is rarely impossible on transparent blockchains.

Privacy Coin
Laundering

A cryptocurrency designed to provide transaction privacy by obscuring sender, receiver, and amount information. Monero (XMR) is the most widely used privacy coin and the most significant obstacle to blockchain tracing.

How It Works

Monero uses ring signatures, stealth addresses, and RingCT to hide transaction details from external observers. Unlike Bitcoin or Ethereum, Monero transactions are not publicly traceable on the blockchain.

Investigative Limitation

If funds are converted to Monero, on-chain tracing ends at that conversion point. Investigation shifts to the exchange or OTC desk that processed the conversion — attempting to obtain KYC data through legal process.

DeFi & Smart Contract Exploits

Flash Loan Attack
DeFi / Exploit

An attack exploiting uncollateralized loans that must be borrowed and repaid within a single blockchain transaction. Attackers borrow massive amounts of capital, manipulate prices across protocols, and repay the loan — all in one transaction — leaving the targeted protocol with losses.

How It Works

Attacker borrows millions in a flash loan. Uses borrowed capital to manipulate an oracle price or drain a liquidity pool. Repays the loan. Keeps the profit from the manipulation. All within one atomic transaction.

How to Detect

Unusual single-transaction price movements. Large flash loan borrows on-chain. Smart contract audits that check for oracle manipulation vulnerabilities. Time-weighted average price (TWAP) oracles resist manipulation.

Reentrancy Attack
DeFi / Exploit

A smart contract vulnerability where a malicious contract repeatedly calls back into a target contract before the first execution completes — draining funds in a loop. The DAO hack (2016), which led to the Ethereum hard fork, was a reentrancy attack.

How It Works

Attacker's contract calls withdraw function. Before the target contract updates its balance, the attacker's contract calls withdraw again. This repeats until the target contract is drained.

How to Detect

Smart contract audits checking for checks-effects-interactions pattern violations. Reentrancy guards in contract code. Unusual recursive call patterns in transaction traces.

Bridge Exploit
DeFi / Exploit

An attack targeting cross-chain bridge protocols — the infrastructure that allows assets to move between blockchains. Bridge exploits have been among the largest individual crypto thefts, with single incidents exceeding $600 million.

How It Works

Attacker finds a vulnerability in bridge smart contract logic, validator consensus, or signature verification. Exploits it to mint unbacked tokens on the destination chain or drain the bridge's liquidity reserves.

How to Detect

Bridge contracts should be heavily audited. Unusual minting activity on destination chain. Large outflows from bridge liquidity pools. Multi-sig validator controls reduce single point of failure risk.

Technical Attack Methods

Seed Phrase Theft
Technical

The theft of a wallet's 12 or 24-word recovery phrase, which grants complete and permanent control over all assets in that wallet. Anyone with the seed phrase owns the wallet — there is no recovery mechanism once a seed phrase is stolen.

How It Works

Obtained via phishing sites, fake wallet apps, fake support agents, malware, or social engineering. Once entered into an attacker-controlled site or transmitted digitally, the wallet is compromised immediately.

How to Detect

No legitimate service ever needs your seed phrase. Never enter it on a website. Never share it digitally. Store offline only. If you've entered it anywhere suspicious, move funds immediately to a new wallet.

Clipboard Hijacking
Technical

Malware that monitors the clipboard for cryptocurrency addresses and silently replaces them with an attacker-controlled address. Victims copy what they believe is the correct destination address, paste it, and send funds directly to the attacker.

How It Works

Malware runs silently in the background. When a cryptocurrency address is detected in the clipboard, it's replaced with the attacker's address. Victim sends transaction believing it's going to the correct destination.

How to Detect

Always verify the first and last several characters of a pasted address before sending. Compare clipboard address to source. Use hardware wallets that display the destination address for verification.

Dusting Attack
Technical

An attack where tiny amounts of cryptocurrency ("dust") are sent to many wallet addresses. If the recipient later spends that dust in a transaction combined with other funds, it can allow the attacker to de-anonymize the wallet by linking addresses together.

How It Works

Attacker sends dust to target addresses. If target spends the dust as an input alongside other known addresses, common input ownership heuristics link the addresses, revealing the target's broader wallet cluster.

How to Detect

Small unexpected deposits from unknown sources. Don't spend dust transactions — mark them as "do not spend" in wallet software. Use coin control features to avoid including dust in transactions.

KYC (Know Your Customer)
Forensics

Identity verification requirements that regulated financial institutions — including cryptocurrency exchanges — must apply to their customers. KYC data typically includes name, address, government ID, and sometimes source of funds documentation.

Relevance to Investigations

When stolen funds reach a KYC-compliant exchange deposit address, that account has identity data attached to it. Law enforcement can subpoena this data to identify the account holder. This is why identifying the exchange deposit is the primary goal of most forensic traces.

Application

KYC data is the bridge between an anonymous blockchain address and a real-world identity. It's obtained through legal process — subpoena, court order, or voluntary disclosure in civil matters.

MLAT (Mutual Legal Assistance Treaty)
Forensics

A bilateral or multilateral agreement between countries that allows law enforcement agencies to share evidence and cooperate in criminal investigations across borders. Relevant when stolen crypto is traced to an exchange operating in a foreign jurisdiction.

How It Works

US law enforcement submits an MLAT request to the target country's central authority. That authority compels local entities — including exchanges — to provide the requested information. Response timelines vary from weeks to months.

Application

Essential for crypto fraud cases where funds reach exchanges in Singapore, Seychelles, Malta, or other common crypto jurisdictions. A forensic report identifying the specific exchange and account is the predicate for an effective MLAT request.

TRO (Temporary Restraining Order)
Forensics

An emergency court order that freezes assets pending further legal proceedings. In crypto fraud cases, TROs can be used to freeze exchange accounts before stolen funds are withdrawn — requiring swift action and strong forensic evidence.

How It Works

Plaintiff's attorney files an emergency motion with forensic evidence showing funds at a specific exchange account. Court issues TRO ordering the exchange to freeze the account. Exchange complies, preserving funds for recovery.

Application

Time-critical — funds can be withdrawn quickly. A forensic investigation identifying the exchange deposit address as early as possible maximizes the window for TRO action.

Encountered One of These in Your Case?

A blockchain forensic investigator can trace what happened to your funds, identify who was behind it, and produce documentation your attorney or law enforcement can act on. Free consultation — no commitment.

Zack Coffing — Wallet Witness

Independent blockchain forensic investigator. ETH/EVM expert covering BTC, USDT, SOL, BNB, and all major chains. Specializing in crypto fraud investigation and digital asset tracing since 2017. Learn more →