← Back to Prevention

Most Prevalent Crypto Scams in 2026

A current field guide to the categories of crypto fraud most likely to hit you or someone in your family this year — what each looks like, why it works, and the single defensive habit that stops it.

Crypto scam taxonomies change every year. The specific platforms, the specific tokens, the specific impersonated brands — all rotate constantly. But the underlying categories are stable. Knowing them lets you pattern-match a new scam before you know its specific name, because the mechanics will always be a variation on one of these themes.

Below is what is actually landing in our intake in 2026, ranked roughly by dollar volume we see across client cases, not by total incident count.

1. Pig-Butchering (Romance-Investment Fraud)

What it is: A long-con scam that starts with a "wrong number" text, dating app match, or friendly DM. Over weeks, the target becomes emotionally invested in the contact — typically portrayed as a successful young professional. The contact eventually mentions a "uncle," "cousin," or "trading platform" that has been very profitable, and invites the victim to try it.

Why it works: The scam is not the investment — it is the relationship. By the time money is discussed, trust is already built. The fake trading platform shows real-looking gains, sometimes allows a small withdrawal to build confidence, and then freezes larger withdrawals behind "tax" or "verification" demands. Average completed case: $100,000–$1,500,000.

Defense: Treat any unsolicited contact that evolves into an investment suggestion as a scam until proven otherwise. Reverse image search photos. Never send crypto to a platform only your romantic or friendly contact has introduced you to.

2. Fake Exchange / Wallet Support

What it is: The victim searches Google for "Coinbase support," "MetaMask help," or a similar term and clicks a promoted ad or forum thread leading to an impersonator. The "support agent" walks them through installing remote-access software, entering their seed phrase on a fake verification page, or approving malicious smart contracts.

Why it works: Panic. People hit the support channels when they are already scared — a missing transaction, a locked account, a login failure. That state bypasses the skepticism they would normally apply.

Defense: Reach support through the official app or the address bar (typed manually, not searched). Never share a seed phrase. Never install software a support agent asks you to.

3. Approval Phishing

What it is: On EVM chains (Ethereum, Base, Arbitrum, BSC, Polygon), a user connects their wallet to a site that asks them to "sign" a transaction. The signature is not a transfer — it is a token approval that grants a malicious contract permission to move an unlimited amount of specific tokens (usually USDC, USDT, or WETH) out of the user's wallet. The drain happens later, when the user's balance is highest.

Why it works: The signing request looks innocuous. Wallet UIs are getting better at warning about this, but the warnings are still bypassed by users who want the free airdrop or the "claim" the site promises.

Defense: Read approval amounts before signing. Use revoke.cash or similar tools quarterly to clear old approvals. Never connect your main holdings wallet to an unfamiliar site — use a separate hot wallet.

Key Distinction

A "transaction" in your wallet moves funds directly. A "signature" or "approval" authorizes someone else to move your funds in the future. Signatures have drained more wallets than direct transfers because users think they are harmless.

4. Address Poisoning

What it is: A scammer generates a wallet address that matches the first 4–6 and last 4–6 characters of an address the victim has recently sent to. They then send a tiny (dust) transaction from that lookalike address to the victim's wallet. When the victim next goes to send funds and copies an address from their recent transaction history, they accidentally copy the scammer's lookalike and send to it.

Why it works: Most users verify addresses by checking the first and last few characters. The middle portion, which is what actually differs, is rarely checked.

Defense: Copy addresses only from trusted sources (the counterparty's own message, a saved address book). Never copy an address from your transaction history. Always verify at least 8–10 characters in the middle of the address.

5. Rug Pulls and Fake Presales

What it is: A new token is promoted aggressively on Twitter, Telegram, or TikTok. Early buyers see rapid gains as the team coordinates hype. At a planned moment, the developers drain liquidity and disappear, leaving holders with worthless tokens.

Why it works: The social proof of a rapidly appreciating price overrides skepticism, and memecoin culture has normalized buying tokens with no real utility or team accountability.

Defense: Do not buy new tokens with money you cannot afford to lose entirely. Check liquidity lock status on DexScreener or similar. Be especially wary of presales — by the time retail can buy, the scam is usually set up.

6. Fake Celebrity / Brand Giveaways

What it is: "Elon Musk," "Vitalik," "MicroStrategy," or a brand's "official" account runs a giveaway: "Send 1 ETH, get 2 ETH back." Often uses AI-generated video or hijacked verified accounts.

Why it works: The impersonation quality is now very high. AI-generated video of real executives is hard to distinguish without side-by-side reference.

Defense: Absolute rule — no legitimate entity has ever, in the history of crypto, doubled funds sent to them. Any "send X, get 2X back" offer is fraud. Full stop.

7. Employment and Task Scams

What it is: A "recruiter" offers a part-time job rating hotels, liking TikTok videos, or completing simple tasks. Early tasks pay out small amounts. Later tasks require depositing crypto into the "work account" to unlock higher-tier tasks. Withdrawals are blocked behind escalating tax and fee demands.

Why it works: Targets people seeking supplemental income. The early payouts build trust before the losses start. See our full breakdown of task scams and side-gig fraud for the full operation.

Defense: No legitimate job requires you to send your own money to the employer to "unlock" pay. Ever.

8. Recovery Scams Targeting Prior Victims

What it is: People who have already lost crypto are contacted by "recovery specialists" who promise to get the funds back for an upfront fee. See our dedicated guide on how to avoid being scammed again.

9. SIM Swap Attacks

What it is: An attacker social-engineers or bribes a telecom employee into porting the victim's phone number to an attacker-controlled SIM. Incoming SMS 2FA codes route to the attacker, who then resets exchange and email passwords and drains accounts.

Defense: Use hardware-key 2FA (YubiKey) instead of SMS. Set a PIN with your carrier that is required for any SIM change.

10. Malicious Smart Contracts (NFT Airdrops, Fake DEX Aggregators)

What it is: A wallet receives an unexpected NFT or token airdrop. Interacting with it — even trying to sell or transfer it — triggers a malicious contract that drains approved tokens. Similar mechanics exist on fake DEX aggregators that route trades through attacker-controlled pools.

Defense: Do not interact with unexpected assets that arrive in your wallet. Hide them. Never sign transactions originating from tokens you did not acquire deliberately.

The Common Thread

Look across all ten categories and one pattern dominates: the scam asks you to take an action quickly, on a platform or interface you did not independently seek out, with someone you met recently or are under emotional pressure from. Every category has a different mechanism, but that triad — unfamiliar platform, recent contact, time pressure — appears in almost every one. Train yourself to freeze when all three are present, and you will block the majority of scams before they reach the step where you lose money. If you're unsure, use the am I being scammed checklist and review the crypto safety best practices guide.