Security

How Beginners Can Spot Crypto Scams and Phishing Sites

Identify fake support, fake exchanges, guaranteed returns, malicious wallet approvals, and phishing messages.

How Beginners Can Spot Crypto Scams and Phishing Sites

How to Spot Crypto Scams

Most scams do not break a blockchain. They exploit urgency, greed, fear, and trust in support staff until a user voluntarily hands over a password, 2FA code, recovery phrase, or funds.

Seven warning signs

  1. Guaranteed profit or capital protection.
  2. An unsolicited message from supposed support, an analyst, or a friend.
  3. A request for a password, 2FA code, private key, recovery phrase, or remote device access.
  4. Pressure to transfer immediately before an account is supposedly frozen.
  5. A domain that resembles the official one but contains an extra letter, hyphen, or unfamiliar ending.
  6. A demand for tax, collateral, or an unlock fee before withdrawal.
  7. A request to sign a wallet approval you cannot explain.

How phishing sites work

A fake site copies an exchange or wallet interface and captures credentials. Do not log in through ads, unsolicited email, or direct messages. Verify the official domain once, bookmark it, and return through the bookmark. A password manager refusing to autofill can be a warning that the domain is different.

Fake support and impersonation

Legitimate support does not need your recovery phrase or private key. When a message claims there is a security problem, do not use its link. Open your saved official site and verify through support inside your account. Knowing your name, email, or part of a transaction does not prove identity.

Investment groups and profit screenshots

Profit screenshots, countdowns, and testimonials are easy to fabricate. Any arrangement that asks you to send money to a personal address, managed account, or unknown platform is high risk. A successful small withdrawal does not prove safety; fraudsters may allow it to encourage a larger deposit.

Wallet approvals

Connecting a wallet may not move funds immediately, but an approval can let a contract transfer tokens later. Verify the site, network, contract, and approval amount. Reject anything you do not understand and revoke permissions you no longer use.

If a message looks suspicious

  • Stop replying and do not download files.
  • Use an official bookmark to review devices, withdrawals, and API activity.
  • Change exposed passwords and revoke suspicious sessions.
  • If a recovery phrase may be exposed, create a new wallet on a trusted device and move remaining assets safely.
  • Preserve URLs, times, transaction hashes, and screenshots for the platform and relevant authorities.

A 30-second verification routine

Pause before every login, signature, or transfer. Ask who initiated the action, whether you reached the site independently, what permission is being requested, and what the irreversible result could be. Read the full domain from right to left, compare it with your saved official address, and verify unusual requests through a second channel. Never let a countdown or a support agent rush this routine. If any answer is unclear, close the page and investigate from a clean browser session. Walking away from a legitimate action for five minutes is usually harmless; approving a fraudulent action may be permanent.

Official sources

Last reviewed: 2026-07-19.