Crypto phishing scams fall into five primary categories: signature phishing, credential phishing, impersonation phishing, lookalike-domain attacks, and transfer-based attacks. Each category exploits a different vulnerability, whether that is a user’s trust in a familiar interface, their habit of copying wallet addresses, or their willingness to approve what looks like a routine transaction. Cryptocurrency-related scams caused reported losses exceeding $5.6 billion in the United States in 2023 alone, a figure that reflects only what victims actually reported to the FBI’s Internet Crime Complaint Center. The real number is almost certainly higher.
Here is a quick-reference breakdown of the five core crypto phishing scam categories:
- Signature phishing: Tricks users into signing malicious smart contract permissions that grant attackers permanent wallet access, often disguised as routine dApp interactions.
- Credential phishing: Harvests exchange login credentials through fake websites, spoofed emails, or fraudulent customer support channels.
- Impersonation phishing: Attackers pose as trusted entities, including exchanges, government agencies, or crypto celebrities, to extract funds or sensitive information.
- Lookalike-domain attacks: Fraudulent websites that closely mimic legitimate platforms, differing by a single character or using alternate top-level domains to deceive users.
- Transfer-based attacks: Manipulate users into sending funds directly to attacker-controlled wallets, often through address poisoning or fake withdrawal instructions.
Understanding these categories is the first step toward protecting your assets. The sections below go deeper into each type, the technical mechanics behind them, and what legal recourse looks like when things go wrong.
1. The main crypto phishing scam categories explained
Crypto phishing attacks are categorized as of 2026 into five major types, each targeting a different point of failure in the user’s interaction with blockchain technology.

Signature phishing
Signature phishing is currently the most technically sophisticated category. Attackers present users with what appears to be a standard wallet approval request, but the underlying transaction grants the attacker unlimited access to one or more token contracts. Because the approval happens off-chain in many cases, there is no immediate on-chain signal that anything went wrong. The drain executes later, often hours or days after the victim signed. Permit-signature drainers work exactly this way: they obtain wallet asset control through off-chain approvals, evading typical detection until the drain is already complete.

Credential phishing
Credential phishing targets centralized exchange accounts rather than wallets directly. A convincing fake login page, a spoofed support email, or a fraudulent two-factor authentication prompt captures the victim’s username, password, and sometimes their authenticator codes. Once attackers have those credentials, they log in, disable security settings, and withdraw funds before the victim notices anything unusual.
Impersonation phishing
This category covers a wide range of deceptions. Attackers impersonate exchange support teams, government regulators, well-known crypto figures, or even law enforcement. The FTC has documented cases where scammers impersonate Amazon, Microsoft, and major financial institutions, directing victims to buy cryptocurrency and send it to a wallet address for “safekeeping.” The common thread is manufactured authority: the victim believes they are responding to a legitimate demand.
Lookalike-domain attacks
A lookalike domain might substitute a lowercase “l” for an uppercase “I,” swap “.com” for “.io,” or add a hyphen to a trusted brand name. Victims who do not scrutinize the URL bar carefully will enter their credentials or connect their wallets without realizing the site is fraudulent. Compromised Discord and Twitter accounts are frequently used to distribute links to these fake domains, lending them an air of legitimacy because the message appears to come from a trusted community source.
Transfer-based attacks
Transfer-based attacks include address poisoning, also called zero-value transfers. An attacker sends a tiny transaction from an address that visually resembles the victim’s own wallet address or a frequently used recipient address. When the victim later copies an address from their transaction history, they may inadvertently copy the attacker’s address instead. The resulting transfer is irreversible. This attack requires no malware and no credential theft; it exploits a single behavioral habit.
2. Common crypto scam typologies you need to recognize
Beyond the five core phishing categories, a broader set of fraud schemes regularly victimizes crypto holders. Many of these overlap with phishing techniques or use phishing as an entry point.
1. Romance scams and pig butchering
Pig butchering is a long-con investment fraud that begins with a fabricated romantic or friendly relationship, typically initiated on dating apps or social media. The attacker spends weeks or months building trust before introducing a “can’t-miss” crypto investment opportunity. Victims are directed to a fraudulent trading platform that displays convincing fake profits. When they attempt to withdraw, the platform demands fees, taxes, or “verification deposits” that never unlock the funds. The California DFPI’s crypto scam tracker documents cases where victims lost tens of thousands of dollars through platforms that vanished entirely after collecting funds.
2. Fake investment platforms and fraudulent ICOs
Scammers build polished websites, fabricate celebrity endorsements, and promise guaranteed returns to lure victims into depositing cryptocurrency. The FTC is explicit: no legitimate investment guarantees profit, and no legitimate business demands payment exclusively in cryptocurrency. Fraudulent initial coin offerings follow the same pattern, issuing worthless tokens while collecting real funds from investors who believe they are getting in early on a legitimate project.
3. Rug pulls
A rug pull occurs when developers of a new token or DeFi protocol attract significant investment, then abruptly withdraw all liquidity and disappear. Unlike a traditional exit scam, rug pulls often use technically legitimate smart contracts that simply include a hidden function allowing the developers to drain the pool. Victims are left holding tokens with no liquidity and no recourse against anonymous developers.
4. Ponzi and pyramid schemes
Crypto Ponzi schemes pay early investors with funds from later participants, creating the illusion of a profitable strategy. They collapse when new investment slows and the operator can no longer sustain payouts. The SEC and CFTC have both brought enforcement actions against crypto Ponzi operators, though prosecuting these cases is complicated by the pseudonymous nature of blockchain transactions and the frequent use of offshore entities.
5. Airdrop scams
Fake airdrop announcements promise free tokens to users who connect their wallets to a claiming site. That site requests a token approval that grants the attacker access to the victim’s holdings. The “free tokens” are worthless; the approval is the actual payload. Token approvals disguised as routine wallet actions have been the dominant phishing vector since 2022.
6. Wallet drainer malware
Drainer-as-a-service kits are sold on dark web marketplaces and allow technically unsophisticated attackers to deploy professional-grade wallet draining tools. These kits generate phishing sites, manage approval requests, and automatically transfer drained assets to the operator’s wallet. The victim’s only interaction is clicking a link and connecting their wallet.
7. Pump-and-dump schemes
Coordinated groups artificially inflate the price of a low-liquidity token through social media hype, then sell their holdings at the peak, crashing the price. Victims who bought during the pump are left with near-worthless assets. This is a form of market manipulation that the CFTC actively investigates in the crypto space.
8. Deepfake and AI impersonation scams
Attackers now use AI-generated video and audio to impersonate executives, celebrities, and financial advisors in live video calls or pre-recorded promotional content. A victim who believes they are speaking with a real person is far more likely to transfer funds or reveal sensitive information. This category is growing rapidly as deepfake technology becomes cheaper and more accessible.
9. Crypto ATM scams
Government impersonators and tech support fraudsters frequently direct victims to physical cryptocurrency ATMs, instructing them to deposit cash and send the resulting crypto to a QR code the scammer provides. The FTC notes that scammers sometimes stay on the phone throughout the entire transaction, coaching victims step by step. Once the transaction confirms, the funds are gone.
10. Extortion and blackmail scams
Attackers send emails claiming to possess compromising photos, videos, or personal data, then demand payment in cryptocurrency to prevent public release. The FBI’s Internet Crime Complaint Center classifies this as criminal extortion and advises victims to report it immediately rather than pay.
Pro Tip: If a platform shows profits but blocks withdrawals unless you pay a fee, that fee demand is the scam itself. Legitimate platforms never require upfront payments to release your own funds.
Why crypto phishing scams are uniquely effective
Crypto phishing succeeds at rates that would be impossible in traditional banking, and the reasons are structural, not accidental.
Blockchain transactions are irreversible. A bank wire can sometimes be recalled; a confirmed on-chain transfer cannot. This removes the safety net that exists in conventional finance and raises the stakes of every interaction a user has with their wallet. Attackers know this and design their attacks to force fast decisions before victims have time to verify.
Wallet interfaces were not designed with phishing resistance in mind. Approval prompts often display technical contract addresses rather than plain-language descriptions of what the user is actually authorizing. A prompt asking a user to “approve unlimited USDC” looks nearly identical to a legitimate dApp interaction, even when it is granting an attacker permanent access to every token in that contract. Sophisticated phishing uses legitimate interfaces and transaction flows, making malicious acts look like normal dApp interactions.
Web3 wallets function as a kind of unfiltered inbox. Malicious tokens, NFTs with embedded phishing links, and zero-value poisoning transactions arrive directly in a user’s wallet with no spam filter, no sender verification, and no warning. The attack surface is the wallet itself.
Key factors that amplify phishing risk in crypto:
- Urgency engineering: Attackers create artificial time pressure (“your account will be suspended,” “claim expires in 10 minutes”) to prevent careful verification.
- Trust exploitation: Phishing messages arrive through compromised official channels, including verified social media accounts, making them appear credible.
- Routine behavior targeting: Address poisoning specifically exploits the habit of copying addresses from transaction history rather than re-entering them manually.
- Off-chain invisibility: Permit-signature attacks leave no on-chain trace until the drain executes, giving victims no early warning.
Pro Tip: Before signing any wallet transaction, expand the full contract details and check the “approved spender” address against the official contract address published on the project’s verified website. A mismatch is a definitive red flag.
How to recognize and protect yourself from crypto phishing
Recognizing a phishing attempt before you act on it is the only reliable defense. Crypto transactions do not have a recall button.
Red flags that indicate a phishing attempt:
- A URL that differs from the official domain by even one character, hyphen, or top-level domain extension.
- Any request for your seed phrase or private key. No legitimate platform, wallet, or support team will ever ask for these.
- Unexpected token approval requests, especially those requesting “unlimited” access to a specific contract.
- Unsolicited messages offering airdrops, investment opportunities, or account alerts through Discord, Telegram, or social media.
- Withdrawal fees demanded before you can access funds you have already deposited.
- Pressure to act immediately, with warnings of account suspension or expiring offers.
Behavioral habits that reduce your risk:
- Bookmark the official URLs of every exchange and dApp you use. Never navigate to them through search results or links in messages.
- Verify contract addresses on a block explorer before approving any transaction.
- Use a hardware wallet for significant holdings. Hardware wallets require physical confirmation of every transaction, making remote approval phishing far more difficult.
- Regularly audit your active token approvals using tools like Revoke.cash and revoke permissions you no longer need.
- Treat every unsolicited message about your crypto holdings as a potential phishing attempt, regardless of the apparent sender.
If you have already lost funds to a phishing attack, the first step is to document everything: transaction hashes, wallet addresses, communications, and platform URLs. That documentation is the foundation of any legal recovery effort. Report the incident to the FBI’s Internet Crime Complaint Center at ic3.gov, the FTC at reportfraud.ftc.gov, and the CFTC or SEC if the scam involved investment products.
Expert legal perspective on crypto phishing and victim recovery
Crypto phishing victims face a legal environment that is genuinely difficult to navigate without professional guidance. The pseudonymous nature of blockchain transactions, the frequent use of offshore infrastructure, and the irreversibility of on-chain transfers all create obstacles that do not exist in conventional fraud cases.
Liam Murphy has litigated matters involving Celsius, Terraform Labs, and BitMEX, and maintains an active docket of crypto fraud and recovery cases. His firm, Murphyslawcrypto, is a licensed law firm with real courtroom experience, not a recovery service operating outside regulatory oversight.
Key legal considerations for phishing victims:
- Civil litigation can target identifiable defendants, including domestic exchanges that processed stolen funds, through subpoenas and asset freezing orders.
- Regulatory complaints to the SEC, CFTC, and FinCEN can trigger investigations that produce evidence useful in parallel civil cases.
- Wire fraud statutes apply to many crypto phishing schemes, particularly those involving U.S.-based victims or infrastructure. Understanding wire fraud in crypto is critical before deciding on a legal strategy.
- Secondary scams targeting victims are pervasive. Unregulated “crypto recovery services” that promise to retrieve stolen funds for an upfront fee are almost always scams themselves.
- Realistic expectations matter. Full recovery is not guaranteed, but partial recovery through civil judgment, exchange cooperation, or regulatory action is achievable in cases where the attacker’s identity or domestic assets can be established.
The multi-jurisdiction regulatory environment for crypto fraud is evolving rapidly in 2026, with new enforcement frameworks emerging across the U.S., EU, and Asia-Pacific. That evolution creates both new tools for victims and new complexity in cross-border cases.
Real-world incidents that illustrate each phishing category
Concrete cases show how these attacks operate in practice, not just in theory.
Signature phishing: The BadgerDAO exploit in late 2021 involved a malicious script injected into the protocol’s front end that inserted attacker-controlled addresses into token approval requests. Users who approved what appeared to be routine transactions unknowingly granted the attacker permission to drain their holdings. The attack resulted in losses of approximately $120 million.
Credential phishing: Multiple major exchanges have reported waves of phishing emails that replicate official communications with near-perfect accuracy, directing users to fake login pages that harvest credentials in real time. Attackers use those credentials immediately, often within minutes of capture, before the victim notices the unauthorized login.
Impersonation phishing: The California DFPI’s scam tracker documents a case involving a fraudulent trading platform that featured the likeness of a widely known crypto trader to attract victims. A family lost nearly $2 million after being directed to the platform through social media and trusting the fabricated celebrity endorsement.
Lookalike-domain attacks: In 2022, a wave of phishing attacks targeting Uniswap users used domains that differed from the official site by a single character. Victims who connected their wallets to these fake sites were presented with approval requests that drained their holdings entirely.
Transfer-based attacks (address poisoning): Blockchain analytics firms have documented coordinated address poisoning campaigns targeting high-value wallets. Attackers monitor the mempool for large transactions, then immediately send zero-value transfers from visually similar addresses to poison the victim’s transaction history. Several victims have confirmed losses of six figures or more after copying the wrong address.
How phishing attacks exploit crypto platform technology
The technical architecture of blockchain platforms creates specific attack surfaces that traditional phishing does not have access to.
Smart contract approval exploitation is the foundation of signature phishing. The ERC-20 token standard includes an approve() function that allows a third party to spend tokens on a user’s behalf, up to a specified limit. Attackers craft transactions that call this function with an unlimited allowance and their own wallet as the approved spender. The user sees a wallet prompt; they do not see the underlying function call unless they inspect the raw transaction data.
Permit signatures extend this attack off-chain. ERC-2612 introduced the permit() function, which allows token approvals to be signed off-chain and submitted later by anyone who holds the signature. A phishing site can collect a permit signature without triggering any on-chain transaction at the time of signing. The victim’s wallet shows no activity. The drain executes when the attacker submits the signature to the blockchain, which can happen at any time.
DeFi protocol front-end attacks inject malicious code into the user interface layer of legitimate protocols. Because DeFi protocols are accessed through web browsers, their front ends are vulnerable to DNS hijacking, CDN compromises, and malicious script injection. The underlying smart contract may be perfectly secure while the interface that users interact with has been compromised.
Fake wallet connection UIs display a realistic “Connect Wallet” interface that fails to connect and instead presents a form asking the user to enter their seed phrase manually to “resolve the connection error.” This exploits a common user experience frustration: wallets do sometimes fail to connect, and users who have encountered that problem before are primed to try alternative steps.
NFT-based phishing payloads arrive directly in a victim’s wallet as unsolicited token transfers. The NFT’s metadata or image contains a link to a phishing site, and the NFT itself may trigger a malicious script when the victim attempts to view or interact with it in certain wallet interfaces.
Emerging phishing categories targeting new crypto technologies
The attack surface for crypto phishing expands every time a new technology gains adoption. Several categories have emerged or accelerated significantly in the past two years.
NFT phishing has become a major vector as NFT marketplaces grew in prominence. Attackers list fraudulent NFTs, send unsolicited NFT transfers containing phishing links, or compromise official project Discord servers to post fake mint links. A victim who clicks a fake mint link and approves the transaction may unknowingly sign a drainer approval rather than a legitimate mint transaction.
Cross-chain bridge phishing targets users moving assets between blockchains. Bridge interfaces are complex, and users are accustomed to approving multiple transactions during a bridge operation. Attackers create fake bridge sites or inject malicious approvals into legitimate bridge flows, exploiting the user’s expectation that multiple approval steps are normal.
AI-generated phishing content has lowered the barrier to creating convincing fraud at scale. Attackers use large language models to generate personalized phishing emails, fake customer support conversations, and synthetic social media profiles that maintain consistent personas over weeks of interaction. The pig butchering playbook, which previously required human operators for each victim, is now partially automatable.
Governance attack phishing targets DeFi protocol participants who hold governance tokens. Attackers send fake governance proposals or voting notifications that direct token holders to a phishing site to “cast their vote.” The voting interface requests a token approval that drains the victim’s holdings.
The regulatory frameworks being developed across jurisdictions in 2026 are beginning to address some of these emerging vectors, particularly around exchange KYC/AML obligations that can help trace funds after an attack. But regulation moves slower than the technology, and the primary defense remains user awareness.
If you have lost funds to a crypto phishing scam
Murphyslawcrypto’s crypto fraud recovery litigation practice handles cases involving all of the phishing categories described in this guide. Liam Murphy, Esq. brings courtroom experience from matters involving Celsius, Terraform Labs, and BitMEX to every case on the firm’s docket. If you have been victimized, the firm can assess your recovery options, identify the appropriate legal strategy, and pursue civil or regulatory remedies on your behalf.

Do not contact an unregulated recovery service before speaking with a licensed attorney. The red flags of fraudulent recovery services closely mirror those of the original scams: upfront fees, guaranteed outcomes, and pressure to act immediately.
Key Takeaways
Crypto phishing scams succeed because blockchain transactions are irreversible, wallet interfaces lack plain-language warnings, and attackers exploit both technical vulnerabilities and human psychology simultaneously.
| Point | Details |
|---|---|
| Five core phishing categories | Signature, credential, impersonation, lookalike-domain, and transfer-based attacks cover the primary threat landscape. |
| $5.6 billion in U.S. losses | Reported crypto scam losses in the U.S. exceeded $5.6 billion in 2023, per the FBI’s IC3. |
| Permit signatures are invisible | Off-chain permit-signature drainers leave no on-chain trace until funds are already gone. |
| Act fast after an attack | Blockchain forensics can trace stolen funds, but the window for effective legal action narrows quickly. |
| Avoid unregulated recovery services | Fake recovery services are a secondary scam; consult a licensed attorney before taking any recovery steps. |
FAQ
What are the main signs of a crypto phishing attempt?
The clearest signs are requests for your seed phrase or private key, unexpected token approval prompts requesting unlimited access, URLs that differ from the official domain by even one character, and withdrawal fees demanded before you can access your own funds. Unsolicited messages about airdrops or account alerts through Discord or Telegram are also strong indicators.
What are the red flags that indicate a cryptocurrency scam?
Guaranteed returns, pressure to act immediately, platforms that show profits but block withdrawals, and any demand for payment exclusively in cryptocurrency are the defining red flags the FTC identifies. Legitimate investment managers never promise profit, and no government agency will ever ask you to buy crypto to resolve a legal problem.
How can you tell if someone is a crypto scammer?
A crypto scammer typically contacts you first, creates urgency, offers returns that sound too good to be true, and eventually asks you to send cryptocurrency or approve a wallet transaction. If an online contact you have never met in person introduces a crypto investment opportunity, that is a pig butchering setup regardless of how long the relationship has been cultivated.
Can stolen crypto be recovered through legal action?
Recovery is possible but not guaranteed. Civil litigation, regulatory complaints to the SEC or CFTC, and blockchain forensics can identify and freeze assets in some cases, particularly when stolen funds passed through a regulated domestic exchange. Consulting a licensed attorney quickly after an attack gives you the best chance of preserving evidence and pursuing viable claims.
What should you do immediately after a crypto phishing attack?
Document everything: transaction hashes, wallet addresses, communications, and platform URLs. Report the incident to the FBI’s Internet Crime Complaint Center at ic3.gov and the FTC at reportfraud.ftc.gov. Then consult a licensed crypto attorney before contacting any recovery service, since many recovery services are scams targeting the same victims a second time.