Safety
How Does a Crypto Scam Work? The Machine Behind the Story
Crypto scams are not improvised. They are a repeatable five-stage process — contact, credibility, control, extraction, exit — and every variant you have heard of is that same process wearing a different costume. Once you can see the stages, the costume stops mattering.
The question "how does a crypto scam work" usually gets answered with a list of story types: the romance one, the fake exchange one, the celebrity giveaway one. That is a description of the costumes, not the machine underneath. Every one of those stories runs the same five-stage process, in the same order, for the same reasons, and the process is far more useful to learn than the stories, because the stories change every few months and the process has not changed in fifteen years.
The five stages are contact, credibility, control, extraction and exit. A scammer must reach you, get you to believe something, get you to act inside a system they own, take the money in a form that cannot be reversed, and then disappear before the act is visible to you. Remove any one stage and the whole thing fails. That is genuinely good news, because you only have to break one link, and the easiest links to break are the earliest ones.
This guide works through the five stages in order, puts real numbers on a single worked case, gives a crypto scam list of the formats those stages get dressed in, explains the specific technical moves that make crypto the preferred medium, and covers how to report a crypto scam in the US once one has happened. If you want the most common variant in close detail first, our breakdown of doubling giveaway scams follows one from the first reply to the last transaction.
The five stages every crypto scam runs
1. Contact — volume, not targeting
The first stage is almost entirely automated and almost entirely free. A wrong-number text, a dating app match, a reply under a popular post, a Telegram invite, a sponsored search result, a comment on a YouTube livestream. Nobody chose you. Messages go out in the hundreds of thousands and the filtering is done by who responds, which is why the opening message often contains an obvious oddity — a strange name, a slightly wrong context. That oddity is a filter. People who query it are dropped; people who play along are worth a human operator's time.
2. Credibility — borrowed, never built
Nobody has time to build trust from scratch, so it gets borrowed from something you already trust. A cloned website on a near-identical domain. A verified-looking account renamed to match a known exchange. A deepfaked video of a public figure. A group chat full of "other investors" who are all the same operator. A dashboard showing your balance rising, which is simply a web page with a number on it, costing nothing to produce and rendering whatever figure the operator types into a database.
The most effective credibility move is a small real payout. Send the mark $200 of genuine cryptocurrency early and you have converted a stranger into someone who has personally verified that the system pays. That $200 is the single best marketing spend in the business, and the worked example below shows what it buys.
3. Control — move the conversation onto their surface
The scam cannot proceed while you are on infrastructure they do not own. So there is always a migration: from the dating app to WhatsApp, from the search result to a cloned login page, from your own wallet to their "platform", from an app store to a direct APK download. Once you are inside their surface, they control what you see — your balance, your profit, the withdrawal button, the support agent. Nothing you see is a fact any more; it is all rendered output.
4. Extraction — the irreversible transfer
This is the only stage where money actually moves, and it takes one of four shapes: you send crypto to their address, you hand over your recovery words, you sign a token approval that grants their contract spending authority over your wallet, or you install software that takes the keys directly. Note that three of those four do not involve you sending anything. People expect the scam to be "I pay them", which is why the other three work so well.
5. Exit — and often a second visit
Funds are split across dozens of addresses within minutes, pushed through a swap or a bridge to a different chain, and consolidated somewhere with weak identity checks. Contact stops. Then, often weeks later, a new party arrives offering to recover what you lost for an upfront fee. That is the same operation reading its own victim list, and it is the second most profitable product they sell.
A worked example, with the numbers
Abstract stages are easy to nod along to and hard to recognise in the moment. Here is a composite of a common investment-grooming case, reconstructed as a ledger. The amounts are typical rather than extreme; cases in the hundreds of thousands exist, but this is the shape most reported losses take.
| Day | What the target experiences | What is actually happening | Running loss |
|---|---|---|---|
| 1–14 | A wrong-number text turns into daily friendly conversation. Nothing is asked for. | Contact and rapport. Cost to the operator: a few minutes a day across many targets. | $0 |
| 15 | They mention, in passing, doing well from a trading platform a relative runs. | Credibility seeding. The target now raises the subject themselves, which feels like their own idea. | $0 |
| 18 | A $500 trial deposit into a professional-looking platform. Balance appears immediately. | Funds go straight to the operator. The dashboard is a web page showing a database number. | $500 |
| 25 | Balance shows $690. A $200 withdrawal is requested and arrives in the target's own wallet. | A real payout of $200, funded from earlier victims. This is the purchase of trust. | $300 |
| 30–60 | Larger deposits, encouraged but never demanded. Total $18,000, including borrowed money. | Extraction. Funds are already split and bridged within minutes of each deposit. | $18,300 |
| 62 | Dashboard reads $47,000. Withdrawal fails; a 20% "capital gains clearance" of $9,400 is required first. | The second extraction attempt. The $47,000 never existed and the fee is the real product. | $18,300 |
| 70 | Messages go unanswered. The platform domain stops resolving. | Exit. The site is rebuilt under a new name within days. | $18,300 |
| 110 | A "blockchain recovery specialist" makes contact, citing the exact loss amount. | The same operation, second visit. The fee is upfront and the recovery does not exist. | Often higher |
Read the ledger from the operator's side and the economics are stark: they spent $200 and about six weeks of part-time messaging to take $18,300, while running the same script against dozens of other people in parallel. Notice also that nothing in the first 17 days would have failed a "is this a scam" check, because nothing had been asked for. The absence of a request is part of the method, not evidence against it.
A successful small withdrawal proves nothing
Being paid once is the standard way trust is manufactured, not evidence that a platform is real. The test that means something is whether you can withdraw your entire balance, on demand, with no fee, tax or "clearance" required first.
A crypto scam list: the formats the stages wear
Every entry below is the same five-stage machine with a different cover story. The final column is the one to memorise — the single observation that settles the question without needing any further research.
| Format | The hook | The tell that ends the conversation |
|---|---|---|
| Giveaway / doubling | Send 1 coin to this address and receive 2 back, endorsed by a familiar name. | You must pay first. No genuine distribution ever requires an outbound payment. |
| Investment grooming | Weeks of friendship, then a platform with a rising dashboard. | The platform exists nowhere except a link you were sent privately. |
| Fake exchange or broker | Sleek site, real-looking order book, a helpful account manager. | Withdrawals require a fee, tax or minimum deposit before release. |
| Seed phrase phishing | Support, migration, validation, or "sync your wallet" prompts. | Anyone asking for your twelve or twenty-four words is stealing, with no exceptions. |
| Wallet drainer signature | Claim an airdrop or mint an NFT by connecting and signing. | The signature grants spending approval rather than receiving anything. |
| Fake app clone | A wallet or mining app that mirrors a real one, often via ad or direct download. | It is distributed outside the official store, or the publisher name is subtly wrong. |
| Rug pull / honeypot token | A new token climbing fast, with a countdown and a Telegram group. | Sells fail or liquidity is unlocked and held by a single address. |
| Job and task scam | Paid micro-tasks, then a deposit needed to "unlock" a higher tier. | Employment that requires you to pay the employer is not employment. |
| Fake cloud or phone mining | Buy a hashrate contract or an app tier and watch daily earnings accrue. | Returns are promised as fixed and guaranteed, which mining cannot be. |
| Address poisoning | A dust transaction from an address resembling one you use, planted in your history. | You copied the address from your transaction list instead of the source. |
| Recovery scam | A specialist who can trace and return your stolen funds. | They contacted you, they know your loss amount, and the fee is upfront. |
If a promised return sounds guaranteed, the format barely matters — no honest crypto product can guarantee a return, because none of them control the price. That includes ours: UNC has no listed price and no exchange listing, so anyone quoting you a future value for it is making it up. Our note on whether phone mining is safe covers the same reasoning applied to the mining app category specifically.
Why crypto is the preferred medium
Fraud predates crypto by several thousand years. What crypto changes is the extraction stage, and it changes it in four specific ways that are worth understanding precisely rather than vaguely.
- Settlement is final. A confirmed transaction has no chargeback window, no dispute process and no issuing bank with authority to reverse it. Card fraud gives you 120 days; crypto gives you zero seconds.
- It is instant and borderless. Funds reach a jurisdiction with no mutual legal assistance treaty before you have finished reading the confirmation screen.
- Addresses are pseudonymous but public. Everything is visible, which helps investigators, but visibility is not identity, and identity only appears where the funds touch a regulated service.
- The interface is unfamiliar. When every step of a process feels strange, a strange step does not stand out — which is why scams cluster around newcomers rather than experienced holders.
The public-ledger point is the one people most often get backwards, and it cuts both ways. You can look up the address you were told to pay, see how much has already arrived at it and from how many distinct senders, and often settle the question in under a minute. Our guide to reading a block explorer covers how to do that, and doing it before sending is worth more than any amount of reading reviews afterwards.
The technical moves under the story
The approval signature that is not a payment
On smart contract chains, a wallet can grant a contract permission to move a token on its behalf — the mechanism that makes exchanges and marketplaces work. A drainer site asks you to "connect" and then to sign what looks like a login or a claim. What you actually sign is an unlimited approval, and the contract empties the balance minutes or weeks later. The wallet popup is technically accurate and almost unreadable, which is the whole attack. If a site offering to send you something asks you to sign anything, stop.
Seed phrase capture dressed as support
A recovery passphrase is not a password; it is the wallet itself, in words. Anyone holding it holds every asset the wallet controls, on every chain, forever, with no way to revoke it. Scammers know most newcomers do not yet feel that distinction, so the request is framed as validation, migration, synchronisation or a support ticket. There is no legitimate circumstance, ever, in which a person or a website needs those words.
Cloned apps and poisoned search results
Searching for the best crypto wallet app and installing the first result is a genuine attack surface, because paid placements and clone listings both sit above organic results. Clones copy the icon, the screenshots and most of the name, then either generate a seed phrase the attacker already knows or exfiltrate the one you import. Get wallet downloads from the developer's own site, check the publisher name and install count, and treat any direct APK download as a hard no.
Address poisoning and clipboard swaps
Two cheap attacks exploit the fact that nobody reads a 42-character address. Address poisoning sends you a zero-value transaction from an address whose first and last four characters match one you use, hoping you will copy it out of your history next time. Clipboard malware silently replaces any address you copy. The defence for both is the same: verify the middle of the address, not just the ends, and send a small test amount first when the sum is large.
How to report a crypto scam in the US
Reporting rarely returns money, and anyone who tells you otherwise is running the recovery scam. What it does is create a record that lets investigators link your case to others hitting the same addresses, which is how these operations are eventually disrupted and how the occasional seizure and restitution happens. File quickly, because the useful window for freezing funds at an exchange is measured in hours.
- Stop all contact immediately, but do not delete anything — chat logs, profiles, emails and screenshots are the evidence.
- Collect the specifics: every transaction hash, every address you sent to, dates and amounts, the platform URL, phone numbers, usernames and any documents you were sent.
- File with the FBI Internet Crime Complaint Center at ic3.gov. This is the primary federal channel for crypto fraud and the one most likely to connect your case to an existing investigation.
- File with the FTC at reportfraud.ftc.gov, which feeds the Consumer Sentinel database used by state and federal enforcers.
- If it was pitched as an investment, also notify the SEC at sec.gov/tcr, or the CFTC at cftc.gov/complaint for anything framed as futures, forex or commodity trading.
- Tell your state Attorney General's consumer protection office, and file a local police report — some banks and insurers require a report number.
- Notify any regulated exchange involved. If funds landed at a major exchange, its compliance team can flag or freeze the account, and it can only act on a report.
- Report the addresses publicly on a scam database such as Chainabuse, so the next person searching that address finds your entry.
- If a bank account, card or wire was used at any point, contact that institution the same day — the reversible leg of the journey is the only one with a chance.
One reason exchanges can sometimes act at all is that regulated venues collect verified identity information on their customers, so an address that terminates at one is attached to a real person somewhere in a compliance file. Our explainer on what KYC involves sets out what those checks actually cover — it is also why scammers work so hard to move funds to venues that do not perform them.
The four checks that stop nearly all of it
You do not need to recognise every format. You need four habits, and they are cheap.
- Payment first is always fraud. Giveaways, airdrops, prizes, refunds, job offers and withdrawals never require you to send money to receive money. This single rule eliminates most of the crypto scam list above.
- Your seed phrase leaves your control exactly never — not to support, not to a migration page, not to a wallet that wants to "verify" you.
- Anyone who contacts you first about money is a stranger with an agenda, regardless of how long the conversation has run or how much you like them.
- Verify through a channel they did not give you. Type the exchange domain yourself, look the company up in the regulator's register, check the address in an explorer. Every piece of the scam is self-referential, so stepping outside it breaks the loop.
A scam has to survive five stages in a row. You only have to break one, and the cheapest one to break is always the first.
Finally, the disclosure our own category deserves. Mining apps sit adjacent to several formats on that list, so judge ours by the same tests: UNC never asks for a seed phrase, never asks for a payment to unlock anything, and never promises earnings, returns or a future price. There is no listed price and no exchange listing, which means nobody can honestly tell you what an allocation is worth. What the app does on your device and how allocation is scheduled are set out in how UNC works, and the design detail behind it is in the whitepaper. If either document dodges a question you have, that is itself an answer.
Frequently asked questions
How does a crypto scam work, in simple terms?
It runs five stages in order: contact you at scale, borrow credibility from something you already trust, move you onto a surface the scammer controls, extract funds through an irreversible transfer, and exit. The cover story changes constantly but the sequence does not. Money only actually moves at stage four, and that transfer takes one of four shapes: you send crypto, you give up your seed phrase, you sign a token approval, or you install software that takes the keys.
Why did they let me withdraw a small amount successfully?
Because a small real payout is the cheapest way to manufacture trust, and it is funded by earlier victims. In the worked example in this article, $200 paid out early led to $18,000 deposited afterwards. A successful small withdrawal proves only that the operator chose to pay it. The test that means something is whether you can withdraw the entire balance on demand with no fee, tax or clearance required first.
How do I report a crypto scam and can I get my money back?
In the US, file with the FBI at ic3.gov and the FTC at reportfraud.ftc.gov, add the SEC or CFTC if it was pitched as investment or trading, tell your state Attorney General, file a local police report, and notify any exchange involved so its compliance team can flag the account. Recovery is uncommon and slow. Anyone who contacts you offering guaranteed recovery for an upfront fee is running the follow-up scam on the same victim list.
Is downloading the best crypto wallet app from search results safe?
Not reliably. Paid placements and clone listings both appear above organic results, and clones copy the icon, screenshots and most of the name. A fake wallet either hands you a seed phrase the attacker already knows or steals the one you import. Get the download link from the developer's own website, check the publisher name and install count in the store, and refuse any direct APK or sideload instruction regardless of the reason given.
Why can crypto scams not be reversed like card fraud?
A confirmed blockchain transaction is final by design. There is no issuing bank, no chargeback window and no authority with the power to undo it, whereas card networks give you roughly 120 days to dispute. Funds are typically split across dozens of addresses and bridged to another chain within minutes. This is the entire reason fraudsters prefer crypto, and it means every effective defence has to happen before you press send.
What is the single most reliable warning sign?
Being required to pay before you can receive. Genuine giveaways, airdrops, prizes, refunds, salaries and withdrawals never require an outbound payment first. Whether it is called a network fee, an activation charge, a tax clearance or a verification deposit, the fee is the product. The second most reliable sign is any request for your recovery words, which has no legitimate use case at all.
Start mining with UNC
UNC distributes tokens to verified participants — no hardware, no subscription, no battery drain. Read the whitepaper for the distribution model, or check network activity in the explorer.
Get UNC on Google Play