How to Spot a Crypto Wallet Scam
Nearly every scam wants one thing: your seed phrase or a bad signature. Learn the common wallet scams, the red flags, and how to stay safe.

On this page
Most crypto wallet scams come down to one trick: getting you to reveal your seed phrase or approve a malicious transaction. Learn to recognize that pattern and you can spot almost any scam, no matter how it is dressed up.
Scammers stole a record amount from crypto users in 2025, and the biggest share came from phishing and compromised keys, not clever hacks. This guide covers the wallet scams you are most likely to meet, the red flags that give them away, and exactly how to protect yourself.
No legitimate wallet, exchange, or support agent will ever ask for your seed phrase. Anyone who does is trying to rob you. That single rule stops most scams cold.
The one line worth memorizing
The golden rule: guard your seed phrase
Your seed phrase is the master key to your wallet. Whoever has it controls every coin inside, instantly and irreversibly. It should never be typed into a website, shared in a chat, entered into a pop-up, or stored anywhere online.
Every scam below is ultimately an attempt to get that phrase, or to trick you into signing a transaction that hands over your funds. Keep the phrase offline and refuse every request for it, and you have already blocked the most common attacks. The scammers change their stories constantly, but this one defense never goes out of date.
The most common crypto wallet scams
Scammers reuse a handful of playbooks. Recognizing them by name makes them far easier to catch.
| Scam | How it works |
|---|---|
| Fake wallet apps | Counterfeit apps mimic real wallets and steal your keys once installed |
| Phishing sites | Fake versions of real wallet or exchange sites capture your seed phrase |
| Support imposters | Fake "support" on Telegram, Discord, or DMs asks for your phrase or remote access |
| Fake airdrops and mystery tokens | Unsolicited tokens link to sites that drain your wallet when connected |
| Address poisoning | A lookalike address is slipped into your history so you copy it by mistake |
| Recovery scams | Fake services promise to recover lost funds for an upfront fee |
Phishing is the single biggest category, behind a large share of individual losses. Fake customer support imposters are close behind, because attackers monitor social media and message victims impersonating brands like Ledger, MetaMask, or a major exchange with near-perfect accuracy. Whatever the wrapper, the goal is your seed phrase, your private keys, or your signature, so never share any of them and treat unsolicited tokens and airdrops as bait.
The red flags that give a scam away
Almost every scam trips at least one of these wires. Treat any of them as a reason to stop.
- A request for your seed phrase or private key, from anyone, ever.
- Guaranteed or doubled returns, which no real investment can promise.
- Urgency and pressure, such as "limited time" or "act now."
- Unsolicited contact, a surprise DM, token, NFT, or investment tip.
- An upfront fee before you can "withdraw" or "unlock" funds.
- Words like Free, Gift, Airdrop, or Congrats attached to something you never signed up for.
How to protect yourself
A few habits close nearly every door a scammer might use.
- Download only from official sources. Get wallet apps from the maker's verified site or the official app store, never a link in an ad or message.
- Verify before you sign. Read what a transaction actually approves, and check token contract addresses on a source like CoinGecko rather than a social media post or DM.
- Use a hardware wallet. A hardware wallet keeps your keys offline, so a phishing site cannot reach them.
- Use app-based 2FA. An authenticator app beats SMS, which can be stolen through SIM-swap attacks.
- Never click unsolicited links. Scam links in ads, DMs, and unsolicited tokens lead to fake sites that harvest seed phrases; type addresses yourself instead.
- Revoke old approvals. Periodically review and revoke the dApp permissions your wallet has granted, part of basic wallet security.
Mystery tokens are a favorite lure: scam tokens land in your wallet, and the site they point to is a fake requesting your seed phrase or a wallet connection. Treat surprise tokens as hostile, and never let one pull you into requesting or entering your seed phrases anywhere.
Assume any unsolicited token, NFT, or message is a scam until proven otherwise. Do not click, do not connect, do not reply.
The default setting that keeps you safe
Watch out for address poisoning
This one catches careful people, so it is worth its own note. A scammer sends a tiny transaction from an address that looks almost identical to one you use, so it appears in your history. Later, if you copy a recent address from your transaction list instead of the real source, you send funds straight to them.
The fix is simple: never copy a receiving address from your transaction history. Always get it fresh from the intended recipient or your own wallet, and verify the full string, not just the first and last few characters.
Beware "recovery" scams after a loss
If you are ever scammed, a second wave often follows. Fraudsters target victims with offers to recover the lost funds for an upfront fee, and people have lost large sums a second time this way.
No legitimate service will DM you promising to recover crypto. Real recovery, where it happens at all, goes through the actual exchange or law enforcement, never a paid "agent" who contacts you first.
What to do if you have been scammed
Act in the first hours
Stop all contact with the scammer and send nothing more. If your wallet may be compromised, immediately move any remaining assets to a new, secure wallet with a fresh seed phrase. Document every address, message, and transaction ID.
Report it
File reports with the relevant authorities in your country and flag the scammer's address on a blockchain explorer. Recovery is rare, so the real value is protecting others and creating a record. Never pay anyone who promises to get the funds back.
Common ways people fall for wallet scams
| Mistake | Do this instead |
|---|---|
| Entering the seed phrase to "verify" a wallet | Never enter it anywhere but the wallet app itself |
| Downloading a wallet from an ad link | Use the official site or app store only |
| Trusting a "support" DM | Real support never messages you first or asks for your phrase |
| Copying an address from transaction history | Get it fresh and verify the full string |
| Paying a fee to "unlock" or "recover" funds | Treat any upfront fee as a scam |
For safe storage habits that back all of this up, see how to store crypto safely and how to back up a seed phrase. If you use a specific app, our is Trust Wallet safe review shows what genuine wallet security looks like.
Frequently asked
How do I spot a crypto wallet scam?
Look for the core pattern: anything asking for your seed phrase or private key, or pushing you to approve a transaction, is almost certainly a scam. Add red flags like guaranteed returns, urgency, unsolicited contact, and upfront fees, and you can catch nearly any scam.
Will a legitimate wallet ever ask for my seed phrase?
Never. No genuine wallet, exchange, or support agent will ask for your recovery phrase by email, chat, pop-up, or phone. Anyone who does is trying to steal your funds. Only ever enter your phrase into the wallet app itself during setup or recovery.
What are the most common crypto wallet scams?
Fake wallet apps, phishing sites, support imposters on Telegram or Discord, fake airdrops and mystery tokens, address poisoning, copycat tokens, and recovery scams that target people who were already scammed. Phishing is the single biggest category.
What is address poisoning?
A scammer sends a tiny transaction from an address that looks almost identical to one you use, so it appears in your history. If you later copy a recent address from that history, you send funds to them. Never copy addresses from your transaction history.
Are unsolicited tokens or NFTs in my wallet a scam?
Assume so. Surprise tokens and NFTs are a common lure: they link to sites that drain your wallet when you connect or approve a transaction. Do not click, do not connect, and do not approve anything they prompt. Hide or ignore them.
How do I avoid fake wallet apps?
Download wallet apps only from the maker's official website or a reputable app store, and verify the developer. Never install from a link in an ad, email, or message, since counterfeit apps mimic real brands to steal your keys once installed.
What are the biggest red flags of a crypto scam?
A request for your seed phrase, guaranteed or doubled returns, urgency and pressure, unsolicited contact, an upfront fee to withdraw, and words like Free, Gift, or Airdrop attached to something you never signed up for. Any one is a reason to stop.
Are crypto recovery services legitimate?
Almost never. Fraudsters target people who were already scammed, promising to recover funds for an upfront fee, and victims often lose again. Real recovery goes through the actual exchange or law enforcement, never a paid agent who contacts you first.
How does a hardware wallet protect against scams?
A hardware wallet keeps your private keys offline, so a phishing site cannot reach them, and it makes you confirm each transaction on the device screen. That extra step helps you catch a malicious transaction before it is signed.
What should I do if I get scammed?
Stop all contact and send nothing more. If your wallet may be compromised, move any remaining assets to a new secure wallet with a fresh seed phrase, document everything, run malware scans, and report it to the relevant authorities.
Is SMS two-factor authentication safe for crypto?
It is weaker than an authenticator app. Criminals can perform SIM-swap attacks to hijack your phone number and intercept SMS codes. Use an app-based authenticator, add a carrier PIN, and consider a hardware security key for important accounts.
How can I tell a real wallet site from a fake one?
Type the address yourself or use a bookmark rather than clicking links or ads, check the exact domain carefully, and never enter your seed phrase to "verify" or "sync." Scam sites clone real ones closely, so the URL and the seed-phrase request are the tells.
See which wallets we actually recommend
Every wallet in the register was bought at our own cost and scored on one fixed standard.
Read the register →