Fake airdrop / claim sites
A lookalike domain (extra letter, different TLD, "claim-" prefix) promoted via replies, ads or hacked accounts. "Connect wallet to claim" then asks for signatures that hand over your tokens.
Defense: only use links from the project's official website/docs that you navigated to yourself. Bookmark them. Be extra careful with sponsored search results.
Wallet drainers & approval phishing
Malicious sites request token approvals (approve, increaseAllowance, setApprovalForAll) or off-chain signatures (Permit/Permit2, Seaport orders). One signature can let the attacker move assets later.
Defense: read the signing request; reject unlimited approvals; use a wallet with transaction simulation; revoke old approvals regularly (e.g. revoke.cash or the explorer's token-approval tool).
Address poisoning
Scammers send you a tiny or zero-value transfer from an address that looks like one you use (same first and last characters), hoping you copy it from your history next time.
Defense: never copy addresses from transaction history. Use an address book, verify the full address, send a test amount first for large transfers.
Impersonation & fake support
Fake accounts copy a project's or influencer's name and avatar and reply "DM us for help" or "claim here". Fake support in Discord/Telegram asks you to "sync" or "validate" your wallet.
Defense: check the exact handle, account age and who follows it. Support never DMs first and never needs your seed phrase.
Pig-butchering & "investment" friends
A friendly stranger (dating app, wrong-number text, social media) builds trust for weeks, then introduces a "trading platform" that shows fake profits. Withdrawals are blocked by "taxes" or "fees".
Defense: never invest through a platform someone you only know online recommends. If you can't withdraw a small amount freely, stop depositing.
Rug pulls & honeypot tokens
New tokens where the team can mint, block selling, or pull liquidity. Honeypots let you buy but not sell. Often pushed by paid, undisclosed promotions.
Defense: check contract ownership, liquidity lock and holder concentration; test a small sell; be skeptical of anything shilled with countdowns and "guaranteed" gains.
Malicious files & fake apps
"Beta tester" invitations, fake job offers or cracked tools ship malware that steals wallet files and browser sessions. Fake wallet apps in app stores and ads steal seed phrases on setup.
Defense: install wallets only from the official site; don't run files from strangers; use a separate device or browser profile for crypto.
Recovery scams
After you've been scammed, "recovery experts" or "blockchain lawyers" promise to get your funds back for an upfront fee.
Defense: nobody can reverse blockchain transactions for a fee. Report to the police and the exchange that received the funds instead.