Crypto fraud is a massive problem. Scammers are creative, organised, and constantly evolving their techniques. They use social media, fake investment platforms, phishing pages, compromised accounts, malicious smart contracts, wallet drainers, impersonation tactics, and money laundering tools to steal funds and hide the trail.
As a compliance analyst, you need to understand the common fraud typologies. This knowledge is the foundation of your ability to detect and prevent financial crime. If you only look at isolated transactions, you may miss the bigger picture. But when you understand typologies, you can connect behaviours, patterns, user stories, wallet activity, and risk signals.
This guide explains the major crypto fraud typologies analysts are likely to encounter and the red flags that can help identify them. It also shows how these typologies appear in real investigations, how analysts can use them in SAR narratives, and how compliance teams can turn fraud patterns into stronger monitoring rules.
For the on-chain side of this work, Blockchain Forensics in Fraud Detection: An Analyst's Guide explains how wallet history, risk scoring, tags and fund-flow analysis support fraud detection.
For a quicker field reference, analysts can also use the Top 10 Crypto Scams You Need to Know (Analyst Guide) article to recognise common scam categories before moving into deeper case analysis.
What is a Fraud Typology?
A typology is a description of a type of crime. In this case, it is a pattern of fraudulent behaviour. A typology explains how the fraud works, who is targeted, what criminals are trying to achieve, and what warning signs may appear.
For example, a pig butchering scam is not just one transaction. It is a pattern: relationship-building, fake investment advice, repeated deposits, fake profits, withdrawal blocks, and final disappearance. A rug pull is also a pattern: hype, rapid buying, weak transparency, liquidity withdrawal, and collapse.
Typologies help analysts move beyond isolated alerts. Instead of asking only whether one transaction looks unusual, the analyst asks what story the behaviour is telling. That shift is important because crypto fraud often unfolds across accounts, wallets, devices, customer conversations, and blockchain activity.
Why typologies matter:
Detection: You can't spot what you don't know. Typologies teach you what to look for.
Training: They are essential for training your team and creating practical case studies.
Reporting: They help you write clear, detailed SAR narratives.
Prioritisation: They help analysts decide which alerts require urgent review.
Communication: They help compliance teams explain risk to product, support, legal, and leadership teams.

Category 1: Investment Scams
Investment scams are among the most common types of crypto fraud. Victims are promised profit, passive income, guaranteed returns, or exclusive access to a new opportunity. The scam often looks professional and may include fake websites, fake trading dashboards, fake support teams, and fake withdrawal rules.
These cases can be difficult because the customer may appear to be acting voluntarily. They may repeatedly send funds to the same destination, insist that the investment is legitimate, and become defensive when questioned. Analysts should therefore look at behaviour, transaction patterns, destination wallets, customer explanations, and known scam indicators together.
1. The Pump and Dump Scheme
How it works:
A group artificially inflates the price of a low-liquidity coin by hyping it on social media, Telegram, Discord, or influencer channels. Once the price is high, insiders sell their holdings, and the price crashes. Retail buyers are left with losses.
The red flags:
- A sudden, massive price increase of a small coin.
- Heavy social media promotion using urgent or exaggerated language.
- Very low liquidity and thin trading history.
- Repeated phrases such as "next 100x," "guaranteed moon," or "limited time entry."
- Large wallets selling shortly after public hype begins.
Analyst tip:
Look for coordination between wallet activity and promotional timing. Sudden concentration of token supply, insider wallet movements, and rapid sell-offs can be strong indicators.
2. The Rug Pull (DeFi Scam)
How it works:
The creators of a DeFi token, liquidity pool, or NFT project attract investors, build hype, and then steal liquidity or abandon the project. Investors are left with worthless tokens or assets.
The red flags:
- A new, unknown token with aggressive promotional claims.
- A team with no public profile or limited accountability.
- Very high yields offered with little explanation.
- Weak or missing audits.
- Contract ownership not renounced or admin permissions retained.
- Liquidity unlocked or controlled by the project team.
- Large amounts of liquidity being withdrawn suddenly.
Analyst tip:
Review contract permissions, liquidity movements, developer wallet behaviour, and promotional claims. Many rug pulls show warning signs before the collapse.

3. The Pig Butchering Scam
How it works:
A scammer builds a romantic, friendly, or professional relationship with the victim online. They slowly gain trust, then introduce a fake crypto investment platform. The victim sees fake profits and sends more funds. When they try to withdraw, the platform demands fees, taxes, or additional deposits.
The red flags:
- A new online friend who is very interested in finances.
- A too-good-to-be-true investment opportunity.
- Repeated deposits to a platform the customer cannot clearly explain.
- The victim is reluctant to withdraw or appears to be coached.
- Payments sent to wallets linked to known scam clusters.
- Claims that taxes, fees, or deposits must be paid before withdrawal.
Analyst tip:
Victims may not realise they are victims. They may defend the scammer or insist the platform is legitimate. Interviewing and customer support notes can be important evidence.

Category 2: Technical Exploitation
Technical exploitation scams use weaknesses in systems, user behaviour, access controls, or wallet permissions. The customer may not be trying to invest. Instead, their account, wallet, credentials, or device may be compromised.
4. Phishing
How it works:
A scammer sends a fake email, text, social media message, or search ad that looks like it comes from a legitimate company. The link leads to a fake website that steals login credentials, seed phrases, 2FA codes, or wallet permissions.
The red flags:
- Emails or messages that create urgency.
- Links to websites that look almost identical to the real platform.
- Login attempts from new devices, IP addresses, or locations.
- Password resets, email changes, or withdrawal address changes soon after the suspicious contact.
- Customer support reports mentioning a suspicious link or fake support page.
Analyst tip:
Check login history, IP changes, device fingerprints, password resets, withdrawal address changes, and timing between account access and fund movement.

5. Wallet Drainers
How it works:
A scammer tricks a user into signing a malicious transaction or approval. The transaction gives the scammer permission to move tokens from the user’s wallet. This often happens through fake airdrops, fake NFT minting pages, malicious dApps, or compromised websites.
The red flags:
- The user claims they lost funds from their wallet.
- Transaction history shows token approvals followed by rapid transfers.
- Funds move to unknown addresses or known scam infrastructure.
- The customer recently interacted with a suspicious dApp.
- Multiple assets are drained shortly after a single approval or signature event.
Analyst tip:
Review token approval events, smart contract interactions, and follow-on fund movement. Wallet drainers often move funds quickly through multiple wallets.
6. SIM Swap Attacks
How it works:
A scammer tricks a mobile phone provider into transferring the victim’s phone number to their SIM card. They can then intercept SMS-based 2FA codes and access the victim’s accounts.
The red flags:
- A customer reports losing access to their phone.
- The account is compromised shortly after the phone outage.
- Password resets, login attempts, email changes, or withdrawal address changes appear in a short time window.
- The customer used SMS-only 2FA rather than stronger authentication.
Analyst tip:
Treat sudden account takeover activity after a phone access complaint as high risk. SMS-only 2FA is weaker than authenticator apps or hardware keys.
Category 3: Social Engineering
Social engineering scams manipulate people, not technology. Criminals use pressure, trust, urgency, authority, fear, or emotional connection to get victims or employees to move funds. These cases often depend heavily on messages, customer behaviour, and unusual decision-making patterns.
7. CEO Fraud (Business Email Compromise)
How it works:
A scammer impersonates a senior executive, vendor, investor, or trusted business contact. They send an urgent message asking an employee to transfer crypto to a specific wallet or update payment instructions.
The red flags:
- A request for a large, unusual transfer.
- The email comes from a slightly different address than the real one.
- The request is urgent, confidential, or outside normal approval procedures.
- The wallet address is new.
- The request bypasses dual approval, finance review, or normal vendor checks.
Analyst tip:
Review whether the transaction bypassed normal approval controls. Look for new wallet beneficiaries, unusual timing, and pressure language.
8. Support Scams
How it works:
A scammer impersonates a customer support team, wallet provider, exchange, or recovery specialist. They contact the customer and ask for private keys, seed phrases, 2FA codes, remote access, or a “verification” payment.
The red flags:
- A customer reports being contacted by “support.”
- The customer is asked for sensitive information.
- The customer gives access to a wallet, screen, or device.
- Funds move shortly after the interaction.
- The scammer pressures the customer to act quickly or not contact official support.
Analyst tip:
Real support teams should never ask for seed phrases or private keys. Support-related scam reports should be escalated quickly because funds may still be moving.
Category 4: Money Laundering Typologies
Money laundering typologies are the methods analysts often see after fraud proceeds have been collected. These behaviours may not show the original scam, but they can reveal how criminals attempt to hide the source, ownership, or destination of funds.
9. Structuring or Smurfing
How it works:
Structuring means breaking up a large transaction into many smaller ones to avoid reporting thresholds, monitoring rules, or internal review.
The red flags:
- Many small deposits or withdrawals close together.
- Similar amounts sent to related wallets.
- Multiple accounts using shared identifiers.
- Activity just below internal thresholds.
- Rapid repeat transactions without a clear economic purpose.
10. Layering
How it works:
Layering means moving funds through multiple wallets, exchanges, chains, bridges, or protocols to hide the source of funds. The aim is to make the trail harder to follow.
The red flags:
- Rapid movement through many addresses.
- Use of newly created wallets.
- Cross-chain transfers and bridges.
- No obvious economic purpose.
- Funds moving shortly after fraud complaints or scam reports.
11. Mixing or Tumbling
How it works:
Mixing means using a service or protocol to combine crypto from multiple sources, obscuring the trail between source and destination.
The red flags:
- Funds entering or leaving known mixer addresses.
- Transactions designed to break traceability.
- Use of privacy-enhancing tools immediately after fraud proceeds are received.
- Cash-out activity after mixing or chain-hopping.
Analyst tip:
Money laundering typologies often appear together. A fraud case may involve structuring, then layering, then mixing, followed by cash-out through an exchange or OTC broker.
How to Use These Typologies
1. In your training
Use these typologies to train your team. Show examples of each type, including screenshots, wallet graphs, customer messages, fake websites, and transaction patterns.
2. In your investigation
When you see a suspicious pattern, ask yourself: “What typology does this look like?” This helps you move from isolated alerts to a full case theory.
3. In your SAR narrative
When you write a SAR, reference the typology. For example: “This pattern is consistent with a pig butchering investment scam followed by layering through multiple wallets.”
4. In your rules and alerts
Typologies should inform monitoring rules. If pig butchering cases often involve repeated deposits to newly created external wallets, that pattern can become an alert scenario.
5. In your product feedback
Analysts should share typology trends with product teams. If fraudsters exploit weak withdrawal controls, poor user warnings, or weak authentication, the product should be improved.
Practical Checklist for Analysts
Use this checklist when reviewing a possible crypto fraud case. It is not a replacement for internal procedures, but it can help analysts build a clearer case theory.
- Identify the suspected fraud typology or typologies.
- Review the customer story, support notes, messages and account activity.
- Check destination wallets, transaction hashes and known scam exposure.
- Look for changes in device, IP address, email, phone number or withdrawal address.
- Map the movement of funds after receipt.
- Check whether layering, mixing, bridging or cash-out activity follows the fraud.
- Document customer statements and any evidence of coaching or pressure.
- Escalate urgent cases where funds may still be recoverable or moving.
- Update monitoring rules if the case shows a repeatable pattern.
Real-World Scenario: A Multi-Faceted Scam
A customer reports that they have been scammed. At first, the case looks like a simple customer complaint. But as the analyst reviews the evidence, multiple typologies begin to appear.
The story: The customer says they met someone online who convinced them to invest in a new crypto token. The person was friendly, supportive, and seemed financially successful.
The evidence: The customer shares the wallet address they sent the funds to. You review the transaction history and see repeated deposits from the victim to the same cluster of wallets.
The typologies: You identify social engineering because the scammer used a romance or friendship-based approach, consistent with pig butchering. You identify an investment scam because the “investment” was a fake crypto opportunity and may also be connected to a rug pull or fake trading platform. You identify money laundering because the funds were moved through multiple wallets shortly after receipt, indicating layering.
The SAR: You file a SAR. You describe the social engineering, investment scam, and laundering typologies. You include wallet addresses, transaction hashes, dates, amounts, customer statements, and the flow of funds.
The outcome: The case is documented clearly, support is informed, the customer is warned, and internal monitoring rules are updated to detect similar patterns in the future.
Conclusion
Understanding fraud typologies is essential for any compliance analyst. It is the foundation of your ability to detect, investigate, and report financial crime. Typologies help you recognise patterns, ask better questions, write better narratives, and connect on-chain activity with real-world victim behaviour.
Crypto fraud will continue to evolve. New scams will appear, old scams will change, and criminals will use better technology. But the analyst who understands core typologies will be better prepared to respond.
Teams that want to reduce losses before cases escalate can also use Crypto Fraud Prevention: 5 Tips for Compliance Analysts to turn recurring fraud patterns into stronger monitoring, customer warnings and internal playbooks.
To build these skills in a structured way, explore the Crypto Fraud Typologies And Red Flags For Analysts course, which helps analysts recognise scam patterns, assess red flags, document evidence and support stronger fraud reviews.
FAQs
What is a fraud typology?
A fraud typology is a description of a specific type of fraud. It outlines the methods, behaviours, patterns and warning signs used by criminals.
What is a rug pull?
A rug pull is a type of DeFi, token or NFT scam where project creators steal liquidity, abandon the project, or leave investors with worthless assets.
What is pig butchering?
Pig butchering is a long-form social engineering and investment scam where the scammer builds trust with the victim before directing them to a fake crypto investment platform.
How should analysts use fraud typologies?
Analysts can use typologies for training, investigation, alert design, customer interviews, escalation decisions and writing clear SAR narratives.
What are common crypto fraud red flags?
Common red flags include sudden unusual transfers, destination wallets linked to scams, repeated deposits to unknown platforms, fake support messages, suspicious login changes, wallet approvals, use of mixers and rapid movement through multiple wallets.
Is every unusual crypto transaction fraud?
No. Unusual activity is not always fraud. Analysts should review the full context, including the customer profile, transaction history, destination wallet, customer explanation and related account activity.
Why are wallet drainers dangerous?
Wallet drainers can move funds quickly after a user signs a malicious approval. Once permission is granted, multiple assets may be transferred before the user realises what happened.
How do fraud typologies help SAR writing?
Typologies help analysts explain the suspicious pattern clearly. A SAR narrative is stronger when it describes the suspected fraud type, supporting evidence, fund flow and customer behaviour.
Who should learn crypto fraud typologies?
Compliance analysts, AML investigators, fraud teams, customer support teams, sanctions analysts, blockchain investigators and compliance managers should understand crypto fraud typologies.


