July 14, 2026
9 min read

Top 10 Crypto Scams You Need to Know (Analyst Guide)

Explore the top 10 crypto scams every compliance analyst should recognize, including phishing, rug pulls, Ponzi schemes, fake exchanges, and investment fraud. Learn the warning signs, transaction patterns, and practical detection techniques to strengthen AML monitoring and reduce financial crime risks.

Ian Hart
Top 10 Crypto Scams blog feature image showing phishing, pump-and-dump schemes, rug pulls, pig butchering, fake support, fraudulent airdrops, clone websites, Ponzi schemes, SIM swaps and fake job offers.

Scammers are everywhere in crypto. They are constantly inventing new ways to steal money, exploit trust, compromise wallets, and hide the movement of funds. Some scams are technical, some are emotional, and some are designed to look like normal investment activity until it is too late.

As a compliance analyst, you need to be familiar with the most common scams. You may see them in customer complaints, transaction monitoring alerts, law enforcement requests, support tickets, blockchain analytics tools, or suspicious activity investigations. The faster you recognise the scam pattern, the faster you can protect customers, preserve evidence, and escalate the case.

This guide explains the top 10 crypto scams analysts are likely to encounter. It also shows how each scam works, how to spot the warning signs, and what analysts should focus on during review.

These scam categories sit within a wider fraud typology framework, which is covered in Crypto Fraud Typologies: A Guide for Compliance Analysts for teams that need a broader view of red flags, reporting and case patterns.

Why Analysts Need a Crypto Scam Playbook

Crypto fraud cases can move quickly. Funds may leave an account, pass through several wallets, bridge to another chain, interact with a mixer, and cash out before a team has completed its first review. A clear scam playbook helps analysts react faster and more consistently.

A scam playbook also helps teams speak the same language. When support, fraud, AML, legal and product teams all understand terms such as phishing, rug pull, wallet drainer, pig butchering and money mule, cases can be escalated with less confusion.

A practical scam playbook should help analysts:

When one of these scam patterns becomes an active case, How to Investigate a Cryptocurrency Fraud Case gives analysts a practical workflow for intake, tracing, evidence preservation and SAR review.

  • Recognise the likely scam pattern early.
  • Ask the right customer questions.
  • Preserve the right evidence before it disappears.
  • Review account, device, wallet and transaction data together.
  • Decide whether to freeze, escalate, report or update controls.

1. Phishing Scams

How it works:

Scammers send fake emails, text messages, social media messages, or search ads that look like they are from a legitimate exchange, wallet provider, or crypto platform. These messages contain links to fake websites that steal login details, seed phrases, 2FA codes, or wallet permissions.

How to spot:

  • Emails with urgent language such as “Your account will be locked.”
  • Links that look slightly different from the real website.
  • Requests for private keys, seed phrases, 2FA codes or verification codes.
  • A customer who recently clicked a link and then experienced an account takeover.

Analyst focus:

For cases where funds have already moved across wallets or chains, Blockchain Forensics in Fraud Detection: An Analyst's Guide shows how on-chain data can strengthen the fraud review.

Check login history, device changes, IP addresses, password resets, email changes, withdrawal address updates, and timing between the suspicious login and outgoing funds.

2. The Pump and Dump

How it works:

A group of people hype a small, low-liquidity coin on social media, Telegram, Discord, or influencer channels. They drive the price up by creating excitement and fear of missing out. Once retail buyers enter, insiders sell their holdings at the peak, causing the price to crash.

How to spot:

  • A sudden, massive price increase on a coin with little history.
  • Heavy social media promotion and influencer-style urgency.
  • Very low liquidity and thin market depth.
  • Language such as “guaranteed 100x” or “next moonshot.”
  • Large wallets selling soon after public hype begins.

Analyst focus:

Look for links between promotional timing and wallet activity. Sudden inflows, rapid sell-offs, insider concentration, and coordinated social activity can help identify this scam.

 

 

3. The Rug Pull

How it works:

The creators of a DeFi token, NFT project, or liquidity pool attract investors and then remove liquidity, abandon the project, or exploit contract permissions. Investors are left with worthless tokens or assets.

How to spot:

  • A new token with a team that has no public profile.
  • Promises of very high returns or unrealistic yields.
  • Liquidity concentrated in a few wallets.
  • Weak or missing audit information.
  • Contract ownership retained by the creators.
  • Sudden liquidity withdrawal.

Analyst focus:

Review token contracts, liquidity pool changes, developer wallet movements, ownership permissions, and fund flows after the liquidity is removed.

4. The Pig Butchering Romance Scam

How it works:

The scammer builds a fake romantic, friendly, or professional relationship with the victim. Over time, they introduce a fake crypto investment platform. The victim sees fake profits and is encouraged to invest more. When they try to withdraw, the platform demands fees, taxes, or additional deposits.

How to spot:

  • A new online friend who is very interested in the victim’s finances.
  • A too-good-to-be-true investment opportunity.
  • Repeated deposits to the same external wallet or fake platform.
  • The customer appears coached, emotionally attached, or reluctant to believe they are being scammed.
  • Screenshots showing fake profits or blocked withdrawals.

Analyst focus:

Customer interviews matter. Victims may not initially accept that the platform is fake. Look for repeated deposits, escalating amounts, fake screenshots, withdrawal problems, and links to known scam wallet clusters.

5. Tech Support Scams

How it works:

Scammers impersonate a company’s support team, wallet provider, exchange, or recovery service. They contact the victim and ask for private keys, seed phrases, 2FA codes, remote access, or a “verification” payment to fix a fake problem.

How to spot:

  • A customer says they received a call, direct message, or email from “support.”
  • They were asked for sensitive information or remote access.
  • They shared wallet credentials or 2FA information.
  • Funds moved shortly after the contact.
  • The contact happened outside the platform’s official support channels.

Analyst focus:

Real support teams should never ask for seed phrases or private keys. Escalate support scam reports quickly because there may still be time to stop further losses.

How to Use This List

Share it with your team

Share this list with analysts, support staff, onboarding teams and fraud teams so everyone can identify the same scam patterns and use consistent language.

Keep it updated

Scams are constantly evolving. Update your internal list with new tactics, new wallet clusters, fake domains, customer reports and law enforcement intelligence.

Use it in training

Use these examples in AML and fraud training. Realistic case studies help analysts remember patterns and apply them under pressure.

Use it in investigations

When a suspicious case appears, compare the customer story and transaction pattern against these scam types. This can help you develop a stronger case theory.

Use it in SAR narratives

Clear scam labels can make reports easier to understand. For example: “The activity appears consistent with a pig butchering investment scam followed by rapid layering.”

Evidence Analysts Should Preserve

Crypto fraud investigations depend on good evidence. Some information can disappear quickly, especially fake websites, social media profiles, chat messages and online ads. Analysts should preserve relevant evidence early.

Useful evidence may include:

  • Customer statements and support tickets.
  • Screenshots of fake websites, emails, chats or investment dashboards.
  • Exact URLs, email addresses, usernames and phone numbers used by the scammer.
  • Login timestamps, IP addresses, device fingerprints and account changes.
  • Wallet addresses, transaction hashes, dates and amounts.
  • Blockchain analytics screenshots or wallet exposure results.
  • Notes explaining why the activity matches a specific scam typology.

Real-World Scenario: A Phishing Attack

A customer contacts support and says: “I just received an email saying my account was frozen. I clicked the link and logged in.”

Identify: The analyst identifies this as a classic phishing scam. The urgent language, fake security warning and login link are all common indicators.

Action: The analyst immediately freezes the customer’s account, resets access controls, and prevents further withdrawals while the case is reviewed.

Investigation: The analyst reviews suspicious transactions and sees that the customer’s funds were moved to a new wallet shortly after the login.

Evidence: The analyst collects the phishing email, fake URL, login timestamp, IP address, device details, transaction hash, withdrawal address and customer statement.

Escalation: The case is escalated to fraud and compliance. The platform checks whether other customers received similar emails.

SAR Review: If the activity meets reporting criteria, the analyst prepares a clear SAR narrative describing the phishing scam, account takeover and flow of funds.

Common Mistakes Analysts Should Avoid

Mistake 1: Treating the scam type as obvious too early

Some cases combine multiple scam types. A phishing attack may lead to account takeover, then layering. A fake job may make a customer look like a mule. Keep the case theory open until the evidence is reviewed.

Mistake 2: Ignoring customer support notes

Support messages often contain the first signs of coaching, pressure, confusion or victimisation. These notes can add important context to blockchain activity.

Mistake 3: Focusing only on on-chain movement

Blockchain activity is important, but account metadata, device activity, customer statements and communication evidence can be equally valuable.

Mistake 4: Writing vague reports

Reports should clearly explain what scam pattern is suspected, what evidence supports it, what funds moved where, and what action the business took.

Conclusion

Staying ahead of crypto scams is a constant battle. Criminals change their tactics, reuse old techniques, and combine multiple scam types in one case. A phishing attack may lead to account takeover. A romance scam may become an investment scam. A fake job may turn a customer into a money mule.

But by knowing the top scams, you are already a step ahead. You can identify patterns faster, ask better questions, protect customers sooner, and write stronger investigation narratives.

Prevention work should also be part of the response. The Crypto Fraud Prevention: 5 Tips for Compliance Analysts article explains how analysts can use monitoring, KYC, education and technology to reduce future losses.

To build these skills in a structured way, explore the Crypto Fraud Typologies And Red Flags For Analysts course, which helps analysts recognise scam patterns, assess red flags, document evidence and support stronger fraud reviews.

FAQs

What is the most common crypto scam?

Phishing scams are one of the most common and successful methods, but investment scams and pig butchering scams are also major risks.

What is a pump and dump?

A pump and dump is a scheme where a coin’s price is artificially inflated before insiders sell at the peak and leave other investors with losses.

What is a rug pull?

A rug pull is a DeFi, token or NFT scam where developers remove liquidity, abandon the project, or exploit contract controls.

What should a customer do if they suspect a scam?

The customer should contact the platform’s support team immediately, stop sending funds, preserve evidence, and report the incident to law enforcement or the relevant fraud reporting body.

Why do analysts need to know crypto scam typologies?

Typologies help analysts recognise patterns, investigate faster, preserve the right evidence, escalate urgent cases and write clearer suspicious activity narratives.

What evidence is useful in a crypto scam investigation?

Useful evidence includes wallet addresses, transaction hashes, customer statements, screenshots, fake URLs, emails, chat messages, login metadata, device changes and blockchain analytics findings.

Can one case involve more than one scam type?

Yes. Many cases involve multiple typologies. For example, phishing may lead to account takeover, and stolen funds may then be layered through wallets or exchanges.