Orca Crypto
Safety

Common scams

These are not clever. They are repetitive, and they work because they arrive when you are distracted.

Updated 2026-08-309 min readEssential
The short answer

The most common crypto scams are fake support agents asking for a seed phrase, giveaway impersonation, romance and investment scams known as pig butchering, fake airdrops that request a draining signature, cloned websites served through search ads, and fake job offers with malicious attachments. Nobody legitimate ever contacts you first and nobody legitimate ever needs your recovery phrase.

The eight playbooks

  1. Fake support

    You post a problem in a public channel. Within minutes someone messages you privately offering help, often with an official looking name and avatar. They direct you to a support form or a wallet sync page that asks for your recovery phrase.

    Defense: real support never messages first and never needs your phrase. Close the conversation.

  2. Giveaway impersonation

    A verified looking account announces a giveaway. Send 0.1 ETH, receive 1 ETH back. Often a livestream with a well known face and a QR code overlay.

    Defense: nobody doubles your money. This has been running for years because it still works.

  3. Pig butchering

    A relationship builds over weeks on a dating app or a wrong number text. Eventually they introduce a trading platform where you make money on paper. Withdrawals require a fee, then a tax, then a deposit. The platform is fake.

    Defense: never take financial direction from someone you have not met in person, however long you have been talking.

  4. Fake airdrops

    An unexpected token appears in your wallet with a name pointing at a website. The site asks you to connect and sign to claim. The signature grants permission to drain your tokens.

    Defense: ignore unexpected tokens entirely. Do not visit, do not connect, do not sign.

  5. Cloned websites

    Attackers buy search ads for wallet and exchange names. The ad appears above the real result and leads to a pixel perfect copy.

    Defense: bookmark every site you use and navigate from bookmarks. Brave blocks these ads by default.

  6. Fake job offers

    A recruiter offers a role and sends a take home task or a video call app to install. The file is malware that searches for wallet data.

    Defense: never run files from a recruiter. Use a machine with no wallets on it if you must.

  7. Address poisoning

    You receive a zero value transaction from an address whose first and last characters match one you use. Later you copy from your history and send to the attacker.

    Defense: verify the full address, or use an address book and name service names.

  8. Recovery scams

    After you are scammed, someone offers to recover your funds for an upfront fee. They found you because your loss was public.

    Defense: funds sent onchain are not recoverable by any private service. This is a second scam aimed at people already hurt.

The one check that defeats most of these

Did they contact me first?

Fake support, giveaways, romance scams, fake recruiters, recovery services. Every one of them requires the attacker to reach you. Legitimate services do not initiate contact about your funds.

If the answer is yes, treat everything that follows as hostile until proven otherwise, and never prove it by doing what they asked.

If you have been hit

  1. Move whatever is left, immediately

    Create a brand new wallet with a new seed phrase and move remaining assets. Assume the old wallet is permanently compromised.

  2. Revoke every approval

    Use revoke.cash on the compromised wallet if anything remains, though moving funds out matters more.

  3. Do not pay a recovery service

    They cannot help. Onchain transactions are final. Anyone claiming otherwise is running the follow up scam.

  4. Report it

    In the US, report to the FBI Internet Crime Complaint Center and the FTC. It rarely recovers funds and it does contribute to investigations.

  5. Document everything

    Transaction hashes, addresses, screenshots. Useful for reports and for tax loss purposes.

Worth remembering
Being scammed is not a sign of stupidity. These operations are professional, patient and well resourced, and they target people when they are tired, hurried or emotionally invested. It happens to experienced people too.

Common questions

Can stolen crypto be recovered?

Almost never. Transactions are final and there is no reversal mechanism. Occasionally exchanges freeze funds if a thief deposits there, and that requires speed and luck. Any private service promising recovery for a fee is a second scam.

How did they get my email or phone number?

Data breaches, usually. Crypto related services have leaked customer lists before, and those lists circulate. It does not mean your wallet is compromised.

Is it safe to connect my wallet to a new site?

Connecting alone is relatively low risk, because it only shares your address. Signing is where the danger is. Use a wallet that simulates transactions, such as Rabby, and use a separate burner wallet for anything unfamiliar.

Where to go next

Get a second pair of eyes on your setup

A security session reviews what you hold, where it sits, what approvals are open and what would happen if your laptop were compromised tomorrow. Most people find at least one thing worth fixing.