Back to Blog
GuidesUpdated September 16, 2026·5 min read

Crypto scams in 2026: the patterns that take the most money, how each one hooks you, and the checks that break the hook

Scams are not random; they follow a dozen scripts that recur because they work. Investment 'platforms' with fake dashboards, romance-led trading tips, fake exchanges and swap clones, airdrop drainers, impersonated support, rug pulls, and fake job offers that install malware. What each looks like from the inside, the moment where the money is lost, and the specific check that stops it — plus how to verify a swap service before sending.

The economics of a scam

Every crypto scam has the same shape: a reason to send, a channel that feels legitimate, and an irreversible transfer. The reason varies — profit, love, urgency, fear, a job, a prize. The channel is where the effort goes: fake sites, cloned apps, hijacked accounts, long conversations. And the irreversibility is why crypto is targeted: once sent, it is gone.

Below are the scripts that take the most money, in roughly that order, with the one moment in each where a check would have stopped it.

1. The investment platform ("pig butchering")

Script: a contact — from a dating app, a wrong-number text, a social-media reply — builds a relationship over weeks, then mentions they trade on a platform. You are shown a site or app with a dashboard, deposit a small amount, see "profits", withdraw a little (it works), deposit much more. When you try to withdraw the large amount, there is a "tax", a "verification fee", a "frozen account" — and then silence.

The moment: the first deposit to the platform. The check: no legitimate trading platform is introduced by a person you met online. Any platform that is not a well-known, independently reviewed exchange with years of history, and any "profit" that is shown only inside the platform's own dashboard, is fiction. The small successful withdrawal is part of the script.

2. Fake exchanges and swap clones

Script: a site that looks like a known exchange or swap service — same layout, similar domain (an extra letter, a different TLD), often promoted through a search ad above the real result or a link in a message. You get a deposit address; it belongs to the attacker.

The moment: pasting a receiving address or sending a deposit. The check: reach the site by typing the domain or from your own bookmark; never from an ad or a message. Verify the domain in the address bar before entering anything. For SyntheticSwap the domain is syntheticswap.io and nothing else. A real swap service shows limits before you commit, gives a status page with the deposit address, and never asks you to "unlock" a payout with a further deposit.

3. Airdrop and "claim" drainers

Script: a token or NFT appears in your wallet, or a post announces an airdrop for holders. The claim site asks you to "connect wallet" and sign. The signature is a token approval or a permit; the drain follows.

The moment: the signature. The check: you never need to sign anything to receive an airdrop — a real airdrop just arrives. Unsolicited tokens in your wallet are bait; do not interact with them. Read every signature request; if it mentions approval, permit, or setApprovalForAll and you did not intend to trade, reject it.

4. Impersonated support and "recovery services"

Script: you ask a question in a public channel; within minutes "support" DMs you. They ask for your seed to "resync", or for remote access, or a "verification deposit". Variant: after you have been scammed, a "recovery service" or "blockchain investigator" offers to retrieve funds for an upfront fee.

The moment: the DM. The check: real support does not DM first and never needs a seed, a payment or screen control. Recovery services that contact you are the same scammers a second time. Nothing can reverse a blockchain transaction.

5. Rug pulls and pump groups

Script: a new token with a viral story; a group promising a coordinated "pump"; liquidity that is removed once enough buyers are in; or a contract with a hidden function that stops selling. Memecoin launchpads have industrialised this.

The moment: buying a token you cannot independently evaluate. The check: if you cannot answer who controls the liquidity, whether the contract is verified and renounced, and why anyone would buy after you, you are the exit liquidity. Pump groups exist to sell to their own members.

6. Fake job offers and "test tasks"

Script: a recruiter for a crypto company sends a coding test or asks you to install a "video-call tool" or run a repository. The package contains malware that reads wallet files and clipboard.

The moment: running unknown code. The check: never run a repository or installer from a recruiter on a machine with wallets. Use a separate machine or a VM, and verify the company through its official channels.

7. Fake hardware wallets and pre-filled seeds

Script: a device bought from a marketplace arrives with a seed card already written, or with "official" instructions to enter the seed on a website.

The moment: using a seed you did not generate. The check: a real device generates the seed on first setup in front of you. Buy from the manufacturer; the hardware wallet guide covers setup.

8. Address poisoning and QR swaps

Script: attacker sends dust from a look-alike address so you copy the wrong one from history; or a QR code in a public place is replaced with one pointing to the attacker.

The moment: copying an address without verifying it fully. The check: the six-and-six rule — compare the first and last six characters against the source; never copy from history. The wallet protection guide has the full routine.

Verifying a swap service before you send

Because instant swaps are account-free, you cannot rely on a login history to tell you where you are. Use these checks instead:

  1. Domain typed or bookmarked; address bar checked. No ads, no message links.
  2. Limits shown before you commit — minimum and maximum for the pair on the page.
  3. A clear rate policy — floating or fixed, and when it locks.
  4. A refund address field and a stated rule for deposits outside limits.
  5. A status page with the deposit address and, later, both transaction hashes you can verify on public explorers.
  6. No second deposit ever. A service that asks for a further payment to "release" funds is a scam, full stop.
  7. Independent presence — listings and reviews on sites you found yourself, not links the service gave you.

SyntheticSwap meets these on every pair page — for example BTC → USDT (TRC-20) shows live limits and the all-in cost before you enter an address.

Frequently asked questions

Can a transaction be reversed if I was scammed? No. Report it (platform, police, the explorer's tagging services), but treat the funds as gone and beware "recovery" offers.

Are privacy coins more scam-prone? No more than others. The scripts are the same; the irreversibility is the same on every chain.

Is a "guaranteed return" ever real? No. In crypto or anywhere.

How do I check a token contract? Block explorer: verified source, ownership renounced or timelocked, liquidity locked, holder distribution not concentrated. If you cannot read those, do not buy.

What is the one habit that stops most of this? Never sending to a destination that came to you — an ad, a DM, a stranger's recommendation. Go to services yourself, by name.

Ready to swap privately?

No account required. Start in seconds.

Start swapping →