Anti-Scam Crypto Master Playbook: 4 Rules + 7 Attack Patterns (2026)
Crypto scams stole an estimated $14B+ in 2024 (Chainalysis), and the real figure is higher. Almost every loss traces back to four broken rules: sharing a seed phrase, signing a transaction without reading it, trusting a "support" DM, or believing returns that are mathematically impossible. Memorize the four rules below and 99% of scams stop working on you.
Not financial advice. This article is for educational purposes only. Crypto is volatile and carries risk. Never invest more than you can afford to lose. Always do your own research.
This is a defensive playbook. For the pattern-by-pattern walkthrough of how the most common scams look, see Common crypto scams 2026. For the technical mechanism behind wallet drainers, see Wallet drainer explained.
Rule #1 โ Never share your seed phrase. Anyone asking is scamming you.#
Your seed phrase is the master key to your wallet. There is exactly zero legitimate reason for anyone โ your wallet provider, exchange support, a tax advisor, a friend โ to need it.
If someone asks, they are scamming you. This includes:
- "MetaMask Support" DM
- "Phantom Helper"
- "Coinbase Verification Team"
- Any DM offering to "fix" or "verify" your wallet
Real wallet providers don't have access to your seed phrase. The math doesn't allow it. They can't help with seed-phrase-related issues. Take this rule to the extreme: if even your closest family member asks, refuse.
See Seed-phrase safety for the practical storage rules.
Rule #2 โ Read every transaction before signing#
Wallet drainers work by getting you to sign a transaction that looks innocent but actually grants the attacker permission to drain a specific token. "Free NFT mint" โ sign โ USDT gone. "Claim airdrop" โ sign โ ETH gone.
The defense:
- Read every signature's actual asset movement before approving.
- Use Rabby instead of MetaMask โ it simulates the transaction and shows "You will lose 1,000 USDC" in plain English, where MetaMask shows raw hex.
- If you use a hardware wallet, read the device screen too. The Ledger/Trezor screen can't be faked by the website.
Rule #3 โ Bookmark every DApp. Never click links from DMs, ads, or unverified posts.#
There is a phishing copy of every major site: fake Uniswap, fake OpenSea, fake MetaMask, fake Etherscan. They rank in Google Ads, appear in Telegram links, and get pinned in "official" Discord channels by impersonator admins.
Defense:
- Once you confirm a site is real, bookmark it.
- Always navigate via that bookmark โ never via search results or shared links.
- On mobile, save to home screen.
Ten seconds of inconvenience prevents the single most common attack vector.
Rule #4 โ If returns sound impossible, they are#
- "Guaranteed 10% per day" โ pure Ponzi.
- "Mirror this whale wallet, automatic 50%/month" โ fake copy trade.
- "Bitcoin doubling event from [celebrity]" โ fake giveaway.
Bitcoin's long-term average has been extraordinary by traditional standards. Anyone offering more reliable returns than that is selling a fantasy.
The 7 attack categories that account for ~99% of losses#
Memorize the pattern and the one-line defense for each.
- Phishing sites โ a fake DApp clone steals seed phrase or tricks you into signing a drainer. Defense: bookmark real sites; never click search ads.
- Wallet drainers โ malicious "free mint" or "claim" transactions that grant token-spending permission. Defense: read transactions in Rabby; revoke old approvals quarterly via revoke.cash.
- Fake support โ DM from "MetaMask support" or "Coinbase team" asking for seed phrase or 2FA codes. Defense: real support never DMs first. Block and report.
- Rug pulls โ project creators drain liquidity and disappear. Defense: check liquidity lock and run a GoPlus scan before buying any new token.
- Airdrop scam tokens โ a token appears in your wallet with a name like "Visit-website-to-claim." Visiting triggers a drainer. Defense: never interact with unfamiliar airdropped tokens. Just ignore them.
- Romance / pig butchering โ long-game scam where someone befriends you on dating apps, then introduces an "investment opportunity." Most losses are $50kโ500k. Defense: never invest based on advice from someone you met online and have not met in person.
- Fake giveaways โ "Elon Musk is giving away Bitcoin โ send 0.1 BTC, get 1 BTC back." Defense: no legitimate giveaway requires you to send first. Period.
A sneakier variant: clipboard hijacking#
Malware can detect when you copy a crypto address and silently replace it with the attacker's. You paste, send, funds go to the wrong place.
Defense: always verify the first 5 and last 5 characters of any pasted address against the source before confirming. Hardware wallets show the destination on the device screen โ read it.
Recovery scams โ when you're already a victim#
After a scam, victims often get contacted by "recovery experts" or "blockchain forensics services" promising to retrieve funds for an upfront fee. These are second-stage scams. Real blockchain forensics firms (Chainalysis, Elliptic, TRM Labs) work with law enforcement, not with individual retail victims. Pay nothing upfront โ that's always the giveaway.
What to do if you've been scammed#
- Stop sending more. Most victims double down trying to "recover" losses, making it worse.
- Document everything โ transaction hashes, addresses, screenshots, dates.
- Report to the platform. If the funds touched Coinbase, Binance, etc., file a support ticket. They sometimes freeze recipient accounts.
- Report to law enforcement. US: IC3.gov. UK: Action Fraud. EU: Europol's EC3.
- Report the scammer's address publicly โ Twitter, Etherscan label, wallet providers (MetaMask phishing list).
- Do NOT pay recovery services. They're follow-on scams.
- Move remaining funds. If your wallet was compromised at any level, move everything to a fresh wallet with a new seed phrase. Don't reuse the compromised one.
Bottom line#
Crypto safety isn't complicated โ it's behavioral. Four rules and a handful of patterns cover almost everything. The reason scams still work is that people don't actually follow the rules, especially when they're tired, excited, or under time pressure.
Next reads: Common crypto scams 2026 ยท Wallet drainer explained ยท How to keep crypto safe.
Frequently Asked Questions
Related Articles
Trust Wallet for Beginners: Mobile-First Multi-Chain Guide (2026)
Trust Wallet for beginners: install on iOS or Android, secure your seed phrase, send across 100+ chains, use the DApp browser, and decide whether Trust Wallet or MetaMask suits your case.
Phantom Wallet for Beginners: Complete Solana (and Multi-Chain) Guide (2026)
Phantom Wallet for beginners: install in 30 seconds, secure your seed phrase, connect to Solana DApps, stake SOL for 6โ8% APY, and use the new Bitcoin + Ethereum support.
Top 10 Crypto Wallets in 2026: Hot, Cold, Mobile & Multi-Sig Compared
The 10 best crypto wallets in 2026 โ MetaMask, Phantom, Ledger, Trezor, Rabby, Safe. Compared by chain support, security, UX, and use case. Includes recommended wallet stacks for each user profile.