How to Spot a Crypto Scam: Six Shapes, and the Step That Takes the Money

Every scheme that removes money in this market needs three things: a way to reach somebody, a period in which credibility is manufactured, and a final step that cannot be reversed. Six shapes account for most losses — a platform that does not exist, a relationship built slowly, a project that removes the floor, a signature that grants permission, a message from support, and a price that was arranged.

Fraud in this market is usually described by its names, which is the least useful way to understand it. Names come from headlines, they change, and they tell a reader nothing about what to look for. The shapes are more stable: every one of the schemes that removes money from a person requires three things — a way to reach them, a period during which credibility is built, and a final step that cannot be reversed. The variation across cases is almost entirely in how the first and third steps are performed, and the second step is where the money actually comes from.

Read that way, the subject becomes a catalogue rather than a series of warnings. Six shapes account for the great majority of losses, and each one can be described by how it arrives, what the decisive step is, and which ordinary assumption it exploits. The assumptions are the interesting part, because they are all reasonable, and each of them is true somewhere other than where the victim applied it.

How to Spot a Crypto Scam: Six Shapes, and the Step That Takes the Money
Six shapes and the assumption each one exploits. In every case the assumption is reasonable, and in every case it is being applied in a context where it does not hold.

The structure, before the shapes

Contact is the first step, and it is usually indirect: an advertisement placed against a search term, a message in a group chat, a direct message from an attractive stranger, a sponsored link that sits above the real site. The channel matters less than its property, which is that the victim arrives at it rather than choosing it.

Credibility is the second step, and it is the part that takes time. A screen with a balance, a chart that goes up, a small withdrawal that clears, a support person who answers questions promptly: each of these is cheap to fabricate and each of them substitutes for the verification a person would perform in the physical world. The step is not designed to convince a sceptic. It is designed to make a final decision feel routine.

The third step is the irreversible one, and it takes exactly three forms. Paying something to receive something larger. Granting permission to move something held elsewhere. And disclosing a secret that constitutes ownership. Every shape below is a different costume on one of those three movements.

Shape one: the platform that does not exist

The first shape is the simplest and the largest by total loss. A convincing interface presents balances, prices, deposit addresses and a support channel, and the balance shown rises as the customer watches. Nothing behind the interface is real: the deposits have moved to an address controlled by the operators, and the balance is a number in a database.

The decisive step is a deposit, usually the second or third one, after a small withdrawal has been allowed to succeed. What the shape exploits is the assumption that a balance displayed by an application corresponds to value held somewhere — an assumption that holds for a bank and for a regulated broker, and does not hold for an address that somebody else controls. Recognizing that a screen can show anything is the entire defence, and it is harder than it sounds because every other financial interface a person uses behaves the way the fake one appears to.

Shape two: the relationship built slowly

The second shape is the one that produces the largest individual losses, and it is a social operation with a technical last mile. Contact comes from an ordinary conversation — a wrong number, a gaming partner, a professional networking message — and the relationship develops over weeks with no mention of money. When the subject does arrive it is framed as an opportunity the person has personally benefited from and is sharing generously.

The technical apparatus is the same as the first shape: a platform, a rising balance, a small withdrawal that clears. What differs is why the victim trusts it, which is not the platform at all. The scheme exploits the fact that a person who has spent a month being treated well will extend trust to the thing the other person recommends, and it is why the defence cannot be technological. Verbal warnings about platforms do not reach a mechanism that operates through a relationship.

Two features of this shape are worth knowing for anyone trying to help somebody who is in it. The first is that the relationship is real to the victim, so arguing about the platform is arguing about a friend. The second is that the sums escalate: the early deposits are small, the intermediate ones are affordable, and the largest one arrives when a withdrawal is blocked and a fee is demanded to release it.

Shape three: the project that removes the floor

The third shape does not require a victim to trust a stranger at all. A token is created, a pool of liquidity is provided so that the token can be bought and sold, and the price is supported by promotion. At a chosen moment the creators withdraw the liquidity they supplied, and the market for the token ceases to exist: buyers can still hold units, and there is nothing left to sell them into.

The decisive step is a withdrawal from a pool, and the mechanism is entirely transparent to anyone who reads the pool’s state. What the shape exploits is a misunderstanding about what a price is in a system with automated market making. A quoted price exists because somebody put assets into a pool; it is not a property of the token, and if the same party can remove what it deposited, then the price was a loan rather than a valuation.

The checkable signals are the same in nearly every case: a creator identity that appeared recently, liquidity that is not locked for a stated period, a supply concentrated in a few addresses, and promotion that arrives from accounts created within the same fortnight as the token. None of those proves intent, and all of them describe a structure in which a single party can end the market at will.

Shape four: the signature that grants permission

The fourth shape does not take anything at the moment it succeeds. It obtains a permission, and the theft happens later, when the attacker chooses to use it. A page requests a signature for a claim, an allow-list, a login or a verification, the amount displayed is zero, and the signature that results authorises a contract to move tokens the user already holds.

What the shape exploits is a difference the interface does not make obvious: sending and allowing are two different operations that arrive as the same gesture. The mechanics of approvals and the pointers contracts can hold are worth understanding precisely because the request looks like nothing, and the thing at risk is never the reward being advertised.

This shape deserves the most attention of the six, for two reasons. It is used against experienced participants as well as beginners, because the defence is not knowledge but the habit of reading each request. And the damage is not limited to what the page appears to offer, since a single unlimited approval can expose an entire balance of a token rather than a quantity anybody agreed to.

Shape five: the message from support

The fifth shape impersonates somebody with authority. A person receives a message that looks like it comes from a venue, a wallet provider or a project they use, and the message states that there is a problem to resolve: a security check, a withdrawal to confirm, a bonus to claim. The continuation is a link and either a request to connect a wallet or a request to enter a recovery phrase into a page.

The decisive step is a phrase typed into a website or shared with a person who claims to be helping. What the shape exploits is the most consequential asymmetry in the industry: the phrase is not a password, it is the asset, and there is no version of the arrangement in which a legitimate operator needs it. Channels are also impersonated at the platform level rather than the message level, which means a link sent through a genuine group chat can still lead to a fabricated destination.

The rule that covers this shape and most of the others is a single sentence. Any interaction initiated by somebody else should be treated as hostile until it has been verified through a channel the user opened, which means typing the address rather than following the link.

Shape six: the price that was arranged

The sixth shape is a market operation rather than a theft. A small token, thinly traded and loudly promoted, rises sharply as coordinated buying meets the absence of sellers, and the rise is reported as evidence that something is happening. Participants who buy into it find that the only liquidity available is the position being sold to them, and when the promotion stops the price returns to where it started.

The decisive step is a purchase into a rising market, which is why this shape is the one most likely to catch people who consider themselves careful. What it exploits is the assumption that a rising price reflects demand rather than supply management. In a market with thin depth, both look identical on a chart, and the difference is only visible in the order book and in the concentration of the holdings.

The variants are worth knowing. Volume can be manufactured by trading between addresses controlled by one party, which produces a convincing histogram and no economic activity. Supply can be released slowly into the rise rather than all at once. And the promotion itself can be outsourced to accounts that are paid to be enthusiastic, which means the people recommending it may also be victims of the arrangement.

What never recovers money, and what sometimes does

A transaction on a public ledger is irreversible by design, which removes the first remedy a person looks for. What remains is a short list, and all of it depends on actors other than the victim. A token issuer can freeze its own liability on a specific address, which is the mechanism that has recovered funds in some cases and which does not reach assets that have been converted into something else. A regulated venue can refuse a deposit, which forces the attacker to find venues with weaker controls and narrows the routes over time.

Investigators can trace, and tracing is easier than people assume: the record is permanent, funded addresses cluster together, and the exit step is visible. What tracing produces is evidence rather than restitution. And a report filed quickly is worth more than the same report filed later, because the first hours are when funds are still moving between intermediaries that can be asked to stop.

The practical ordering for someone who has just lost money is therefore short and urgent: revoke outstanding approvals, move whatever remains to a fresh address, preserve the transaction records, report to the relevant national authority and to any venues involved, and do not pay anybody who offers to recover the funds — a second scheme in this market is tailored precisely to people who are in the state that the first one created.

Three sentences that cover almost everything

How to Spot a Crypto Scam: Six Shapes, and the Step That Takes the Money
Three patterns that appear in almost every case, with the legitimate cousins each one has. None of the three is conclusive on its own, and together they are close to sufficient.

The first is a promise of a return. Markets price risk, and a marketed financial product that guarantees an outcome is either paying from a budget that will end or describing something that is not a return at all. Legitimate versions of this exist — an incentive programme is a real subsidy — and they are honest about being temporary.

The second is a reason to hurry. Urgency is the mechanism by which verification is prevented, and every legitimate process in finance tolerates the time it takes a customer to check. An opportunity that expires in ten minutes is an opportunity whose expiry is the product.

The third is a request to pay, to permit, or to disclose. A fee to release funds, an approval to claim a reward, a phrase to verify ownership: all three transfer value or control away from the person being asked. A legitimate service may charge a network fee and may ask for a signature, and it never asks for the ability to move assets it did not just receive.

Where legitimate products look similar

Two honest situations resemble the shapes above, and knowing them keeps the list from becoming a reason to distrust everything. The first is the genuine promotion: a new protocol paying above-market rates to acquire deposits, with a published schedule and a token that may or may not hold its value. The wording is similar to a scheme’s and the structure is verifiable, which is the difference.

The second is the legitimate request for permission. Every interaction with a decentralised application requires a signature, and a person who refuses all of them can use nothing. The distinction is not whether permission is requested but whether the request is understood, which is why the useful habit is not suspicion as a personality trait but a fixed routine: read the screen, verify the destination, and refuse to sign what cannot be explained.

Why the interface is the weakest link

Almost every shape above relies on the gap between what an interface shows and what an instruction does. A balance shown by an application is a number, a price shown by a pool is a quotation, an amount shown on a confirmation screen of zero is a description of the present rather than of the authority being granted. None of those displays is lying in the sense that a forger lies; each of them is accurate about one thing and silent about another.

That is why the hardware device with a screen remains the most effective single control, and why it is not sufficient. It removes the computer from the act of signing, which defeats the malware that redirects addresses, and it does not translate a contract call into a sentence about its consequences. The last mile of security in this market is a person reading a screen that was designed to be skimmed, and the industry has not solved that, which is the reason the fourth shape keeps working.

Who is targeted, and what actually helps

The targets are not selected by ignorance. They are selected by two properties that are easy to identify from outside: access to money, and anxiety about having missed something. Both are ordinary, and both are what the second step of every scheme is designed to work on. The professional participant who has spent a decade in the market and the person who opened their first account last month are both reachable, and the shapes are simply adjusted.

What helps is procedural rather than educational. A rule that large transfers leave after a delay. A rule that addresses are verified from a source the user opened. A rule that a phrase is never typed into anything connected to a network. And a rule that no decision is made within an hour of being asked, which is the only defence that works against a relationship that has been built over a month.

The economics of the operators

These schemes are a business, and understanding the business explains why they concentrate in this asset class. Three properties make the environment unusually favourable to an operator. Transfers are irreversible, so a successful step cannot be unwound by the victim’s bank. Settlement is global and permissionless, so a recipient in one country can be paid by an address in another without either party having an account anywhere. And the tools required to run a convincing front end are cheap, because the appearance of a trading platform is a matter of design rather than of infrastructure.

The organisational side has professionalised as well. The pattern reported most often by investigators is a compound of operations where some people run the initial contact, others staff the support conversations, and others handle the movement of funds through a chain of exchanges, brokers and over-the-counter desks. That division of labour is why the person a victim spoke to for a month often has no access to the money and no ability to return it.

The targets are selected by two signals that are visible from outside: available funds, and some anxiety about having missed an opportunity. Neither is a failure of intelligence, and the second is especially effective in an asset class whose public conversation is largely about things that have already gone up.

What the industry changed, and what it still cannot fix

The response to these schemes has been institutional rather than individual, and three of the changes are visible in any transaction. Deposit screening at regulated venues has improved to the point that moving stolen funds through a large exchange is materially harder than it was a few years ago, which pushes laundering toward brokers and over-the-counter desks. Wallet software now surfaces approvals, offers to revoke them, and warns about addresses that match those already in a user’s history.

A third change is specific to the structure of these assets: an issuer can freeze its own token on a given address, which is the only mechanism in the system capable of moving value back after a transfer. It reaches the assets that are still the ones that were taken, and it does nothing once they have been converted, which is the same asymmetry that governs recovery in every other case.

What cannot be fixed is the part that happens before any of those controls apply. A person who types a phrase into a website has transferred ownership, and a person who sends funds to a platform that does not exist has sent them to an address that will not return them, and no improvement in monitoring changes either outcome after the fact. That is why the useful interventions remain procedural and unglamorous: a delay before large transfers, verification of destinations through channels the user opened themselves, and a personal rule about never signing a request that cannot be explained in a sentence.

Failure is not fraud, and the difference matters

Two situations resemble the shapes above without being schemes, and confusing them produces bad judgement in both directions. The first is the project that fails honestly: a team raised money, built something, and the thing did not work, so the token fell and the product closed. The second is the ordinary loss: an asset was bought, the market fell, and the position is worth less than it was.

The distinguishing question is about intent and disclosure rather than about outcome. A failed project that published its code, its holdings and its changes of plan has done something different from one that moved funds to an address nobody can identify, even when the financial result for a holder is the same. And an asset that fell has done something different from one whose price was arranged by the party selling it.

The reason the distinction matters is practical. A person who cannot tell fraud from failure will treat every loss as a betrayal, which destroys the ability to evaluate anything. A person who treats every loss as market risk will not learn the signals that were available. The signals are in the structure rather than in the outcome: whether the rules were published, whether the funds were controlled by one party, and whether the people involved answered questions before the price moved rather than after.

A catalogue, not a warning

Six shapes, three irreversible steps, and one structural fact: the interface can show anything, and the ledger records only what was actually done. Every one of the schemes above ends with a payment, a permission or a disclosure, and every one of them begins with a period during which credibility was manufactured more cheaply than it could be verified.

The useful conclusion for a reader is not a list of names to avoid, since the names change every quarter. It is the shape of the trade: somebody is offering an outcome, on a timetable they set, in exchange for an action the reader cannot undo. Where those three conditions appear together, the offer is either a scam or a legitimate product the reader should understand before accepting — and in both cases, the correct next step is the same.

Analysis

The Bitget Hack and the $387 Million Question: Should a Public Chain Freeze Stolen Funds?

2026-10-2 10:53:37

Blockchain

Alpenglow's Real Risk Isn't the 150 Milliseconds. It's the Word Incompatible.

2026-9-28 19:28:22

0 comment A文章作者 M管理员
    No Comments Yet. Be the first to share what you think
❯
Profile
Cart
Coupons
Check-in
Message Message
Search