Here's the uncomfortable truth nobody puts on a banner. Most people who lose money in crypto don't get hacked by some shadowy genius. They get talked into it. A friendly DM, a too-good return, a fake support agent, and they hand over access themselves, often quite politely. The good news buried in that is that almost all of these scams wave the same flags before they take your money, which means they're learnable, and avoidable.

Learn the flags and you dodge the large majority of them. Here's the routine I'd give any beginner before they send a single dollar anywhere.

The five checks before you trust anything

  1. Guaranteed returns? Walk away. No real investment promises fixed profits, ever. 'Double your ETH in 24 hours' isn't an opportunity, it's a theft with a marketing budget.
  2. Are they rushing you? Urgency is the scammer's favorite tool, because thinking is their enemy. 'Offer ends tonight' exists to stop you checking. Real chances don't evaporate in an hour.
  3. Did they message you first? Unsolicited DMs offering help, jobs, giveaways, or profit are almost always traps, even from accounts with official-looking names and logos.
  4. Are they asking for your seed phrase? Nobody legitimate ever needs it. Not support, not a developer, not an airdrop, not a 'wallet verification.' Anyone who asks is trying to steal from you, full stop.
  5. Did you verify the link yourself? Type addresses in manually or use a saved bookmark. Never trust a link from the message that's pushing you to act, because that's how fake sites harvest your wallet.

The scams that catch beginners most

A few patterns come up over and over, and recognizing them is half the battle. Fake support is a big one: you post a problem publicly in a Discord or on social media, and a 'support agent' DMs you within minutes, warm and helpful. Real support almost never slides into your DMs first. Then there's the giveaway scam, the 'send 1 ETH, get 2 back' classic, which is simply theft with a countdown timer bolted on. And the slow ones, romance or friendship scams, where someone invests weeks building genuine-feeling trust before casually mentioning a can't-miss investment they can help you into.

There are fancier versions, fake exchange apps, cloned websites a character off from the real URL, malicious token approvals that drain a wallet after you click 'connect.' But underneath the variety, the same handful of signals keep showing up. Master the signals and you don't need to memorize every individual scam.

What to do if you've already connected or clicked

If you suspect you interacted with something malicious, move quickly but calmly. Transfer any remaining funds to a fresh wallet you control, because a compromised wallet should be treated as permanently compromised. Revoke token approvals using a reputable approval-checker tool. And stop engaging with whoever contacted you, because 'recovery agents' who promise to get your stolen funds back are very often the same scammers running a second act on the same victim.

Your one habit

If you take one thing from this, take this: slow down. Almost every one of these scams relies on you acting fast and feeling something strongly, either excitement or fear. The scammer needs speed, because speed switches off the part of your brain that asks sensible questions. So your single best defense is a deliberate pause. When something pushes you to act right now, treat that pressure itself as the red flag. Close the app, breathe, verify independently. The opportunity that can't survive ten quiet minutes of checking was never a real opportunity in the first place.