Crypto fraud hit a record $11.37 billion in 2025 according to the FBI. The seven scam playbooks that account for most of it, the specific tells in each, and what to do if you have already sent funds.

Last updated: 28 July 2026
The FBI's Internet Crime Complaint Center recorded 11.37 billion dollars in cryptocurrency-related fraud losses in 2025 across more than 181,000 complaints, a record, and more than half of all internet crime losses reported that year. Americans aged 60 and over filed 44,555 crypto complaints and lost roughly 4.4 billion dollars, by far the largest share of any age group.
Those numbers describe a professionalised industry, not opportunistic theft. Chainalysis put total scam revenue above 17 billion dollars for the same year and reported that impersonation scams grew by more than 1,400% year over year, driven substantially by generative AI. This guide covers the seven playbooks doing most of the damage and the specific tells in each.
The largest category by value. The scammer builds a relationship over weeks, often starting with a wrong-number text or a dating app match, avoids discussing investments early, and only later introduces a trading platform that shows spectacular returns. The platform is fake. Small withdrawals are honoured to establish trust. The large one triggers a demand for tax or unlocking fees.
The tells: a stranger initiating contact who steers toward money; a platform you cannot find independently; returns without volatility; pressure to increase the position; and above all, a fee demanded before you can withdraw. No legitimate venue requires payment to release your own funds.
Rather than stealing keys, this attack persuades you to sign a transaction that grants a contract permission to move your tokens. The signature looks routine. The approval is unlimited and permanent until revoked. This is the dominant on-chain theft mechanism for people who otherwise practise good security, and it is covered in depth in our guide to wallet drainers and approval phishing.
The tells: urgent airdrop claims, "your wallet is compromised, migrate now" messages, and any signature request whose plain-language summary you cannot explain to yourself.
The fastest-growing category. Voice cloning needs only seconds of audio; video deepfakes of well-known figures now run convincingly in livestreams promoting fake giveaways. Chainalysis attributes the 1,400% growth in impersonation scams substantially to these tools, and the average scam payment rose sharply as a result.
The tells: any giveaway requiring you to send first; support agents who contact you rather than the reverse; urgency plus a familiar face. Verify through a separate channel you initiate yourself. A real executive does not livestream a doubling offer.
Cloned front ends of real platforms, or entirely invented exchanges with fabricated volume. Deposits work; withdrawals do not. The 2026 exchange closure wave has made this worse, because users are actively searching for new venues and for withdrawal help, which is exactly the moment a cloned site does its best work.
The tells: the URL reached via an advertisement, a search result or a message rather than typed; no verifiable corporate entity; not present in any regulatory register. Our guide to verifying MiCA authorisation covers how to check a platform against the official registers.
The attacker sends a zero-value transaction from an address whose first and last characters match one you regularly use. It lands in your transaction history. Later you copy an address from that history, glance at the familiar start and end, and send funds to the attacker.
The defence: never copy an address from transaction history. Use a saved address book, and verify the full string rather than the ends.
A token launches with real liquidity and marketing, attracts buyers, and the team removes the liquidity or dumps the supply. Variants include contracts with hidden mint functions or transfer restrictions that prevent selling.
The tells: anonymous teams with no verifiable history, unlocked liquidity, concentrated token supply, unverified contracts, and returns promised as a fixed rate. Sustainable yield comes from identifiable sources: trading fees, lending interest, staking rewards. If nobody can explain where the return originates, that is the answer.
The second robbery. Having lost money once, victims are approached by "recovery specialists" or fake law enforcement who promise to trace and return the funds for an upfront fee. Victim lists circulate among fraud groups, which is why the approach often arrives soon after the original loss. Covered fully in our guide to crypto recovery scams.
For businesses, the equivalent controls are analytical rather than behavioural. Blockchain analytics platforms such as Crystal Intelligence trace stolen funds and flag exposure to known fraud infrastructure before a deposit is credited. Identity verification providers such as iDenfy address the onboarding side, where synthetic identities and deepfaked verification attempts are now a routine attack rather than an edge case.
The FBI's IC3 recorded 11.37 billion dollars in cryptocurrency-related fraud losses in 2025 across more than 181,000 complaints, a record and more than half of all reported internet crime losses. Chainalysis estimated total scam revenue above 17 billion dollars for the same period.
A long-form investment fraud in which the scammer builds trust over weeks through social or dating apps before introducing a fake trading platform showing fabricated profits. Small withdrawals are honoured to establish credibility; larger ones trigger demands for fees that never end.
Americans aged 60 and over reported roughly 4.4 billion dollars in crypto losses in 2025, the largest share of any age group. The combination of accumulated savings, less familiarity with on-chain mechanics and greater social isolation makes the long-relationship playbooks unusually effective.
Sometimes, but only through law enforcement. Blockchain transactions are irreversible, and no private service can force a return. Recoveries occur when authorities seize assets at exchange off-ramps, which is why prompt reporting matters. Anyone who contacts you offering paid recovery is running a second scam.
A mandatory delay. Nearly every playbook depends on urgency, so a personal rule that no significant transfer happens within 24 hours of first hearing about the opportunity removes the pressure the scam requires to work.
Legitimate protocols are not, but the category attracts imitators. The distinctions that matter are verifiable: published audits, open-source contracts, documented and explicable yield sources, and a real team. Yield promised as a fixed guaranteed rate with no stated source is the clearest warning sign.