Introduction
The previous paper in this series argued that cryptocurrency attracts unusual concentrations of fraud because of a combination of structural features — irreversibility, pseudonymity, global reach, near-zero token creation costs — and cultural ones — tribal communities, influencer-driven information, narratives of overnight wealth, and the relentless pull of fear of missing out. That argument was diagnostic. The present paper is practical.
Its aim is to equip the reader to recognize the shape of a scam even when the particular story is unfamiliar. Scams in this space mutate constantly in surface detail, but their underlying structures are remarkably stable. A person who understands the categories can usually identify a new variant within a few minutes of encountering it, even when the specific tokens, platforms, and personalities are ones he has never heard of.
The taxonomy that follows is organized by the level at which the fraud operates: at the level of an individual token, at the level of a platform that holds or trades tokens, at the level of direct social manipulation of users, at the level of investment schemes that merely use crypto as a wrapper, at the level of affinity relationships that exploit existing trust, and at the level of impersonation. A final section addresses the red flags that cut across all categories. Throughout, the discussion focuses on patterns rather than on specific incidents, and avoids identifying particular victims in identifying ways.
A note before beginning. The descriptions that follow are meant to inform readers so that they can protect themselves; they are not meant to serve as instructions for anyone tempted to imitate the schemes. Each of the categories described is illegal in most jurisdictions, and the legal consequences for those caught operating them have grown substantially more severe in recent years.
Token-Level Frauds
These are schemes in which the cryptocurrency token itself is the instrument of fraud. The token exists to extract money from buyers, and the mechanism of extraction is built into the token’s design.
Rug Pulls
A rug pull is the simplest and most common form of token-level fraud. The creators of a new token build enthusiasm through marketing, attract buyers who exchange real money for the new token, and then, once a sufficient amount has been gathered, sell their own holdings and disappear. The token’s price collapses to zero or near-zero, and the buyers are left holding worthless assets. The funds, by then, have typically been moved through a series of intermediary addresses and converted into other assets, making recovery nearly impossible.
The distinguishing feature of a rug pull, as opposed to a project that simply fails, is intent. A failed project loses its buyers’ money because the team could not make it work; a rug pull loses it because that was the plan from the start. Distinguishing the two from outside can be difficult, which is part of what makes the scheme effective.
Honeypot Contracts
A honeypot is a more technically sophisticated variant. The token’s underlying code is written so that buyers can purchase the token but cannot sell it. The seller’s wallet, or a small set of insider wallets, retain the ability to sell, but everyone else is trapped. The price chart of a honeypot often looks attractive — steadily rising, with no sellers — because the only people who can sell are the perpetrators, and they wait until the trap is full before doing so.
The mechanism is invisible without inspecting the token’s code, which most retail buyers neither do nor know how to do. Several services now exist that attempt to detect honeypots automatically, but the perpetrators adapt their techniques to evade detection, and the arms race continues.
Coordinated Pump-and-Dump Groups
In a pump-and-dump, a group of organizers acquires a large position in a low-volume token, coordinates a sudden burst of promotional activity to attract retail buyers, and sells into the resulting price rise. The retail buyers, arriving late, are left holding the token as the price collapses.
These groups operate openly on certain messaging platforms, with members paying for early access to “calls” — announcements of which token will be promoted next. The earliest tier of members buys first, the middle tier second, the lowest tier third, and the public last. By design, only the earliest tier reliably profits; everyone else is, in effect, the exit liquidity for those above them in the structure. Members who lose money rarely complain, both because the loss confirms their own low position in the hierarchy and because they hope to recoup on the next call.
Platform-Level Frauds
These are schemes in which the fraud operates at the level of a platform — an exchange, a lender, a custodian — rather than at the level of any particular token. The platform itself is the instrument.
Fake Exchanges
A fake exchange is a website or application that presents itself as a venue for buying, selling, and storing cryptocurrency, but which in fact has no real trading engine and no real custody. Users deposit funds, see fictional balances and trading activity on the interface, and may even be allowed to withdraw small amounts initially to build trust. Larger withdrawals are blocked under various pretexts — “verification fees,” “tax withholdings,” “anti-money-laundering reviews” — that themselves often require further deposits. When the operators have extracted as much as they can, the website disappears.
Distinguishing a fake exchange from a real one is harder than it should be. Legitimate exchanges and fake ones can look nearly identical from the outside, and the warning signs — implausible returns, unsolicited recruitment, pressure to deposit quickly — overlap with patterns sometimes seen at legitimate platforms during promotional periods.
Long-Running Exit Scams
A more patient variant is the platform that operates legitimately, or nearly so, for an extended period — months or years — and then exits with customer funds. During the operational period, the platform builds a reputation, attracts deposits, processes withdrawals, and earns fees. When the operators decide the time has come, customer access to withdrawals is suspended, communication ceases, and the funds are moved through obfuscating channels.
Several of the most consequential exchange collapses of the past decade have followed this pattern, though in most cases the operators argue afterward that the failure was the result of mismanagement or external shocks rather than fraud. The legal proceedings that follow typically take years to resolve and rarely return more than a small fraction of customer funds.
“Lending” and “Yield” Platforms That Are Actually Ponzi Schemes
A particularly destructive variant of platform-level fraud is the lending or yield platform that promises high returns on deposited cryptocurrency. The promised yield is justified in marketing materials by various claimed activities — lending to institutional traders, providing liquidity to decentralized exchanges, sophisticated arbitrage strategies — that the platform’s operators are said to perform with customer funds.
In a meaningful number of cases over the past several years, the actual source of the promised yield has been the deposits of new customers, paid out to earlier customers as “interest.” This is the classic Ponzi structure described by Charles Ponzi a century ago, dressed in modern vocabulary. The scheme runs as long as new deposits exceed withdrawals, and collapses as soon as withdrawals catch up. The collapse, when it comes, is sudden and total.
The warning sign for this category is consistent above all others: any return that is substantially higher than what legitimate lending markets pay, and that is presented as low-risk or risk-free, is almost certainly being paid from somewhere other than the activity claimed.
Social Engineering
These are schemes in which the technology and platforms are largely incidental, and the fraud operates through direct manipulation of the user. The target is not the system but the person.
Phishing
Phishing in cryptocurrency follows the familiar pattern from the wider internet, with a few twists specific to the field. The attacker constructs a website, email, or pop-up that imitates a legitimate service — a popular wallet, a major exchange, a token project — and induces the user to enter credentials or, more damagingly, the user’s private key or seed phrase.
A seed phrase is a sequence of words from which all of a wallet’s private keys can be derived. Anyone who obtains the seed phrase has full control of the wallet and all of its funds, permanently. Legitimate services never ask for a user’s seed phrase, for any reason. The single most important defensive habit in this entire field is the absolute refusal to enter a seed phrase anywhere other than the wallet software for which it was originally generated, and even there only when restoring access — never in response to a prompt, a support request, or a “verification” of any kind.
Fake Customer Support
A related pattern: the user posts a question or complaint on a public forum about a wallet, exchange, or project. Within minutes, a private message arrives from an account identifying itself as customer support, offering to help. The “support agent” walks the user through a process that requires entering the seed phrase, connecting the wallet to a fraudulent site, or transferring funds to an address for “verification.” The funds, of course, are gone.
Legitimate support staff never reach out unsolicited through private messages on public platforms, and never request the information these impersonators request. The pattern is reliable enough to function as a near-perfect filter: an unsolicited private message offering support after a public post is, in this field, almost always fraudulent.
SIM Swap Attacks
A SIM swap is a technique in which the attacker convinces a mobile carrier to transfer the victim’s phone number to a SIM card under the attacker’s control. With the phone number captured, the attacker can intercept text messages used for two-factor authentication, reset account passwords, and gain access to accounts that the user believed were protected.
This attack has been used to compromise both crypto exchange accounts and the personal wallets of public figures known to hold substantial cryptocurrency. The defense is to avoid using text-message-based two-factor authentication for accounts that hold significant value, and to use hardware-based authentication keys or authenticator applications instead. The next paper in this series will treat the operational security measures in more detail.
Investment Fraud in Crypto Clothing
These are schemes that would be recognizable as ordinary investment fraud in any market, but that use cryptocurrency as the medium because it makes the fraud easier to execute and harder to prosecute.
High-Yield Investment Programs
The high-yield investment program — promising returns of one percent per day, or five percent per week, or some similar figure that no legitimate investment can sustain — is a pattern older than the internet. In cryptocurrency form, it usually involves a polished website, a story about proprietary trading algorithms or arbitrage opportunities, and an interface that displays accumulating returns in real time. Withdrawals work for a time. Then they do not.
The mathematics of these programs are unforgiving. A return of one percent per day compounds to more than three thousand seven hundred percent per year. No legitimate investment activity in the world generates such returns sustainably. Any program advertising them is either a Ponzi scheme that will collapse or an outright fraud that has no investment activity behind it at all. The two outcomes are equivalent for the buyer.
Fake Managed Accounts
A variant: the buyer is recruited by someone presenting himself as a successful trader who manages money for clients. The buyer is invited to open an account on a platform — sometimes a fake exchange, sometimes a legitimate one — and to grant the “trader” access. The buyer sees impressive gains accumulate in the account over a period of weeks. When the buyer attempts to withdraw, fees and taxes are demanded, deposits cannot be matched, and the gains turn out to have been entirely fictional.
Signal Groups and Subscription Trading Services
A milder but still predatory variant: services that charge a monthly fee for trading “signals” — recommendations on which tokens to buy and sell. The signals are usually generated by the operators’ own trading positions, so that subscribers’ purchases drive up the prices of tokens the operators already hold and are about to sell. The subscribers pay both the subscription fee and the cost of being on the wrong side of the operators’ trades.
Affinity Fraud
These are schemes that exploit existing relationships of trust — family, friendship, romance, community membership, shared faith — to gain access to victims who would have rejected the same pitch from a stranger.
“Pig Butchering”
The term, awkward but vivid, is the one commonly used in the field for a class of schemes in which the perpetrator builds an emotional relationship with the victim over weeks or months before introducing any financial element. The initial contact may be through a dating application, a social network, an apparent wrong-number text message, or a professional networking site. The perpetrator presents himself or herself as an interesting, successful, attractive person, and invests substantial time in establishing rapport.
Eventually, financial topics arise naturally in the conversation. The perpetrator mentions an investment that has been going well. The victim expresses interest. The perpetrator demurs, then offers to help. The victim makes an initial small investment and is shown impressive returns. Larger investments follow. When the victim attempts to withdraw, complications arise; fees are demanded; the demands escalate; the relationship eventually evaporates along with the funds.
The schemes are operated, in many cases, by organized criminal enterprises with extensive infrastructure. Some involve workers who are themselves victims of human trafficking, compelled to operate the schemes under threat. The cruelty of the form is matched by its effectiveness; reported losses to these schemes have grown into the billions of dollars annually.
Community-Based Schemes
A related pattern involves the exploitation of trust within tight-knit communities. The perpetrator is a member of the community, or convincingly presents himself as one, and uses his standing to recruit fellow members into an investment scheme. The community context lowers the buyer’s natural caution: a person who would scrutinize a stranger’s pitch may accept a brother’s or a fellow congregant’s recommendation with little examination.
These schemes have been documented in immigrant communities, professional associations, religious congregations, and various other settings where strong bonds of mutual trust exist. They have appeared specifically in churches, where the perpetrator’s apparent piety serves the same function that wealth or credentials serve elsewhere — as a marker of trustworthiness that bypasses ordinary scrutiny. The Apostle Paul warned that men would creep into households and lead astray those who were weak; the warning applies with full force to financial deception conducted under the guise of fellowship.
The defense against affinity fraud is simple to state and difficult to practice: the trustworthiness of the messenger is not evidence of the soundness of the investment, and a sound investment can withstand the same scrutiny regardless of who recommends it. A brother who is genuinely offering a good opportunity will not be offended by careful questions; a brother who is offended by careful questions is offering something else.
Imposter Scams
These are schemes that exploit the names, images, and reputations of real people or organizations to lend false credibility to a fraudulent pitch.
Deepfaked Public Figures
Advances in video and audio generation have made it possible to produce convincing fake recordings of public figures appearing to endorse cryptocurrency products. These recordings circulate on social media platforms, often as advertisements, and direct viewers to fraudulent websites. The figures depicted — business executives, financial commentators, and others — have not endorsed the products and in many cases do not know their likeness is being used.
The defense is suspicion of any video advertisement for a financial product that depicts a famous person making claims that would be remarkable if true. Legitimate financial products almost never advertise through unsolicited celebrity endorsements on social media.
Fake Giveaways
A persistent pattern: a social media post or website announces that a major company, prominent individual, or cryptocurrency project is conducting a giveaway, in which participants who send a small amount of cryptocurrency to a specified address will receive a larger amount in return. The promise is sometimes presented as a promotional event, sometimes as a security verification, sometimes as a charitable initiative. The sent funds are never returned.
No legitimate giveaway has ever required participants to send funds first. The pattern is sufficiently universal that the request itself is conclusive evidence of fraud.
Fraudulent “Official” Communications
The final variant: communications that present themselves as official announcements from cryptocurrency projects, exchanges, or wallet providers, directing recipients to take specific actions — visit a particular site, sign a particular transaction, provide particular information. The communications are crafted to look authentic, often using the same logos, formatting, and language as genuine announcements. The actions they request, however, result in compromised accounts or drained wallets.
Legitimate projects communicate through their established official channels and rarely require urgent action from users. The combination of urgency and a request for sensitive action is, in this field, a near-universal indicator of fraud.
Red Flags That Cut Across Categories
A reader who has followed the survey to this point will have noticed that certain warning signs recur across nearly all of the categories. The recurrence is not accidental; it reflects the underlying logic that all of these schemes share. A short list of cross-cutting red flags can serve as a portable summary.
Guaranteed returns, or returns substantially above what legitimate markets pay. No legitimate investment offers guaranteed returns. Any pitch that does is, at best, misrepresenting risk, and is more likely a fraud.
Pressure to act quickly. Legitimate financial opportunities tolerate careful consideration. Fraudulent ones cannot, because careful consideration reliably uncovers them.
Unverifiable team or unverifiable underlying activity. A project whose team members cannot be confirmed to exist, or whose claimed underlying activity cannot be confirmed to take place, is presumptively fraudulent.
Custody held by the project itself. When the entity offering the investment also holds the customer’s funds, with no independent custodian, no audit, and no insurance, the customer is entirely dependent on the entity’s honesty. This dependence has been violated often enough that the structure itself should be viewed with skepticism.
Promises that do not survive the question “what is the source of the yield?” Every payment to an investor has to come from somewhere. If the source cannot be explained in concrete, verifiable terms, the most likely source is the deposits of later investors, which means a Ponzi scheme.
Unsolicited contact. Legitimate investment opportunities do not arrive through dating applications, wrong-number text messages, or private messages from strangers on social media. The unsolicited nature of the initial contact is itself diagnostic.
Requests for sensitive information. Seed phrases, private keys, and account passwords should never be shared with anyone, for any reason, under any pretext. The category of requests for these items contains zero legitimate cases.
Reliance on a single individual’s claims. When the entire case for an investment rests on one person’s representations — a charismatic founder, a trusted community member, a confident trader — and cannot be independently verified, the investment is functionally a bet on that individual’s character. Such bets, in this field, lose with unusual regularity.
Conclusion
The taxonomy presented here covers the great majority of cryptocurrency frauds in circulation, though the surface details continue to evolve and new variants appear regularly. A reader who has internalized the categories and the cross-cutting red flags is in a substantially better position than one who tries to evaluate each new scheme on its own terms. The underlying logic of fraud is older than cryptocurrency, older than the internet, older even than the modern financial system. Recognizing it requires not technical sophistication but ordinary wisdom applied steadily, with the humility to admit that one is not too clever to be deceived.
The Scriptures observe that the simple believes every word, but the prudent man looks well to his going. The categories in this paper are, in effect, a description of where the going requires the most careful looking.
The final paper in this series turns from recognition to participation. For the reader who has weighed the promise and the peril and has concluded that some measured involvement is right for him, what does prudent participation actually look like?
Notes
- The vocabulary of cryptocurrency fraud changes more rapidly than the underlying patterns. Readers encountering this paper at some distance from its writing should expect that the terminology has shifted in places, but the structures it describes are likely to remain recognizable. New names, in this field, are usually applied to old schemes.
- The figure of one percent per day, used in the discussion of high-yield investment programs, is chosen because it is the threshold at which a return becomes mathematically incompatible with any legitimate underlying activity. Programs offering substantially less than this can still be fraudulent, but the certainty grows with the promised rate.
- The phenomenon described as “pig butchering” appears to have originated in criminal enterprises operating from compounds in several countries in Southeast Asia, with workers in many cases trafficked from elsewhere and held in coercive conditions. The schemes have global reach, with victims documented in essentially every wealthy country and many less wealthy ones. The U.S. State Department and several humanitarian organizations have documented the human-trafficking dimensions of these operations; readers interested in pursuing that aspect will find the references useful.
- Affinity fraud within churches has a long history that predates cryptocurrency by centuries. The Apostle Paul’s warning in 2 Timothy 3 about men who creep into households is one ancient example; the warnings in 2 Peter 2 about false teachers who through covetousness make merchandise of the faithful are another. The patterns described in this paper are not new in kind, only in vehicle. Congregations would do well to apply the same prudence to financial recommendations from fellow members that they would apply to recommendations from strangers, and pastors would do well to remind their flocks of that prudence rather than to assume it.
- The remarks on deepfaked endorsements should not be read as suggesting that all video advertisements involving public figures are fraudulent. They are not. But the rate of fraudulent ones has grown enough that suspicion is the appropriate default, particularly when the advertised product is a financial one and the platform is one on which advertising standards are weakly enforced.
- The red flag concerning custody held by the project itself reflects one of the most consistent findings of post-mortem analyses of failed crypto platforms: customer funds were commingled with platform funds, used for purposes the customers did not know about, and could not be recovered when the platform failed. The structural separation of customer assets from platform assets that is taken for granted in regulated financial markets has been the exception rather than the rule in cryptocurrency markets so far.
- The recurring observation throughout this paper that legitimate operators do not engage in particular behaviors — never ask for seed phrases, never require funds to be sent before a giveaway, never offer guaranteed returns — is not a guarantee that every legitimate operator avoids every such behavior in every case. It is a statement about base rates: the population of entities engaging in these behaviors consists overwhelmingly of fraudulent ones, and treating the behaviors as decisive indicators is the strategy that produces the best outcomes for the user across the full range of cases.
References
Cross, C., Holt, K., & Powell, A. (2023). Understanding romance fraud: Insights from domestic violence research. British Journal of Criminology, 63(1), 1–17. https://doi.org/10.1093/bjc/azab108
Federal Bureau of Investigation, Internet Crime Complaint Center. (2024). Internet crime report 2023. U.S. Department of Justice. https://www.ic3.gov/AnnualReport/Reports/2023_IC3Report.pdf
Federal Trade Commission. (2024). Consumer Sentinel Network data book 2023. Federal Trade Commission. https://www.ftc.gov/reports
Gandal, N., Hamrick, J. T., Moore, T., & Oberman, T. (2018). Price manipulation in the Bitcoin ecosystem. Journal of Monetary Economics, 95, 86–96. https://doi.org/10.1016/j.jmoneco.2017.12.004
Hamrick, J. T., Rouhi, F., Mukherjee, A., Feder, A., Gandal, N., Moore, T., & Vasek, M. (2021). An examination of the cryptocurrency pump-and-dump ecosystem. Information Processing & Management, 58(4), Article 102506. https://doi.org/10.1016/j.ipm.2021.102506
Li, T., Shin, D., & Wang, B. (2021). Cryptocurrency pump-and-dump schemes. SSRN. https://doi.org/10.2139/ssrn.3267041
Mazza, M. F. (2022). Is crypto-property prone to fraud? Lessons from the collapse of major exchanges. Stanford Journal of Blockchain Law & Policy, 5(2), 88–117.
Mei, Y., Gül, M., & Bütün, İ. (2024). Detecting honeypot smart contracts: A multi-stage classification approach. IEEE Access, 12, 14523–14538. https://doi.org/10.1109/ACCESS.2024.3357821
Moore, T., & Christin, N. (2013). Beware the middleman: Empirical analysis of Bitcoin-exchange risk. In A.-R. Sadeghi (Ed.), Financial cryptography and data security (pp. 25–33). Springer. https://doi.org/10.1007/978-3-642-39884-1_3
North American Securities Administrators Association. (2023). Enforcement report 2023. NASAA. https://www.nasaa.org/industry-resources/enforcement/
Securities and Exchange Commission. (2023). Crypto assets and cyber enforcement actions. https://www.sec.gov/spotlight/cybersecurity-enforcement-actions
United Nations Office on Drugs and Crime. (2023). Casinos, money laundering, underground banking, and transnational organized crime in East and Southeast Asia. UNODC. https://www.unodc.org/roseap/
U.S. Department of Justice. (2023). International virtual currency money laundering enforcement actions. https://www.justice.gov/criminal/cryptocurrency
U.S. Department of State. (2024). Trafficking in persons report 2024. https://www.state.gov/trafficking-in-persons-report/
Vasek, M., & Moore, T. (2015). There’s no free lunch, even using Bitcoin: Tracking the popularity and profits of virtual currency scams. In R. Böhme & T. Okamoto (Eds.), Financial cryptography and data security (pp. 44–61). Springer. https://doi.org/10.1007/978-3-662-47854-7_4
Vasek, M., & Moore, T. (2018). Analyzing the Bitcoin Ponzi scheme ecosystem. In A. Zohar et al. (Eds.), Financial cryptography and data security (pp. 101–112). Springer. https://doi.org/10.1007/978-3-662-58820-8_8
Xia, P., Wang, H., Gao, B., Su, W., Yu, Z., Luo, X., Zhang, C., Xiao, X., & Xu, G. (2020). Trade or trick? Detecting and characterizing scam tokens on Uniswap decentralized exchange. Proceedings of the ACM on Measurement and Analysis of Computing Systems, 5(3), Article 39. https://doi.org/10.1145/3491051
Xu, J., & Livshits, B. (2019). The anatomy of a cryptocurrency pump-and-dump scheme. In Proceedings of the 28th USENIX Security Symposium (pp. 1609–1625). USENIX Association.
