Threats, Scams and Privacy

Recognise account takeovers, malicious approvals, impersonation, device compromise, and the physical risks created by public transaction history.

Last updated: July 202614 Articles4 h 19 min read
Warning symbol surrounded by common scam hooksStart here
01.07.26Beginner14 min

10 Most Common Crypto Scams and How to Spot Them

A crypto scam is a fraud that manipulates a person into authorising the loss of their own cryptocurrency, whether by sending funds to a criminal, revealing a seed phrase or login code, or signing a transaction that hands over spending power. Scams attack judgement rather than cryptography, which is why the defences are habits rather than software.

Clipboard swapping a verified wallet address for a malicious lookalikePart 2
01.10.26Beginner17 min

Address Poisoning and Clipboard Attacks Explained

Address poisoning is a payment-redirection attack that plants attacker-controlled lookalike addresses in a victim's transaction history, using zero-value token events, counterfeit tokens or tiny transfers, so that a later copy from that history selects the attacker's address.

Microphone soundwave turning into a masked synthetic face beside a warning signPart 3
01.10.26Beginner18 min

AI Voice Clones and Deepfake Crypto Scams

AI voice-clone and deepfake crypto scams are a form of impersonation fraud that uses generative models to copy the voice, face or writing of someone the target trusts, such as a relative, executive, support agent or celebrity, to press for an urgent crypto transfer or login codes.

Person shielding against a phishing messagePart 4
01.07.26Medium29 min

Crypto Scams and Threats: How to Spot and Avoid Them

Chainalysis identified at least 14 billion US dollars of 2025 on-chain inflows to addresses classified as scams or fraud according to on-chain analysis, with the full total projected to exceed 17 billion as more illicit addresses are identified.

Rising returns chart on a fishhook dangling above a spiked trap and a warning signPart 5
01.10.26Beginner23 min

Guaranteed Returns: The Biggest Red Flag in Crypto

A guaranteed-return offer is an investment pitch promising a fixed, above-market return with little or no claimed risk. The SEC lists "high returns with little or no risk" first among its Ponzi scheme warning signs.

Two hands repairing a broken security keyPart 6
01.07.26Beginner15 min

How to Respond If Your Crypto Is Hacked or Stolen

Crypto incident response is the sequence of actions that limits damage after assets or access are compromised: diagnose the type of breach, evacuate remaining funds from a clean device, revoke or freeze what the attacker can still use, secure surrounding accounts, report to platforms and law enforcement, and rebuild in a safer structure.

Wallet connected to a malicious approval requestPart 7
01.07.26Medium14 min

How Wallet-Draining and Approval Attacks Work

A wallet drainer is criminal infrastructure, typically rented as a service, that steals through usable authority: a new authorisation the owner is deceived into signing, a signature made with an already-stolen key, or a permission granted long ago to a spender that later turns hostile.

Anonymous figure protected inside a privacy enclosurePart 8
01.07.26Medium15 min

On-Chain Privacy: What Your Wallet Reveals

On-chain privacy is the degree to which blockchain activity can be linked to a real-world identity. Transparent blockchains publish every transaction, amount, address and timestamp forever, so privacy rests entirely on unlinkability: keeping addresses unconnected to each other and to a name.

Discreet wearable representing physical crypto securityPart 9
01.07.26Medium14 min

Physical Security and Coercion: Staying Off the Radar

A wrench attack is a physical attack on a crypto holder that replaces hacking with force: robbery, home invasion, kidnapping or extortion aimed at making the victim hand over keys or authorise transfers. The name comes from a security comic's observation that a five-dollar wrench beats expensive cryptography by hitting the person instead of the maths.

Friendly chat messages leading from a phone to a fishhook and a Bitcoin falling into a holePart 10
01.10.26Beginner17 min

Pig Butchering: How Long-Con Crypto Scams Build Trust

A relationship investment scam is investment fraud that begins with a relationship. A scammer, usually making contact out of the blue online, builds trust and then steers the person into depositing money, often crypto, on a counterfeit trading platform. It shows invented gains and may pay out a small early withdrawal.

Fingerprint and lock representing layered account authenticationPart 12
01.07.26Beginner17 min

Two-Factor Authentication, SIM-Swaps, and Account Security

Two-factor authentication is an account security method that requires two independent proofs of identity before granting access: typically something you know, such as a password, plus something you have, such as a phone, an authenticator app or a hardware key. It protects an account even when the password leaks.

Magnifying glass revealing the hidden details of a transaction before it is signedPart 13
01.10.26Medium19 min

What Is Blind Signing? How to Verify Before You Sign

Blind signing is a way of approving a crypto transaction or message that commits the signer's key to data the signer cannot read or check. It happens when a wallet cannot decode the request and shows raw data, or when compromised software describes the request as something it is not. The approval then depends on trusting whoever built the request.

ID card and fingerprint sending personal data into an exchange profilePart 14
01.10.26Beginner26 min

Why Do Exchanges Ask for Your ID? KYC and What They Know

Know-your-customer (KYC) is an anti-money-laundering control that requires regulated financial businesses to identify and verify their customers; where a jurisdiction's law covers crypto businesses, it applies to exchanges alongside record-keeping, transaction monitoring and suspicious-activity reporting. Each jurisdiction sets its own duties, thresholds and start dates.

What is...

See more

FAQ

Where should I start with Threats, Scams and Privacy?

10 Most Common Crypto Scams and How to Spot Them. Start with the first guide. It introduces the vocabulary used by every later guide in this learning path.

Do I need to read every guide in this path?

No. Follow the sequence for a structured introduction, or open the guide that answers your current question and return to earlier material when a concept is unfamiliar.

What should I read after finishing this path?

Continue with one of the related clusters below. Each path approaches the same systems from a different angle.

How should I use the Threats, Scams and Privacy learning cluster?

Recognise account takeovers, malicious approvals, impersonation, device compromise, and the physical risks created by public transaction history. Keep the glossary open alongside the articles and use each knowledge check to identify concepts worth revisiting.

Where do the biggest risks appear in Threats, Scams and Privacy?

Recognise how people actually get hit—account takeovers, scams, and malicious approvals—and the habits that keep you safe. The guides separate protocol behaviour from the operational, market, custody, and human risks that surround it.