You are one click away from sending money to a stranger who spent weeks earning your trust, or to a “platform” that looks flawless and will never let you withdraw. Crypto scams work because they copy the look of the real thing and lean on one weakness: trust given too fast. The fix has nothing to do with luck or technical genius. It is a short, repeatable check you run before every deposit, transfer, or token buy. This guide hands you that routine, plus a checklist to keep.
The Crypto Trading Starter Kit
A plain-English PDF: what to check before you trade, how orders and risk really work, and the mistakes to skip. Get it free.
TL;DR / Quick take: Most crypto scams collapse against one habit: verify before you trust, every time. Learn the handful of scam types you will actually meet, run a 30-second red-flag scan on any message or platform, lock down your wallet and recovery phrase, and vet a venue or token with free public tools before spending a cent. If something already went wrong, act in the first hour, preserve evidence, and never pay anyone who promises to recover your funds – that is a second scam.
Scammers love crypto because it moves fast and a transfer cannot be reversed once it confirms on the blockchain. A bank can sometimes claw back a fraudulent card payment. A crypto transfer is final. So the whole game comes down to moving the decision to the front, before money leaves your control. This checklist works for a complete beginner. You do not need to understand how a blockchain works to use it.
Adopt the one rule that beats most scams
If you remember nothing else: verify before you trust. One wrong transfer costs you the whole amount, while a check costs two minutes. Scammers engineer situations where you feel you have to decide right now. The rule flips that. Anything urgent gets slower, not faster.

Two terms come up constantly. Your private key is the secret that controls your crypto, the master password to a safe; whoever holds it owns what is inside. Your seed phrase (or recovery phrase) is usually 12 or 24 plain words that regenerate that key, the spare master key on paper. No legitimate person, app, or “support agent” ever needs either one. That single fact defuses a huge share of scams.
The rule in one line: Unsolicited contact + pressure to act now + a request that touches your money or keys = stop and verify, every time.
Match each common scam to its clearest tell
You do not have to memorise a hundred schemes. The same handful keep reappearing in new costumes. Learn each one by its tell, the single thing that gives it away, and you will spot the next variant.

| Scam type | How it works | The clearest tell |
|---|---|---|
| Fake exchange / platform | Looks like a real broker; deposits work, withdrawals never do. | Money goes in easily but “fees” block taking it out. |
| Phishing / wallet drainer | A fake link or airdrop page asks you to approve a transaction that empties your wallet. | An unexpected link to connect, sign, or approve to “claim” something free. |
| Rug pull / honeypot | A token you can buy but cannot sell, or whose creators vanish. | Big hype, anonymous team, no one accountable. |
| Pig butchering | A warm stranger befriends you, then steers you to a fake app showing fake profits. | An online stranger introduces an “amazing” investment with screenshots of gains. |
| Impersonation / deepfake | Fake celebrity or exec endorsements, fake “support”, AI-generated video. | A famous face “personally” promising returns off official channels. |
| Giveaway “send 1, get 2” | “Send any amount and we double it.” Nothing returns. | Any promise that multiplies money you send first. |
| Recovery scam | Targets people already scammed: “we can retrieve your funds” for a fee. | Unsolicited offer to recover losses for a fee or your keys. |
Every row shares a pattern: free money, secret access, or pressure. If a message hits one of those notes, you have your answer. Do not engage to “find out more”, because that is the door they want open.
Spot the red flags in 30 seconds
Run this scan before any deposit, transfer, or buy. It takes half a minute and catches most attempts. If even one flag goes up, stop and verify before you do anything.

The 30-second scan:
Guaranteed or “risk-free” returns? → red flag.
Asked for your seed phrase or private key? → red flag, always.
Pushed to act now before an offer “expires”? → red flag.
Did the contact arrive unsolicited (DM, text, random call)? → red flag.
Is the team anonymous or impossible to verify? → red flag.
Asked to pay off-platform or to a personal wallet? → red flag.
Does the domain look almost right but slightly off? → red flag.
Take the last crypto message you received and run those seven questions on it now. Real opportunities survive scrutiny. Scams need you to skip it.
Protect your wallet and keys
Most crypto loss has nothing to do with a clever hack. It is access handed over by accident. Do these five steps today.
- Write your seed phrase on paper, never online. Store it offline and private. Never enter it into a website, chat, “validator”, or support form, because no service ever needs it.
- Use app-based two-factor authentication rather than SMS. Two-factor (2FA) means a second code on top of your password. An authenticator app beats SMS, because phone numbers can be hijacked (“SIM-swapped”) and text codes stolen.
- Separate spending from savings. Keep a small “hot” wallet online for daily use and a separate long-term wallet you rarely connect. If the hot one gets drained, your main holdings stay safe.
- Revoke old token approvals. Crypto apps ask for permissions (“approvals”) that let a contract move your tokens. Clear out the ones you no longer use every so often.
- Verify the full address before you send. Malware can swap a copied address for the attacker’s, so check the first and last characters and test with a tiny amount first.
One habit ties these together: slow down at the moment of transfer. That is when mistakes become permanent.
Vet a platform or token before you buy
You can avoid most “fake platform” losses because the warning signs sit in public and cost nothing to check. Run this workflow before your next deposit, and walk away the moment something does not add up.
Vetting workflow:
Check the exact domain (look-alikes use tiny misspellings) → look up the company and its regulator on the official register → verify the token contract on a major data site like CoinGecko or CoinMarketCap and on a block explorer (the public ledger viewer that shows every transaction) → test with a small deposit and a real withdrawal before committing → prefer a regulated, transparent venue so “is this platform fake?” stops being a question.
That last step removes a whole class of risk. A scam “platform” hides its costs, has no verifiable licence, and skips identity checks because it never intends to be accountable. A regulated venue does the opposite. Volity, for example, operates under a published regulatory footprint (CySEC licence 186/12 via UBK Markets, plus Saint Lucia, Cyprus and Hong Kong entities), publishes a full fee schedule at SEE FEES AND ACCOUNT TYPES, and runs real KYC, covering identity, proof of address and source of funds, the exact verification a fake platform avoids. None of that makes any platform “scam-proof”, and no honest service claims to be. It simply takes the “fake venue” question off the table. See the Volity crypto hub for plain-English guides.
Verdict: If you are a beginner, vet any platform before depositing and start on a regulated, transparent venue with a published fee schedule and real identity checks. OPEN A VOLITY ACCOUNT at volity.io, or practise risk-free with a FREE DEMO ACCOUNT first.
Act fast if you have already been scammed
If you think you have been caught, the first hour matters and panic works against you. You cannot undo a confirmed transfer, but you can stop further losses and preserve evidence. Follow these four steps in order.
- Stop all further transfers. Send nothing more, and pay no “release fee”, “tax”, or “unlock” payment. Those demands are the scam continuing.
- Move remaining funds and cut access. If a wallet may be compromised, revoke its approvals and move remaining crypto to a fresh wallet with a new seed phrase. Change passwords and 2FA on linked accounts.
- Screenshot everything. Capture wallet addresses, transaction IDs, chat logs, profiles, links, and amounts, because this is what any platform, bank, or authority will ask for.
- Report through official channels. Notify the real platform, your bank or card issuer if fiat was involved, and your local or national fraud body.
Be honest with yourself about recovery: nobody can guarantee it, and “recovery experts” are a second scam that targets the freshly burned. Do not pay anyone who promises to get your funds back. Real reporting goes through official bodies, never a stranger asking for a fee or your keys.
Save the crypto safety checklist
Here is the whole routine in one place. Save it and run it before every deposit, transfer, or buy. It folds the red-flag scan, wallet hardening, and platform vetting into a single pass.
The crypto safety checklist:
1. Run the 30-second red-flag scan (guaranteed returns, seed-phrase request, urgency, unsolicited contact, anonymous team, off-platform payment, look-alike domain).
2. Never share or type your seed phrase or private key, anywhere, for any reason.
3. Use app-based 2FA, not SMS, on every account.
4. Keep a small hot wallet separate from your long-term savings wallet.
5. Verify the exact domain and the token contract on a major data site and a block explorer.
6. Look up the platform’s licence on the official register; prefer a regulated, transparent venue.
7. Test with a small deposit and a real withdrawal before committing real size.
8. If scammed: stop transfers, move remaining funds, screenshot everything, report officially – and never pay a “recovery” service.
Build the habit of verify before you trust and you remove most of the risk that catches beginners. If you want a calm place to learn and practise without the “is this real?” anxiety, a regulated venue with a free demo makes a sensible start, and the Volity trader education hub walks through safe habits step by step.
Reviewed by: A. Bennett, Volity editorial desk.
Data accuracy: all Volity facts here (regulatory footprint, free demo, KYC, fee schedule, account types) are verified against the Volity fact bank and the published fee schedule, current to June 2026. No scam-loss figures, recovery rates, or named projects are stated, as none are independently verified here.
Related Volity guides
- How to choose a trading platform
- How to deposit and withdraw from a trading account
- How much money do you need to start trading?
Related coverage on Volity
- Crypto Regulation 2026: USDC, Solana and CLARITY Act
- Bitcoin Price Holds K as Whales Buy, XRP CLARITY Act in Focus
- Demo vs Live Trading Account: A 7-Step Checklist Before You Go Live
- How to Choose a Trading Platform: A 10-Point Checklist
- Fractional Shares Explained: How to Start Investing With
Frequently asked questions
What are the most common crypto scams?
Fake exchanges and platforms, phishing and wallet-drainer links, rug pulls and honeypot tokens, pig-butchering romance-investment schemes, impersonation and deepfake endorsements, “send 1 get 2 back” giveaways, and recovery scams. Learn each one by its tell, whether that is free money, secret access, or pressure, and run the 30-second scan before you act.
How do I know if a crypto platform is legit?
Check the exact domain for look-alike misspellings, look up the company and its licence on the official regulator register, and test a small deposit and a real withdrawal before committing. Prefer a regulated, transparent venue that publishes its fee schedule and runs real KYC. If withdrawals stall behind surprise “fees”, treat it as a scam.
Can you get scammed crypto money back?
Nobody can guarantee recovery, since a confirmed transfer is final. Your best move is to act in the first hour: stop further transfers, move remaining funds, screenshot all evidence, and report to the platform, your bank, and your local fraud authority. Never pay a “recovery service” that contacts you, because that is a common second scam.
No, never, with no exceptions. Your seed phrase (the 12 or 24 recovery words) and private key control your crypto completely. No legitimate wallet, exchange, or support agent ever asks for them, so anyone who does is trying to rob you. Write the phrase on paper, store it offline, and never type it online.
Is crypto trading safe for beginners?
Crypto carries real market risk, and no one can promise safety or guaranteed returns. That promise is itself a red flag. You remove a large slice of avoidable risk by trading on a regulated, transparent venue with good habits: verify before you trust, harden your wallet, and vet every platform and token. A free demo account lets you learn without risking real money.
What is the fastest way to check a suspicious message?
Run the 30-second scan: does it promise guaranteed returns, ask for your seed phrase or keys, push you to act now, arrive unsolicited, come from an anonymous source, request off-platform payment, or use a slightly-off domain? One yes is enough to stop and verify through official channels first.
Sources
The guidance above draws on the following public sources.
- Financial Conduct Authority – regulator advice on spotting scams
- Action Fraud (UK national fraud reporting centre) – how investment fraud is reported
- CISA – recognise and report phishing
- UK National Cyber Security Centre – set up two-step verification
- NIST (SP 800-63B Digital Identity Guidelines) – why SMS codes are weaker
- bitcoin.org – common crypto scam patterns
- bitcoin.org – securing your wallet and backup
- ethereum.org – revoke old token approvals
- arXiv (An Explorative Study of Pig Butchering Scams) – research on pig butchering scams





