Skip to content

Common scams

8 min read

Most Bitcoin theft has nothing to do with breaking cryptography, it relies on tricking a person into handing over access willingly.

Quiz still to takeGo to the quick check

Answer every question correctly (100%) to complete this lesson.

Your progress is kept in this browser. An account keeps it across your devices.

Giveaway scams promise to send back double whatever bitcoin is sent to an address, often impersonating celebrities or companies on hijacked or fake social media accounts. There is no mechanism by which sending bitcoin can ever return more bitcoin automatically; the address simply keeps everything sent to it.

Fake support scams contact people who posted about a wallet problem publicly, or plant fake support numbers in search results and ads, then ask for recovery words or remote screen access to "fix" the issue, the fix is the theft.

Romance and investment-platform scams build trust over weeks or months before directing a victim to a fake trading platform showing fabricated gains, encouraging larger deposits, and blocking withdrawals once a large amount is in. Address poisoning sends a tiny transaction from a look-alike address to a wallet's history, hoping the owner later copies that similar-looking address by mistake instead of the correct one.

Explain more simply

Real Bitcoin support never asks for your recovery words, and nobody legitimate can "double your bitcoin" by sending them some first.

Common tricks include fake giveaways, fake customer support, romance scams that lead to fake investment platforms, and messages pretending to be from a well-known company.

If something creates urgency ('act now or lose access') or asks for secret words, slow down, that pressure is itself a warning sign.

Real-world analogy

These scams rarely pick a lock; they convince the owner to hand over the key while smiling. The defence is not a better lock, it is recognising the smile.

Key facts

  • No legitimate service ever needs your recovery words to help you.
  • "Send bitcoin to get double back" has no legitimate version, it is always a giveaway scam.
  • Address poisoning relies on you copying a similar-looking address from history by mistake.
  • Completed Bitcoin transactions cannot be reversed by any third-party "recovery service".

Common misconception

A scam recovery service can get stolen bitcoin back for a fee.

Completed transactions on Bitcoin cannot be reversed by anyone, including the network itself. Services promising recovery for an upfront fee are, with rare exception, a second scam targeting people already victimised once.[3]

Go deeper

Clipboard-hijacking malware silently replaces a copied Bitcoin address with an attacker's address before pasting, so verifying the pasted address on the signing device's own screen (not just the source app) defeats this class of attack.

Fake hardware wallets or tampered pre-generated seed phrases (a device shipped with a seed already written down, meant to look like a convenience) exploit the assumption that a seed is safe as long as it is written somewhere, always generate a fresh seed on a new device yourself.

Because Bitcoin transactions are irreversible by design, no scam recovery service can "claw back" a completed transaction, and any service claiming to do so for a fee is itself typically a second-stage scam targeting victims of the first.

Quick check

Answer every question correctly (100%) to complete this lesson.

  1. 1.What should you do if a 'support agent' asks for your recovery words to fix a wallet issue?

    What should you do if a 'support agent' asks for your recovery words to fix a wallet issue?
  2. 2.What is address poisoning designed to exploit?

    What is address poisoning designed to exploit?

Counts towards your streak in this browser.

Extra exam questions

Every question here counts towards your accuracy, XP and rank. No guessing: every answer is explained.

16 questions

Quick check

Answer every question correctly (100%) to complete this lesson.

  1. 1.What is the standard pattern behind most phishing messages about wallets or exchanges?

    What is the standard pattern behind most phishing messages about wallets or exchanges?
  2. 2.What is "address poisoning"?

    What is "address poisoning"?
  3. 3.What is the safest way to defeat both address poisoning and clipboard malware?

    What is the safest way to defeat both address poisoning and clipboard malware?
  4. 4.What is "pig butchering" in the context of crypto scams?

    What is "pig butchering" in the context of crypto scams?
  5. 5.Why should you be suspicious of a 'recovery agent' who promises to retrieve stolen crypto for an upfront fee?

    Why should you be suspicious of a 'recovery agent' who promises to retrieve stolen crypto for an upfront fee?
  6. 6.What is a major red flag common to almost all crypto scams?

    What is a major red flag common to almost all crypto scams?
  7. 7.Why is a website insisting your wallet must 'connect' to fix, validate, or claim something considered a red flag?

    Why is a website insisting your wallet must 'connect' to fix, validate, or claim something considered a red flag?
  8. 8.What does a "dusting attack" attempt to do?

    What does a "dusting attack" attempt to do?

Counts towards your streak in this browser.

Sources