
The crypto market runs without a single regulator, without deposit insurance, and without a bank you can call to reverse a transfer. That's both its biggest advantage and its biggest vulnerability. Any blockchain transaction is irreversible: send to the wrong address, sign the wrong smart contract, enter your seed phrase on a fake site — and the money is gone for good.
By various estimates, the PlusToken scheme alone drained somewhere between $2 and $6 billion in cryptocurrency from investors, with the victim count running into the millions. Squid Game Token crashed from $2,860 to zero in five minutes, taking about $3.3 million from more than 40,000 holders. These aren't rare exceptions — they're the market's regular statistics, where hype outruns common sense.
I've been following these stories for a while, and there's one pattern that keeps showing up: the victim almost always noticed a warning sign but ignored it because they wanted so badly to believe in fast profit. This article isn't about panic. It's about the specific signs that let you spot a scam in five minutes — before the money leaves your account.
Crypto fraud breaks down into several categories based on how it's executed. Understanding the difference matters: phishing protection won't save you from a rug pull, and knowing how to read a smart contract won't help you spot a fake exchange.
Phishing is stealing access to a wallet or exchange through a fake interface that visually copies the real one. There's one goal: get the victim to enter a private key, seed phrase, or password on a resource controlled by scammers.
The scheme is almost always the same. First comes the trigger: an email about "suspicious account activity," a Telegram message from "exchange support," a search ad for a popular wallet's name. The domain gets faked by one or two letters (binance.com becomes binaance.com, or Ьinance.com with a Cyrillic "Ь" that's visually indistinguishable from the Latin B). The victim then enters their data on the clone site, and within minutes scammers drain the real account.
A separate category is phishing through browser extensions and fake wallet apps in official stores. An app can sit in Google Play for months disguised as MetaMask or Trust Wallet, with a few hundred downloads and inflated reviews, before it gets taken down.
Another vector is phishing through transaction signing. The victim gets a link to an "airdrop" or "token claim" that requires connecting a wallet and signing a transaction. On the surface it looks harmless, but the approve permission can grant the smart contract unlimited access to every token in the wallet. Sign one transaction, and a minute later the wallet is empty.
A rug pull (literally "pulling the rug out") is a scheme where a project team collects investor funds, then withdraws liquidity and disappears. Developers either dump their entire token supply on the market at once, crashing the price to zero, or physically pull the funds out of the liquidity pool on a decentralized exchange.
The classic case is Squid Game Token. In October 2021, riding the popularity of the Netflix series of the same name, an anonymous team launched the SQUID token with a promise of "play-to-earn" gaming. Within days the price rose from fractions of a cent to $2,861. On November 1, 2021, the developers took down the website, deleted all social media, and pulled the liquidity, walking away with about $3.3 million. The token crashed to zero within minutes. The project had a sell restriction built into the smart contract: you could buy SQUID freely, but you couldn't sell it. That's the main technical signature of a rug pull — an "anti-dump" mechanism that blocks investors from exiting while the developers close out their own positions.
In my experience, if a token only allows buying with no way to sell (or selling carries a punitive 50-90% fee), that's not a borderline case anymore — it's a rug pull blueprint.
There's also a softer version — the soft rug pull, where the team doesn't steal outright but simply stops developing the project, gradually sells off its token allocation (slowly enough not to crash the chart too hard), and quietly fades away. It's harder to catch because there are no formal signs of theft — the asset just dies slowly.
A Ponzi scheme pays "returns" to earlier investors using money from new ones, with no real economic activity behind it. It works as long as the inflow of new money exceeds the outflow of payouts. The moment inflow slows down, the whole thing collapses within days or hours.
PlusToken is the largest crypto Ponzi scheme in history. The project launched in April 2018 as a wallet promising monthly returns of up to 9-18% annually, supposedly from mining and exchange arbitrage. In reality there was no mining at all — payouts came from new participants' money. By the time it collapsed in June 2019, organizers had accumulated, by various estimates, between $2 and $6 billion in cryptocurrency, including roughly 180,000 BTC and 6-9 million ETH. The mass movement of stolen coins onto exchanges in July 2019 coincided with a sharp drop in Bitcoin's price, and some analysts link the two events directly. Chinese authorities arrested over 100 people in the case, and the organizers received sentences of up to 11 years.
One question helps tell a Ponzi scheme apart from a legitimate project: where does the promised return actually come from? If the answer is "trading algorithms," "a secret arbitrage strategy," or "the referral program," and nobody shows concrete numbers on the profit source, that's a red flag. Legitimate trading or mining activity leaves a verifiable trail: wallet addresses, reporting, audits. A Ponzi scheme never has that trail. The same "guaranteed profit without risk" logic underlies binary options schemes too — technically not crypto scams, but they run on the same casino psychology.
Formally in the same category are referral pyramids, where earnings come not from investing but from recruiting new participants under you. If a project pays more attention to its multi-level referral network than to the actual product, that's a pyramid scheme wrapped in crypto terminology.
A fake exchange is a platform that mimics trading functionality but doesn't actually route orders to a real market. Deposits go through, the interface shows the balance "growing," and withdrawals never work — always blocked by verification, taxes, "insufficient liquidity," or a plain technical error that somehow takes weeks to fix.
A separate problem is low-quality listings on exchanges with weak project screening. Market analysts estimate that up to 90% of new tokens on exchanges with loose compliance (like MEXC) are short-lived projects with a quick dump after listing. That doesn't make the exchange itself fraudulent — it just means the entry bar for a token issuer is minimal there, and the team and tokenomics barely get checked. Tier-1 exchanges (Binance, Bybit, Bitget) screen harder: the team checks the smart contract for hidden minting functions, sell-blocking backdoors, and token concentration in a handful of wallets.
This is where the coin screener in Secret Terminal helps: it flags abnormal volume spikes on fresh listings, which often precede a dump — before the price actually collapses on the chart.
A fake token is a related story. Scammers create a coin with the name and ticker of a well-known project (say, a counterfeit USDT on an obscure blockchain network) and add it to a DEX pool. An inexperienced trader copies the contract address from an unverified source, buys the "token," and ends up with an asset that has no value outside that specific pool.
A separate genre is paid "mentors" and Telegram channels selling trading signals. The pattern is simple: the channel posts a few profitable trades (often backdated or from a demo account), builds an audience, and sells a paid subscription or "private club" for $200-500 a month. After that, the signals either stop working, or they were rigged from the start so the channel owner profits from subscriptions, not trading.
A more aggressive version is "mentors" who offer to manage a student's deposit directly through API keys with withdrawal permissions. My standing advice here is to check exactly one thing: if the API key you're handing over has withdrawal permission enabled, that's not education — that's direct access to your money. Legitimate trading terminals and bots operate on keys with read-only balance access and trading rights, never withdrawal rights.
By the way, there's a free lesson in the Secret Terminal YouTube crypto trading course that covers exactly how to create and connect an exchange API key without excess permissions — it also walks through the whole access-rights logic using Binance, Bybit, and OKX as examples.
A quick check takes five minutes and filters out the vast majority of scam projects right at the start. Crypto fraud almost always leaves technical traces that are visible in advance, if you know where to look. The problem is that in the middle of the hype, almost nobody spends those five minutes.
These eight points aren't a hard pass/fail threshold. One match could be a coincidence. Three or more is almost guaranteed to be a scam.
First thing I do is open a blockchain explorer (Etherscan, BscScan, or the equivalent for the relevant network) and check the token distribution across wallets. If the top 3 addresses hold more than half the supply, that's a risk concentration that almost always ends badly for small holders.
Next I check whether liquidity is locked. Services like Team.Finance or Unicrypt show time-locks publicly. No lock means a high risk the developer pulls the pool whenever they want.
The smart contract is worth at least a quick check through automated audit services (like De.Fi Scanner or Token Sniffer), which catch typical vulnerabilities: hidden minting, sell-blocking functions, fee honesty. A full manual code audit is a job for a specialist, but an automated scanner filters out most obvious traps in seconds.
And last, a simple search for the project name plus the word "scam" on Google or Reddit. If a project has been around for more than a couple of months and it's a scam, someone has almost always already written about it.
Even knowing the checklist, people regularly lose money on the same mistakes.
The eight signs catch most blatant scams, but not all of them. A professionally prepared rug pull can imitate a legitimate project for months: the team doxxes itself with real names, the audit was done by a real company, liquidity is formally locked through a multisig wallet. The catch is that the multisig is controlled by three anonymous addresses belonging to the same team. Technically the checklist passes; in reality the risk remains. In cases like this, the only real protection is not putting into a single project any amount whose loss would actually hurt you — no matter how convincing the team looks.
A separate risk zone is the market segments where deals happen directly between people, without the guarantees of a centralized exchange.
Crypto arbitrage is legal on its own, but a whole scam industry has grown up around it. In arbitrage and P2P communities, offers regularly pop up to buy a ready-made "bundle" (a set of accounts, cards, and instructions) promising stable, risk-free income. In reality, these bundles often sell schemes that are already "burned" or blocked, leaving the buyer with either an empty how-to guide or accounts the bank will freeze within the first week of use.
The pattern in closed P2P chats looks similar: the "bundle" seller usually makes money not from arbitrage but from selling the bundle itself to the next buyer. Once a scheme has been sold to a third or fourth round of people, it's already "burned" in the eyes of banks and exchanges, and the new owner gets not a profitable strategy but a ready-made reason for their account to get frozen.
P2P arbitrage (buying crypto for fiat from one counterparty and selling to another at a premium) is legal on its own, but it's been under heightened financial-monitoring scrutiny since 2025. The problem isn't the scheme itself but the source of the counterparty's funds.
If the crypto seller received fiat from a fraudulent scheme (phishing, darknet "services" scams, cashing out stolen cards) and the buyer simply transferred money to pay for the coins, when the bank investigates the incident, it's the buyer's account that gets frozen — because technically it was their transfer to a "suspicious" recipient. You can prove good faith later, but that means weeks of correspondence with the bank and all funds in the account frozen the whole time.
What reduces the risk: working only with verified counterparties who have a deal history and platform rating, avoiding deals with amounts far outside your account's normal profile, and paying attention to how recently the money landed with the counterparty (if fiat hit the seller's account literally a minute before the deal, that's a reason to walk away).
If the money is already gone, what to do next depends on exactly where it went: to an exchange, into a scammer's wallet, or into a scam project's smart contract.
If the funds were withdrawn to a known exchange (Binance, Bybit, and similar), contact the exchange's support team with the transaction address and hash attached. Exchanges sometimes freeze addresses flagged as fraud-related, especially when there are many victims and the address is already blacklisted by analytics firms like Chainalysis.
For larger amounts, it's worth filing a police report (in Ukraine, the cyber police) and reaching out to specialized blockchain forensics firms that track stolen funds through mixers and exchanges. This isn't free and doesn't guarantee a result, but for amounts starting at a few thousand dollars, it can be worth it.
If the phishing happened through a compromised exchange account (not a wallet), the first steps are changing the password, disabling all active API keys and sessions, and enabling or recreating two-factor authentication.
It's worth being honest here: in most cases, you can't fully recover the funds. Blockchain transactions are technically irreversible — the money can only be tracked, with an attempt to freeze it at the next link in the chain (usually a centralized exchange, where the scammer eventually cashes out to fiat).
Partial recovery is realistic in a few scenarios: if the scammer used a KYC exchange and was identified before cashing out to fiat, if law enforcement managed to seize the assets (as happened in the PlusToken case, where Chinese authorities confiscated crypto worth up to $4 billion), or if the scam project turned out to be a soft rug pull and part of the liquidity is still recoverable through a lawsuit or class action.
Either way, the faster you file with exchange support and the police, the better the chance of freezing something before the scammer manages to cash everything out or split it across dozens of transactions.
A normal correction is a price drop while you can still sell the asset and the dev team is still active. A rug pull is the liquidity, the team, and the website all disappearing at once, often within minutes. If you can sell the asset and find a live project website, that's not a rug pull — just a bad market.
An audit from a known company (CertiK, Quantstamp, Hacken) reduces the risk of technical vulnerabilities like hidden minting, but it doesn't protect against a rug pull via a simple liquidity withdrawal — that's not a technical vulnerability, it's an action by the wallet owner with admin rights. Check both the audit and the liquidity lock separately.
Anywhere from a few minutes to a couple of hours for private key phishing. With a compromised exchange account it takes a bit longer, since they often need to bypass the exchange's own extra security checks.
The airdrop mechanic itself is legal, but the danger is in connecting your wallet to an unfamiliar site and signing unlimited-approve transactions. Before signing, check exactly what permission you're granting using services like Revoke.cash , and if possible use a separate "cold" wallet with no large sums specifically for interacting with new projects.
Don't hand them over. No legitimate deposit management service requires withdrawal rights — only read access to the balance and the ability to trade. Withdrawal rights exist for exactly one purpose: taking the money for themselves.
The listing entry bar there is lower than on Tier-1 exchanges, and team/contract screening is minimal. That doesn't make the exchange itself fraudulent, but it does mean the trader needs to personally check every new asset before trading it.
Through public liquidity-lock services ( Team.Finance , Unicrypt) — they show the pool address, the amount, and the unlock date. If liquidity isn't locked at all, the developer can pull it out at any moment without warning.
Trade only on verified exchanges with a solid reputation, and track the market through Secret Terminal's professional toolset — the order book, the tape, and cluster analysis show you the real liquidity picture, not whatever the marketing of the next scam project wants you to see.
Was helpful
Your rating will help us improve the quality of published materials and increase their usefulness.
We publish product updates, setup guides, and practical materials on working with Secret Terminal tools

What binary options are, why it's not trading but gambling. How the scam works and what to do instead....

Crypto account security rules: 2FA, API keys, phishing, and storage best practices

12 mistakes beginner crypto traders make. Check yourself.