QuantoLogDescribe the incident
QuantoLog · Knowledge base

10 common crypto theft and fraud schemes

These are not QuantoLog case studies and do not imply any guaranteed outcome. This is an overview of recurring incident patterns. In each case, preserving source data quickly and assessing the technical prospects separately is important.

1. Address poisoning

Address poisoning

How it works. An attacker creates a visually similar address and inserts it into wallet history with a zero-value or dust transaction. The victim later copies the wrong address after checking only the beginning and end.

What matters first. Preserve the original transaction, destination address, network and time. With USDT, response speed can matter before funds move further.

2. Approval phishing and drainer-as-a-service

Approval phishing and drainer-as-a-service

How it works. A fake mint, airdrop or migration page tricks the user into granting broad token permissions to a malicious contract.

What matters first. Review approvals/delegates, revoke dangerous permissions and preserve URLs, signatures and transactions for analysis.

3. Permit / Permit2 signature phishing

Permit / Permit2 signature phishing

How it works. The victim signs an off-chain message, so compromise may occur without an immediate transaction or gas payment. The signature can be used later.

What matters first. Investigate the preceding signing/session history, not only the final outgoing transaction.

4. Pig butchering

Pig butchering

How it works. Long-term social engineering leads the victim to a fake investment platform. Small withdrawals may work before larger deposits and additional “fees” are demanded.

What matters first. Preserve chats, wallet addresses, tx hashes, domains and payment details. Do not pay unknown parties for “taxes” or “unlocking”.

5. Fake support and seed-phrase theft

Fake support and seed-phrase theft

How it works. A fake support agent asks for a seed phrase, wallet “validation” or a transfer to a “safe” address.

What matters first. If the seed phrase was disclosed, treat the wallet as fully compromised and move remaining assets to a new wallet with a new seed as quickly as safely possible.

6. Fake job offers and device malware

Fake job offers and device malware

How it works. A malicious file, test assignment or fake application update steals wallet keys, browser extensions or clipboard data.

What matters first. Isolate the device, stop using old keys, preserve artifacts and migrate assets only after creating a clean environment.

7. SIM swap and exchange account takeover

SIM swap and exchange account takeover

How it works. The attacker gains control of a phone number, resets credentials and bypasses SMS-based 2FA to withdraw exchange assets.

What matters first. Contact the exchange and mobile operator immediately, request withdrawal restrictions and preserve login history and notifications.

8. Rug pull and honeypot contracts

Rug pull and honeypot contracts

How it works. A token team removes liquidity or a contract prevents ordinary holders from selling.

What matters first. Analyze contracts, holder distribution and liquidity before purchase; after an incident, preserve the contract address and transaction history.

9. Second-wave recovery scams

Second-wave recovery scams

How it works. After the initial loss, the victim is approached by “lawyers” or “investigators” promising guaranteed recovery in exchange for another prepayment.

What matters first. Verify the provider, contract and methodology. No legitimate investigator can guarantee recovery of digital assets.

10. P2P and tainted USDT

P2P and tainted USDT

How it works. A good-faith participant receives assets linked to a suspicious cluster and later encounters an AML review or service freeze.

What matters first. Screen counterparties and addresses before transactions and preserve source-of-funds documentation and communication history.

If an incident has already happened, an initial review usually starts with a short description, tx hash or wallet address. Never share a seed phrase or private key.

Describe the incident