All guides
Security

Five Bitcoin Scams That Empty Wallets — and How to Spot Each One

6 min read

Giveaway frauds, cloned websites, fake support agents, and the psychology behind every pitch — a field guide to the attacks that take the most Bitcoin from real holders.

Very little Bitcoin is stolen by breaking cryptography. It is stolen by breaking trust — or more precisely, by manufacturing trust where none should exist. Scam techniques change their costumes every year, but the underlying scripts are remarkably stable. Learn the five scripts below and you will recognise virtually every attempt that will ever land in your inbox, feed, or DMs.

1. The giveaway: pay ten, receive a hundred

A video or post shows a well-known figure promising to multiply any Bitcoin sent to a specific address. The video is real; the promise is fabricated with a deepfake or an edited caption. The address on screen is static, so the scammer can even pre-load it with a few 'wins' — comments from fake accounts thanking them for doubled coins. The arithmetic is the tell: nobody with money doubles it for strangers, and a genuine promotion never requires you to send funds first.

Every 'send first, receive more' scheme is a one-way transfer. There is no second half of the deal.

2. The cloned site: a perfect wallet, one wrong letter

Phishing kits copy popular exchange and wallet websites pixel for pixel and host them at lookalike domains — a swapped letter, an extra hyphen, a different ending. They rank in search advertisements precisely because ad platforms verify far less than people assume. The victim logs in, and the credentials are relayed to the real site in real time so nothing looks wrong until the balance is gone. Bookmark the true address once and navigate only from that bookmark; never reach a financial site through a search ad or an emailed link.

3. Fake support: the unsolicited helper

Post publicly that your deposit is stuck, and within minutes an 'official support agent' appears. Real support teams do not monitor social media for victims and then message first. The script always converges on the same demand: read out your seed phrase, or enter it into a 'validation tool' to 'sync' your wallet. No legitimate company, developer, or support agent ever needs your seed phrase for any reason. That single sentence, believed, defeats the entire category.

  • An incoming call from 'support' asking to 'verify' your phrase — hang up.
  • A screenshare request during troubleshooting — decline; it exposes everything on screen.
  • An urgent warning that your wallet is compromised and must be 'migrated' — urgency is the product.

4. The romance and the trading genius

Long-con frauds build a relationship — romantic or mentorship — over weeks or months, then introduce a 'exclusive' investment platform. The dashboard shows spectacular, steadily climbing returns, and small withdrawals are allowed at first to build confidence. The deposit grows until the platform demands an 'exit fee' or simply vanishes. The tells: returns that never go down, pressure to move funds off regulated exchanges, and a platform that exists only as an app the contact installed for you.

5. Tampered tools and address swapping

The quietest scams involve software and devices rather than conversations: wallet apps repacked with a key-stealing patch and offered outside official stores, 'discounted' hardware wallets that arrive pre-configured with a known seed phrase, and clipboard malware that silently replaces a copied address with the attacker's. Verify every download against the project's official source, refuse any device that arrives with a seed phrase or PIN already set, and compare the first and last characters of every address after pasting.

before copy:  bc1q xy7k9m2v...3fq8
after paste:  bc1q xy7k9m2v...9zk2   <- last 4 differ: stop, infected clipboard

The common denominator

Strip away the costumes and every script asks for one of exactly three things: your seed phrase, a payment made in advance, or a login entered somewhere you arrived via a link. A private key generated and stored offline is immune to all three by construction — there is nothing to phish, no balance an attacker can see, and no reset to social-engineer. Security is less about detecting each new costume than about refusing the three requests underneath them.