Security

The frauds that target experienced traders

Advice about crypto fraud is written for people buying their first coin, which is why it does not protect anybody else. The schemes that reach traders with years of experience do not rely on ignorance. They rely on routine, on timing, and on the fact that an active account signs things all day long.

· 10 min read

Why experience is not the protection people assume

The naive scam needs you not to understand what is happening. The competent one needs the opposite: it needs you to be doing something familiar, quickly, in a context where the action it wants is the action you were already about to take. Knowing more makes you faster, and speed is the vulnerability being exploited.

There is also a selection effect nobody enjoys. An active trader has balances on multiple platforms, several sets of credentials, automated systems holding keys, and a public footprint from forums or social accounts. That profile is worth far more effort than an ordinary one, and it receives it. The messages that reach it are researched, correctly spelled, and aimed at something the target actually does.

The scheme that catches experienced people never asks them to learn something new. It asks them to do something they do twenty times a week, one time too fast.

Address poisoning, and the clipboard you trust

Nobody types a destination address. Everybody copies one, and the usual source is the transaction history. The attack exploits exactly that: a tiny transfer is sent to your address from a lookalike address, generated so that its first and last characters match one you use regularly. It now sits in your history looking like a place you have transacted with before.

The next time you copy from that list in a hurry, you copy the impostor. The middle of the string is different and nobody reads the middle of a string. The transfer is valid, irreversible, and goes to somebody who spent a few units of gas to be there when you were distracted.

The defence is procedural and takes a second: verify characters from the middle of the address rather than the ends, and copy destinations from a saved list you built yourself rather than from history. Whitelisting withdrawal addresses on any platform that offers it removes the exposure entirely for the destinations you use repeatedly.

The support conversation you did not start

Real support answers you. It does not find you first. Yet the most productive version of this fraud is precisely inbound: shortly after you post a question in a public forum or a community channel, someone contacts you privately, uses your first name, references the exact problem you described, and offers to help.

What follows never asks for a password, because asking for one would break the spell. It asks you to connect a wallet to a verification page, to run a diagnostic command, to enter your recovery phrase into a form that looks like a wallet restore, or to install a remote assistance tool so they can see the issue. Each request is plausible in the context of the problem you announced publicly.

One rule handles the entire category and it needs no judgement. Support conversations begin from inside the platform, initiated by you, through a channel you navigated to yourself. Anyone who contacts you first about an account is, without exception worth entertaining, not who they claim to be.

Signature phishing, and why a hardware wallet does not stop it

The most expensive losses of recent years have not involved stolen keys. They involved a signature the owner produced, on a page that looked like one they used regularly, granting a spending permission rather than making a transfer.

The mechanics deserve stating plainly because the vocabulary hides them. Granting a permission does not move anything, so nothing appears wrong afterwards. The balance leaves later, at a time chosen by whoever holds the permission, which is why the loss so often seems disconnected from any action the victim can remember. A hardware wallet performs this signature exactly as faithfully as any other.

Two habits handle it. Read what a wallet is asking you to approve, and specifically whether it is a transfer or an authorisation, because the interface does distinguish them. And treat any signature request that appears without you having initiated an action as hostile, particularly one that arrives immediately after connecting to a site you reached from a link.

A key that cannot be stolen still signs whatever you approve. The threat has moved from the key to the moment of approval.

The phone number that is not a second factor

A text message can be redirected by persuading a mobile operator to move a number to a new device. The process is designed to help customers who have lost a phone, it is executed by people under time pressure, and it has been repeatedly shown to be defeatable with information that is not hard to gather about a public person.

Once the number moves, every code sent to it arrives at the attacker, including password resets for the email account that anchors everything else. Traders whose exchange accounts, email and social profiles all fall back to the same number are one operator error away from losing all three at once, and the sequence takes minutes.

The fix is unglamorous: use an authenticator application or a physical security key everywhere it is offered, remove the phone number as a recovery method wherever the platform allows it, and set a port-out lock or equivalent with your operator. None of this is difficult and almost nobody does it before an incident.

The tools traders install without thinking

A browser extension with permission to read and change data on every site is a permanent observer of every trading interface you open. Extensions change hands, get sold to new owners, and receive updates that were not written by the person you originally trusted. This is not hypothetical, it is a recurring pattern, and the update mechanism means the change reaches you silently.

The same reasoning applies to trading automation. A bot that connects to your account needs an API key, and any bot that asks for withdrawal rights is asking for something no trading strategy requires. A script copied from a forum runs with your permissions, and reading it is the entire security review it will ever get.

Keep the browser profile you use for anything holding value separate from the one you browse with, install as little as possible into it, and audit what is installed on a schedule. The point is not paranoia, it is reducing the number of parties who can silently change code running next to your account.

The second fraud that follows the first

After a public loss, a second wave arrives: services offering to trace and recover stolen funds, often referencing the specific incident, sometimes claiming a relationship with an investigator or a law enforcement body. They ask for a fee in advance, or for access to the wallet in order to assess it.

The premise is false in the way that matters. A settled transaction on a public ledger cannot be reversed by a private company, and tracing where funds went, which is genuinely possible, is not the same as being able to retrieve them. What is being sold is a second loss to someone already demonstrated to be reachable and motivated.

There is one thing genuinely worth doing after a loss, and it is not commercial: document everything with timestamps and addresses, report it to the platform involved and to your national authority, and accept that recovery is unlikely. That is a bleak sentence and it is more useful than the alternative being offered.

Where the money actually goes: the group you were invited to

The largest sums in this field are not lost to technical exploits, they are handed over voluntarily over weeks. The pattern is consistent: a relationship formed somewhere social, a shared interest in markets, an eventual introduction to a platform where the newcomer's early trades perform remarkably well and withdrawals work perfectly at small size.

Everything is real until the amount is large. The interface, the balances, the customer service, the withdrawal that arrived last month: all of it is designed to establish that the money is retrievable. The failure appears only at the point where it is not, usually accompanied by a tax or a fee that must be paid first, from outside funds.

The structural tell is not the returns, which are often modest enough to be credible. It is that the platform reached you through a person rather than through the market, and that the person appeared before the opportunity did. Anything discovered that way should be checked against a public register of licensed entities before a single transfer, and most of them are not in one.

The checks that actually work

Almost every scheme above is defeated by one of a small number of habits, and none of them requires expertise. Never act on an inbound contact about an account, ever, regardless of how much the sender appears to know. Verify addresses by their middle characters and keep a saved list. Read whether you are signing a transfer or an authorisation. Remove SMS from the recovery path of anything that matters. Keep long-term holdings on an address that has never approved a contract.

The last one is about time rather than technique. Every scheme in this article works better under pressure, and each is built to create it: a limited window, a position at risk, a support agent waiting for your answer. An action that cannot wait ten minutes is an action somebody else has scheduled for you, and the ten minutes is almost always enough to see it.

Urgency is the common ingredient. Nothing legitimate about your own account requires you to act before you have had time to check it.

Frequently asked

I got a small unexpected transfer into my wallet. Is that dangerous?

It usually means your address has been marked for address poisoning. The transfer itself is harmless; its purpose is to place a lookalike address into your transaction history so you copy it later by mistake. Do not interact with it, and copy destinations from a list you maintain rather than from history.

Support contacted me first about a problem I posted about publicly. Is that normal?

No. Genuine support responds to requests you initiate through the platform, it does not find you in a forum. The fact that they know the details of your problem proves only that they read the same public post you wrote. Close the conversation and open a ticket yourself from inside your account.

How can funds leave if I never sent a transaction?

Through a spending permission you signed earlier. Approving a contract to move a token on your behalf is a separate action from transferring, it moves nothing at the time, and it stays valid until revoked. The withdrawal happens later at a moment of the holder's choosing, which is why it seems unconnected to anything you did.

Does a hardware wallet protect me from phishing?

It protects the key, not the decision. The key never leaves the device, so it cannot be extracted, but a signature you approve on that device is a valid signature regardless of what it authorises. Reading the destination and the operation on the device's own screen is what closes the gap.

Is SMS two-factor authentication better than nothing?

Better than nothing and considerably worse than the alternatives, because a phone number can be moved to another device by convincing an operator rather than by breaking anything. Where an authenticator application or a physical key is offered, that is the option to take, and the number should be removed from account recovery entirely.

Should a trading bot have withdrawal permission?

No trading strategy requires the ability to move funds off the platform. A bot that asks for it is asking for a capability its stated function does not need, and that alone is sufficient grounds to refuse. Grant trading rights only, restrict the key to the addresses your infrastructure uses, and rotate it on a schedule.

Someone offered to recover funds I lost. Can that work?

Tracing where funds moved is genuinely possible and is not the same as retrieving them. A settled transaction cannot be reversed by a private firm, and any request for payment in advance or for access to your wallet is a second fraud aimed at someone already known to be reachable. Document the incident and report it instead.

What is the single most useful habit?

Refusing to act quickly on anything concerning your own account. Every scheme described here manufactures urgency, because none of them survives ten minutes of checking. Nothing legitimate about your positions, your withdrawals or your access requires an immediate decision made inside somebody else's conversation.

Open an account All articles