Loading prices …
inotoken

Security · Everyday security

Spot a crypto scam before the money is gone

Fraud with crypto-assets rarely works through technical tricks; it works through time pressure, trust and a faked account screen. This piece shows the reported methods, the figures behind them, the red flags and the steps that make sense in that order on suspicion. The figures come from two countries and are labelled as such.

By the inotoken editorial teamUpdated 13.09.20268 min readChecked, with sources
Illustration: coins behind a warning sign, with a screen showing price curves behind themAI illustration
The answer in one sentence

Almost every crypto scam shows the same combination: contact you did not ask for, a provider without authorisation from the supervisor, large gains on screen that cannot be withdrawn, and a new fee that falls due before every payout.

Crypto-assets are attractive for fraud because transfers are fast, final and cross-border. Nobody pulls back a confirmed transaction, and whoever triggered the payment is as a rule left with the damage. The better news: the methods repeat themselves, and most can be recognised by two or three features before money moves.

Six methods that come up again and again

At the start there is usually the fake trading platform. The Verbraucherzentrale, the German consumer advice centre, describes the sequence like this: advertising online or on social media, at first only a small amount of starting capital, then a personal adviser on the phone who builds trust. On screen the gains grow, but the balance is a display without any value behind it. The supposed advisers often ask for direct access to your computer through remote maintenance software, allegedly to help set up the trading account.

The second method runs through groups in messengers and social networks: supposed insiders, daily signals, screenshots of profits and a sign-up link. The third is confidence or romance fraud, where a relationship is built over weeks and the money is then invested together. The fourth is the recovery method, the fraud after the fraud: some months later, supposed law firms or officials get in touch saying the lost money has turned up, perhaps after a frozen account was released, but a payment is due up front before it can be released. The Verbraucherzentrale describes exactly this sequence and reports in addition callers who pass themselves off as its own staff and promise money from a supposed pot; it states plainly that genuine consumer advice centres neither call unprompted nor compensate losses from investments. Callers also invoke BaFin, the German financial supervisory authority, which for its part does not contact private individuals unasked and demands no payments. The fifth method targets the backup words of a wallet, the sixth new tokens that are dropped once the money has been collected.

What the figures show and what they do not

Solid figures on crypto fraud come above all from the United States. The Internet Crime Complaint Center (IC3) of the FBI counted exactly 1,008,597 reports for 2025, with reported losses of 20.877 billion US dollars, 26 per cent more than the year before, an average of 20,699 US dollars per case. The cryptocurrency marker was attached to 181,565 reports with 11.37 billion US dollars of losses. Investment fraud accounted for 72,984 reports and 8.65 billion US dollars, of which crypto investment fraud alone made up 7.2 billion US dollars. Crypto ATMs appeared in 13,460 reports with 389 million US dollars of losses, 23 per cent more reports and 58 per cent more losses than in 2024. People aged 60 and over reported 201,266 cases and 7.7 billion US dollars across all offence types. Broken down by offence type, of the 181,565 reports with a crypto link, 61,559 were investment fraud, 23,797 extortion, 7,164 phishing and 5,925 confidence or romance fraud. For the recovery method the report counted 10,516 reports with 1.4 billion US dollars; it notes that this sum may also contain losses from the preceding fraud.

These figures apply to the United States and to reported cases, not to Germany and not to reality. For Germany there is no comparable figure on crypto fraud. The Bundeskriminalamt (BKA), the German Federal Criminal Police Office, records a combined 333,922 cases in its Cybercrime situation report 2025, of which 207,888 were committed from abroad and 126,034 inside Germany. That total counts cybercrime in the narrow sense, meaning offences against the internet and against information technology systems. It is not a figure on crypto fraud and not one on investment fraud: the word investment fraud does not appear in the report, and it shows no crypto share. The BKA also records that a large number of unreported cases must still be assumed. The count by the consumer advice centre of North Rhine-Westphalia quoted there came to 382,470 phishing emails of all kinds in 2025, around 10 per cent fewer than the year before, again without a separate crypto share. Anyone reading figures on crypto fraud in Germany should therefore always check whether they come from police statistics, an association survey or a company analysis.

Method, red flag and protection at a glance

The table below sums up how each of the six methods can be recognised. The figures column gives the reference value from the annual report of the IC3 complaint centre, with country and year. These are the totals of that report's categories for cases reported in the United States, not counts of the individual method and not figures for Germany; where no solid figure exists, the table says so.

Six methods with the red flag, the protection and a documented reference figure. All figures in the last column are reported cases in the United States, 2025; no comparable count of cases recorded in Germany exists.
MethodTypical red flagWhat protects youFigure on it
Fake trading platforman adviser calls and wants remote access to your computercheck the authorisation in the supervisor's company database, grant no remote access61,559 reports of investment fraud with a crypto link, reported cases in the United States, 2025
Investment group in a messengersupposed insiders, daily signals, a fixed returnleave the group, no return is ever assured7.2 billion US dollars of losses from crypto investment fraud, reported cases in the United States, 2025
Confidence and romance frauda new acquaintance suggests investing together after a few weekskeep money matters and the relationship apart, talk to someone else5,925 reports with a crypto link, reported cases in the United States, 2025
Recovery methoda fee up front for supposedly retrieving your moneypay nothing, report it to the police, end the contact10,516 reports, reported cases in the United States, 2025
Phishing for the backup wordsa form or a support agent asks for your 12 or 24 wordsnever enter the words anywhere, set the wallet up again7,164 reports of phishing with a crypto link, reported cases in the United States, 2025
A new token with nothing behind itanonymous team, blocked withdrawals, time pressureno entry without documents you can check and an authorisationno solid figure available, neither for the United States nor for Germany

How to check a provider in ten minutes

In Germany the first step is the company database of BaFin, the German financial supervisory authority. It records which companies hold an authorisation, which have notified an activity and which are represented in Germany. If a provider is not in it, the Verbraucherzentrale advises staying away; in case of doubt a free call to the BaFin consumer helpline on 0800 2 100 500 helps. BaFin also publishes warnings about unauthorised business on an ongoing basis, often covering whole series of near-identical platform sites. Readers in other countries should use the register of their own national supervisor in the same way.

The second step is the legal position: since 30 December 2024, providers of crypto-asset services in the EU have needed an authorisation under Regulation (EU) 2023/1114, and the German transition period for existing providers ended at the close of 31 December 2025. Anyone offering crypto-asset services in Germany today without an authorisation is operating unlawfully. What the regulation covers and what it does not is in our piece on the MiCA regulation. After that, check three small things that fraudsters rarely get right: a complete legal notice with an address where documents can be served, a small withdrawal that works without a new fee, and payment routes with no diversion to private accounts or crypto ATMs.

Phishing goes after the backup words

The second large group of cases concerns wallets rather than platforms. The pattern is always the same: a page, an advert or supposed help in a forum asks you to enter the 12 or 24 words of your wallet, allegedly to verify, to synchronise or to release a balance. Anyone entering them hands over complete access, because all the private keys of the wallet are calculated from those words. No reputable provider asks for them, no support desk needs them, no check requires them.

Related variants: fake wallet apps with almost the same name, an update that came from an advert, or an approval prompt that quietly grants a contract unlimited permission to move your funds. A hardware wallet helps against malware, but not against an approval you confirm on the device yourself. How the keys come about and why the words are the assets is in the piece on the difference between hardware and software wallets; which form of custody fits your situation is sorted out by the wallet type finder.

What to do once it has happened

Break off the contact first, even if gains are still showing on screen. Then secure everything you have: names, web addresses, phone numbers, chat logs, emails, bank statements, transaction IDs of the transfers. Report it to the police and report the provider to the supervisor, in Germany to BaFin, so that others can be warned. Speak to your bank or payment service: in rare cases money can be pulled back, most likely with card payments and only if you are quick.

Four things not to do. Pay nothing more, not even the supposed tax or fee demanded before a payout. Grant nobody remote access to your computer. Hire no service that wants to retrieve money against payment up front. And do not hand over your backup words, even if somebody claims they can rescue your account with them. If you want to test how reliably you spot the usual traps, the crypto knowledge quiz helps; terms such as phishing, rug pull or cold storage are in the glossary.

Frequently asked questions

How do I recognise a dubious trading platform?

By three things at once: the provider is not in the company database of BaFin, the German financial supervisory authority, the contact came unprompted through advertising, a messenger or the phone, and a new fee or a supposed tax is demanded before the first payout. If a request for remote access to your computer is added, the matter is settled. Since 30 December 2024 providers in the EU also need an authorisation under Regulation (EU) 2023/1114.

Can I get my money back after a crypto scam?

Usually not, because a confirmed transfer of crypto-assets is final and cannot be reversed technically. Still worth doing: report it to the police, notify the supervisor and speak quickly to your bank or payment service, because with card payments a chargeback occasionally works. Supposed recovery services that want payment up front are the recovery method; the Verbraucherzentrale states plainly that genuine consumer advice centres neither call unprompted nor compensate investment losses, and BaFin does not contact private individuals unasked.

Would a reputable provider ever ask for my seed phrase?

No, never. All the private keys of a wallet are calculated from the 12 or 24 words, so whoever knows them can empty the whole balance. Neither support nor manufacturer nor trading venue nor any authority needs those words for any process at all. Every page, every message and every form that asks for them is an attack, no matter how genuine the design looks.

How many people are affected by crypto fraud?

There is no solid figure for Germany, because investment fraud is not recorded separately in the cybercrime statistics and the Bundeskriminalamt assumes a large number of unreported cases. From the United States, the IC3 complaint centre reports exactly 181,565 reports with a crypto link for 2025 and 11.37 billion US dollars of losses. Those numbers describe reported cases in another country and cannot be transferred to Germany.

What do I do if I have entered my backup words?

Act at once, because attackers often empty such wallets within minutes. Set up a new wallet with new words on a clean device and move everything that is left to it. The old wallet counts as burned for good, even after a reset. After that, report it, secure your evidence and have the device checked for malware.

Sources

  1. 2025 IC3 Annual ReportInternet Crime Complaint Center, FBI, United States · reporting year 2025
  2. Bundeslagebild Cybercrime 2025Bundeskriminalamt (BKA), the German Federal Criminal Police Office, cybercrime situation report for Germany · 12 May 2026
  3. So erkennen Sie unseriöse Online-TradingplattformenVerbraucherzentrale, the German consumer advice centre · 30 September 2025
  4. Unternehmensdatenbank der BaFinBaFin, the German financial supervisory authority, company database · retrieved 13 September 2026
  5. Warnmeldungen zu unerlaubten GeschäftenBaFin, the German financial supervisory authority, warnings about unauthorised business · retrieved 13 September 2026
  6. Übergangsvorschrift zur Erbringung von Kryptowerte-Dienstleistungen, § 50 KMAGGerman Crypto Markets Supervision Act (Kryptomärkteaufsichtsgesetz), section 50, published by the Federal Office of Justice · retrieved 13 September 2026