10 common crypto scams and how to avoid them
Crypto scams are rising in Canada. Learn about the most prevalent schemes and how to protect yourself.
Advertisement
Crypto scams are rising in Canada. Learn about the most prevalent schemes and how to protect yourself.
Cryptocurrency investing offers new and exciting opportunities, but it’s also rife with scams and tech-savvy con artists. And since the crypto space remains largely unregulated, it’s often difficult to distinguish between genuine investment opportunities and scams.
In just the first half of 2024, investment scams conned Canadians out of nearly $107 million—almost half of that ($51.6 million) via cryptocurrency scams, according to the Canadian Anti-Fraud Centre (CAFC). Crypto investments are the top type of investment scams reported to CAFC, says Nancy Cahill, acting client and communications outreach officer. Fewer than 5% of scams are reported, so the actual numbers are likely much higher.
Cryptocurrency scams are often intertwined with other types of scams—and the criminals behind them cast a wide net. Con artists frequently find potential marks on social media. According to an analysis by TradingPlatforms based on FTC data, nearly one-third of social media crypto fraud happens on Instagram, and one-quarter on Facebook. Some ruses start out as romance scams. Once suspects gain a victim’s trust and affection, they present an “investment opportunity” or request crypto or money to pay for a made-up expense, such as medical bills.
There are many types of scams to watch out for, and unfortunately, as investors get savvier, the cons evolve and become trickier to spot. To protect yourself, always know where your money is going, understand the crypto advertising rules in Canada, and only use trusted and compliant crypto trading service providers. (As a starting point, see MoneySense’s picks for the top crypto platforms in Canada, all of which securities regulators have approved to do business in this country.) An exhaustive list of crypto scams is likely impossible, but to protect yourself, here are 10 to watch out for.
In a “pump and dump” or “rug pull” scheme, promoters of a cryptocurrency hype it up to boost demand, and when the price soars, they sell all their coins for a quick profit. Because they sell in large volumes, other investors get nervous and sell their coins, too. As panic sets in and the selling spreads, the coin’s value plunges. The promoters get rich and small investors are left “holding the bag,” faced with huge losses.
A notorious example of an alleged crypto pump-and-dump scheme is a coin called Squid Game. Launched in October 2021, it rode the popularity of the Netflix series of the same name—despite having no affiliation. Less than two weeks later, Squid Game’s crypto developers suddenly sold their holdings when the coin’s price hit $2,800, making themselves $3.3 million richer (all figures in U.S. currency). Today, one Squid coin is worth about a tenth of a penny.
The pump-and-dump scam is not unique to crypto, of course. It’s what high-flying stockbroker Jordan Belfort—the subject of the Hollywood film The Wolf of Wall Street, starring Leonardo DiCaprio—engaged in during the 1990s. His firm was accused of artificially inflating the price of penny stocks before selling their shares to make lots of fast money—costing investors up to $200 million. In the early 2000s, Belfort served 22 months in federal prison for securities fraud. He’s now marketing himself as an investment guru.
In a giveaway scam, someone asks you to send cryptocurrency to their wallet address, with the promise of sending you double the amount. “Send me 1 token, I’ll send you 2 in return” is a typical overture.
This type of scam is especially effective during crypto bull markets when investors may be experiencing FOMO and the prospect of free crypto may seem too tempting to pass up.
Phishing scams use phony communication through channels like email or social media to trick people into sharing confidential information like credit card numbers and PINs. It’s called “phishing” because scammers try to bait people into clicking a link that will take them to fraudulent websites—for example, an imitation of a bank or crypto exchange site.
Once the target has taken the bait, the scammers get in touch by email or other means and ask them to share or enter their data using various pretexts, such as a software upgrade or a limited-time special offer. The scammers then use it to hack into the victim’s exchange accounts and wallets.
Airdrop scams are a type of giveaway scam. In a typical airdrop, coin marketers give away assets like new crypto coins and non-fungible tokens (NFTs) in an effort to promote a project. To qualify, users may have to complete tasks like resharing social posts or creating an account. Once received, these assets need to be “claimed” in order to be sold.
For this, scammers may use airdrops as a ruse to lure people to a fraudulent website in the hope of collecting sensitive information, like the private keys to their crypto wallet. It’s much like those email scams that ask you to tap a link to sign into a bank account to receive a refund or wired money—same strategy, different currency.
Also be wary of initial coin offerings (ICOs), in which a crypto promoter solicits investments in a new cryptocurrency. Most ICOs are scams. Some red flags to watch for: little or no information about the team launching the coin, no whitepaper or other foundational document (but note that these can also be faked) and fake celebrity endorsements. Recently, several ICO scams, created using AI-generated images and fake social media accounts, tried to exploit public excitement around the 2024 Olympic Games.
Support scams are an internet-wide problem, and crypto is no exception. Con artists pretend to be representatives of crypto companies to trick their targets into parting with their money or revealing private information, such as passwords to their crypto exchange accounts or the private keys to their crypto wallets. With this information, they could rob you of your investments.
Scammers impersonate the staff of crypto services—such as decentralized apps (dApps), wallets and exchanges—on community platforms and messaging apps such as Discord or Telegram. They create authentic-looking accounts to gain the trust of unsuspecting investors, asking for passwords, private keys or remote access to their devices. Then they transfer the victim’s assets to their own accounts.
Genuine service providers will not communicate through unofficial channels like unverified social media accounts or personal email addresses, nor will they ask for your passwords or private keys.
Ponzi schemes, which get their name from con artist Charles Ponzi, are a type of scam in which new investors are paid what they’re owed using the money of existing investors—rather than from legitimate investment gains.
In the crypto world, Ponzi scams are applied to mining and staking pools. With the growing popularity of crypto, many investors want to participate in blockchain technology and the decentralized economy. One way is to mine or stake coins such as bitcoin (BTC), ethereum (ETH), polkadot (DOT) and cardano (ADA) through a mining pool or a stake pool—more often the latter.
How does staking work? Investors contribute to the operation of a blockchain—the technology that securely and permanently records crypto transactions—by pledging, or locking up, their coins for a period of time. In return, they may receive crypto rewards.
Scammers try to trick people into joining fake pools. Unlike other scams where the goal is to make a quick buck, mining and stake pool scams are a variation of a classic Ponzi scheme. They typically begin with an unsolicited invitation to join a pool, with the promise of lucrative rewards. You may initially receive returns, as the scammers attempt to gain your trust. However, as in all Ponzi schemes, these rewards are paid using the money received from new investors, rather than from legitimate returns on investment.
The scammers hope that receiving returns will prompt you to invest more of your crypto in the pool. If you stake a larger amount, your crypto could be transferred to an unknown address—and you will likely never see it again.
In June 2023, the CAFC warned about a surge in “pig butchering” scams, where fraudsters establish contact with a potential victim on social media or a dating app and pretend to be romantically interested in them. Once the con artist has gained the person’s trust, they try to convince them to invest in a supposedly profitable cryptocurrency scheme. Often, the charade begins with the scammer asking the person to buy crypto on a legitimate crypto exchange or platform. Then, the person is asked to transfer the purchase to another crypto wallet—which is controlled by the fraudsters. Victims are permitted a few small “withdrawals,” to bait further investments. Of course, when they try to “withdraw” their money, they discover that it’s gone.
Investment recovery pitch scams target people already victimized by fraud, preying on their desperation. According to the CAFC, these scams are on the rise.
Here’s how they work: Scammers contact victims by phone, email or social media and offer to help them recover their money. Once the scammers have won the victims’ trust, they ask for a fee for their “recovery services.” They may even ask for remote access to the victim’s computer—and online bank account, perhaps leading to further losses.
Was that really Reese Witherspoon touting NFTs? Can you really buy virtual property near Snoop’s? Trend-jacking off these real endorsements is a slew of faux celebrity crypto endorsements—including sophisticated deepfake videos and ads. A common concern around crypto investing is whether a coin or a project is genuine and trustworthy—but if your favourite actor or influencer is on board, it’s probably fine, right?
For marketers, exploiting the popularity and credibility of celebrities is a time-tested way to feign authenticity and garner trust. But things may not always be what they seem. Scammers create fake social media content or manipulate existing content to make it appear as though celebrities endorse a particular cryptocurrency. They tend to use faces already prominent in the crypto space—such as Tesla CEO Elon Musk or Ethereum founder Vitalik Buterin—to draw investors in.
Also beware of fake influencers: people who create social media accounts, buy followers and pretend to be influencers in order to peddle specific coins, crypto products or services. Scammers also use fake comments to make it appear that social media users recommend their services.
Blackmail scams are among the most disturbing crypto schemes. Scammers issue threats, often claiming they have access to a victim’s internet browsing history, passwords or an embarrassing webcam recording. They demand that the victim transfer crypto to their wallet address to make the problem go away. Or, the demand may be for the victim to promote a particular crypto to their contacts. While these experiences can be harrowing for victims, it is important not to respond to blackmailers.
Unfortunately, at least for now, scams are rampant in the crypto ecosystem. Here’s what you can do to avoid being trapped.
If you think you may be a victim of a crypto scam or other financial fraud, contact your bank to stop payment of any money transfers or cheques, then report the scam to the police and the CAFC—online or by phone. If you don’t report, authorities can’t investigate, and we won’t understand the extent and nature of crypto fraud in Canada.
In addition to protecting yourself from scams, remember this: Cryptocurrency investing can be profitable, but prices are also highly volatile. Before you buy or stake any digital coin, consider whether it fits your investment plan, risk profile and long-term goals. Always do your own research, and carefully review service providers’ user agreements and risk disclosures before you click “buy.”
Newsletter
Share this article Share on Facebook Share on Twitter Share on Linkedin Share on Reddit Share on Email