Scams & FraudAdvanced6 min read

Crypto fraud defense: rug pulls, wallet drainers, and seed-phrase traps

Crypto's irreversibility makes fraud uniquely unforgiving. A defensive guide to rug pulls, approval-drainer wallets, and seed-phrase social engineering — and the habits that keep your keys yours.

Every property that makes crypto powerful also makes fraud unforgiving. Transactions are irreversible — there is no chargeback, no bank to call, no undo. You are your own bank, which means you are your own security department with no backup. And the ecosystem moves fast enough that scams evolve faster than warnings spread. This is a defensive guide, not an investing one: whatever you think of crypto as an asset, if you hold any, the ways it gets stolen are specific, technical, and largely preventable once you understand the three dominant attack patterns — rug pulls, wallet drainers, and seed-phrase social engineering.

Rug pulls: the exit scam

A rug pull is when the creators of a token or project take investors' money and disappear. It usually follows a script: launch a hyped token with a slick site and a loud community, drive the price up with promises and influencer shilling, then either drain the liquidity pool (so the token instantly becomes unsellable and worthless) or dump the founders' massive hidden holdings on buyers. Because 'investors' bought willingly and the code often technically permitted it, there's rarely any recourse. The defenses are due-diligence habits, not technical tricks.

  • Anonymous teams: no verifiable people behind the project. Anonymity isn't automatically fraud, but it means no one to hold accountable when the money vanishes.
  • Unlocked or founder-heavy token supply: if creators hold a huge share and it isn't locked, they can dump on you at will. Check tokenomics and lockups.
  • Guaranteed or absurd returns: '100x guaranteed,' 'risk-free staking at 400% APY.' The number is the bait.
  • Manufactured urgency and hype over substance: countdowns, 'get in before launch,' influencer blitzes, and no real product or audited code underneath.
  • Liquidity you can't verify is locked, and contracts that haven't been independently audited.

Wallet drainers: the malicious approval

The most technically dangerous modern crypto scam doesn't steal your password — it tricks you into signing a transaction that grants a malicious contract permission to move your tokens. You connect your wallet to a fake or compromised site (a phony airdrop, a fake mint, a spoofed version of a real app), and a pop-up asks you to 'approve' or 'sign.' It looks routine. What you're actually authorizing is unlimited access to a token, and moments later the drainer empties it. Because you signed it, the transaction is valid and irreversible.

The 'free airdrop' that cost $14,000
Dev sees a post announcing a token airdrop for early users of an app he actually uses. The site looks identical to the real project. He connects his wallet and clicks 'Claim' — which prompts him to sign a transaction. He approves without reading it. The signature wasn't claiming anything; it granted a drainer contract unlimited spending approval on his stablecoins and staked tokens. Within one block, $14,000 is gone to an address he'll never trace, and there is no reversal, no support line, no recourse. Had he paused to read what the wallet was actually asking him to approve — an unlimited allowance to an unknown contract — or used a separate 'burner' wallet for unknown sites, the loss would have been zero. The real project's airdrop, it turned out, never asked anyone to sign a spending approval at all.
  1. Read what you sign. Wallets and tools now show what a transaction actually does; an 'approval' for an unlimited amount to an unknown contract is a red flag, not a formality.
  2. Use a burner wallet for anything experimental. Keep the bulk of your holdings in a wallet that never touches unknown sites, mints, or airdrops.
  3. Revoke stale approvals. Periodically review and revoke token approvals you've granted over time using a reputable revocation tool.
  4. Treat 'free' as bait. Unsolicited airdrops, surprise NFTs, and 'you've won' tokens are common drainer lures; interacting with them is the trap.
AttackWhat it exploitsCore defense
Rug pullHype and trust in a new projectDue diligence: team, tokenomics, audits
Wallet drainerA signed approval you didn't readRead transactions; burner wallet; revoke
Seed-phrase theftTricking you into revealing keysNever share/enter your seed phrase, ever
Fake support / impersonationPanic and trust in 'help'Real support never DMs or asks for keys
What each attack targets and the core defense

Seed-phrase social engineering: the master key

Your seed phrase (or recovery phrase) is the master key to your entire wallet. Anyone who has it owns everything in the wallet, permanently, with nothing you can do about it. Every remaining crypto scam ultimately tries to get it: fake 'wallet support' agents in DMs, phishing sites that ask you to 're-enter your phrase to validate,' fake wallet apps, 'you must migrate your wallet' messages, and QR codes that lead to key-harvesting pages. The rule is absolute and admits no exceptions.

No one legitimate ever needs your seed phrase
Not wallet support, not an exchange, not a 'migration,' not a giveaway, not a validator, not a website 'syncing' your wallet — no one. A seed phrase is used exactly once, by you, to restore your own wallet on your own device. Any person, app, form, or QR code asking you to type, share, photograph, or 'verify' your seed phrase is trying to steal everything, without exception. Write it on paper, store it offline, and never enter it anywhere except your own wallet's restore screen.
Cold storage for anything you can't afford to lose
For meaningful holdings, move them to a hardware (cold) wallet that keeps your keys offline and requires physical confirmation for transactions. It neutralizes drainers and remote theft in one move — a malicious approval can't execute without the physical device, and your seed phrase never touches an internet-connected machine. Treat hot wallets like the cash in your pocket and cold storage like the vault.

The bottom line

Crypto punishes mistakes because it's irreversible and self-custodied — no chargebacks, no support line, no undo. The three attacks that take most people are rug pulls (beaten by due diligence on team, tokenomics, and audits), wallet drainers (beaten by reading what you sign, using burner wallets, and revoking approvals), and seed-phrase theft (beaten by one unbreakable rule: never share it with anyone, ever). Keep serious holdings in cold storage, treat every 'free' token and 'support' DM as bait, and remember that in crypto, prevention isn't the best protection — it's the only one.

Check your understanding

1 of 3
You connect your wallet to a site for a 'free airdrop' of a project you actually use, and it prompts you to sign a transaction to 'claim.' What are you most likely actually authorizing?

Not quite — try again.

The Worth letter

Get smarter about money every week

One email, no spam — practical guides and Worth updates. Unsubscribe anytime.

Put this into practice

Worth tracks your accounts, budgets, and goals — so the concepts in this article aren't just theory.

Start free trial