Crypto fraud defense: rug pulls, wallet drainers, and seed-phrase traps
Crypto's irreversibility makes fraud uniquely unforgiving. A defensive guide to rug pulls, approval-drainer wallets, and seed-phrase social engineering — and the habits that keep your keys yours.
Every property that makes crypto powerful also makes fraud unforgiving. Transactions are irreversible — there is no chargeback, no bank to call, no undo. You are your own bank, which means you are your own security department with no backup. And the ecosystem moves fast enough that scams evolve faster than warnings spread. This is a defensive guide, not an investing one: whatever you think of crypto as an asset, if you hold any, the ways it gets stolen are specific, technical, and largely preventable once you understand the three dominant attack patterns — rug pulls, wallet drainers, and seed-phrase social engineering.
Rug pulls: the exit scam
A rug pull is when the creators of a token or project take investors' money and disappear. It usually follows a script: launch a hyped token with a slick site and a loud community, drive the price up with promises and influencer shilling, then either drain the liquidity pool (so the token instantly becomes unsellable and worthless) or dump the founders' massive hidden holdings on buyers. Because 'investors' bought willingly and the code often technically permitted it, there's rarely any recourse. The defenses are due-diligence habits, not technical tricks.
- Anonymous teams: no verifiable people behind the project. Anonymity isn't automatically fraud, but it means no one to hold accountable when the money vanishes.
- Unlocked or founder-heavy token supply: if creators hold a huge share and it isn't locked, they can dump on you at will. Check tokenomics and lockups.
- Guaranteed or absurd returns: '100x guaranteed,' 'risk-free staking at 400% APY.' The number is the bait.
- Manufactured urgency and hype over substance: countdowns, 'get in before launch,' influencer blitzes, and no real product or audited code underneath.
- Liquidity you can't verify is locked, and contracts that haven't been independently audited.
Wallet drainers: the malicious approval
The most technically dangerous modern crypto scam doesn't steal your password — it tricks you into signing a transaction that grants a malicious contract permission to move your tokens. You connect your wallet to a fake or compromised site (a phony airdrop, a fake mint, a spoofed version of a real app), and a pop-up asks you to 'approve' or 'sign.' It looks routine. What you're actually authorizing is unlimited access to a token, and moments later the drainer empties it. Because you signed it, the transaction is valid and irreversible.
- Read what you sign. Wallets and tools now show what a transaction actually does; an 'approval' for an unlimited amount to an unknown contract is a red flag, not a formality.
- Use a burner wallet for anything experimental. Keep the bulk of your holdings in a wallet that never touches unknown sites, mints, or airdrops.
- Revoke stale approvals. Periodically review and revoke token approvals you've granted over time using a reputable revocation tool.
- Treat 'free' as bait. Unsolicited airdrops, surprise NFTs, and 'you've won' tokens are common drainer lures; interacting with them is the trap.
| Attack | What it exploits | Core defense |
|---|---|---|
| Rug pull | Hype and trust in a new project | Due diligence: team, tokenomics, audits |
| Wallet drainer | A signed approval you didn't read | Read transactions; burner wallet; revoke |
| Seed-phrase theft | Tricking you into revealing keys | Never share/enter your seed phrase, ever |
| Fake support / impersonation | Panic and trust in 'help' | Real support never DMs or asks for keys |
Seed-phrase social engineering: the master key
Your seed phrase (or recovery phrase) is the master key to your entire wallet. Anyone who has it owns everything in the wallet, permanently, with nothing you can do about it. Every remaining crypto scam ultimately tries to get it: fake 'wallet support' agents in DMs, phishing sites that ask you to 're-enter your phrase to validate,' fake wallet apps, 'you must migrate your wallet' messages, and QR codes that lead to key-harvesting pages. The rule is absolute and admits no exceptions.
The bottom line
Crypto punishes mistakes because it's irreversible and self-custodied — no chargebacks, no support line, no undo. The three attacks that take most people are rug pulls (beaten by due diligence on team, tokenomics, and audits), wallet drainers (beaten by reading what you sign, using burner wallets, and revoking approvals), and seed-phrase theft (beaten by one unbreakable rule: never share it with anyone, ever). Keep serious holdings in cold storage, treat every 'free' token and 'support' DM as bait, and remember that in crypto, prevention isn't the best protection — it's the only one.
Check your understanding
1 of 3Not quite — try again.
Get smarter about money every week
One email, no spam — practical guides and Worth updates. Unsubscribe anytime.
Put this into practice
Worth tracks your accounts, budgets, and goals — so the concepts in this article aren't just theory.
Start free trial