Crypto Scam Typologies
August 18, 2026
Insights

Crypto Scam Typologies: How Fraud Actually Operates

SHARE THIS POST

Crypto fraud rarely announces itself as crypto fraud. It shows up as a customer moving savings to “top up a trading account.” A business client paying a crypto invoice to a counterparty that doesn’t exist. An employee with legitimate-looking access to a firm’s digital asset wallets. At the point of transaction, each looks routine.

 

That’s the core challenge behind crypto fraud detection: understanding how these scams are built, staffed and run matters more than reacting once the funds are already gone.

 

At Token Recovery, this is the gap we sit in every day. By the time a case reaches our investigators, the typology is usually clear in hindsight. This guide builds on analysis our Head of Token Recovery, Scott Pounder, published in The Paypers, breaking down the main crypto scam typologies for banks, PSPs, exchanges, and any institution that touches funds moving toward digital assets.

Key Takeaways

  • Crypto fraud is run as an organised industry, not isolated incidents — UNODC estimates USD 18–37 billion in regional losses in 2023 alone
  • The four typologies most likely to touch a financial institution: pig butchering, phishing/wallet-draining, fake investment platforms, and insider threats
  • Newer techniques — address poisoning, quishing, and AI-generated deepfakes — are outpacing many internal risk models
  • Regulators in the UK, EU and US now expect crypto-fraud exposure to be managed before funds reach a digital asset platform, not after

Crypto Fraud Is an Industry, Not a Series of Incidents

The scale behind crypto fraud is consistently underestimated. Large parts of the pig-butchering economy — the blend of romance and investment fraud driving a huge share of global losses — are run out of industrial-scale compounds across Myanmar, Cambodia and parts of Laos. Trafficked workers are coerced into running scripted fraud campaigns against victims in North America, Europe and East Asia.

 

The UNODC has estimated scam losses targeting East and Southeast Asian victims at USD 18–37 billion in 2023 alone, with expansion continuing since.

 

The practical takeaway for risk and compliance teams: fraud showing up in transaction monitoring is almost never opportunistic. It’s the output of a professionalised operation — with scripts, escalation paths, and its own quality control.

 

The 4 Crypto Fraud Typologies Most Likely to Touch Your Institution

Typology What it looks like from inside a bank
Pig butchering (romance & investment scam) A string of legitimate-looking crypto purchases or transfers from a previously unremarkable retail customer, escalating quickly in size
Phishing / wallet-draining Spoofed login pages or malicious approvals; often surfaces well after the original customer interaction
Fake investment platforms / Ponzi schemes New stablecoin deposits used to pay earlier “investors”; convincing platforms built and marketed cheaply at scale
Insider threats Privileged staff access to wallets or trading infrastructure — invisible to conventional, externally-focused fraud controls

 

Pig Butchering: Romance and Investment Scams

Victims are cultivated over weeks or months through dating apps or social media before being steered to a fraudulent trading platform showing fabricated returns.

Phishing and Wallet-Draining Attacks

Fraudsters use spoofed exchange login pages or malicious browser extensions to harvest seed phrases and private keys. The more technical variant — approval phishing — tricks a victim into signing a transaction that grants a malicious smart contract standing permission to move their tokens, sometimes executed days after the original interaction. This technique was significant enough to trigger a joint 2026 operation between the US Secret Service, the UK’s National Crime Agency, and Canadian authorities.

Fake Investment Platforms and Ponzi-Style Schemes

A pre-crypto fraud pattern, now accelerated by how cheaply a convincing platform accepting stablecoin deposits can be built and marketed at global scale.

Insider Threats in Digital Asset Custody

As more traditional institutions stand up digital asset trading desks, staff with privileged access to wallets or trading infrastructure represent a distinct and growing risk category — one that conventional, externally-focused fraud controls simply aren’t built to catch. 

Why Geography Still Belongs in a Crypto Fraud Risk Model

Certain scam types stay concentrated in specific regions — not because of the technology, but because of the infrastructure and labour behind them:

 

  • Southeast Asia — pig-butchering compounds
  • Eastern Europe / CIS region — fake investment and affinity-fraud platforms
  • West Africa — romance-scam operations, predating crypto but increasingly using digital assets as a payment and laundering rail
  • No fixed region — DeFi-native exploits (rug pulls, smart contract attacks), since blockchain’s anonymity lets perpetrators operate from anywhere against a global investor base

None of this replaces transaction-level monitoring — but it’s a genuinely useful input for corridor-level risk scoring and correspondent banking due diligence.

Emerging Crypto Scam Techniques Outpacing Risk Models

Generative AI has lowered the skill threshold for convincing scams considerably. Deepfake video calls, cloned voices, and AI-generated chat personas are now routinely used to defeat the scepticism that trained staff and customers alike are told to rely on.

 

Two typologies worth flagging specifically for 2026 monitoring:

  • Address poisoning — scammers send small transactions from wallet addresses that closely resemble ones a target has previously interacted with, exploiting the habit of copying addresses straight from transaction history
  • Quishing (QR-code phishing) — exploits the fact that a QR code hides its destination until it’s already been scanned

 

Perhaps most consequential: the rise of scam-as-a-service — ready-made phishing kits, fake exchange templates, even scripted customer-support flows, sold openly on underground forums. This has professionalised the lower end of the market and materially increased the volume of attempts compliance teams have to screen against.

Why Crypto Fraud Is No Longer a “Crypto-Native Firm” Problem

Regulators across the UK, EU and US have increasingly signalled that banks, PSPs, and cryptoasset firms need to manage crypto-fraud exposure earlier in the customer journey — including at the point customers first move funds toward digital asset platforms. Meeting that expectation isn’t possible without understanding how these scams are actually constructed, who runs them, and where the operational patterns diverge from ordinary customer behaviour.

What This Means in Practice

Recognising a typology only matters if it changes what a risk team does next:

  • Treat escalating retail crypto transfers from previously low-activity accounts as a pig-butchering signal, not just a velocity flag
  • Build specific controls for approval-phishing patterns — token approvals executed well after the triggering interaction — rather than relying solely on point-in-time transaction review
  • Extend insider-threat monitoring to cover privileged wallet and custody access, not just traditional account access
  • Use regional typology patterns as one input into corridor risk scoring, alongside — never instead of — transaction-level monitoring

Understanding the typology is the foundation. What happens once a scam has already succeeded — how it’s detected, how funds are traced on-chain, and what a coordinated response between exchanges, banks, regulators and forensic investigators looks like in a live, time-pressured case — is where our investigators spend most of their time, and it’s the subject we’ll cover next. 

 

This article expands on public reporting and case pattern analysis by Token Recovery’s investigations team, building on “Inside the world of crypto scams” by our Head of Token Recovery, Scott Pounder, published in The Paypers.

Frequently Asked Questions

What is pig butchering in crypto fraud? Pig butchering is a long-con investment or romance scam where victims are groomed over weeks or months — typically via dating apps or social media — before being directed to a fake trading platform showing fabricated returns. It’s named for the practice of “fattening up” a victim before the financial loss.

 

What is approval phishing? Approval phishing tricks a victim into signing a blockchain transaction that grants a malicious smart contract standing permission to move their tokens — sometimes exploited days or weeks later, making the connection hard to trace back to the original interaction.

 

How does address poisoning work? Address poisoning exploits the habit of copying wallet addresses from past transaction history. Scammers send small transactions from an address deliberately crafted to closely resemble one the victim has legitimately used before, hoping the victim copies the wrong address for a future transfer.

 

Are crypto scams only a risk for crypto-native companies? No. Regulators in the UK, EU and US have signalled that banks, payment service providers, and cryptoasset firms all need to manage crypto-fraud exposure — particularly at the point customers first move funds toward digital asset platforms.

 

How can financial institutions detect crypto scams earlier? By treating typology patterns — not just transaction size — as risk signals: escalating transfers from dormant accounts, delayed token approvals, and privileged internal wallet access are all detectable before funds leave the institution, given the right monitoring controls.

 

Sources

  1. UNODC, Transnational Organized Crime Convergence Report 2024 — https://www.unodc.org/roseap/uploads/documents/Publications/2024/TOC_Convergence_Report_2024.pdf
  2. FinCEN Alert on Virtual Currency Investment Scams — https://www.fincen.gov/news/news-releases/fincen-issues-alert-prevalent-virtual-currency-investment-scam-commonly-known
  3. NCA / US Secret Service, Operation Atlantic — https://www.nationalcrimeagency.gov.uk/news/operation-atlantic; https://www.secretservice.gov/OperationAtlantic
  4. UNODC, Emerging Threats in Southeast Asia: AI and Automation in Regional Cybercrime — https://www.unodc.org/unodc/frontpage/2025/September/emerging-threats-in-southeast-asia–exploitation-of-ai-and-automation-in-the-regional-cybercrime-landscape.html
  5. FCA, Cryptoasset Financial Promotions guidance — https://www.fca.org.uk/firms/cryptoasset-financial-promotions-and-fiat-crypto-ramp-services; ESMA, MiCA — https://www.esma.europa.eu/esmas-activities/digital-finance-and-innovation/markets-crypto-assets-regulation-mica
SHARE THIS POST
READ MORE
GET IN TOUCH

Speak with a Token Recovery Specialist

Submit your case details or contact our team regarding investigations, partnerships, or general enquiries. Our specialists will respond promptly to review your request.

Initial assessments conducted securely and confidentially
We never request private keys, seed phrases, or wallet access
First forensic assessment typically within 1–24 hours
Global coverage across jurisdictions and blockchains