The 5 Most Common Crypto Wallet Scams in 2026
Fake MetaMask popups, drainer sites, and Discord 'support' DMs — how to recognize them before you sign.
Crypto scams have evolved far past the Nigerian-prince emails of the 2000s. Today, attackers clone entire DEX frontends, hijack X (Twitter) accounts of verified projects, and pay for Google Ads that outrank the real protocol. According to Chainalysis's 2024 Crypto Crime Report, wallet drainers alone stole over $494 million in 2023 — and the average victim loses funds in under 90 seconds.
The good news: every drainer relies on tricking you into *one signature*. Learn the five patterns below and you'll spot them every time.
1. Drainer sites disguised as airdrops
You click a link from a hijacked Twitter account or a "free claim" notification. The site looks identical to the real project. You connect, click "Claim", and your wallet asks you to sign a signTypedData or setApprovalForAll request. That single signature gives a malicious contract permission to move every token in your wallet.
- Defense: never sign a message you don't understand. The MetaMask security guide explains what each prompt actually does.
- Use a hardware wallet for anything > $500. Cold signatures force you to read what you're approving on a screen attackers can't fake.
2. Fake support DMs (Discord, Telegram, X)
You post a transaction issue. Within minutes a "Support Bot" or "MetaMask Help" account DMs you a Google Form, Calendly link, or a "validate wallet" URL. No legitimate team will ever DM you first. Discord's own scam guide confirms support is *only* through official ticket channels.
3. Address poisoning
The scammer generates an address that starts and ends with the same characters as one you've sent to before — say 0x7Fa3…91bC — then sends you a 0 tx. Later, you copy from your transaction history and accidentally paste the lookalike. Always verify the *middle* of the address, or save trusted addresses to your wallet's address book.
4. Stale token approvals
Months after using a DEX, the old approve(unlimited) you signed is still live. If that contract is exploited, your tokens drain without any new action from you. Quarterly hygiene:
- Run revoke.cash or Etherscan's Token Approval Checker and revoke anything you don't actively use.
- Prefer DEXs that support Permit2 with bounded expirations.
5. Cloned wallet extensions and mobile apps
Searching the Chrome Web Store or App Store for "MetaMask" or "Phantom" returns dozens of look-alikes. Some are clean clones with one line changed: the seed-phrase entry screen ships your phrase to an attacker server. The Phantom security center recommends installing only from the wallet's *own* website link.
The universal rule
Treat every signature request as if it costs you everything — because some do. Before you connect to *any* new dApp:
- Paste the URL into ScreenConnect Shield's scanner. We flag known drainer infrastructure and lookalike domains.
- Check the contract address on a block explorer. If it has fewer than a few hundred transactions and was deployed yesterday, walk away.
- Sign with a hardware wallet whenever the value justifies it.
Learn more & verify
Authoritative sources used in this article — open in a new tab.
Have a suspicious link? Don't click it.
Paste it into the ScreenConnect Shield Link Scanner for an instant safety verdict.
Scan a link