Home / Scam safety / The eight playbooks
The eight playbooks beginners run into
Crypto fraud is rarely sophisticated. What catches people is pacing — the other side is always one step ahead. Here is each script, with the point where it breaks.
One: did they contact you first? Two: have they asked you to transfer money, install something, or say a set of words out loud? Three: is there time pressure? Two out of three and the conversation can end there.
What follows lays out each playbook in full. It is long, but read once, most of these fall apart on the first sentence.
Start with something counter-intuitive: crypto fraud is generally not technically sophisticated. What catches people is not the technique, it is the pacing — the other side is always one step ahead, always moving to the next scene before you have processed the last one.
So recognition is not about seeing through the method. It is about breaking the rhythm. For each playbook below, we point at where it is weakest.
One: fake support
The script: you ask a technical question in a public group, or your account genuinely has a problem, and within minutes someone messages you privately claiming to be support for the platform, with a convincing avatar and handle.
It then goes one of three ways: click a link to log in and "verify", install a "secure version" of the app, or read out a code that just arrived on your phone.
Why they always find you
Because you exposed yourself first. Asking "why hasn't my withdrawal arrived" in a public channel tells everyone lurking there that here is a user who is anxious right now. Nobody had to break into anything; they just watch public information.
Worth remembering, because it dictates the defence: say less about your account in public. Use the official ticket system rather than shouting in a group.
Where it breaks
- Real platform support does not message you first. You open the ticket; the reply comes back in the ticket.
- No support process needs your verification code, password or seed phrase. That code is for you — reading it out is opening the door.
- No support agent hands you a download link. Apps come from the official store or the site's own entry point.
How to verify channels concretely has its own piece: three checks on whether what you are looking at is real.
The variant: fake announcements
The same operators run another version — a social account made to look almost exactly like the official one, posting "system upgrade, register your wallet address here" or "airdrop redistribution, claim now", with the replies seeded to look authentic.
They share one feature: every one contains a link that requires you to do something. Genuine announcements tell you what happened; they do not send you to a third-party page to perform an action. Whatever you need to do, you do inside the app you are already logged into.
Two: fake apps and fake sites
Cheaper to run and more damaging. Build an interface identical to the real one; whatever you deposit goes straight to the operator while the balance on your screen keeps climbing.
It usually arrives attached to the first playbook — fake support hands you a link, and the link is the fake site. It also appears in paid search results: you search for an exchange and the first advertisement is an impersonation.
Bookmark the official address of every platform you use, and from then on always enter through the bookmark — never through search results, never through a link in a chat. One habit, almost no effort, and it eliminates this whole category.
How to tell you are on a fake
The reliable signals are behavioural, not visual:
- It asks you to deposit to a personal address rather than a deposit address assigned to your account.
- Withdrawals are permanently "processing", or require a tax, a margin, or an activation fee first.
- Support inside the app contacts you unprompted and is very friendly.
- The domain differs from the official one by a character or two, or uses a different suffix.
The second is close to decisive: anything that requires you to pay in before you can take money out has a problem. Legitimate withdrawal fees come out of the amount withdrawn. You never have to top up separately.
One action that saves a lot of trouble: withdraw small, early
On any new platform, the first thing to do is not deposit — it is deposit a small amount and immediately withdraw it. The round trip might cost a few dollars in network fees, and it verifies the two things that matter most: whether withdrawals actually work, and whether they come with conditions attached.
Fake platforms usually break here, because the entire model depends on money only going in. The more polished ones will let a small withdrawal succeed and produce conditions when you try a large one — so the safer approach is to test again once your balance has grown.
I do this on every new platform. It costs very little and the trouble it has saved is out of proportion to the cost.
Three: the relationship build, or "let me trade for you"
The longest running and the largest in value. Nobody mentions money at the start; there are weeks or months of ordinary conversation first, and only once the relationship exists does investing come up, apparently by accident.
The full six-act structure, and why those middle withdrawals genuinely arrive, is in the long con, act by act. The identifying features:
- They built the relationshipWhether the opening was a wrong number, a job ad, a dating app or a local group.
- Money comes up naturallyNot a pitch — "this is what I do, have a look if you like".
- The platform is one you have never heard ofAnd it can only be reached through their link.
- You made money earlyThat is an investment on their side, not evidence of anything.
The fourth is the dangerous one, because it clears out your doubt. You think: if this were fake, why did the first withdrawal work? Because that money was their cost of doing business.
Four: airdrops and approval phishing
Real airdrops exist, which is exactly what makes the fake ones effective.
The shape: a message arrives, or an unfamiliar token appears in your wallet, pointing you at a site to claim it. You connect your wallet, press approve, and the assets are gone.
The concept you need: approvals
On-chain, you can grant a program permission to move a particular asset on your behalf. The mechanism is legitimate and every decentralised application relies on it. The problem is that a malicious contract requests an enormous or unlimited allowance, and once you confirm it, it can drain that asset from your wallet at any point afterwards — without your private key, and without asking again.
Which is why what phishing sites usually want is not your seed phrase but one signature. It is also the answer to "I never told anyone my seed phrase, so how did the money go".
- Do not interact with tokens you did not expect, and especially do not try to sell them — many exist purely to make you interact.
- Check the domain before connecting, and read what permission is being requested before signing.
- Review and revoke approvals you no longer need; every major chain has official or community tooling for it.
Five: high-yield programmes
The characteristics barely change: a promised daily or annual rate, heavy emphasis on safety, tiered referral rewards, and pressure to recruit.
The test is simpler than people expect. Ask: where does the yield come from?
Legitimate yield has a source. Lending interest comes from borrowers, market-making revenue from spreads, staking rewards from protocol issuance. All of those move with market conditions, so the rate has to float. Anyone telling you the return is fixed, identical every day and unaffected by markets is describing money that comes from the people who join after you.
Features you can treat as red flags
- Tiered referrals — so much for recruiting one person, a share of what they recruit. Legitimate products do not need users to build downlines.
- Emphasis on lock-up periods — locking funds in buys time to absorb new deposits.
- Grand documentation that never explains the revenue — plenty of technical language, no one-sentence answer to how money is made.
- Explicit "team bonuses" or "management bonuses" — the vocabulary comes straight from pyramid structures.
- Withdrawals that need review, have caps, or require conditions — controlling the outflow is a requirement of this structure.
And a plainer test: if something reliably produced returns far above the market, why would it need money from strangers? Borrowing costs much less. That question alone disposes of most of them.
There are no capital-protected products in crypto, and no such thing as a sure thing. Any arrangement promising a fixed return or claiming zero risk can cost you your entire stake. Tiered referral rewards deserve particular suspicion — that is the standard shape of a ponzi.
Six: recovery services, the second harvest
This one targets people who have already been defrauded, which makes it the ugliest of the set.
The script: you post about your experience in a support group or on social media, and someone contacts you claiming to be a technical team, a lawyer, or an on-chain tracing specialist who can retrieve the funds — for a service fee, or an "unfreezing deposit".
The reality is that on-chain transfers are irreversible and no private organisation has the ability to retrieve crypto that has already moved. The only routes with any standing are a police report and a ticket with the platform, and neither charges you.
The single most important thing after being defrauded is to stop spending money. Everyone knows that in the abstract, and in the state of wanting to undo a loss, people are unusually easy to catch a second time.
Seven: "just receive a payment for me"
This one does not look like fraud at all, because the other side appears to be doing you a favour: receive a transfer, or run one trade through your account, and keep a couple of hundred.
The problem is where that money came from. Once it passes through your account, your account is part of the chain. The consequences are frozen funds, demands to prove source of funds, and in serious cases legal exposure.
The mechanism and how to protect yourself are in the piece on frozen accounts.
Eight: jobs, task work and "digital asset assistant" roles
Growing quickly, because it sidesteps the word "investment" entirely. The listing looks ordinary: remote, paid daily, simple tasks, no experience needed.
The work is variously described as completing trading tasks for a company, boosting order volume for a merchant, or managing a pool of funds. The first few days genuinely pay — small amounts, on time.
Then the turn: one day you are asked to front the money. Because the task is larger, because the system requires a minimum balance, or because you made an error and an order is stuck until you top it up.
What separates this from the others is that you believe you are working, not investing, so the question "is this a scam" never gets asked. That is precisely why it works.
One rule handles it: any job that requires you to put money in first is not a job. In an employment relationship money flows from the company to you, never the other way.
The more insidious version: hiring you as an account
The description sounds legitimate — settlement officer, cross-border collections assistant. The actual work is receiving and forwarding funds through your own bank and exchange accounts.
That is beyond being defrauded; it can make you a link in a chain, with the consequences described in the frozen accounts piece. The test is easy: if the "job" requires accounts in your own name, decline.
Nine: several frequent but scattered tactics
Fake "verification is expiring"
An email or message says your account verification is about to lapse and you must resubmit or be restricted. The link goes to a clone that harvests your identity documents and face data. Real verification does not expire in a way that requires redoing it from an email link, and redoing it happens inside your account. Leaked identity documents get used elsewhere for a long time afterwards.
Fake "you must update the client"
A prompt says your version is insecure and offers a download. The installed app looks normal, and the passwords and codes you type go elsewhere. Update only through the system app store and this one stops existing.
Screenshot groups
You are added to a group where people post profit screenshots all day and the mood is excellent. Most members are accounts run by the same operation. Its job is not to defraud you directly; it is to provide background noise that makes the next step feel normal.
"Official partner" intermediaries
Someone claims to be an agent, a channel partner or a regional representative of a platform who can get you better rates or unlock a permission. Exchange referral programmes are public and open to anyone; they do not create an agent role, and nobody obtains permission to operate your account through one.
Why these work on intelligent people
This section exists because "only greedy people get scammed" is both wrong and actively harmful — it makes the people who most need to be careful relax.
These scripts do not exploit intelligence. They exploit mechanisms everybody has:
| Mechanism | How the script uses it |
|---|---|
| Reciprocity | A small favour first — solving a problem, letting you earn a little — makes the next request harder to refuse |
| Commitment and consistency | Once you take a small first step, every step after that is taken partly to stay consistent with the earlier decision |
| Social proof | Other "students" posting results make it feel like an ordinary thing many people do |
| Scarcity and deadlines | Limited places, only until tonight — compressing the time you have to think |
| Sunk cost | The more you have put in, the harder it is to stop; the final "fees" are extracted with this |
| Authority | Fabricated credentials, a "mentor" persona, professional-looking charts |
Knowing them does not make you immune, but it gives you a concrete self-check: when you notice you are constructing reasons for a decision, you are usually already inside one of these.
One observation while I am here: what people find hardest to give up in these situations is not the money, it is the belief that they are a good judge of character. Admitting the fraud means admitting the misjudgement — which is why people keep paying well after it has stopped adding up. Anyone watching from outside should understand that; see the last section of the long con.
Eight playbooks compressed into four questions
| Ask yourself | Why it works |
|---|---|
| Who spoke first? | Almost every one of these starts with them approaching you. Entry points you found yourself, and tickets you opened, are an order of magnitude safer. |
| What action am I being asked to take? | Transfer, install, sign, read out a code, say a set of words — any one of those five is worth stopping for. |
| Why the hurry? | Time pressure is a requirement, not a coincidence. Real opportunities survive you sleeping on it. |
| Where does the money come from? | A programme that cannot explain its yield is paying you with later entrants' money. |
We turned this into something you can tick through: the script checker. If you are hesitating right now, ticking off what they have said is clearer than weighing it in your head.
If it has already happened
In this order, without skipping:
- Stop paying, immediatelyIncluding fees, margin, tax, unfreezing charges. Those are the next section of the same funnel.
- Preserve evidenceChat logs, transfer records, their accounts and receiving addresses, site domains. Screenshot and save separately — they will delete things.
- Change the related credentialsIf they obtained a code, or you logged in on a suspicious page, change passwords, reset two-factor, and check whether any withdrawal address was added.
- Open a ticket with the platformIf an exchange account is involved, describe it through the official channel. What a platform can do within its obligations is limited, but the record matters.
- Report it to law enforcementThe only route with any formal standing.
- Ignore anyone offering recoverySee section six.
How to organise the material
Whichever route you take, they want the same things. Preparing them saves a lot of back-and-forth.
- A timeline — when you were contacted, when you first transferred, the amount and time of each payment. One page is enough.
- The money trail — bank statements, exchange withdrawal records, on-chain transaction IDs. The on-chain portion is publicly verifiable and carries the most weight.
- Their details — handles, avatars, every receiving account used, domains and app names.
- The conversation — exported in full, not just the key lines. Context often establishes the nature of it better than a single sentence.
One thing for anyone who has lost money: this is not embarrassing. These scripts have been refined over many iterations against how people judge things under specific emotional conditions. Being clever was never the defence. What matters now is that it does not happen twice.
How do I tell whether a trading platform is fake?
Three things: how you found it (an official entry point you located yourself, or a link someone sent), whether the deposit address is assigned to your account, and whether withdrawals come with extra charges. The third is close to decisive — anything requiring you to pay in before you can take out is fake.
Why did the early withdrawals actually work?
That was an investment on their side. Letting a withdrawal succeed once or twice removes your doubt so that you commit far more later. Early withdrawals working is a standard move in this playbook, not evidence of safety.
I only opened the link — is that a problem?
Simply loading a page does not usually cost you anything. The danger is entering credentials, entering a seed phrase, or connecting a wallet and signing an approval. If you did any of those, change passwords, review approvals, and move assets to a new address.
Is there any chance of getting the money back?
On-chain transfers are irreversible and actual recovery rates are low. The legitimate routes are a police report and a platform ticket, neither of which charges a fee. Anyone charging to recover funds is running the second scam.