2026 Latest Scam Prevention Guide: How Many Types of Scams in the Crypto World Do You Know?
Author: Biteye
"I have bought fake coins, fake NFTs, and invested in fake projects; today is the first time I encountered a fake chain."
The emergence of the GIWA fake mainnet last night should have made many people realize for the first time: it turns out that even the "chain" in the crypto world can be fake.
To some extent, this statement highlights the most frightening aspect of current crypto scams: scammers can always find a new way to deceive you that you have never seen before.
Therefore, this article starts with the GIWA fake mainnet and systematically organizes several of the most common and easily fallible scams in the crypto world in 2026.
1. X Scams
1️⃣ Fake project websites | KOL forwarding and phishing
At the time, Circle's Arc mainnet had not officially opened for cross-chain, but scammers had already set up a fake cross-chain bridge called onbridge in advance and promoted it on X: "Arc mainnet is Live now, you can directly cross USDC in."
Scammers even specifically purchased KOL comments and forwarding services on third-party platforms.
Some KOLs involved in airdrops and giveaways would directly reply or retweet under the scam post, causing fans to see "familiar people are interacting," naturally lowering their vigilance, thinking this is a verified official entry.
In the end, users clicked on the "cross-chain bridge" in the post, connected their wallets, and authorized assets, only to find they had entered a phishing website.
💡 How to prevent: Always return to the project's official account to reconfirm all entries, and ask AI whether all links are official links.
2️⃣ Fake recruitment/fake investment institutions | Business cooperation phishing
The essence of these scams is the same: first approach you with a seemingly reasonable identity, then find a way to get you to run malicious files on your computer.
Scammers may impersonate VCs, investment institutions, or project parties, discussing financing and cooperation, and then schedule meetings through Calendly or Google Meet, only to suddenly say there is a problem with the meeting software, asking you to download new Zoom, Teams, or Meet plugins.
They may also impersonate crypto or AI companies or headhunters, asking developers to complete coding tests by downloading projects from GitHub or Bitbucket and running the code.
The earlier processes usually seem normal, but the real attack hides in the last step: the meeting plugins, update programs, coding tests, or project codes actually contain trojans.
Once run, they may steal sensitive information such as browser cookies, Telegram sessions, API keys, wallet private keys, and mnemonics.
Some scammers may lay the groundwork for a long time, while others may be more impatient, directly throwing a fake meeting link or GitHub project on the first contact.
💡 How to prevent: Do not download or run any meeting links or software sent by strangers; try to use only familiar official entry points like Zoom or Google Meet for business communication. If the other party insists on changing platforms or installing plugins, terminate the conversation immediately.
3️⃣ Stealing KOL accounts to issue tokens / shout orders
These scams specifically target influential KOLs, founders, and executives in the crypto world.
Scammers usually first use DMCA complaints, account anomalies, or security verifications to send phishing links to steal the other party's X account. Once they obtain the account, they immediately use the original account's influence to issue memes and promote projects, making fans mistakenly believe it is endorsed by the real person.
Sometimes scammers even continue to open Spaces and reply to comments, making the act seem more like the real person.
The X accounts of 0xSun, Professor Hash Wesley, and Nano Labs founder Kong Jianping have all been stolen, with almost identical tactics: once the account is obtained, they issue tokens and shout orders, quickly generating trading volume using the original KOL's existing fans, and then the token price plummets to zero.
💡 How to prevent: If a familiar KOL suddenly issues tokens, first confirm through other channels whether it is really them.
2. Tg Scams
1️⃣ Impersonating Telegram friends | Fake accounts borrowing money / phishing
Scammers will directly register a new Telegram account, copying your friend's avatar, nickname, and username style, making it look almost identical to the real person.
They will then actively message you, starting with normal small talk, and then say they have an urgent matter, need to borrow U, or change an address for payment, or ask you to help with a transfer.
Some scammers will even research your relationship with the other person in advance, mimicking the chat tone, and even knowing your mutual friends, making the entire conversation seem more real.
💡 How to prevent: Directly call or use another common channel to confirm the person's identity.
2️⃣ Telegram fake verification | Scamming verification codes to steal accounts
Scammers will impersonate Telegram officials, group administrators, or Safeguard verification bots, telling you "account anomaly," "login expired," or "verification needed to enter the group," and then ask you to fill in verification codes, scan QR codes, or enter two-step verification passwords.
Once you give out the verification code, they can log into your Telegram on their device and further kick off other logged-in devices and modify two-step verification.
After obtaining the account, they will not only steal your account but will also directly browse your contacts and client groups, starting to use your identity to borrow U or send payment addresses to others.
💡 How to prevent: Never send verification codes, login QR codes, or 2FA passwords to anyone.
3. Phishing entry scams
1️⃣ Google fake official website | The top search result may also be fake
Many people go directly to Google to search for Hyperliquid, MetaMask, or a project’s official website.
Scammers will prepare a phishing website that looks almost identical to the official website in advance, and then use search ads, SEO, and other methods to push the fake website to the top of the search results.
Users see that it is something they actively searched for, and since it ranks high, their vigilance is usually much lower than when they receive a strange link.
In August this year, a user searched for Hyperliquid and clicked on the top fake official website, signing a malicious authorization inside, ultimately losing about 550,000 USDC.
💡 How to prevent: Try to enter the official website from the project's official X homepage; if unsure about the account's authenticity, you can first use XHunt to confirm the official account and then verify the domain name.
2️⃣ Discord fake verification | Malicious authorization to steal coins
Scammers will disguise phishing entries as normal Discord identity verification.
Once users enter the group, they will be asked to click Verify, which then redirects to a third-party website to connect their wallets. The entire page looks like a normal "identity verification," but in reality, it connects to a wallet drainer.
Once users connect and sign, scammers will use the old authorizations left by the wallet in protocols like Morpho and Uniswap to directly transfer assets away.
💡 How to prevent: If entering a group and verifying requires connecting a wallet or signing, first confirm the domain name and the content of the signature; do not blindly click confirm.
3️⃣ Email fake airdrop | "You have an airdrop waiting to be claimed"
Scammers will send bulk emails that look very official from project parties, telling you "you meet the airdrop eligibility," "there are tokens to claim," and "Claim deadline is approaching." The logos, layouts, and even sender names in the emails will be made to look very similar to the official ones.
Clicking Claim / Check Eligibility will redirect you to a counterfeit project official website, prompting you to connect your wallet to check the airdrop.
The website will lure you to sign and authorize, while in reality, it connects to a wallet drainer; some will even directly ask for your mnemonic or private key.
💡 How to prevent: Try not to click on Claim links directly in emails; always verify information against the project's official X account.
4. Wallet/On-chain scams
1️⃣ Address poisoning | Copying historical addresses to get scammed
Scammers will specifically generate a wallet address that looks very similar to your commonly used address, usually with the first few and last few digits almost identical.
Then they will transfer a very small amount to your wallet, or even directly transfer 0 U, with the aim of making this fake address appear in your on-chain transaction records.
When you make your next transfer, if you habitually copy addresses directly from your transaction history and only check the first and last few digits, it is very easy to mistake this fake address for your commonly used address.
In the end, you will find that you clearly "copied a familiar address," but the money has been transferred to the scammer's wallet.
💡 How to prevent: Use QR codes for transfers; for large transfers, first do a small transfer; do not copy addresses directly from transaction history; always verify the full address at least for several digits at the beginning and end.
2️⃣ Fake mainnet / fake cross-chain bridge | Chain ID is real
GIWA officially announced Chain ID 9134 long ago, but the mainnet has not officially launched yet, and there are no official RPC or official cross-chain bridges.
Scammers took advantage of this information gap to set up a fake "GIWA Mainnet": using the real Chain ID 9134, along with fake RPC and fake cross-chain bridges.
Once users add the network to their wallets, they will find that the Chain ID matches perfectly, easily mistaking it for the official mainnet. As a result, this fake chain quickly spread in the community, and even some DEXs integrated it, further enhancing its credibility.
Many users, with a mindset of "rushing to get in early," transferred ETH into the so-called GIWA Mainnet. Ultimately, a total of 1,335 addresses transferred about 767.65 ETH to the fake mainnet, of which about 766.25 ETH was withdrawn by the scammers, resulting in a loss of nearly 2 million USD.
💡 How to prevent: Before rushing into new chains, only recognize RPC, bridges, and contract addresses in official announcements; a matching Chain ID does not mean it is real.
5. Device/account theft
1️⃣ Malicious apps | Poisoning updates after normal listing
FomoPeek is presented as a normal on-chain monitoring tool that does not require connecting wallets or filling in mnemonics.
Scammers first listed a normal version on the App Store, then through KOLs and airdrop groups, sent out a large number of invitation codes, attracting many real users to install it with the lure of "download and experience to receive 5 U."
Once the installation volume rises, FomoPeek quietly adds malicious code in subsequent updates, which can exploit iOS vulnerabilities to read sensitive information such as wallets, private keys, and notes stored on the phone.
💡 How to prevent: Do not install unfamiliar apps just for a few U rewards; important wallets must be isolated from daily phones, and devices that have installed suspicious apps should not continue to hold large assets. iOS is not absolutely secure; both the system and apps should be updated to the latest versions in a timely manner.
2️⃣ Exchange account theft | Falsifying identity documents through appeals
Attackers will collect users' names, identification, phone numbers, transaction records, and other information in advance, then use forged videos, AI face recognition, or other social engineering techniques to impersonate the user and apply to the exchange for "lost email" or "unable to use Google Authenticator" and other security item resets.
Once approved, scammers may change the email and 2FA to their own, and create API, withdrawal addresses, or other long-term permissions in advance. Even if users later recover their accounts and reset passwords and authenticators, if these hidden permissions are not cleared, assets may still be transferred away.
With the increasing prevalence of AI face-swapping, voice cloning, and forged materials, there have already been multiple similar cases this year.
💡 How to prevent: Regularly check the exchange's API, withdrawal whitelist, login devices, and security settings; if any anomalies are found, do not just change the password, but also clear related permissions.
🌟 Final Thoughts
After reading these cases, you will find that the real strength of many scams does not necessarily lie in how advanced the technology is, but rather in how well social engineering is done.
Scammers will use familiar scenarios such as acquaintances, KOLs, official websites, meetings, recruitment, and verification processes to lower your guard and then induce you to complete transfers, sign, input verification codes, download files, or run code.
Therefore, rather than demanding that you never make mistakes, it is better to isolate risks in advance and minimize the cost of a single mistake.
First, assume that everyone could be a scammer. Even acquaintances, partners, and KOLs should be confirmed through another channel when it involves transfers or money; do not skip verification just because "you know this person."
Second, isolate devices and assets. Try to keep large assets and main wallets on independent devices that are not used for daily chatting, meetings, downloading software, or running code.
Third, do not click on unfamiliar links directly. Whether it is sent by friends, KOLs, or found on Google, check the domain name, search for project announcements, or directly ask AI to help you judge before clicking.
Fourth, keep systems and commonly used software updated to the latest versions. As soon as security updates are released for iOS, macOS, browsers, wallets, etc., upgrade them promptly; many attacks exploit vulnerabilities that have already been disclosed but not yet patched by users.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Bloomberg: Why is Trump Pushing for Perpetual Contracts in the U.S.?

The Era of Fundamentals in Crypto: Buybacks, Cash Flow, and Three Valuation Logics

In Conversation with Zhao Changpeng: We Are Still in the Early Stages of the Biggest Cryptocurrency Surge

Hyperliquid to Increase HIP-4 Deployment Limit

Analyst Claims Variational's $1.5 Billion FDV Valuation is Overly Optimistic, Conservative Estimate at $167 Million

Payward, the parent company of Kraken, invests billions in financial infrastructure

CZ Welcomes More DEX Participation in Competition

Crypto Treasuries No Longer Attracting Investors
![[Column] Which Coins Strengthen as Prices Rise](/public-static/050_2dc4cf2ce9.png?format=avif)
[Column] Which Coins Strengthen as Prices Rise

Hyperliquid and Phantom Submit Comment Letter Advocating That Protocol Developers Should Not Be Considered Financial Intermediaries

xStocks adds Ledger hardware wallet support for tokenized shares

DoubleZero Launches Dedicated Market Data Source for Hyperliquid

Perpetuals on Gold, Oil, and Stocks: $117 Billion Traded in One Month

Only 4 of top 20 crypto treasury firms trade above asset value: report

CoinShares report shows RWA deposits tripling to $7.4B

Privy Expands Support for TRON with Enhanced Wallet and Payment Infrastructure for Developers

Exclusive Interview with Frontier Technology Investor Zheng Di: SEC's 'Innovation Exemption' Opens the Door to a Compliant Bull Market, Which Assets Are Potential Stocks?

Grayscale Positively Evaluates Payward's Entry into the U.S. Hyperliquid Market

a16z: August RWA perpetual contract trading volume reaches $117.3 billion, on-chain trading share rises to 86%

Dave Weisberger Discusses Bitcoin FOMO and Collateral Treatment

Altcoin demand meets $18B threat as flows move into RWA perps as just 19% of traders keep alts

Can Kraken's Parent Company Open the Door for Hyperliquid to Enter the U.S. Market?

AI and Crypto: Why BlackRock Sees a Major Convergence

What is Travix? An on-chain omnibroker combining AI trading and blockchain verification

Hyperliquid open interest reaches record $18 billion: What’s driving activity?

Coinmetrics Report: The Competition of Tokenized Stocks and Their Future Development Path

HyperLiquid Launches Perpetual Contracts for Chinese Assets, Challenging Global Financial Regulation

Kinetiq Hyperliquid L2 Elysium Testnet Launched

Crypto: Kalshi accused of inflating its volumes with thousands of identical orders










