Crypto safety

Crypto Scams for Beginners: A Field Guide to the Five Most Common Traps

New to crypto? Learn the five scams that catch beginners most often, from phishing links and seed-phrase requests to fake support and look-alike tokens, plus the four checks that stop them.

Most crypto scams aimed at beginners don't break any code. They trick a person into doing one of four things: opening a fake site, typing a seed phrase, approving a wallet request they didn't read, or sending funds to the wrong address. Learn to spot those four moments and you have already blocked the large majority of attacks.

Our mascot is a very small kitten in very big armor, holding a shield it hasn't quite grown into. That is roughly what your first months in crypto feel like. You don't need to be an expert to be safe. You need good armor and a few habits you use every time. This guide is the map; each section links to a deeper article.

Why beginners are the favourite target

Scammers go where mistakes are permanent and help is hard to find. Crypto has both.

  • Transfers are usually irreversible. The US Federal Trade Commission notes that crypto payments typically can't be reversed and don't carry the legal protections of a credit or debit card.
  • You are your own bank. A self-custody wallet means nobody can freeze your funds, and also that nobody can reset your password if you give it away.
  • Everything is new. When every screen is unfamiliar, a fake screen doesn't look any stranger than a real one.
  • Excitement lowers guard. Airdrops, new tokens and "free gifts" create exactly the rush scammers want.

The scale is real. The FBI's Internet Crime Complaint Center received 181,565 crypto-related complaints in 2025, with reported losses of about $11.4 billion, according to its 2025 annual report.

None of this means crypto is too dangerous to try. It means the safety work happens before you click, not after.

The armored pause: four checks before you click

Every scam in this guide fails if you stop and run four checks. We call it the armored pause.

Four checks before you click: slow down, confirm who is asking, read where the link goes, read what you are approving
Run these four checks on any surprise message, link or wallet prompt. A real offer survives a ten-minute pause. A scam usually doesn't.
  1. Slow down. Countdowns, "last chance" banners and "your wallet will be suspended" warnings exist to rush you past the next three checks.
  2. Who's asking? Confirm through a channel you already trust: call the friend, open the app yourself, check the project's official account. Don't reply in the thread that contacted you.
  3. Where does it go? Read the web address before you connect anything. Your own bookmark beats any link you were sent.
  4. What am I approving? Read the wallet prompt. If you don't understand what a transaction does, reject it. Never type a seed phrase into a website.

A phishing link leads to a copy of a real site: a wallet, an exchange, a DEX like Jupiter, or an "airdrop claim" page. The copy might ask for your seed phrase, or it might ask you to connect your wallet and sign a transaction that quietly hands over your tokens. These signing traps are often called wallet drainers.

Phantom's own safety guide tells users to never visit apps or airdrops from paid search results. The links arrive through sponsored search results, replies under popular posts, Discord and Telegram DMs, emails and QR codes. The tell is usually in the address bar, if you know how to read it.

Read the full guide: how to spot a crypto phishing link.

Trap 2: Anyone asking for your seed phrase

Your seed phrase, also called a recovery phrase, is the master key to your wallet. Whoever has those words controls everything in it, from any device, without your permission.

Wallet makers agree on this. Phantom says its support team will never ask for your recovery phrase, and Solflare says no official support team will ever ask for it. Scammers ask anyway, with endless cover stories: a "wallet validation" page, a support agent fixing a stuck transaction, a form to "sync" your wallet for an airdrop, a friendly stranger helping you set up. The answer to all of them is the same.

Read the full guide: seed phrase scams and how to protect your recovery phrase.

Trap 3: Social scams and impersonators

Some scams are mostly conversation. A "support agent" DMs you minutes after you post a question. A stranger becomes a friend over weeks, then introduces a trading platform that shows impressive (fake) profits. A celebrity account promises to double any crypto you send. A "recovery expert" offers to get stolen funds back for an upfront fee.

These work because they feel personal. The defence is to move every important decision out of the conversation: check claims yourself, through official channels, and never pay money to receive money.

Read the full guide: social scams in crypto: fake support, impersonators and friendly strangers.

Trap 4: Fake tokens and look-alike addresses

On Solana, anyone can create a token with any name, ticker and logo. That includes copies of real tokens, $ARMORED among them. The only reliable identity of a token is its mint address. A related trick, address poisoning, plants a look-alike wallet address in your transaction history and waits for you to copy the wrong one.

Read the full guide: fake tokens, look-alike mints and address poisoning.

Trap 5: Too-good-to-be-true offers

Guaranteed returns, "send 1, get 2 back" giveaways, surprise tokens worth thousands, and job offers that pay you to "boost" orders with crypto all share one pattern: you pay first, and the reward never arrives. The FTC is blunt that only scammers guarantee profits or big returns.

A real gift never costs the recipient anything to receive. If a "gift" needs a fee, a deposit or your seed phrase before you can have it, it isn't one. Our guide is gifting crypto safe? covers gift-shaped scams in detail.

Build your armor before you need it

A few minutes of setup removes most of the risk above.

Beginner's armor checklist

  1. Install wallets from the official website.

    Go to the wallet's own site and follow its App Store or Google Play link. Fake wallet apps and search ads exist.

  2. Write your seed phrase on paper.

    Keep it offline. No screenshots, cloud notes, emails or chat messages.

  3. Bookmark the sites you use.

    Your wallet, your exchange, Jupiter, and this site if you send greetings.

  4. Keep a small everyday wallet.

    Use a separate wallet with a small balance for trying new apps, and keep larger amounts in a wallet that never connects to unfamiliar sites.

  5. Turn on every protection your exchange offers.

    Use an authenticator app for two-factor sign-in rather than SMS where you can.

  6. Leave your wallet's transaction warnings on.

    Most Solana wallets preview what a transaction will do. Read that preview.

  7. Start small.

    Learn with amounts you'd be fine losing. Mistakes are cheaper that way.

  8. Agree a check-in with someone.

    A friend you can ask "is this real?" before you approve anything big.

What to do if you think you've been scammed

Act quickly, and assume the attacker is still watching the wallet.

If something went wrong

  1. Stop interacting.

    Don't sign anything else on the suspicious site, and don't reply to the scammer.

  2. Move what's left.

    If you shared your seed phrase, create a brand-new wallet in the official app and transfer the remaining funds there immediately. The old wallet can't be made safe again.

  3. Write down the details.

    Transaction signatures, wallet addresses, website addresses, usernames and screenshots of the conversation.

  4. Report it.

    In the US, report to the FBI's IC3 and the FTC at ReportFraud.ftc.gov. In the UK, use Report Fraud, which replaced Action Fraud in December 2025 (in Scotland, call Police Scotland on 101). Elsewhere, contact your national fraud reporting service or the police. Tell the exchange or wallet involved, too.

  5. Ignore recovery offers.

    People who contact you promising to trace or recover the funds for a fee are running a follow-up scam. The FBI notes that law enforcement does not charge victims a fee for investigating crimes.

How Armored Kitten keeps its own corner safe

We make personal greeting cards. Where the feature is enabled, senders can add an optional $ARMORED gift. We designed that flow so the safe path is also the easy one:

  • The greeting needs no wallet. Your recipient reads the card in a normal browser.
  • We never ask for a seed phrase or private key. Not in the editor, not by email, not in a chat.
  • We never DM you about a gift on Telegram, Discord, X or anywhere else.
  • We never ask a recipient to pay to receive. The sender pays the sending costs, which are quoted before they approve anything in their own wallet.
  • Claims happen in one known place. Token gifts are claimed in the Jupiter Mobile app, not on a look-alike website.
  • One token, one mint. We only gift $ARMORED, so the token on a card is always the official mint `Bq4iwaa2hGWweyCeM9ZNyWnZSj6pCMeUDKZgmtb5pump`.

Until a gift is claimed or returned, the service keeps an encrypted copy of its claim code. Anyone with that code, or with the private greeting link, can claim the gift, so treat a gift link like cash. Our gift safety page explains the rest.

The Armored Kitten gift safety page, with sections on schedules and expiry and on truthful states
Our gift safety page sets out what the service does and never does. If a message about an Armored Kitten gift contradicts it, the message is fake.

Frequently asked questions

What is the most common crypto scam?

By money lost, investment fraud is the biggest: the FBI's 2025 report puts crypto investment fraud losses at $7.2 billion, its top loss category. Beginners most often meet phishing links, fake support and seed-phrase requests. They all depend on getting you to act quickly without checking.

Can stolen crypto be recovered?

Rarely. Transfers are usually final. Report the theft to the authorities and to any exchange involved, because exchanges can sometimes freeze funds that reach them. Be wary of anyone who promises recovery for a fee.

Is it safe to connect my wallet to a website?

Connecting usually only shares your public address. The danger is in what you sign next. Only connect to sites you opened from your own bookmark or the official app, and read every transaction before you approve it.

How do I know a crypto support agent is real?

Assume anyone who contacts you first is not. Official support rarely starts conversations in DMs, and it never asks for your seed phrase. Open the help centre yourself from the official app or website.

I'm new to crypto. Where should I start?

Start with a small amount, a wallet from the official website and your seed phrase on paper. Our beginner's guide to buying $ARMORED walks through a first wallet step by step.

Small kitten, strong armor

You don't need to understand every protocol to stay safe. You need to pause, check who's asking, read the address, and read what you sign. Do that every time and most scams simply run out of road. If a friend is just starting out, share this guide with them, or send them a card that says you've got their back.

Plain-language disclaimer: this guide is general safety information, not financial, legal or security advice for your specific situation. Crypto can lose value, and transfers are usually final. Armored Kitten never asks for your seed phrase.

Armored Kitten is an independent greeting studio and is not affiliated with or endorsed by Jupiter. Token gifts are optional, can change in value, and are not investment advice. Check the rules that apply where you live.