In 2025, cryptocurrency scams have become more sophisticated and highly organized, blending emerging AI technology with traditional fraud tactics to precisely target users, making them increasinglyIn 2025, cryptocurrency scams have become more sophisticated and highly organized, blending emerging AI technology with traditional fraud tactics to precisely target users, making them increasingly
新手学院/Cryptocurrency Knowledge/Security Knowledge/How to Spot Crypto Scams: The Complete MEXC Anti-Fraud Guide

How to Spot Crypto Scams: The Complete MEXC Anti-Fraud Guide

Sep 21, 2026
13 分钟

In 2025, cryptocurrency scams have become more sophisticated and highly organized, blending emerging AI technology with traditional fraud tactics to precisely target users, making them increasingly difficult to detect and posing serious security challenges.

According to the latest Hacken security report, phishing attacks alone caused nearly $600 million in losses in the first half of 2025, while rug pull schemes accounted for over $300 million. Combined, these represent roughly one-third of all digital assets stolen during the same period. In addition, since 2023, AI-related exploit incidents have surged by 1,025%, becoming an emerging threat within the scam ecosystem. Fraudsters now leverage AI-driven deepfake videos and voice cloning to further increase the difficulty of defense.

This article will provide an in-depth analysis of common crypto scams, strategies to counter them, and the security measures offered by MEXC to help investors identify traps and safeguard their assets.

1. Common Types of Crypto Scams


1.1 Phishing Scams


Phishing remains the most common attack vector in the crypto space. Scammers impersonate official entities or public figures to lure users into visiting fraudulent websites or apps. Once a user grants wallet permissions, the attacker can swiftly transfer their assets. Common tactics include impersonating official X (Twitter) accounts, sending deceptive emails, posing as customer service, or offering fake airdrops, all highly convincing. In 2025, phishing attacks have been further enhanced through AI-generated deepfake videos and voice calls, making them harder to detect.

Case Study: Following a major exchange data leak, scammers used compromised KYC information to impersonate customer service representatives. They contacted users via phone or email, prompting them to click phishing links, resulting in over $100 million in losses within months. In another case, during the so-called "XRP Airdrop" scam, fraudsters used high-subscriber YouTube channels to post AI-generated videos mimicking Ripple executives, claiming to launch a "bonus program" that required users to transfer funds in order to receive the airdrop.

Countermeasures:
  • Cross-verify the source of any link and ensure it originates from official channels; never click on unofficial links.
  • Never disclose your private key or password to anyone claiming to be "official staff" (MEXC staff will never request this information).
  • Use a hardware wallet to store crypto assets, minimizing online exposure.
  • Regularly review and revoke suspicious dApp wallet permissions.
  • Enable two-factor authentication (2FA) to prevent unauthorized account access.

1.2 Address Poisoning Attack


In an address poisoning attack, scammers send tiny "dust" transactions from a wallet address that closely resembles one you've recently interacted with. The goal is to "poison" your transaction history so that if you later copy a recipient address from past transactions, you may accidentally select the attacker's look-alike address instead of the legitimate one, resulting in an irreversible transfer of funds.

Case Study: A KOL crypto influencer planned to make a large USDT transfer and first tested by sending 1 USDT. Within minutes, two attacker-controlled wallets sent 1 USDT back, each from an address nearly identical to the intended one (e.g., real address: 0x1234...5678, fake address: 0x1234...5b78). When the influencer copied the wrong return address for the main transfer, the funds were stolen.

Countermeasures:
  • Manually verify every character of the recipient address; cross-check using a blockchain explorer.
  • On platforms like MEXC, enable the wallet address whitelist so withdrawals can only go to pre-approved addresses.
  • Avoid using public Wi-Fi for wallet transactions; regularly scan devices for malware.
  • Periodically review and revoke suspicious dApp permissions.
  • Treat unsolicited micro-transfers (e.g., 1 USDT) as potential attack vectors; never return funds to such addresses. Instead, investigate and label them as suspicious.

1.3 High-Return Investment Scams


These scams are common in Telegram and Discord groups, where fraudsters promise "high returns," "cross-platform arbitrage," or other lucrative opportunities to lure victims into transferring funds, which are then quickly stolen.

Case Study: A California resident was contacted via WhatsApp and enticed to invest through a fake trading platform. The account interface displayed fabricated profits, but withdrawals were blocked. Shortly afterward, the platform was shut down, resulting in a loss of $40,000 for the victim.

Countermeasures:
  • Be wary of any claim offering "risk-free high returns." In legitimate markets, higher returns almost always mean higher risk.
  • Trade only on reputable, regulated exchanges; avoid unverified platforms and unofficial links.
  • Verify a platform's legitimacy using trusted sources such as CoinMarketCap, CoinGecko, or DappRadar.
  • Before committing significant funds, perform a small-value test withdrawal to ensure the platform processes payouts.
  • Join official, verified community channels and promptly report suspicious behavior to moderators or admins.

1.4 DeFi Scams


Scammers create fake DeFi projects to lure users into participating in fraudulent liquidity mining or staking programs, only to execute a rug pull and steal the deposited funds.

Case Study: In the Ionic Money incident, scammers posed as a team called "Lombard Finance" and convinced the platform to list a fake token, LBTC. They minted 250 counterfeit LBTC and used them as collateral to borrow approximately $8.6 million in real assets from Ionic Money. After withdrawing the funds, they abandoned the worthless collateral, causing severe losses to both the platform and its users.

Countermeasures:
  • Only participate in DeFi projects audited by reputable security firms; personally review the audit reports and pay close attention to any identified risks.
  • Use blockchain security tools such as GoPlus or TokenSniffer to evaluate a project's legitimacy.
  • Check contract open-source status and track team wallet activity via blockchain explorers like Etherscan.
  • Assess the project's credibility based on community engagement quality and its historical track record.
  • If a project's security is uncertain, test with a small amount first to evaluate protocol stability and withdrawal functionality, never commit large sums upfront.

1.5 Fake Token Issuance and Rug Pulls


In 2025, the memecoin boom made the sector a hotspot for fake token launches and rug pulls. Scammers exploit the "get-rich-quick" sentiment by deploying malicious smart contracts or concentrating token supply in a few wallets. They then combine social media hype with fabricated celebrity endorsements to trigger FOMO, before pulling liquidity or dumping tokens at price peaks, sending the token value to near zero within minutes.

Case Study: One of the most notorious rug pull scandals of 2025 involved the Libra token. Argentine President Javier Milei posted about the token on social media, which the market interpreted as a celebrity endorsement. The token's market cap subsequently soared into the billions of dollars. After a surge of retail investors poured in, Milei deleted the post, and the token's price plummeted by 94%. The incident was widely accused of being a carefully orchestrated "pump-and-dump" scheme.

Countermeasures:
  • Verify liquidity lock and contract audits, e.g., via MEXC DEX+ security checks and audit reports.
  • Monitor team wallets through blockchain explorers to detect abnormal sell-offs.
  • Independently verify celebrity endorsements; never rely solely on public figures as a credibility signal.
  • Treat memecoin investments as high-risk. Strictly limit position size, set stop-loss levels, and avoid overexposure to a single asset.

1.6 AI-Driven Scams


With the rapid advancement of artificial intelligence, crypto scams in 2025 have become increasingly sophisticated. These AI-powered schemes are not only technically advanced but also highly deceptive, making them difficult to detect. Below are several common and particularly dangerous AI-driven fraud methods:

1) AI-Generated Celebrity Videos: In 2024, an AI-generated deepfake video of Elon Musk appeared in a YouTube livestream soliciting funds. Within just 20 minutes, the scam wallet received multiple transfers from victims. From March 2024 to January 2025, this scheme reportedly stole over $5 million.

2) AI-Generated Fake Customer Support Audio/Video: Scammers use AI tools to produce highly realistic voice or video impersonations of exchange support staff or official project representatives. Through social engineering, they trick users into revealing private keys, seed phrases, or transferring funds. The lifelike realism and targeted nature of such scams make them especially effective at breaching trust.

3) AI-Fabricated Live Facial Video to Bypass KYC: Fraudsters create AI-generated dynamic facial videos that mimic genuine expressions and movements, successfully bypassing biometric KYC verification on exchanges and stealing funds from compromised accounts.

Countermeasures:
  • Always verify information through official channels (e.g., the project's official website or verified social media accounts).
  • Never disclose private keys, seed phrases, or passwords, even to "official" personnel.
  • Enable two-factor authentication (2FA) to strengthen account security.
  • Treat unsolicited requests and "guaranteed high returns" offers with suspicion, and maintain critical judgment at all times.

2. MEXC's Anti-Scam Support Measures


1) Account Security Protection: MEXC has implemented a comprehensive account security framework with multiple layers of technical safeguards to prevent unauthorized access. Measures include enabling two-factor authentication (2FA), setting up an anti-phishing code, and real-time interception of suspicious login links. In addition, MEXC stores user assets using a cold–hot wallet separation model combined with multi-signature technology, enhancing fund security from the ground up.

2) Trading Security Protection: The platform leverages advanced algorithms and AI to monitor abnormal price fluctuations and suspicious wash trading patterns (such as volume manipulation or market rigging) in real time. Once potential malicious activity is detected, MEXC promptly restricts the relevant suspicious accounts to prevent wash trading, pump-and-dump schemes, and other manipulative behaviors, thereby maintaining market fairness and transparency. Notably, MEXC's high-performance matching engine ensures transactions are executed stably and efficiently, reducing the possibility of malicious traders exploiting system latency for arbitrage.

3) Verify Official Channels With MEXC Verify: To prevent users from being misled by counterfeit official channels, MEXC has introduced MEXC Verify, an official account verification tool. By clicking on MEXC Verify located under the "About" section at the bottom of the MEXC website, users can enter the ID of a social media account (e.g., Telegram, X/Twitter) to verify its authenticity. If the search result displays a green "Verified Official Source" checkmark, it confirms the account is officially operated by MEXC (and will list other official channels linked to that ID). If a red "Unverified Source" warning appears, it indicates the account is not official, prompting users to exercise caution and avoid clicking any links it provides.

4) AI-Driven Scam Detection: MEXC leverages artificial intelligence to enhance both the speed and accuracy of its risk controls. The platform has developed AI models to monitor abnormal trading behavior, irregular login patterns, and unusual on-chain fund movements in real time. Upon detecting suspicious activity, the system automatically blocks the action or escalates it for manual review. This "AI and human" hybrid risk monitoring framework significantly improves response times to emerging scams. In Q2, MEXC's AI-based monitoring successfully reduced the number of scam attempts by 12% quarter-on-quarter.

5) User Security Education: In addition to technical defenses, MEXC places strong emphasis on enhancing user security awareness, helping users identify and avoid scams on their own. The platform's official website features an educational section that provides guidance on account security, fraud prevention in trading, and other best practices. Furthermore, in August, MEXC will launch a series of security awareness campaigns to strengthen users' knowledge and vigilance.

6) Rapid Scam Reporting and Response: MEXC has established a rapid response mechanism to assist users at the first sign of potential fraud. If a user encounters scenarios such as a fake customer service representative requesting a transfer, or being added to an investment group by a stranger who then urges them to deposit funds, they can immediately report it via MEXC's official online Customer Service or the designated support email. Once a report is received, the platform promptly investigates the suspected fraudulent account. If the suspicion is confirmed, MEXC will temporarily freeze the assets in the account to prevent illicit funds from being moved further.

3. User Anti-Fraud Strategy: The "Identify, Prevent, Mitigate" Three-Step Approach


With scam tactics constantly evolving, users must adopt a proactive three-step approach to enhance their defenses:

3.1 Identification: Stay Alert


First, familiarize yourself with the common warning signs of scams mentioned earlier, and always maintain a healthy degree of skepticism. Remember, there's no such thing as a free lunch. Any investment opportunities promising high returns with zero risk should raise immediate suspicion.

Be alert to inconsistencies, such as:
  • A friend suddenly recommending an obscure token you've never heard of.
  • A stranger or "customer service" agent privately messaging you for passwords or verification codes.
  • A trading platform URL that looks almost identical to the official one but contains subtle differences.

These are classic red flags.

Also, follow industry news and official announcements. Many fraudulent tokens exploit the names of well-known figures or institutions. If the official channels have already denied the existence of such a project, you can safely assume it's a scam.

In short, vigilance is your first line of defense. When in doubt, pause all actions and verify directly through official channels.

3.2 Prevention: Build a Strong Defense


Once you've developed the awareness to spot scams, the next and more critical step is to actively implement preventive measures to minimize the risk from the outset.

1) Protect your private keys and account security: Never disclose your account password, verification codes, Google Authenticator codes, or wallet private keys through any non-official channel. Use strong, unique passwords for each account, and enable two-factor authentication (2FA) for an added layer of protection. Take advantage of MEXC's security features, such as binding an anti-phishing code to verify legitimate communications. Regularly update your password, review logged-in devices, and avoid logging in from public networks or shared devices to eliminate account theft risks at the most basic level.

2) Be cautious with links and QR codes: Do not open email attachments, group chat links, or URLs sent via private message from unknown sources, nor should you enter sensitive information on such pages. Always access important websites by manually typing the official domain or using saved bookmarks, rather than clicking links provided by others.

3) Isolate wallets and diversify risk: It's recommended to prepare a "small test wallet" for interacting with new dApps or suspicious websites. This wallet should only hold a minimal amount of funds, while your main assets remain stored in a secure wallet. Once you've confirmed that the transaction process and fund flows are correct, you can proceed with larger trades. This approach helps protect against losses caused by contract vulnerabilities or counterfeit tokens. Additionally, regularly use tools such as Etherscan's Token Approval Checker, SlowMist, or Scam Sniffer to review and revoke unnecessary long-term contract approvals, preventing malicious contracts from exploiting permissions.

4) Reduce trading and investment risks: First, always verify the authenticity of any token. Before purchasing a new token or participating in an airdrop, check whether the project is listed on major exchanges such as MEXC, or confirm that the contract address provided in official announcements is legitimate. Exercise extreme caution with high-risk products such as liquidity mining or staking programs that promise annualized returns in the hundreds or thousands of percent. Choosing a secure and reputable trading platform like MEXC, and fully understanding the project's background and risk disclosures, is a key step in minimizing investment scam exposure.

3.3 Mitigate Losses: Take Immediate Action


If you realize you've been scammed, or even suspect fraudulent activity, act decisively to mitigate further losses. Immediately cut off all contact with the scammer; do not take chances by sending additional funds or sharing more information. If the compromised assets are still in your own wallet, withdraw or transfer them to safety without delay, and replace any exposed seed phrases or private keys.

If the incident involves an exchange account and the stolen funds have not yet been fully withdrawn, contact the exchange's customer service immediately to request an account or asset freeze. In some cases, if the scam proceeds have flowed into centralized platforms or well-known stablecoin contracts, reporting quickly can prompt those entities to freeze suspicious funds.

Important: Do not fall for so-called "fund recovery services." Many individuals on social media posing as blockchain tracing experts are in fact running secondary scams. The only reliable avenues for action are filing an official police report and working with the exchange service team. Even if it's not possible to recover all losses, documenting the incident and reflecting on the experience will strengthen your defenses and help prevent future victimization

Summary


Overall, MEXC has built a comprehensive anti-fraud defense system through a combination of technological safeguards (AI-driven real-time monitoring, account protection), operational measures (abnormal transaction interception, freezing of suspicious assets), and user education (security guides, community awareness campaigns). These efforts create a fairer, more transparent trading environment.

At the same time, users must take primary responsibility for safeguarding their own assets. By enhancing security awareness and following the “Identify, Prevent, Mitigate" strategy, they can dramatically reduce exposure to risk. Every extra layer of caution cuts the odds of falling victim to a scam. With robust platform protection and vigilant user behavior, most fraudulent schemes can be detected and neutralized early.

Looking ahead, as scam techniques grow more sophisticated, exchanges are expected to further upgrade their defenses. For example, combating AI-generated scams and identity impersonation may involve integrating advanced KYC verification tools such as biometric authentication and behavioral pattern analysis. Ultimately, only through close cooperation between platforms and users can we build a strong, enduring security framework that enables safe trading and long-term, steady investment growth.

Disclaimer: This material does not constitute advice on investments, taxes, legal matters, finance, accounting, consulting, or any other related services, nor is it a recommendation to buy, sell, or hold any assets. MEXC Learn provides information for reference only and does not constitute investment advice. Please ensure you fully understand the risks involved and invest cautiously. All investment decisions and outcomes are the sole responsibility of the user.

市场机遇
SynFutures 图标
SynFutures实时价格 (F)
$0.003792
$0.003792$0.003792
+1.52%
USD
SynFutures (F) 实时价格图表

热门新闻

查看更多
Coldcard Mk3 警告紧随 3800 万美元 Bitcoin 被扫荡事件,但原因仍未确认

Coldcard Mk3 警告紧随 3800 万美元 Bitcoin 被扫荡事件,但原因仍未确认

比特币硬件钱包制造商Coinkite已警告用户,Coldcard设备存在种子生成问题,影响从4.0.1版本起的所有Mk3固件版本。该警告是在安全研究人员调查一起涉及594.48 BTC(约合3,800万美元)的协同转移事件时发出的。然而,目前尚无公开的技术证据证实Coldcard的问题导致了这些转账。

Bitget 将退出日本:面向日本居民的服务将于 2026 年 12 月 31 日终止

Bitget 将退出日本:面向日本居民的服务将于 2026 年 12 月 31 日终止

Bitget 将于 2026 年 12 月 31 日终止对日本用户的服务。受影响的用户必须在截止日期前平仓并提取资产。

万事达完成对BVNK的收购,交易金额高达18亿美元——稳定币进入全球支付核心

万事达完成对BVNK的收购,交易金额高达18亿美元——稳定币进入全球支付核心

万事达于2026年8月3日完成了对稳定币基础设施提供商BVNK的收购,此前已于三月宣布该交易。

DEX对CEX现货交易量比率达24%,中心化交易所活动减弱

DEX对CEX现货交易量比率达24%,中心化交易所活动减弱

根据 The Block 的当前数据系列,2026年7月,去中心化交易所现货交易量与中心化交易所现货交易量之比达到24.14%。该数字并不意味着 DEX 控制了合并现货市场的24.14%:它意味着 DEX 交易量相当于数据集中包含的 CEX 交易量的24.14%。与此同时,DEX 现货交易量环比下降约26%,至约1307.7亿美元,为近两年来最低水平。

相关文章

查看更多
MEXC 可用和受限国家/地区说明

MEXC 可用和受限国家/地区说明

MEXC 致力于为用户打造一个便捷高效安全的交易平台,助力全球加密爱好者探索加密世界。同时 MEXC 坚持最高标准的监管合规性,以负责任的态度履行对用户的承诺,积极为区块链行业的可持续发展贡献力量。您可以通过我们的用户协议,阅读查看当前受限的国家/地区,确认自己所处区域是否支持使用 MEXC 服务。1. 禁止使用的国家/地区名单目前,MEXC 不向以下国家/地区提供服务,也不接受用户注册或交易申请

如何识别短信钓鱼

如何识别短信钓鱼

短信钓鱼是一种利用短信(SMS)作为媒介进行的欺诈行为,旨在窃取用户的敏感信息(如钱包私钥、登录凭据)或骗取加密货币资产。这种钓鱼行为通常通过伪装成可信赖的实体(如交易所、钱包服务商或政府机构)来诱骗受害者。1. 常见的短信钓鱼类型1.1 伪装成交易所的钓鱼链接骗子发送一条短信,声称来自知名交易所(如 MEXC 等),并附上一个链接。短信内容可能会警告用户账户有异常活动,需要立即登录。点击链接后,

貔貅币防范指南

貔貅币防范指南

加密货币交易新兴项目和币种层出不穷,由于潜在的高收益特点,对投资者来说同时隐藏着巨大风险。“貔貅币”这一说法,主要是投资者用来调侃那些只进不出、无法提现或流动性极差的加密货币的形象化称呼。在这个快速变化的市场中,了解“貔貅币”的特征和风险,成为每个投资者的必修课。1. 什么是貔貅币貔貅币(Honeypot Token)通常被用来形容那些具有“只进不出”特性的加密货币或项目。它通常有以下几类情况:无

什么是网络钓鱼攻击?

什么是网络钓鱼攻击?

在加密货币交易市场中,网络钓鱼攻击是一种常见的欺诈手段,攻击者通过伪装成合法的加密货币平台或客服提供虚假务,诱骗用户提供敏感信息,如登录凭据、私钥或财务信息。1. 网络钓鱼攻击类型伪造网站:创建与合法交易所或钱包极为相似的网站,诱导用户输入信息。虚假电子邮件:发送看似来自官方机构的邮件,要求用户点击链接并输入个人数据。社交媒体骗局:在社交平台上冒充可信的交易平台或个人,诱骗用户泄露信息。2. 网络

注册MEXC账号
注册 & 获得高达10,000 USDT奖金
你的华尔街DNA是什么?
你的华尔街DNA是什么?你的华尔街DNA是什么?
6种投资人格测试,100%中奖——$30,000等值NVDAX等你来拿!

加入 MEXC 社区

通过我们的官方 Telegram 频道,实时获取最新上币、活动和动态。

25k+ 位成员