Web3 brings ownership, transparency, and open markets — but it also brings new forms of scams that many users have never encountered in traditional finance. As the space grows, attackers are becoming more sophisticated, using psychological tricks and technical exploits to target both beginners and experienced users.
Below are the four most common Web3 scams, how they work, and real examples to make them easier to recognize and avoid.
1. Airdrop Phishing — “Free Tokens” That Cost Everything
Airdrop phishing exploits the excitement around token giveaways.
Scammers impersonate real projects, claiming users are eligible for an airdrop. To “claim,” users are directed to connect their wallet to a fake website.
Once connected, the site typically asks users to:
-
sign malicious signatures
-
send gas to activate a fake “claim”
-
authorize a transaction that drains assets
Real Example:
In 2024, thousands of users received fake “Blast Airdrop Claim” links on Twitter.
Users who clicked were asked to sign a seemingly harmless signature that actually granted attackers full control over their wallets. Many lost their ETH instantly after signing.
How to stay safe:
Legitimate projects never DM users a “claim link.”
Always verify announcements on official channels only.
2. Malicious Contract Approval — The Silent Asset Drain
This is one of the most dangerous Web3 scams because users lose funds without sending any transaction.
Scammers trick users into approving a malicious smart contract.
Once approved, the contract can:
-
transfer NFTs
-
drain ERC20 tokens
-
move assets without further permission
Real Example:
A popular case involved fake “token swap tools” that offered users “cheaper gas.”
When users approved the contract, the tool quietly obtained unlimited spending approval for USDT and USDC. Days later, attackers drained the tokens directly from users’ wallets while they were offline.
How to stay safe:
If a site asks for an “Unlimited Approval,” pause and verify.
Use on-chain scanners to check contract reputation.
3. Fake Wallet Apps — Stealing Keys Before You Notice
Fake wallets appear in app stores, search engines, or third-party download links.
These apps look identical to trusted wallets but:
-
record your seed phrase
-
transmit credentials to attackers
-
drain funds the moment you deposit assets
Real Example:
A fake version of MetaMask circulated on Google Play in Southeast Asia.
The interface was flawless — but it sent users’ seed phrases to a private Telegram server.
Hundreds of wallets were emptied within seconds of deposit.
How to stay safe:
Only download wallets from official websites or verified app store publishers.
Never install wallets shared by “friends,” YouTubers, or Telegram links.
4. Fake Telegram Bots — An Emerging Threat in Web3 Communities
Telegram bots are widely used for trading, wallet notifications, and airdrop management.
Scammers now create bots that:
-
mimic real project bots
-
request users to “verify wallet ownership”
-
ask for seed phrases
-
request on-chain signatures
Real Example:
A fake “TON Staking Bot” spread across multiple channels in 2024.
Users were told to connect their wallet via a bot link to “activate staking rewards.”
The bot redirected them to a cloned staking site that collected seed phrases.Losses exceeded millions.
How to stay safe:
No official bot will ever ask for your seed phrase.
Never trust a bot link forwarded by strangers or new accounts.
5. Address Poisoning — When “Copied Addresses” Betray You
Address poisoning exploits user habits rather than smart contracts.
Attackers send small transactions from an address that closely resembles one you’ve previously used.
When you later copy an address from your transaction history, you may unknowingly copy the attacker’s address instead of the legitimate one.
Because blockchain addresses are long and unreadable, most users only check the first and last few characters — exactly what attackers manipulate.
Real Example:
In 2024, multiple high-value Ethereum users reported losses after copying recipient addresses from their wallet history.
Attackers generated addresses with matching prefixes and suffixes, sent tiny “dust” transactions, and waited.
When victims reused the address from history, funds were sent directly to the attacker — permanently.
How to stay safe:
Never copy addresses from transaction history.
Always verify the full address or use address whitelists and ENS names.
6. Dusting Attacks — Small Transfers with Big Consequences
A dusting attack starts with tiny, seemingly harmless token transfers.
Attackers send small amounts of tokens (dust) to thousands of wallets.
These tokens may:
-
contain malicious contract hooks
-
be linked to tracking systems
-
lure users into visiting phishing sites
In some cases, interacting with the dust token — even attempting to swap or burn it — triggers malicious approvals or wallet drains.
Real Example:
Users received tiny amounts of unknown tokens labeled as “rewards.”
When attempting to swap them on a DEX, users unknowingly approved malicious contracts that drained their main holdings.
How to stay safe:
Ignore unknown tokens.
Do not interact with unsolicited assets.
Hide or blacklist suspicious tokens in your wallet interface.
7.Remaining vigilant is an essential survival skill in Web3.
Though these scams may appear deceptively simple, the losses they inflict are staggering.
According to multiple on-chain security reports, over the past year:
– Losses from hacking, phishing, and fraud exceeded RMB 21 billion in 2024
– Phishing and social engineering scams alone caused losses amounting to hundreds of millions of RMB
Police forces across multiple nations disclosed that crypto-related frauds account for approximately 20%–25% of national fraud losses
Although the median loss per case is relatively small, over 70% of total losses stem from instances involving the theft of substantial assets
These figures illustrate one crucial point:
Web3 scams are not rare occurrences but represent a core security threat facing the entire industry.
It is precisely for this reason that the existence of professional custodial institutions becomes paramount.
In an industry where scams inflict billions in annual losses, GDC delivers what self-custody cannot:
Regulatory-backed secure custody, professional risk management, and genuine peace of mind.
Leveraging a licensed trust structure, institutional-grade security technology, and systematic management processes, GDC effectively mitigates common Web3 risks including phishing, malicious contracts, fake wallets, and fraudulent bots.
About us
Global Digital Custody Limited (GDC) is a leading digital asset custodian dedicated to providing the most secure, compliant, and trustworthy solutions for the digital asset economy.
As the exclusive agent of the licensed trust institution Hong Kong Trust Capital Management Limited (HKTCM), GDC provides digital asset custody services. This institution holds a Hong Kong Trust License (registered under Section 78(1) of the Trustee Ordinance (Chapter 29 of the Laws of Hong Kong); approved and directly regulated by the Financial Secretary of Hong Kong). We are committed to providing reliable digital asset custody services for clients requiring highly secure, compliant, and dependable professional services. Leveraging the licensed institution’s extensive resources, global network, and expert team, we rigorously promote HKTCM’s digital asset custody services through strict regulation and systematic management.
