How to Spot a Crypto Scam: Rug Pulls, Fake Airdrops and Wallet Drainers
Crypto scams look endlessly varied and are structurally quite few. Almost everything that takes money from people is one of four things: a token whose liquidity can be removed, a contract approval that lets someone spend your balance, a fake version of something real, or a person who gains your trust over weeks before mentioning an investment.
Knowing the shapes matters more than memorising names, because the names change every cycle and the shapes do not. Below is what each one looks like, the checks worth doing before you connect a wallet, and what to do if you have already signed something.
Table of Contents
The four shapes
A rug pull is a token whose creators keep the ability to withdraw the pooled liquidity, or to mint more supply, or to block selling. Buyers can get in and the price rises. Then the liquidity is pulled and the chart goes vertical downward, because there is nobody left to sell to.
A wallet drainer takes nothing by force. It persuades you to sign a transaction that grants a contract permission to move your tokens, and then it moves them. The signature usually arrives disguised as a claim, a mint, a verification or an airdrop, and the damage happens later, sometimes days later, which is why people fail to connect the two events.
Checks that take two minutes
- Check whether liquidity is locked and for how long. Block explorers and token scanners show this. Unlocked liquidity, or a lock expiring next week, means the team can withdraw the pool whenever they choose.
- Look at how the supply is distributed. If a handful of wallets hold most of the tokens, the price on screen is decoration. Those holders decide what happens, and they can exit into your buying at any moment.
- Read the contract permissions, or at least run the address through a scanner that does. Functions that can pause transfers, change fees after launch, or blacklist addresses are not bugs. They are the mechanism.
Red flags that repeat every cycle
None of these is proof on its own. Two or more together is usually enough to walk away.
- A guaranteed return. Nothing in markets is guaranteed, and the word is essentially a confession. Fixed daily percentages are the same claim wearing a smaller number.
- Pressure to act now. Countdown timers, closing allocations, a bonus that expires. Urgency exists to stop you doing the two-minute check, which is the only thing standing between the scammer and your wallet.
- A team that cannot be verified. Anonymous is not automatically fraudulent, but a team with stock-photo faces, borrowed LinkedIn histories or advisors who have never heard of the project is a specific and deliberate lie.
- A link that arrived instead of one you went looking for. Almost every drainer reaches people through a direct message, a reply under a popular post, or a sponsored search result. Typing the address yourself removes most of this category at once.
Habits that prevent most of it
1. Separate your wallets
Keep long-term holdings in a wallet that never connects to a website, and use a second wallet with small balances for anything interactive. This does not make you harder to fool. It makes being fooled survivable, which is a more realistic goal.
2. Review and revoke approvals
Token approvals do not expire. A permission you granted to a dapp two years ago is still live, and if that contract is later compromised the permission is what gets used. Revoke anything you no longer use, and prefer approving an exact amount over an unlimited one wherever the interface offers the choice.
3. Slow down the ones that feel urgent
Every scam is built on the assumption that you will not pause. Making it a personal rule to wait an hour before signing anything that arrived unsolicited costs you almost nothing over a year, because real opportunities are almost never destroyed by sixty minutes. The ones that are were never opportunities.
If you have already signed something
- Move the remaining funds first, to a wallet whose seed phrase has never been typed into anything. Revoking takes time and the attacker does not wait.
- Revoke the approval afterwards, through a revocation tool for that chain. Moving funds does not cancel a permission, and the permission still applies to anything you send back to that address later.
- Assume the wallet is compromised if you entered your seed phrase anywhere at all. An approval can be revoked; a leaked seed phrase cannot. That wallet has to be abandoned entirely.
- Ignore anyone who offers to recover the funds for a fee. Recovery services that contact victims are the second scam that follows the first, and they work because people who have just lost money want very badly to believe.
Watching your own positions instead of a chat group
A lot of bad decisions start with needing information fast and getting it from whoever replies first. Having your own alerts on the assets you hold removes that dependency. TradeSlayers sends price and indicator alerts to WhatsApp, so the thing that tells you a position moved is a system you configured rather than a stranger with a link.
Where that leaves you
You do not need to identify every new scam. You need a small number of habits that make the common ones fail: a separate wallet for anything interactive, approvals reviewed and revoked, links typed rather than clicked, and an hour of delay on anything that arrived uninvited. None of that is sophisticated, and together it removes the large majority of the risk.
Frequently Asked Questions
Can a rug pull happen to a large, well-known token?
A classic liquidity rug is much harder once a token trades on major exchanges with deep independent liquidity, because no single party controls the pool. Large projects fail in other ways instead: insider selling, failed treasuries, exploits. Size reduces one specific risk, not risk generally.
Is it safe to connect my wallet to a website?
Connecting on its own only shares your public address, which is already public. The risk begins at the next step, when you are asked to sign something. Read what the signature grants rather than the label on the button, and be most careful with requests for unlimited spending permission.
Are tokens that appear in my wallet unprompted dangerous?
Holding one harms nothing. Interacting with one can. These dust airdrops exist to make you visit a site to sell or claim, and that site is where the drainer lives. Leave them alone, hide them in your wallet interface, and never approve anything to dispose of them.
Take Your Trading to the Next Level
Build your trading edge with automation, smarter execution, and practical risk controls.