The Seven Most Common Ways People Lose Crypto
Ranked by how often they happen rather than by how dramatic they are. Only two of the seven involve anyone being hacked.
Priya Raman · 2 min read
Most crypto losses are not hacks. They are ordinary mistakes and ordinary confidence tricks, and the ranking below reflects how often each one actually occurs rather than how much coverage it gets.
1. Approving a malicious contract
You connect a wallet to a site and sign what looks like a routine permission. Nothing happens immediately. Days or weeks later the tokens are gone.
You were not hacked. You granted a contract permission to move your tokens, and it eventually did. Many interfaces request unlimited approval by default, and approvals do not expire.
Defence: read what you are signing, prefer limited approvals, and revoke old ones periodically. Every major block explorer has a revocation tool.
2. Fake support
You post a question publicly. Within minutes someone with a support-looking account replies. They are patient, technically accurate about small things, and eventually need your recovery phrase or send you to a validation site.
Defence: one absolute rule, admitting no exceptions. Nobody legitimate ever needs your recovery phrase. Real companies do not send the first direct message.
3. Losing access to your own wallet
No attacker involved. A recovery phrase written down wrong, stored somewhere that flooded, or protected with a passphrase that was never documented.
This is the category people prepare for least and it is one of the largest.
Defence: write the phrase legibly, verify it word by word, store it away from the device, and test a restore before funding.
4. Sending to the wrong address or network
A transaction to a mistyped address, or the right address on a network the recipient is not watching. Irreversible either way.
Defence: send a small test amount first, every time. Check the network selector before the address, since wrong-network errors outnumber typos.
5. Investment platforms that stop paying
A platform offering a fixed return. Withdrawals work for months, which is what persuades people to add more. Then they stop.
The return was paid from new deposits.
Defence: ask where the yield comes from until you get a mechanism rather than an adjective. Legitimate venues such as Collect & Exchange quote a price and a fee, not a guaranteed return.
6. Buying a token that cannot be sold
The contract permits purchases and blocks sales, or the creators hold the majority of supply and sell into the buying.
Defence: check supply concentration and liquidity locks on a block explorer before buying. Both take two minutes.
7. Exchange or custodian failure
The platform holding your coins stops honouring withdrawals. This is rarer than the coverage suggests and larger in impact when it happens.
Defence: use regulated venues, and do not leave long-term holdings anywhere you do not hold the keys.
The pattern
Five of the seven require you to take an action: to sign, to send, to type, to deposit. That is good news, because an action can be interrupted by a habit.
The habits that prevent most of this list are: send a test transaction, never type a recovery phrase anywhere you did not navigate to yourself, and assume anyone who contacts you first is not who they say they are.
Move any remaining funds to a wallet with a newly generated seed phrase before anything else. Then revoke token approvals, and report the incident to your local authorities and the exchange involved. Do not pay anyone who promises to "recover" your coins. That is a second scam, aimed at victims of the first.