Normal view

AliExpress accused of fingerprinting shoppers with silent audio trick that also muted a dev's headphones

24 August 2026 at 12:32
Developer Matt Callaghan claims he caught Alibaba's B2C website, AliExpress, trying to track web users by playing sounds through browsers vulnerable to audio fingerprinting. The software engineer drew attention to the issue late last week after investigating why his Bluetooth headphones stopped playing music whenever he visited the AliExpress website. “Recently I ran into a strange problem with my Bluetooth headphones,” Callaghan wrote. “They support multipoint Bluetooth audio, so they can be connected to my PC and phone at the same time. Normally, the PC takes priority playing audio, with my phone being able to play audio when nothing is playing on the PC. “Usually I listen to music on my phone but with notifications or YouTube playing through the PC, this works reliably until I open an AliExpress page in Firefox or Chrome. “Shortly after loading the AliExpress homepage, audio from my phone would stop playing. Closing the AliExpress tab fixes it immediately. Muting the tab/Firefox/Windows does not help, and there is no visible video, music, or other media playing on the page.” Callaghan tried to find any hidden conventional media elements but found nothing. Further digging revealed two audio scripts that he said were “extremely obfuscated” within AliExpress's browser security and anti-abuse tooling. He said the scripts built a WebAudio graph that introduced a sawtooth oscillator to generate a waveform, an analyzer to measure the result after the waveform passes through a browser’s audio implementation, and a script to read the associated frequency data. The scripts set the audio’s gain to zero, meaning the end user won’t hear anything, but the WebAudio graph will still be processed by the browser. “This is very different from an autoplaying video,” said Callaghan. “There is no media element for the browser's normal tab mute control to stop. As far as the page is concerned, it is performing live audio processing. “In my case, that appears to have been enough for Firefox or Windows to keep the Bluetooth audio path active, preventing my multipoint headphones from switching cleanly back to the phone.” Callaghan found further evidence in the code looking for data related to screen dimensions, device memory, browser plugins, WebGL rendering, mouse events, and more. As well as signs that AliExpress is encrypting data and sending it to its telemetry services, the developer said all of it amounts to “a fairly comprehensive browser and device fingerprint.” The Register has asked Alibaba to comment. Despite Callaghan saying he could reliably reproduce this issue on both Firefox and Chrome, Firefox issued a Xtatement saying its anti-fingerprinting technology thwarts AliExpress’ tracking tricks. It pointed to a blog post from Tom Ritter, a security engineer on the Firefox team, who explained that as of version 118 (September 2023), the protections it introduced eliminated the efficacy of WebAudio-based fingerprinting. These protections are not designed to stifle fingerprinting efforts at the source. Instead, they work to group all users together, making it look like all fingerprinted users are the same, effectively nullifying the tracking attempts. For 99.24 percent of users, they fall into one of three “buckets” – user categories delineated by types of hardware. The vast majority fall into buckets one and two: Bucket one: x86/x64 CPUs lacking FMA (Fused Multiply-Add) instructions Bucket 2: x64 CPUs with FMA instructions And for the remaining 0.76 percent, the fingerprinting script failed entirely, according to Firefox’s data. However, Ritter said there are 48 users worldwide who do not fall into the three buckets, or the 0.76 percent whose machines did not allow the scripts to run. These 48 users fell into 23 other minuscule buckets, which means they are not grouped into the masses like the rest, and so fingerprinting is more effective on this vast minority of users. “This is very unfortunate, as it makes these users completely unique, but it is also not terribly unusual - computers are weird and these results could have been caused by bad RAM, a CPU bug, or possibly some crazy architecture (LoongArch??),” said Ritter. “But at the end of the day, WebAudio fingerprinting is nearly useless. I don't expect browser fingerprinting to disappear from websites entirely (unless some regulatory action occurs, fingers crossed) - it's still going to be effective against a majority of users on the web, but at least for privacy-focused browsers, it should be wildly less effective.” Brave, maker of the eponymous privacy-centric browser, also Xeeted a response to Calalghan’s findings, saying it has protected users from fingerprinting for six years. “Brave injects random data into the browser's output so you show a different fingerprint to different sites. This fingerprint also resets across sessions. “For added protection, we also block the specific scripts used by AliExpress for the tracking method mentioned above. Again, this is done by default for all Brave users. You don't have to change any settings to be shielded from this audio fingerprinting.” Ritter said Chrome and Safari “probably have defenses against this [brand of fingerprinting].” Safari deploys Advanced Tracking and Fingerprinting Protection to prevent WebAudio-based tracking and other methods of fingerprinting. It works differently to Firefox, though, injecting audio errors into an audio buffer, instead of trying to lump all users into an identical bucket. Chrome, on the other hand, does not aggressively protect users from fingerprinting, as privacy consultant Alexander Hanff said earlier in the year. "There are at least thirty distinct fingerprinting techniques that work in Chrome right now, today, as you read this," he wrote. "Not theoretical attacks from academic papers that might work under laboratory conditions – real, production techniques deployed on millions of websites to identify and track you without your knowledge or consent." ® Updated 08/25 at 1805 GMT to clarify the behavior was observed on AliExpress, which is Alibaba's B2C web site for small-scale purchases.

Security vets rally around $4 paper password books for sale in Australia

24 August 2026 at 10:17
Are you sick and tired of maintaining a password manager? Struggling with choosing the right one for you? Well, readers who live Down Under can get themselves down to their local AusPost branch where they can pick up an old-school alternative for just AU$4.90 (US$3.51). Password books are something of a historical relic, phased out largely because of the scrutiny associated with using one and the now-gray-haired elders who once scoffed at the mere notion of such an opsec crime. They might not be able to suggest a strong password for each of your many online accounts, and they won’t do you much good if your house is burgled, but you could argue that there is still value to be found in a pen-and-paper password vault. That’s exactly the conclusion drawn by the thousands of social media users who flocked to a post this week from one Australian who found stacks of password books for sale in their local post office. Small books are priced at AU$4.90 (US$3.51), while larger options will set you back a dollar extra. Granted, there are myriad issues associated with relying on a physical document for digital account security. For one, it’s a single point of failure. Lose the book or have it stolen, and it’s a painful road to restoring access to all your accounts. One could argue that if it’s kept inside the home and it’s stolen, then you’ve got bigger problems on your hands, but perhaps that’s not as true nowadays, when so many of our valuables are either stored or primarily accessed online. That said, it might bring a quick end to a hostage scenario – the type that is becoming all the more common as crypto wealth becomes increasingly common. Password books are also not as easily manageable as a modern password manager. The technological equivalent can auto-fill credentials, auto-update them if they’re found in public breaches, and suggest unique, strong strings to minimize the risk of compromise. You can’t store a passkey in a password book, either – a major issue now that the world is transitioning toward the new authentication standard. But using a password book no longer carries the same stigma as it once did among infosec types. The general consensus, gleaned from the hundreds of social media comments on the post, now seems to be that there's little wrong with storing passwords on paper at home. It’s certainly more secure than reusing the same weak password across multiple accounts, provided the book contains strong strings unique to each website. With the prevalence of infostealers nowadays, it's far more likely that crims will use a weak, reused, seldom-changed password to break into an online account than burgle a house to gain access to someone’s online banking. Plus, as many pointed out, it’s a much better route than writing passwords in a cloud document, which can be accessed by any device that has access to it – think Apple Notes, Google Docs, etc. At work, though, it’s probably best to stick to the password manager, the IT guys say. Mistakes by staff working at even the lowest rungs of the corporate ladder could lead to multimillion-dollar cyberattacks should that password book fall into the wrong hands. Pentesting consultants often send hired white hats to breach a company’s office and extract whatever value they can, sometimes through piss corridors. Such access can lead to malicious USB sticks dropping malware, bugs planted near the water fountain, and even someone stealing the password book from your desk drawer. Don’t believe it’s real? Security consultant Alethe Denis told us two years ago that’s exactly how her pentest team was able to surreptitiously extract corporate data over a company’s own Wi-Fi for over a week. They went dumpster diving, got the Wi-Fi creds, walked straight into a conference room, and deployed a data-stealing implant. In and out, all using physically stolen secrets. Helpful in the worst of times So, yes, password books contain plenty of potential pitfalls, Poignantly, however, they often prove invaluable in the event of a loved one’s passing. Having access to a password book, or at least some sort of plan to share passwords in the event of a death, is vital to ensuring family and friends have space to grieve without going through the arduous process of recovering an account through a platform provider, or via the courts. A slew of Redditors agreed, saying it made the whole process so much easier. One shared the tale of how their mother’s own special way of storing passwords resulted in a treasured family investigation. After password books spent years as outcasts of the cybersecurity world, they’re now having a second moment in the sun. And while the leading minds in cybersecurity are busy working on ways to stop phisherfolk from hacking into your accounts, or rogue AI agents from doing the same, there’s still something to celebrate in the safeguards of yesteryear, both in life and death. ®

If you're not using AI to attack your own systems, your adversaries will

22 August 2026 at 15:02
AI agents excel at hacking organizations, as they’ve demonstrated in real-life attacks multiple times over the past few weeks. They also expose a whole new attack surface for organizations trying to protect against both human and AI intrusions. As if defenders needed more worries to keep them up at night, agents introduce new data-integration channels that attackers can abuse. They also introduce a new type – and ever growing number – of non-human identities that are difficult to manage and can bypass traditional, static security policies. “There is tremendous risk associated with agentic AI and machine identities,” Matt Hartman, former acting head of cyber of the US Cybersecurity and Infrastructure Security Agency (CISA), told The Register. “As AI moves from generating content – yesterday's use case – to taking actions, it is inevitable that agents are going to receive access to sensitive systems and sensitive data,” Hartman said. “One area where organizations are struggling today is that they're going to need to treat every agent as a privileged identity.” Enterprises also face agentic threats from outside their organization, he added. “AI-enabled or AI-amplified identity and social engineering attacks are increasing significantly by the minute,” Hartman said. “We're seeing very highly personalized phishing, very good impersonation, automated reconnaissance. That really makes traditional indicators of trust increasingly unreliable.” For defenders, this means a “continued focus on strong identity, on phishing-resistant authentication, on behavioral signals, and on zero-trust principles therein,” he added. “Nothing deeply new here - but it is a whole new attack surface.” Meanwhile, on the attackers’ side, agents don’t take time off, and they remain singularly focused on completing a task, whether that’s finding vulnerabilities and exploit chains or mapping networks and identifying sensitive files. All of this makes these near-autonomous attack bots a gift from the heavens for financially motivated criminals and government-backed cyber operatives. It also presents a security use case for defenders: agentic red teaming. As former NSA cyber boss Rob Joyce said during a talk at RSAC: if you aren’t using AI agents to attack your own organizations, you can bet that someone else is. “You are going to be red-teamed whether you pay for it or not,” Joyce said. “The only difference is, you know who gets the results delivered to them.” Hartman echoed Joyce’s words. “What we are seeing as the leading capabilities to help defenders – there is a burgeoning market for continuous, AI-native, AI-enabled, automated red teaming and pen-testing,” he told us. After spending nearly two decades in the federal government at CISA, Hartman joined Merlin Group in October as its chief strategy officer. In his new private-sector role, he helps determine which early- to growth-stage cybersecurity and emerging technology companies the group invests in, and then works with these firms to navigate government, critical infrastructure, and other highly regulated markets. The goal is to integrate and scale “promising technologies” into critical environments, Hartman said. Right now, most of these technologies use AI agents to fight AI agents. “Organizations are just inundated with vulnerabilities, and adversaries are able to leverage AI to find vulnerabilities and exploit them in seconds when it used to take days,” he said. Agentic red teaming “is a category of products that every organization, including federal agencies, absolutely needs in the near term just to keep pace.” 'Largest controlled live AI cyberattack on record' Mandiant founder and former CEO Kevin Mandia has a new company, Armadin, which launched in March with a startling $190 million in seed and Series A funding. The firm builds and trains autonomous attacker swarms – thousands of AI agents that run 24/7 in organizations’ infrastructure to simulate real-life attackers. Ahead of Black Hat earlier this month, the startup said it and Tenex.ai, an agentic security operations provider, executed what they called the “largest controlled live AI cyberattack on record” for an unnamed “leading” global institution. Over the three-day attack, Armadin's swarm generated 17 million offensive actions, discovered 38 validated attack paths, and produced 238 security findings. Tenex.ai's agentic platform separately triaged 100 percent of 101,169 alerts and reconstructed the entire attack across 231 billion raw events. This exercise, we’re told, would have taken a five-person analyst team about 2,400 hours – or four months – to pull off. Co-founder and Chief Offensive Security Officer Evan Peña was the global red-team lead at Mandiant before co-founding Armadin. At Mandiant, he led a 210-person team whose members spanned the globe. “The problem was it was 100 percent human-led security assessments, and that would generally limit the amount of time that we would have,” Peña told The Register. His red team “would do a couple weeks or a one-month engagement, and then we would report on the engagement, give them a PDF file, walk away, and they would hire us again in a year. In today’s age of AI, it’s very archaic to think about that when we can scale so significantly with AI.” Attack yourself before someone else does At Armadin, Peña leads the human team that trains the AI agents. One of the lessons learned from OpenAI’s models autonomously attacking Hugging Face, according to Peña, is that organizations need to perform safe offensive AI attacks against their own systems. "Safe" is the keyword here: remember OpenAI’s rogue models intentionally didn’t have any guardrails in place. Yes, his statement is self-serving as it's core to Armadin's business. But he’s not wrong. “Organizations can cover so much more attack surface because we are able to leverage these agents at scale, and we have three things that we didn’t have before,” he said. “We have more time, because agents don’t sleep and they don’t take holidays. There’s no workforce requirements for them.” Number two, he said, is expertise. Attack agents need pre-training before they are set loose on organizations’ infrastructure. They need to know how to code, and perform source-code review. They need to know how to do application security, how to spot network misconfigurations, and hack into different systems and networks. “And then you add post-training to that from human expertise,” Peña said. “Number three is coverage,” he said. “We were only able to cover a finite amount of attack surface in the past. So if you had 10,000 external systems with a limited amount of time and humans, you could maybe cover 2,000 or 1,000 of those within that particular period of time. Now we can cover all 10,000 in probably hours.” Armadin’s AI agents have broken into every single customer’s environment, according to Peña. “We have found over 50 zero-days, and by zero-days, I don't just mean this zero-day allowed you to deface a web page. That’s cool, but I want to break into your network from the internet,” he said. “The zero-days I'm referring to allow an attacker to get remote code execution on an actual system. They're very high-impact zero-days. We don't care about noise, we care about impact.” Quarterly pen-testing doesn't cut it anymore The biggest challenge these days for defenders is the scale and speed AI brings to previously manual attackers’ dirty work – like scoping potential victims, performing reconnaissance, identifying vulnerable systems and exploits, and reading logs. Now all of these tasks can be automated. Penetration testing needs to keep up, Jay Bavisi, founder and group president of EC-Council, told The Register. The largest and best organizations do pen-testing once a year to meet compliance requirements, and “the better ones” run these exercises quarterly, Bavisi said. This is largely because human-led pen-tests take about three months. “So you have a serious problem with speed,” he said in an interview. “Then comes the second problem, which is scope. Nobody pen tests the entire organization.” There’s also what Bavisi calls a “sophistication problem,” because different human pen-testers will produce varied results, and organizations can’t hire hundreds of thousands of humans to try to break into their networks on a continuous basis. “The bad guys are already using AI to get rid of the speed problem. You pen-test once a year for compliance. They do it all the time because you're a gold mine. They don't have a scope problem because they're not just looking at the crown jewels - they're looking at your entire organization. And they don't have a sophistication problem because they're using algorithmic systems.” In June, the global cybersecurity training organization began offering pen-testing professionals a sponsored attempt to take the CPENT AI examination, and upskill themselves for the AI era. For every participant who passes, the council donates $1,000 in cybersecurity training and certification credits to nonprofit partners. For every completed training program, regardless of an exam pass or fail, the nonprofits get $250, and all of this has a $1 million max. “The traditional model of pen-testing once a year or once a quarter, that’s going away, and AI will take over with automated pen-testing,” Bavisi said. “But will the role of pen testers vanish? No, it will not. It will evolve into something much bigger and something far more important.” AI systems and AI-integrated applications mean there’s a lot more for security professionals to try to break and break into, and humans need to determine: What is the result of this system breaking? What’s the business impact? What do I prioritize fixing? “The present pen-testers have to be reskilled into understanding business impact and being able to make those important engineering decisions,” Bavisi said. Meanwhile, “offensive AI security professionals are the ones that are going to have to test the robustness of AI systems, because AI systems will become the heartbeat of organizations,” he added. “Pen-testers have to become masters of testing LLMs, understanding agentic behavior, thinking about what is the harm taxonomy, figuring out what kind of guardrails did we put in place.” The job of pen-testers has changed, in other words. “It now has a far wider scope.” ®

How to Spot a Crypto Scam: The Top Red Flags to Watch For

By: McAfee
18 July 2026 at 16:08

An old friend messages you about an incredible crypto opportunity they’ve been using, showing screenshots of impressive returns. The platform looks professional and the interface is slick, so you decide to invest a few thousand dollars to test it. Seeing your money grow daily encourages you to add more. Just when you want to withdraw your funds, the platform vanishes overnight, your friend stops responding, and you realize the entire thing was an elaborate hoax designed to separate you from your savings.

Incidents like these don’t only target tech enthusiasts or risk-seeking traders. The victims also included retirees, first-time investors, and everyday people trying to build financial security who are systematically targeted by criminal operations.

If you are considering investing in cryptocurrency, this guide will help you learn about common types of crypto fraud, recognize their warning signs, and adopt strategies to avoid falling victim to crypto-related cyber threats.

Key Takeaways

  • The 66% increase in crypto-related fraud over the previous year makes investment scams the costliest fraud category the country faces today.
  • From early, short-lived crypto scams to today’s organized criminals, months of relationship-building, professional marketing, fake trading platforms, and smart-contract manipulation are used to appear legitimate.
  • Individuals aged 60+ lost more than $2.8 billion in crypto-related scams in 2024, while people of all ages are targeted in social media, dating apps, and fake brokerage sites.
  • You can dramatically reduce your risk in crypto investments by understanding how these scams work, recognizing red flags, and following essential security practices.

What Are Crypto and NFT Scams?

Crypto and NFT scams are fraudulent schemes that exploit the unique characteristics of blockchain-based digital assets to deceive victims and steal their money or tokens. Unlike traditional financial fraud, these scams leverage the irreversible and complex nature of blockchain transactions, the lack of consumer protection mechanisms in an unregulated sector, and the fear of missing out on the next big opportunity.

Cryptocurrency is digital money that uses cryptography for security and is traded on decentralized networks called blockchains. It is digital cash that no single bank or government regulates. On the other hand, non-fungible tokens (NFTs) are unique digital certificates of ownership recorded on a blockchain, commonly used to represent digital art, collectibles, or membership rights. Being non-fungible means each token is one-of-a-kind and can’t be exchanged one-to-one like currency.

The scams targeting these assets take many forms, including fake investment platforms that display fabricated profits, fraudulent token projects where creators disappear with investors’ money, phishing websites that steal your digital wallet credentials, and long-con relationship scams. Unfortunately, transactions related to these scams cannot be reversed by calling your bank or credit card company. Once your crypto or NFTs are gone, they’re almost always gone for good.

Why Scammers Prefer Cryptocurrency and NFTs as a Payment Method

In 2024, the Federal Bureau of Investigation’s Internet Crime Complaint Center recorded 859,000+ cybercrime complaints, with total losses of $16.6 billion, a 33% increase over 2023. Of that total, approximately $9.3 billion involved crypto investments or payments, spread across roughly 150,000 complaints.

Losses from global rug-pull scams, which are phony crypto offerings that quickly skyrocket and then plunge to near worthlessness, reached nearly $6 billion in early 2025, despite a decline in incidents.

Scammers now prefer cryptocurrency as the payment method for all kinds of fraud, whether it’s for tech support, romance, phishing, or extortion scams, because it’s difficult to trace and impossible to reverse. The moment someone tells you to download a crypto wallet app or send payment via Bitcoin, Ethereum, or any other digital currency, you’re likely dealing with a criminal.

Everyone Is a Target, But Some Groups Face Higher Risk

Because of the decentralized, borderless nature of cryptocurrency, international criminal syndicates are able to operate from jurisdictions with weak enforcement while targeting victims worldwide. This problem isn’t just affecting young, tech-savvy early adopters or risk-seeking day traders. It is also affecting ordinary people worldwide, including first-time investors and victims of other types of scams across all age groups.

Individuals aged 60 and over, who lost a total of $2.8 billion in 33,000 crypto fraud incidents in 2024, face particularly severe financial impact as this amount represents their life savings, retirement funds, or money earmarked for healthcare, housing, or supporting family members. The emotional and financial devastation extends far beyond the dollar figures.

Older adults are so heavily targeted because they’re more likely to have substantial savings available to invest, may be less familiar with how cryptocurrency works, and often have more time to engage with scammers. In some cases, individuals were seeking to financially recover after recent market downturns, making high-return crypto promises particularly appealing.

Younger investors are targeted through different channels, such as social media, but the fundamental vulnerability remains the same: the promise of quick wealth and sophisticated social engineering.

The Most Common Crypto and NFT Scam Types

Pig-Butchering Investment Schemes 

Considered the most devastating category, pig-butchering scams originate from the farming practice of fattening a pig before slaughter, chillingly describing the scammer’s approach. These long cons run for months as criminals build relationships with victims through dating apps, social media, or wrong-number texts that turn into friendly conversations.

Gradually, the scammer will introduce the topic of cryptocurrency, positioning themselves as either a successful investor or someone learning from a knowledgeable mentor. Patiently, they guide the victim onto a fake but professionally designed, fully functional trading platform that shows real-time market data and walk them through making initial deposits and trades. On screen, the victim sees their account balance grow, which encourages them to deposit increasingly larger sums. Many even liquidate retirement accounts, take out loans, or sell property to invest more.

When the victim attempts to withdraw funds, the platform suddenly requires tax payments or verification fees, or threatens frozen accounts unless more money is deposited. 

If victims refuse to send additional funds, the scammer ghosts them, the platform shuts down, and they discover that no trading ever occurred. Every dollar they sent went directly into criminal wallets.

Rug Pulls in Memecoins and DeFi Projects 

Modern rug pull schemes are named for the action of pulling the rug out from under someone and leaving them shocked or helpless. One popular rug-pull method involves memecoins such as Dogecoin and Shiba Inu, which were hype-driven cryptocurrencies inspired by internet trends. Another involves DeFi (decentralized finance) projects, which offer financial services such as trading, lending, and investing outside of traditional banks. 

Both can be legitimate, but their fast-moving, lightly regulated nature also makes them prime targets for scams, especially rug pulls where creators suddenly drain funds and disappear. However, these schemes do not offer a clear utility or roadmap, relying entirely on hype, memes, and community without articulating a specific use case, technical innovation, or development path.

To build credibility before they exit, scammers might:

  1. Launch a crypto campaign with seeming transparency, using identities that are often stolen or fabricated
  2. Seed a liquidity pool that is locked for a period to demonstrate their commitment
  3. Employ obscure auditing firms that merely rubber-stamp the project without a genuine security review
  4. Coordinate with influencer networks to create viral social media buzz around the fake crypto project
  5. Use bot networks to simulate active trading and enthusiastic community discussion
  6. Gradually siphon the funds through complex smart-contract functions while maintaining the appearance of locked liquidity
  7. Finally drain the remaining funds and disappear, often blaming hackers or claiming the project was itself compromised

Phishing and Wallet-Draining Attacks

Targeting NFT holders and crypto traders, this evolving scam includes:

  • Fake mint sites and marketplace clones: Scammers create websites that look identical to legitimate NFT platforms. Victims who connect their wallets to these phishing sites and approve transactions inadvertently sign malicious contracts that drain their assets.
  • Discord and social media impersonation: Criminals compromise or imitate official project Discord servers, Twitter accounts, and Telegram groups, posting fake announcements about NFT drops or security updates that link to phishing sites.
  • Malicious wallet updates: These involve fake browser extensions, mobile apps, or email warnings claiming your wallet software needs an urgent security patch. Once you install the malicious version, attackers access your private keys or seed phrases.
  • Customer support impersonation: Scammers pose as support staff from crypto exchanges, wallet providers, or NFT platforms, asking victims to share security information or provide remote access to their computers to resolve fabricated issues.

The common thread across all these attacks is social engineering combined with the irreversible nature of blockchain transactions. Your confusion, an urgent email, one click, and your assets are gone with no way to reverse the transaction.

Crypto and NFT Scams Still Evolving

From 2020 to 2022, many of these early crypto and NFT scams consisted of poorly designed websites, unrealistic promises, and little effort to hide criminal intentions. Today, crypto criminals have become more efficient and effective. As an example, the number of rug-pull incidents declined by about 66% in early 2025, yet the total value stolen still exploded to $6 billion, up from roughly $90 million the year before. 

Organized crypto scam operations are characterized by:

  • Multi-wallet structures where funds might pass through dozens of addresses across different blockchains before disappearing into mixers that blend transactions to hide their origin or are cashed out through unregulated exchanges.
  • Honeypot smart contracts, which are seemingly legitimate tokens that can be purchased normally, but the underlying code contains hidden functions that prevent buyers from selling when they want to cash out. The contract is designed to trap liquidity, hence the name.
  • Professional marketing and community-building, where scammers may hire website designers, influencers, and individuals to post fake positive reviews on social media. They could also deploy bots to simulate active trading and enthusiastic community discussion, and create fabricated LinkedIn accounts with AI-generated profile photos.

How to Protect Yourself from Crypto and NFT Scams Today

Protecting yourself from modern crypto scams requires more than awareness; it demands consistent habits, smart decision-making, and the right tools. As threats continue to evolve, building strong security practices today is the best way to stay ahead of increasingly sophisticated attacks.

Step 1: Decide If Crypto and NFTs Fit Your Risk Profile

Given that investment fraud is now the top fraud category by value in the U.S. and crypto-enabled fraud accounts for the majority of those losses, you will need to critically evaluate whether investing in cryptocurrency or NFTs aligns with your financial goals and risk tolerance.

This space combines extreme price volatility, complex technical requirements, irreversible transactions, minimal consumer protection, and a target-rich environment for criminals. If any of the following apply to you, your wisest choice is to proceed with extreme caution or avoid crypto investment entirely:

  • You’re investing money you can’t afford to lose.
  • You feel time pressure or fear of missing out, driving your decisions.
  • You don’t fully understand cryptocurrency wallets, private keys, and blockchain transactions.
  • You’re being introduced to the opportunity by someone you met only online.
  • The promised returns seem unusually high compared to traditional investments.
  • If something goes wrong, you likely have no way to recover your funds.

Choosing not to invest in crypto isn’t missing out, but making a risk-aware decision. Traditional, regulated investment vehicles may offer lower potential returns, but they come with legal protections, regulatory oversight, and mechanisms for recovering from fraud.

Step 2: Adopt Essential Anti-Scam Rules

If you decide to invest in cryptocurrency or NFTs anyway, adopt these fundamental security practices to dramatically reduce your vulnerability:

Never Send Crypto Based on Unsolicited Contact

If someone reaches out to you through any medium who steers the conversation to cryptocurrency investment opportunities, you’re almost certainly being targeted for fraud. Legitimate investment opportunities don’t find you this way.

Similarly, any communication that promises guaranteed returns, uses urgency, or pressures you before you can independently verify information is a red flag.

Verify Platforms Independently and Exhaustively

Before depositing funds anywhere, verify the platform’s legitimacy through multiple independent sources. Look for:

  • Regulatory registration: Many scam platforms falsely claim regulatory compliance, so verify directly with your country’s regulator. In the U.S., check the websites of the Securities and Exchange Commission and the Commodity Futures Trading Commission for registered entities. 
  • Independent reviews: Beyond testimonials or reviews on the platform, look for experiences on Reddit, Twitter, and crypto community forums. Scammers might seed fake positive reviews, so look for detailed negative experiences rather than just star ratings.
  • Team transparency: Legitimate projects are run by real people whose professional backgrounds can be verified through LinkedIn, academic publications, or previous work. Note that AI-generated faces and bios are common in scams.
  • Active audit reports: If a DeFi project claims to be audited, verify that the audit was performed by a reputable firm and read the report, not just the passed audit badge.
  • Domain age and history: Use WHOIS lookup tools to check when a website’s domain was registered. Scam sites are often brand new, while legitimate platforms have longer operational histories.

Master Wallet Security Fundamentals

If you’re holding cryptocurrency or NFTs yourself rather than on an exchange, you’re personally responsible for security. Essential practices include:

  • Use hardware wallets: These are physical devices such as Ledger or Trezor for significant holdings rather than software wallets on your computer or phone. Hardware wallets keep your private keys isolated from internet-connected devices, dramatically reducing risk.
  • Store your seed phrase offline in multiple secure locations: This is the 12- to 24-word recovery phrase for your wallet. Write it on paper or stamp it on metal plates, never store it digitally in photos, cloud storage, or password managers.
  • Never share your seed phrase or private keys: No legitimate support person will ever ask for these. If someone does, they’re attempting theft.
  • Verify transaction details carefully before approving: Check that the recipient address, amount, and token type are exactly what you intend. Malware can change clipboard contents, so compare addresses character by character.
  • Use a separate email account: Create a separate email address for your crypto activities, distinct from your day-to-day credentials, and enable two-factor authentication, preferably via authenticator apps rather than SMS.
  • Be extremely skeptical: In the current environment, you should assume any new cryptocurrency token or NFT project is a scam until you’ve verified otherwise through sustained, careful research. 

Step 3: Respond Immediately If You’ve Been Scammed by Crypto and NFTs

Discovering you’ve been scammed is devastating, but taking immediate action could limit the damage and help law enforcement track and stop criminal operations:

Stop All Further Payments Immediately

Scammers often follow successful scams with additional pitches: recovery services usually run by the same criminals, tax payments supposedly required to unlock frozen funds, or claims that you’re so close to breaking even if you just invest a bit more. Every additional dollar you send is stolen money. Stop entirely.

Document Everything Comprehensively

Before anything disappears or times out, make sure to save:

  • Screenshots of all conversations, transactions, and account dashboards
  • Email messages, text messages, and voice messages
  • Wallet addresses, transaction hashes, and blockchain records
  • Platform URLs and any documents or contracts you signed
  • Names, social media profiles, and phone numbers used by the scammers

This documentation is essential for law enforcement investigations and any potential recovery efforts.

Report to Multiple Authorities

While full recovery is rare, rapid reporting has occasionally allowed exchanges to freeze funds or helped international task forces seize assets before they’re fully laundered. Don’t expect miracles, but don’t assume recovery is impossible either.

Make formal reports to the:

  • FBI Internet Crime Complaint Center (IC3): Even if your loss seems small compared to the billions reported annually, your complaint adds to the IC3 pattern analysis that helps identify and dismantle criminal networks.
  • Federal Trade Commission: Complaints made to ReportFraud.ftc.gov feed into consumer protection initiatives and help identify trending scam tactics.
  • Your exchange or wallet provider’s fraud team: If you used a legitimate platform for any part of the transaction, reporting the incident will enable your exchange or wallet to flag addresses or provide transaction data to investigators.
  • Your local or state law enforcement: These agencies work with federal law enforcement, particularly if losses are substantial. 

Consider Professional Help for Significant Losses

If you’ve lost large sums, consider consulting with lawyers who specialize in cryptocurrency fraud or employing blockchain forensics firms that can trace funds across chains. 

Protect Yourself from Recovery Scams

After a crypto scam, many victims are approached by fake recovery specialists who claim they can get your money back for an upfront fee in, you guessed it, cryptocurrency. These are almost always the same criminals or their associates running a second scam. Legitimate legal professionals work on contingency or retainer, and will not ask victims to send cryptocurrency for recovery services.

Step 4: Install a Trusted Security Solution

Comprehensive cybersecurity solutions may not be a guaranteed shield against all fraud, but they serve as a critical layer that catches threats you might not spot in that moment. Solutions such as McAfee+ help block known phishing sites and warn you before you enter credentials or connect wallets to fraudulent platforms. They also help detect malware and keyloggers that capture your password and seed phrase keystrokes, take screenshots when you open wallet applications, or even replace destination addresses in your clipboard when you copy-paste. Antivirus and anti-malware tools continuously monitor for threats and help remove them before they can compromise your security.

A secure virtual private network (VPN) can protect your connection on public Wi-Fi networks or compromised routers, preventing man-in-the-middle attacks that might intercept your login credentials or transaction data.

Since many crypto scams begin with or lead to broader identity theft, identity monitoring services can alert you if your personal information, passwords, or financial details appear in data breaches or on dark web marketplaces. This early warning allows you to change compromised credentials before they’re exploited.

Final Thoughts

The rising number of crypto-related fraud incidents and losses represents a grim milestone. As long as these scams promise high returns and operate with minimal oversight, criminal organizations will continue developing new tactics to steal from investors. 

Going forward, your effective defense strategy will combine healthy skepticism, technical hygiene, continuous education, and practical tools. Approach any crypto investment opportunity with a questioning eye until you’ve independently verified that it is legitimate.

Maintain strong security practices, including using hardware wallets for significant holdings, storing seed phrases offline, enabling two-factor authentication everywhere, and carefully verifying transactions before approving.

Most importantly, build a network of trusted advisors, such as family members, friends, or financial professionals, who can offer guidance when you’re evaluating opportunities. Share what you’ve learned from this article and other McAfee guides with people in your life who might be exploring crypto investments, especially those who may be more vulnerable to relationship-based scams.

The post How to Spot a Crypto Scam: The Top Red Flags to Watch For appeared first on McAfee Blog.

❌