Loading prices…
Security

Scams

Crypto scams and fraud — rug pulls, phishing, fake airdrops, and address-poisoning attacks.

Scams are the cost of doing business in crypto — and one of the few risks this market can't route around with a hardware wallet. The Scams beat at Zipp tracks how fraud operators find victims, where the money actually flows, and which enforcement actions, on-chain analytics, or platform changes are closing the gap. We cover the full range: Rug pulls and exit scams on newly launched tokens, phishing campaigns that drain wallets through fake websites or signatures, address-poisoning attacks that rely on copy-paste mistakes, fraudulent airdrops engineered to capture approvals, and large Ponzi schemes that surface only when authorities step in.

A crypto reader needs this beat because the threat surface changes weekly, and the same headline can mean different things depending on the venue. A "whale moving funds to an exchange" might be a routine rebalance, an over-the-counter desk trade, or the prelude to a dump. A "flash crash on launch" can signal thin liquidity, a coordinated exit, or a misconfigured emission. Zipp's newsroom follows suspicious-transaction reports from firms like TRM Labs, Chainalysis, and Elliptic, court filings, exchange and stablecoin issuer statements, and project governance votes tied to team-held supply — and we publish what we confirm, not what influencers amplify.

Day to day, we watch address-poisoning campaigns targeting high-value BTC and ETH holders, fake-airdrop lures around trending tickers like SOL ecosystem projects, SIM-swap rings operating across borders, and regulatory moves that shift liability (recent examples include U.S. state-level rules making crypto ATM operators responsible for scam refunds). When a major incident breaks — a suspected rug pull, a seized-funds transfer between wallets, or a DOJ case that gets dropped or revived — we publish the on-chain evidence alongside the court record so readers can judge for themselves.

Related tokens

Frequently asked questions

  1. What is a rug pull in crypto?

    A rug pull is when the team behind a token project removes liquidity or sells its holdings, leaving buyers with a worthless asset. It is most common on newly launched tokens where developers retain a large share of the supply or control the liquidity pool.

  2. How does address poisoning work?

    Attackers send a tiny transaction from a wallet address that matches the first and last characters of a victim's real contacts, hoping the victim copies the wrong address during a future transfer. The attack relies on visual similarity, not on any code exploit.

  3. What is a crypto Ponzi scheme?

    It is a fraud that pays early participants with funds from new investors rather than with real revenue, and it collapses once inflows slow down. Crypto Ponzi cases are typically uncovered by chain analytics or whistleblower complaints rather than by users spotting the math.

  4. Are crypto airdrops ever legitimate?

    Yes, established projects use airdrops to distribute tokens to active users, but the same word is also used by scammers to lure victims into signing malicious wallet approvals. Always verify the contract address and the official project channel before claiming.