Crypto scams stole more money in 2025 than in any year on record, and the first half of 2026 shows attackers moving even faster. Chainalysis, CertiK, and independent security researchers have all published data this year that tells the same story: losses are rising, tactics are shifting away from simple seed-phrase theft toward more sophisticated wallet permission attacks, and impersonation scams are growing faster than almost any other category of crypto crime. Here is a breakdown of the numbers, what is driving them, and how to protect yourself.

Key Crypto Scam Statistics 2026

  • $17 billion (estimated) was stolen through crypto scams and fraud in 2025, up from a revised $12 billion in 2024, according to Chainalysis
  • The average scam payment grew 253% year-over-year to $2,764 in 2025
  • Impersonation scams grew more than 1,400% year-over-year in 2025 - the fastest-growing scam category Chainalysis tracks
  • AI-enabled scams extracted an average of $3.2 million per operation, 4.5 times more than scams without AI involvement
  • $1.31 billion was lost to Web3 security incidents in the first half of 2026 alone, per CertiK's Hack3D report
  • Phishing caused $366 million in losses across 63 incidents in H1 2026, the second-costliest attack category
  • At least $5.69 million was stolen after a flaw in the CryptoJS code library made 2,000+ wallet recovery phrases predictable, security firm Coinspect found in 2026
  • Roughly 38% of Web3 losses over $1 million in 2026 involved malicious "Permit" signature approvals rather than stolen credentials, per SlowMist
  • Americans aged 60 and older reported $2.8 billion in crypto-related fraud losses in a single year, per FBI Internet Crime Complaint Center data
  • Some phishing kits used in large-scale campaigns sell for under $500, letting low-skill criminals run million-dollar operations

How Much Was Lost - the Big Picture

Padlock with light trails, symbolizing financial loss from crypto scams

Total losses: $17 billion was stolen through crypto scams and fraud in 2025, according to Chainalysis' 2026 Crypto Crime Report - up from a revised $12 billion in 2024 (originally reported as $9.9 billion before later on-chain attribution). Chainalysis expects the 2025 figure to be revised upward again as more illicit wallets are identified, following a pattern where its estimates have grown by an average of 24% between reporting periods in past years.

Average payment size: grew from $782 in 2024 to $2,764 in 2025, a 253% jump. Scammers are not just running more scams - each successful one is extracting more money per victim, largely because AI tools let a small number of operators run convincing, personalized attacks at scale.

The first half of 2026 has kept pace. CertiK's Hack3D report puts total Web3 security losses at $1.31 billion for H1 2026 alone, with phishing responsible for $366 million of that across just 63 incidents - a sign that fewer, larger attacks are replacing the high-volume, low-value phishing campaigns common in prior years.

Impersonation Scams: the Fastest-Growing Threat

Impersonation is now the single fastest-growing scam category in crypto, up more than 1,400% year-over-year in 2025. These scams involve fraudsters posing as government agencies, exchange support staff, or other trusted parties to convince victims to hand over funds directly.

Government impersonation: the "E-ZPass" toll-payment text scam, run by a China-based group known as the Smishing Triad, reportedly reached 330,000 texts in a single day and amassed roughly $1 billion over three years by impersonating toll collection agencies across the US.

Exchange impersonation: in one Brooklyn case, a scammer posing as Coinbase customer support - using data obtained through a bribed insider - defrauded victims of nearly $16 million by convincing them to move funds to "secure" wallets that the scammer controlled.

The average severity of impersonation-scam payments increased more than 600% year-over-year, meaning victims are not just more numerous - they are losing more per incident.

Phishing and Wallet Drainers: the Tactics Have Changed

The old image of a crypto scam - a fake exchange login page harvesting a password - has given way to more targeted attacks. Modern wallet drainers rarely try to steal your seed phrase directly. Instead, they exploit the legitimate permission systems that let wallets interact with apps.

  • Malicious token approvals that grant a scam contract ongoing access to your funds
  • Gasless "blind signature" requests (EIP-712 permits) that look harmless but authorize a transfer
  • Fake dApp connection requests on cloned websites
  • Address poisoning, where scammers send a near-identical wallet address to your transaction history hoping you copy the wrong one

SlowMist's 2026 data shows that roughly 38% of Web3 losses over $1 million involved malicious Permit signatures rather than stolen credentials. Once a victim signs a malicious approval, the transfer is irreversible - there is no chargeback in crypto.

Seed-Phrase Scams Still Cost Millions

Despite the shift toward permission-based attacks, seed-phrase phishing - tricking someone into typing their recovery phrase into a fake site or handing it to a fake "support agent" - remains the most common way individual wallets get emptied.

The CryptoJS case: in 2026, security firm Coinspect discovered that at least five wallet apps (RRWallet, Bexo Wallet, NanChat, Bitcoin Libre, and Milo) used a weak random-number generator in the CryptoJS library to create recovery phrases. The flaw made more than 2,000 seed phrases across five blockchain networks predictable enough to guess with commodity hardware, leading to at least $5.69 million in theft. Upgrading the library does not fix wallets that already generated a compromised seed phrase - anyone affected has to move funds to a newly generated wallet entirely.

Laptop computer, representing online crypto scam vectors

Outside of software bugs, most seed-phrase theft still comes down to social engineering: fake "wallet verification" emails, QR codes mailed to Ledger and Trezor owners claiming a "mandatory security check," and unsolicited messages from people posing as wallet support staff. No legitimate wallet company or exchange will ever ask for your seed phrase.

Who Is Being Targeted

Elder fraud remains one of the most damaging categories by dollar volume. Americans aged 60 and older reported nearly $2.8 billion in crypto-related losses in a single year to the FBI's Internet Crime Complaint Center, with crypto ATMs frequently used as the on-ramp - victims are instructed to convert cash to crypto at a kiosk, then send it directly to scammers.

AI is making every category more effective. Scams with on-chain links to AI vendors extract 4.5 times more revenue than scams without, largely through deepfake video calls, cloned voices, and language models that write far more convincing phishing messages than earlier scam scripts.

How to Protect Yourself

Tangem

Most of the scams above rely on tricking you into exposing a seed phrase or approving a transaction. Tangem has no seed phrase and no screen to spoof.

Get Tangem

Most of the losses above share a common thread: the victim was tricked into approving a transaction or handing over information, not hacked in a technical sense. That means the defense is mostly about habits and hardware, not software alone.

  • Never enter your seed phrase into a website, app, or message - no legitimate wallet or exchange will ever ask for it
  • Use a hardware wallet for anything you are not actively trading. Keeping your private keys offline removes the single biggest attack surface for phishing and malware
  • Check transaction requests carefully before signing, especially "Permit" or "approve" requests you do not recognize - these are the mechanism behind most modern wallet drainers
  • Revoke old token approvals periodically using a tool like a block explorer's token approval checker
  • Treat unsolicited "support" contact as a red flag, whether it comes by phone, email, text, or a mailed letter with a QR code
  • Type URLs manually or use a bookmark you saved yourself for wallet and exchange sites instead of clicking links

A hardware wallet will not stop every scam on this list, but it closes off the fastest and most common path scammers use - direct access to your seed phrase - and it forces you to physically confirm transactions on a separate screen before anything moves. If you are deciding between options, our Best Hardware Wallet 2026 roundup and Ledger vs Trezor comparison cover the tradeoffs in detail.

Sources

Share this post