Scam Alerts
Active incidents and unsafe practices, grouped by how urgently you should act.
Active alerts
Per an April 2026 Chainalysis analysis, OFAC designated Cambodian Senator Kok An and 28 associated people and entities while the DOJ's Scam Center Strike Force charged two managers of Burma's Shunda compound, seized 503 web domains posing as legitimate crypto investment platforms and restrained over $701.9M. Chainalysis calls pig butchering, run largely from industrial-scale compounds in Burma and Cambodia, one of the most financially devastating forms of cybercrime, with the FBI's IC3 reporting estimated losses of $7.2B in 2025. Source: https://www.chainalysis.com/blog/asian-scam-centers-crypto-fraud-april-2026/
TraderTraitor actors took $292M from KelpDAO's rsETH LayerZero bridge on April 18 after poisoning internal RPC nodes so a lone verifier approved a forged cross-chain message, while a separate DPRK group drained $285M from Solana's Drift Protocol on April 1 following months of social engineering against protocol signers, including in-person meetings with employees. TRM Labs puts North Korea's attributed thefts since 2017 above $6 billion. Source: https://www.trmlabs.com/resources/blog/north-korea-stole-76-of-all-crypto-hack-value-in-2026-with-just-two-attacks
Blockaid tracked five separate drainer campaigns in April 2026 piggybacking on the Drift, KelpDAO, ZetaChain, Aftermath Finance and Wasabi incidents, using lookalike domains such as revokes-drift[.]trade pushed through X reply threads as fake security guidance. Users trying to revoke approvals or migrate assets on Solana, Ethereum, Base and Sui instead signed wallet-draining transactions, with distinct kits, infrastructure and operators behind each campaign. Source: https://blockaid.io/blog/how-wallet-drainers-use-fake-revoke-sites-and-twitter-phishing-to-exploit-victims
Blockaid has flagged over 65.4M poisoning transactions since January 2025 and reports Ethereum overtook BSC as the most-poisoned chain in January 2026 after the December 3 Fusaka upgrade cut fees roughly 6x, with attempts rising from 628,000 in November 2025 to 3.4M in January. Documented losses include $50M in USDT in December 2025 and 4,556 ETH (~$12.4M) on January 30, 2026, the latter following a two-month dusting campaign. Source: https://www.blockaid.io/blog/address-poisoning-the-growing-threat-draining-millions-from-crypto-users
A July 20, 2026 FBI PSA documents fraudulent social media profiles posing as FBI agents, AI-generated deepfake videos of senior FBI leaders promoting spoofed IC3 websites, and malicious links pushed via Facebook Messenger and Telegram to revictimize people who already lost funds. The FBI states IC3 never asks for payment to recover lost funds and never refers victims to companies requesting payment for fund recovery. Source: https://www.ic3.gov/PSA/2026/PSA260720
The BBB's 2026 employment-scam update counts nearly 50,000 reports over 2023-2025 with reports doubling year-over-year in 2025, as task-based schemes — liking videos or rating products on fake platforms — demand deposits, often in cryptocurrency, to release fake commissions. Median task-scam losses reached $2,300 in 2025, and the FTC saw a 400% increase in task scams in 2024. Source: https://www.bbb.org/all/scamstudies/jobscams/employment-scams-2026-update
Kaspersky's April 2026 report details a FakeWallet campaign active since at least fall 2025 that hijacks the recovery-phrase entry screen in trojanized hot-wallet apps and shows phishing prompts to cold-wallet users, sending encrypted mnemonics to command-and-control servers; researchers suspect the same threat actors are linked to the SparkKitty trojan. Apple pulled several apps after disclosure, but Kaspersky identified similar apps from the same actors with malicious features likely awaiting activation. Source: https://securelist.com/fakewallet-cryptostealer-ios-app-store/119474/