CHAINDOKU
Crypto scams

Crypto scams · 7 cases

Rigged signatures, sites and apps

Here the victim acts on their own: they sign an approval, scan a QR code, copy an address or install an extension. Everything looks official, and that is the trap. These cases show what a signature really authorizes, and why an address must be checked in full.

The hijacked clipboard

How it works
Pirated software quietly swaps every crypto address you copy for the scammer's. You paste, you send: the money goes elsewhere.
Warning sign
A pasted address that doesn't start or end like the one you copied.
The reflex
Check the start and end of every pasted address, and never install cracked software.

The case

VictimFreelance Editor

The Clipboard Hijack

Three clients paid his invoices. Not a cent reached his wallet.

Easy7×7~4 min

The trapped signature

How it works
A fake or fake site has you “sign to claim”. The signature actually gives the contract the right to take all your .
Warning sign
A free gift to claim by signing, a request for .
The reflex
Read what you sign, and regularly revoke the approvals you no longer need.

The cases

VictimSecurity Researcher

The Unlimited Approval

A free NFT, a single signature. The wallet was drained token by token.

Medium8×8~6 min
VictimFront-End Engineer

The Hijacked Site

The right address, the right logo, the padlock. And every signature drains the wallet.

Medium7×7~12 min

The look-alike address

How it works
The scammer forges an address that starts and ends like your contact's, then slips it into your history so you copy it by mistake.
Warning sign
You copy an address from your history rather than from a trusted source.
The reflex
Check the whole address, and send a small test amount first.

The case

VictimPayments Controller

The Lookalike Address

Two million sent to an almost identical address. The one who saw it all vanished that same evening.

Hard10×10~9 min

The copycat software

How it works
An extension or app copies the logo and reviews of the real . Once installed, it drains yours.
Warning sign
A download link found in an ad or a message, not on the official site.
The reflex
Only install a from the official site's link.

The case

VictimSecurity Researcher

The Rigged Extension

The right logo, thousands of five-star reviews. Then an “urgent update”.

Hard7×7~19 min

Blind signing

How it works
A shared 's interface is hacked: the screen shows the usual transfer, but the signers approve an entirely different transaction.
Warning sign
A hardware that shows unreadable data, or data different from the screen.
The reflex
Before signing, read the transaction on the hardware 's screen, and refuse what you cannot read.

The case

VictimThird Signer

The Blind Signature

Three signers, the usual transfer, the right address on screen. And the vault drains.

Hard7×7~19 min

The booby-trapped QR code

How it works
A sticker covers the real on a parking meter, a menu or a poster: the payment goes to a fake site.
Warning sign
A sticker stuck on top, an unusual website address.
The reflex
Before paying, check the address of the site that opens.

The case

VictimScam Hunter

The Rigged QR

A fresh sticker over the real QR code. People scanned, paid, and the money went elsewhere.

Hard10×1030+ min