Common crypto scams in the UK (and how to avoid them)

How crypto scams typically target UK residents

Crypto fraudsters often start with a trusted channel and then move the conversation to a private space. Social media adverts, messaging apps, and search results can all lead to cloned websites that mimic real exchanges or wallet services. Some scams use “investment managers” who promise steady returns and apply pressure to act quickly, often by claiming a limited-time offer or a tax deadline. Fraudsters may also ask to install remote access software, then take control of a device to approve transfers.

Many attacks rely on UK-specific cues. Criminals may impersonate a bank, a solicitor, or a government body, then request a “verification” payment or a transfer to a “safe account”. Others exploit current events, such as cost-of-living concerns, to promote fake staking schemes or high-yield lending. Phishing emails and texts also remain common, with links that capture login details or seed phrases.

UK residents can reduce risk by treating unexpected contact as suspicious, checking web addresses carefully, and refusing to share recovery phrases under any circumstances. When a firm claims authorisation, confirm the details on the Financial Conduct Authority (FCA) website before sending funds. A quick call to a known number can also help verify a request.

Common crypto scams in the UK (and how to avoid them)

Common crypto scams in the UK (and how to avoid them)

Fake FCA registration and impersonation of regulated firms

Some fraudsters claim Financial Conduct Authority (FCA) registration or impersonate regulated firms to appear legitimate. Common tactics include using a real firm’s name, address, or FCA reference number, then directing victims to a cloned website, a different phone number, or a “case handler” who does not work for that firm. A genuine FCA entry does not confirm that a crypto investment is authorised, since many crypto activities sit outside FCA regulation.

  • Check the firm on the Financial Services Register and use the contact details shown there, not those provided in adverts or messages.
  • Compare the website domain carefully and watch for subtle spelling changes.
  • Search the FCA Warning List for known clones and unauthorised firms.
  • Reject requests for remote access, upfront “tax” payments, or transfers to personal bank accounts.

Fraudulent crypto investment schemes and guaranteed returns

Fraudulent crypto investment schemes often centre on “guaranteed returns”. A scammer may claim a fixed daily profit, a risk-free arbitrage strategy, or a private trading bot that “cannot lose”. Crypto markets move quickly and unpredictably, so any promise of certain profit should raise immediate concern.

Many schemes use polished dashboards that show steady gains. Those figures often come from a controlled website rather than a real exchange. Some fraudsters allow a small early withdrawal to build trust, then push for a larger deposit. Once the amount increases, access may disappear, withdrawals may “fail”, or the platform may demand extra payments labelled as tax, verification, or liquidity fees.

Pressure tactics also feature heavily. A promoter may insist on acting within hours, discourage independent checks, or ask for remote access to a phone or computer. That access can enable account takeovers and new payments without clear consent. Requests to pay in cryptocurrency, gift cards, or via unfamiliar payment routes also signal high risk, because those methods can limit recovery options.

To reduce exposure, treat returns as uncertain and verify claims using independent sources. Check warnings and guidance from the Financial Conduct Authority (FCA) ScamSmart, and confirm whether a firm appears on the FCA Financial Services Register. If a scheme claims authorisation, ask for written evidence and compare contact details with official listings. When doubt remains, stop payments and seek advice before sending any funds.

report crypto fraud in the UK

report crypto fraud in the UK

Romance and social media crypto scams affecting UK consumers

Romance and social media crypto scams often begin with a friendly message on a dating app, Instagram, Facebook, or WhatsApp. The fraudster builds trust over days or weeks, then introduces a “safe” crypto opportunity, sometimes framed as a shared plan for the future. A common pattern involves moving the chat off-platform, then directing the victim to a fake exchange or wallet app that shows convincing profits. When the victim tries to withdraw funds, the scammer invents “tax”, “verification”, or “release” fees to extract more money.

UK consumers can reduce risk by treating any investment tip from an online contact as a red flag, even when the relationship feels genuine. Verify claims using independent sources, and check warnings and guidance from the Financial Conduct Authority (FCA) and Action Fraud.

  • Refuse requests to keep the opportunity secret or to act quickly.
  • Do not install remote access tools or “support” apps suggested by a stranger.
  • Confirm website addresses carefully; avoid links sent in direct messages.
  • Test withdrawals early with a small amount; stop if fees escalate.

Phishing, wallet-draining links, and seed phrase theft

Phishing aims to trick a person into handing over login details or approving a transaction. Messages often pose as a wallet provider, exchange, or courier and push an urgent “security check”. Attackers also buy search adverts that lead to cloned sign-in pages, then capture passwords and one-time codes. Treat unexpected links as hostile and type the address directly instead.

Wallet-draining links work differently. A site may ask a visitor to “connect” a wallet and then request permission to spend tokens. Once a person approves the request, the attacker can move assets out within seconds. Before approving any prompt, read the permissions, check the domain carefully, and cancel anything that requests unlimited spending or access to all assets.

Seed phrase theft remains one of the most damaging tactics. A seed phrase (also called a recovery phrase) restores full control of a wallet, so anyone who has it can take funds. No legitimate service, including MetaMask or Ledger, will ask for it in a chat, email, or form. Keep the phrase offline, never share it, and use official support pages such as the National Cyber Security Centre for guidance on spotting phishing.

Practical steps to verify providers and report crypto fraud in the UK

Before sending funds, verify the provider through independent checks rather than links in adverts or messages. Use the Financial Conduct Authority (FCA) Financial Services Register to confirm the firm name, reference number, and contact details, then call the number shown on the register. Confirm that the service appears on the FCA list of registered cryptoasset businesses, which relates to anti-money laundering supervision and does not approve investments.

Next, validate the website address carefully. Type the domain manually, check spelling, and avoid “sponsored” search results when possible. Where the provider offers it, enable multi-factor authentication (an extra sign-in step) and set a withdrawal allowlist so funds can only go to approved addresses.

If fraud occurs, act quickly. Contact the bank or card provider at once and ask for a recall or chargeback where available. Report the incident to Action Fraud and keep evidence such as wallet addresses, transaction hashes, screenshots, and chat logs. When the scam involves a regulated firm or misleading promotions, submit a report to the FCA. For ongoing risk, seek guidance from Citizens Advice.