By Sam Rogers, Associate Director of Product, Scam Alert, Crystal Intelligence
Phishing, Fake Apps, and Digital Impersonation
The Human-Targeted Crypto Scams Surging Right Now
The newest scams don’t hack code. They hack people.
For years, crypto users feared technical exploits. Complex smart-contract breaches. Multi-chain laundering. Protocol failures. But now, the biggest threat is not code. It is psychology.
Criminals have realised something powerful. It is easier to trick a person than to break an algorithm. It is easier to impersonate a support agent than to engineer a vulnerability. It is easier to lure a victim into installing a fake app than to penetrate an exchange.
Human-targeted scams are now the most successful attacks in crypto, and they are evolving faster than users can adapt.
The Gemini-style phishing attacks that changed everything
Crystal Intelligence tracked one of the largest phishing-driven thefts the industry has ever seen. Criminals impersonated Gemini employees using fake verification messages and fraudulent support chats. Victims believed they were speaking to real staff members, and more than 240 million dollars’ worth of Bitcoin was drained through cleverly disguised instructions and fraudulent authorisations .
This attack became a blueprint for countless others. Criminals realised they could scale impersonation the same way they scale botnets.
No complex exploit.
No code injection.
Just believable lies.
Fake apps are becoming indistinguishable from real ones
The new wave of fraud includes convincing mobile apps made to look identical to real services. Fake staking platforms, bogus “tax refund tools”, imitation wallet apps and fraudulent self-custody managers. Criminals pay designers to produce interfaces that even experienced users struggle to tell apart from legitimate services.
Once installed, these apps request wallet access, permissions or seed phrases. Many victims believe they are completing a normal update or linking their accounts through official verification. Sometimes the apps appear in search results long enough to trap hundreds of users before being removed.
For scammers, it is a profitable pattern.
For victims, it can be financially catastrophic.
Impersonation is now industrialised
The era of amateur scammers sending sloppy messages is over. Criminal organisations now operate impersonation farms. They use:
- AI voice replicas of exchange support agents
- Realistic customer service scripts
- Fake LinkedIn profiles with long employment histories
- Coordinated SMS campaigns
- Professional-looking email templates
- Knowledge of internal processes stolen from compromised staff accounts
To the victim, everything appears legitimate.
To the criminal, every interaction is another opportunity.
Why these scams succeed
Human-targeted crypto scams succeed for three reasons.
1. They exploit emotion.
Fear, urgency, embarrassment, excitement. Scammers play with all of them.
2. They mimic authority.
When a “support agent” tells you your account is compromised, the instinct is to comply, not question.
3. They create confusion.
Fake security alerts, unfamiliar prompts, technical jargon. Victims panic and follow instructions without checking.
Criminals know that people freeze when confronted with perceived danger. That is when they strike.
How Scam Alert helps protect consumers from impersonation attacks
Scam Alert plays a critical role in identifying and disrupting these human-targeted threats. When users submit suspicious messages, URLs, apps or dialogues, analysts compare them with known fraud operations tracked by Crystal Intelligence.
Scam Alert helps users by:
- Verifying whether a message or request is genuine
- Identifying clusters of impersonation campaigns targeting specific regions
- Sharing malicious links and apps with exchanges and law enforcement
- Alerting the public when a new impersonation method is spreading
- Building a public scam library users can search before taking action
A single report of a fake “verification request” can expose an entire criminal operation targeting thousands.
What consumers should do when approached by “support”
If you ever receive an unexpected message from anyone claiming to represent an exchange, wallet provider or regulator, treat it as suspicious until proven otherwise.
Here are the golden rules for 2026:
- Never share your seed phrase.
- Never install apps sent through private messages.
- Never click a verification link without confirming through the official site.
- Never allow remote access to your device.
- Always confirm support requests through official channels.
- Report all suspicious contact to Scam Alert immediately.
A legitimate organisation will never pressure you to act instantly.
Criminals always will.
The battle has shifted from code to conversation
This new era of crypto crime is deeply personal. Scammers study your behaviour, your online presence and your emotional triggers. They craft their attacks to feel authentic, urgent and believable.
Technology alone cannot stop these scams. Awareness can.
Verification can.
Reporting can.
The faster Scam Alert receives information about impersonation attempts, the faster we can warn the public and support investigators trying to shut these operations down.
You are not powerless. You are part of the defence.
Have you been scammed out of crypto or did you spot something suspicious? Report it to us here: https://scam-alert.io/
Categories
Here are some common questions about crypto scams and resources available for victims.

