Crypto fraud is no longer a fringe spillover from speculation. The Federal Trade Commission said U.S. consumers reported losing more than $12.5 billion to fraud in 2024, including $5.7 billion to investment scams. The FBI’s 2024 IC3 report logged 149,686 complaints referencing cryptocurrency and $9.3 billion in associated losses, with $5.8 billion tied specifically to crypto investment fraud.
Even those figures likely undercount the full market because complaint data and on-chain analytics capture different slices of harm. Chainalysis estimated at least $14 billion in on-chain scam inflows in 2025, up from an initial $9.9 billion estimate for 2024 that it later recalculated to $12 billion as more illicit addresses were identified. Fraud in crypto is no longer a series of isolated scams. It is organized financial infrastructure with measurable throughput.
The fraud market is scaling faster than the industry admits
The most important change is industrialization. Treasury’s May 29, 2025 sanctions described Funnull Technology as infrastructure for hundreds of thousands of websites tied to virtual currency investment scams and linked it to more than $200 million in U.S. victim-reported losses. Treasury’s September 8, 2025 action described Huione Group as a critical laundering node for Southeast Asian pig-butchering and related cyber-scam networks. These are not lone fraudsters posting Telegram links from a laptop. They are service providers, traffic brokers, laundering hubs, and labor systems.
FinCEN made the same point earlier from the anti-money-laundering side. Its September 8, 2023 alert said U.S. law enforcement sources estimated that Americans had lost billions to pig-butchering and other virtual currency investment frauds, and it described the scams as largely perpetrated by criminal enterprises in Southeast Asia that use victims of labor trafficking to conduct outreach at scale. The scam is social engineering on the front end and industrial process on the back end.
The current trendline is getting worse, not better. Chainalysis said impersonation scam inflows grew by more than 1400% year over year in 2025, while the average payment to scam clusters rose from $782 in 2024 to $2,764 in 2025. That combination matters. It means the fraud stack is broadening its victim funnel while also extracting more from each successful target.
Fake investment platforms are now the center of gravity
Relationship investment scams sit at the center because they combine the oldest fraud mechanic in finance with the least forgiving settlement rail. The joint investor alert says fraudsters typically reach out through social media or text, build trust slowly, and then defraud victims through fake investments. The SEC’s anti-fraud campaign on April 16, 2025 described the same structure as a “long con” that starts with online contact and ends with money sent into phony investments.
The SEC’s September 17, 2024 NanoBit and CoinW6 cases are useful because they show the mechanism cleanly. According to the SEC, scheme participants used WhatsApp, LinkedIn, and Instagram to lure investors, lied to build trust, and moved them onto fake crypto trading platforms that displayed false information. In NanoBit, the platform allegedly even claimed that an affiliate was an SEC-registered broker to manufacture credibility. Crypto did not create the fraud logic. Crypto reduced settlement friction for the fraudster.
This matters for Web3 participants because the visible token or dashboard is often the least important part of the scam. The decisive layer is control over the interface, the off-chain narrative, and the withdrawal gate. Once the victim accepts a fake balance as real, every next step becomes programmable: more deposits, fake taxes, fake compliance checks, fake freezes, fake recovery agents. The wallet transfer is final, but the “portfolio” only existed as UI theater. That is why relationship fraud and crypto fraud have effectively merged.
Crypto ATMs and impersonation are not edge cases
Crypto ATMs have become a core cash-in rail for scams that begin with impersonation, panic, or fake support. The FTC said reported fraud losses at bitcoin ATMs rose nearly tenfold from 2020 to 2023 and topped $65 million in just the first half of 2024, with a median reported loss of $10,000. The FBI’s 2024 IC3 report separately logged 10,956 crypto ATM or kiosk complaints and $246.7 million in losses, with victims over 60 accounting for $107.2 million.
The FTC’s data is especially revealing because the front-end stories were mostly not “investment opportunities.” In the first half of 2024, the agency said BTM losses were overwhelmingly tied to government impersonation, business impersonation, and tech support scams. In other words, crypto is often the settlement layer for fraud categories that victims do not even perceive as “crypto” until the cash is already gone.
Impersonation is now a first-order risk because it scales trust theft. Chainalysis said government impersonation became especially effective in 2025, and Treasury’s Funnull action described a business model centered on selling the infrastructure behind mass scam websites. That should change how informed users read inbound messages. If a payment flow begins with an unsolicited text, a spoofed support interaction, or a demand to “protect” funds by converting them into crypto, the base rate is no longer ambiguous. It is hostile until proven otherwise.
Centralization is a fraud amplifier
Structural centralization is not just an ideological concern. It is one of the cleanest fraud amplifiers in crypto. In the FTX case, DOJ said Samuel Bankman-Fried misappropriated billions of dollars of customer funds and directed code changes that allowed Alameda to withdraw effectively unlimited amounts of cryptocurrency from the exchange. Users were not taking protocol risk. They were taking hidden operator risk with no meaningful self-custody backstop inside the platform.
DeFi branding does not solve that problem if insiders still control the keys. The SEC said SafeMoon marketed its token as protected by locked liquidity and even as “Completely Rug Free.” DOJ later said SafeMoon executives lied about whether insiders could access the liquidity pool and then used that access to divert and misappropriate millions for personal benefit. The lesson is blunt: if a small insider set can still move liquidity, then the word “decentralized” is doing marketing work, not control work.
Upgradeable smart contracts create the same trust surface in a more technical form. OpenZeppelin’s documentation states that a proxy’s logic contract can be replaced, that the proxy holds the system’s state and funds, and that upgrader keys create additional compromise risk. OpenZeppelin also notes that transparent proxies are controlled through a ProxyAdmin owned by a deployer or designated initial owner. For users, the implication is straightforward: code is only as decentralized as the entity that can replace it.
The threshold question is not theoretical. L2BEAT’s current Linea permissions page lists bridge-related roles spread across a 3/5 multisig and a 5/9 multisig, and it shows several components upgradeable with no delay while the listed timelock minimum delay is 0 seconds. That is not evidence of wrongdoing by Linea. It is evidence that concentrated authority is still common in production crypto systems, even where the public narrative emphasizes decentralization. A decentralization purist should read those threshold numbers before reading the slogan.
Manipulated markets are fraud, not marketing
Crypto fraud is not limited to fake wallets and fake dashboards. It also includes fake markets. DOJ said Gotbit provided market-manipulation services between 2018 and 2024 to create artificial trading volume for client token issuers, used multiple accounts to avoid detection, and in June 2025 was ordered to forfeit roughly $23 million in seized cryptocurrency. The SEC’s October 9, 2024 action described the same business as “market-manipulation-as-a-service” sold to token promoters to induce retail investors to buy into the false appearance of active trading.
The broader DEX environment gives that behavior room to hide. Chainalysis identified 2,063,519 tokens launched in 2024, of which 74,037, or 3.59%, displayed patterns that may be linked to pump-and-dump schemes. It also found that about 94% of DEX pools in suspected schemes appeared to be rugged by the same address that created the pool, and that the average suspected scheme lasted about 6.23 days. These are methodology-based detections, not court findings, but they are strong enough to destroy any presumption that raw DEX activity equals honest price discovery.
For token buyers, the practical takeaway is simple. A chart can lie without the underlying chain lying. Wash trades, coordinated liquidity pulls, insider-funded volume, and paid “market making” can all be visible on-chain while still misleading any user who confuses recorded activity with organic demand. Market integrity in crypto is therefore not a cosmetic issue. It sits directly inside fraud analysis.
What to check before you touch a token or platform
The minimum serious screen is not “Is the community active?” It is “Who can change the rules, move the assets, or fabricate the market today?” The table below is a more useful starting set.
| Surface | What to verify | Why it matters |
|---|---|---|
| Upgrade and admin control | Identify the ProxyAdmin or equivalent owner, signer threshold, timelock duration, and emergency pause scope. | Upgradeable contracts can have their logic replaced, and the proxy holds the state and funds. If upgrade rights are concentrated, users are trusting admins, not just code. |
| Liquidity and treasury claims | Check whether liquidity is actually locked on-chain, who can withdraw or reroute it, and who signs treasury movements. | SafeMoon is the clearest warning that “locked liquidity” can be a marketing claim while insiders still retain access. |
| Market quality | Look at holder concentration, venue concentration, suspicious volume spikes, market-maker arrangements, and whether volume support is disclosed. | Artificial volume and wash trading are active fraud channels, not rare anomalies. |
| Funding path | Treat unsolicited texts, social DMs, QR codes, unknown exchanges, and BTM deposits as high-risk until independently verified. | Relationship scams and impersonation scams frequently end with victims sending funds to fake platforms or scam wallets through irreversible crypto rails. |
| Decentralization milestones | Ask for dated plans to narrow admin powers, raise thresholds, add real delays, rotate signers, and reduce concentrated operational control. | “Progressive decentralization” without measurable milestones is not a control model. It is a promise. Current production systems still commonly retain small multisigs and zero-delay authority. |
What this means for token economy design
Scam resistance is a token economy design issue before it becomes a legal issue. Authority over upgrades, minting, blacklisting, liquidity withdrawal, treasury transfers, bridge settings, validator selection, and market-making programs defines the real perimeter of user risk. A token can have elegant emissions, careful vesting, and a plausible narrative of community ownership while still being structurally one insider decision away from extraction.
From FinDaS Tokenomics’ standpoint, credible decentralization needs measurable milestones. The relevant disclosures are concrete: who holds the keys, what threshold signs, what delay exists before execution, what powers remain discretionary, what validator or committee concentration exists around cross-chain assets, and on what dates those privileges narrow or expire. If those details are absent, the token economy is not decentralized in the way that matters for fraud resistance. It is decentralized mainly in optics.
A serious tokenomics advisor should therefore treat scam prevention as part of token economy design, not as a post-launch communications layer. Narrow discretionary powers. Put the remaining ones behind higher thresholds and real timelocks. Separate operational coordination from user custody. Refuse volume engineering that manufactures false market depth. In crypto, fraud usually enters through trust surfaces that were visible long before the collapse.
