Skip to content

EU9MY3 Crypto Resource

How to Avoid Crypto Scams in India in 2026: A Practical Anti-Fraud Guide

  • Author: EDITORIAL TEAM
  • Last updated:
  • Educational information

How to Avoid Crypto Scams in India in 2026: A Practical Anti-Fraud Guide content

Last updated: 2026

Author: EDITORIAL TEAM

Affiliate disclosure: This article may contain affiliate links. We may receive compensation when a reader follows an eligible link or registers with a featured service. Affiliate relationships do not change the security checks, warnings or reporting guidance presented here. No platform should be treated as risk-free merely because it appears on this website.

Crypto scams rarely introduce themselves as scams. They usually arrive disguised as something useful: an exchange support message, an investment opportunity, a tax warning, a profitable Telegram group, a new trading app or an expert offering to recover previously stolen funds.

That disguise is what makes crypto fraud dangerous.

A fake platform can display realistic market prices and fabricated profits. A WhatsApp group can contain hundreds of accounts posting convincing payment screenshots. A caller can know your name, exchange account details or recent complaint. A malicious application can use the logo of a real company. A deepfake video can appear to show a recognisable business leader promoting an investment.

The safest response is not to become better at guessing which stranger looks trustworthy. It is to stop relying on appearances and verify every important claim through an independent channel.

This guide explains how to avoid crypto scams in India by examining where fraud normally begins, what the scammer wants you to do and which checks can interrupt the attack before funds leave your control.

It covers:

  • Fake and cloned cryptocurrency exchanges
  • Telegram and WhatsApp investment groups
  • Exchange, government and celebrity impersonation
  • Remote-access and screen-sharing scams
  • Phishing websites, malicious APKs and fake apps
  • Seed-phrase and wallet-connection traps
  • UPI and peer-to-peer transaction risks
  • Crypto recovery scams
  • Immediate reporting through India’s official cybercrime system

This information is educational. It is not financial, investment, tax or legal advice, and following a checklist cannot eliminate every risk.

Quick Answer: How Can You Avoid Crypto Scams in India?

To avoid most crypto scams in India, apply five rules before sending money, connecting a wallet or sharing account information:

  1. Do not trust financial opportunities received through unsolicited messages.
  2. Open exchanges and wallets only through a previously verified bookmark or official application.
  3. Never reveal your password, OTP, private key or recovery phrase.
  4. Never install a remote-access application for an unsolicited support caller.
  5. Treat every demand for an additional withdrawal, tax, verification or recovery fee as a possible continuation of the fraud.

If money has already been sent through UPI, IMPS, a card or another banking channel, contact your bank immediately and report the incident to the National Cyber Crime Reporting Portal. India’s official portal directs victims of cyber financial fraud to call 1930 for immediate reporting.

Speed matters. Reporting quickly does not guarantee that funds will be recovered, but delaying gives fraudsters more time to move the money through additional bank accounts, exchanges or wallets.

Why Crypto Scams Are Difficult to Recognise

Many people imagine a scam website as a badly designed page full of spelling mistakes. That stereotype is outdated.

Modern fraud operations may use:

  • Professionally designed dashboards
  • Live prices copied from legitimate exchanges
  • Customer-support chat systems
  • Fake KYC procedures
  • Mobile applications with polished interfaces
  • Fabricated withdrawal histories
  • Real company registration details copied from unrelated businesses
  • Paid advertisements
  • Artificially generated reviews
  • Deepfake videos and AI-generated voices
  • Groups populated by bots or coordinated operators

CERT-In warned in 2026 that AI-assisted phishing, impersonation, fake websites and deepfake-based financial requests may appear highly convincing. Its guidance recommends independently verifying urgent calls, videos and messages rather than trusting the quality of the presentation.

The fraudster’s goal is usually to move you through several psychological stages.

The usual scam sequence

StageWhat the victim seesWhat is actually happening
AttentionAn ad, message, call or group invitationThe scammer is identifying possible targets
AuthorityA mentor, support agent, official or public figureTrust is being manufactured
ProofProfit screenshots, reviews or a successful small payoutResistance is being lowered
EscalationA request for a larger depositThe main financial extraction begins
ObstructionWithdrawal pending, KYC failure or tax noticeThe victim is being prepared for another payment
ExtortionUnlock fee, security deposit or recovery chargeThe scam continues after the original loss
DisappearanceAccounts, websites and contacts vanishThe operation changes identity and targets new victims

The most effective moment to stop a scam is before the first transfer. The second-best moment is when the scammer asks for more money to release funds that supposedly already belong to you.

1. Fake and Cloned Crypto Exchanges

A fake crypto exchange is a website or application created to imitate a legitimate trading platform. Some clones copy a real exchange’s logo, colours, menus and sign-in page. Others invent a professional-sounding brand and present themselves as an exclusive institutional trading service.

A fake exchange does not need to execute genuine trades. It only needs to convince the user that trading is happening.

After a victim deposits INR or cryptocurrency, the dashboard may display a growing account balance. The scammers can add fictional bonuses, profitable trades and referral rewards. None of these figures prove that assets are actually held for the user.

How a fake exchange normally works

The journey often begins with one of these routes:

  • A sponsored search advertisement
  • A Telegram or WhatsApp investment group
  • A fake social-media support account
  • A dating or friendship contact recommending a platform
  • A direct message promising access to an exclusive token sale
  • A cloned app promoted as an Indian or VIP version
  • A website address that differs from a known exchange by one character

The user is encouraged to make a modest initial deposit. The platform may then allow a small withdrawal. This is not reliable proof of legitimacy. Processing an early withdrawal can be part of the confidence-building stage.

An I4C advisory about fraudulent investment applications describes the same broader pattern: victims are directed from advertisements and messaging groups to fake trading platforms, early payouts may be used to gain trust, and communication stops after a significant deposit is made.

Once a larger amount is deposited, the account may be frozen. The supposed support department then requests one or more of the following:

  • Withdrawal processing fee
  • GST payment
  • Income-tax clearance
  • Anti-money-laundering deposit
  • Credit-score repair payment
  • Security verification amount
  • Wallet activation charge
  • Cross-border transfer fee
  • Insurance payment
  • Liquidity proof
  • Refundable risk deposit

Paying one charge usually produces another obstacle. The displayed balance may continue to rise, but the user still cannot access it.

How to check a crypto exchange before using it

Start with the domain. Search for differences such as:

  • Additional hyphens
  • Reversed letters
  • Unusual subdomains
  • Misspelled brand names
  • Different domain extensions
  • Words such as “VIP,” “pro,” “India,” “secure” or “official” added to the brand
  • A login page hosted on an unrelated domain

Do not assume that appearing in a paid search advertisement makes a platform legitimate. Open the exchange through a manually verified bookmark rather than searching for it every time.

Check the company’s support documentation, legal identity, fee schedule and withdrawal rules. Search for independent warnings about the exact domain, not only the displayed brand name.

India’s National Cyber Crime Reporting Portal now provides a Suspect Repository through which citizens can check certain mobile numbers, email addresses, account numbers, URLs and other identifiers for possible links to cybercrime. It also allows suspicious websites, applications, WhatsApp numbers and Telegram handles to be reported.

Does FIU-IND registration prove that an exchange is safe?

No.

FIU-IND reporting-entity registration is an important compliance checkpoint for a virtual digital asset service provider operating within the applicable Indian anti-money-laundering framework. FIU-IND published updated AML and counter-terrorist-financing guidelines for VDA service providers in January 2026, along with revised registration material.

However, registration should not be interpreted as:

  • Government insurance for customer deposits
  • A guarantee against hacking
  • Approval of every token listed by the platform
  • Proof that every advertisement is genuine
  • A guarantee that withdrawals will always be available
  • Protection against market losses
  • A substitute for checking the exact website or app

A scammer can falsely claim that a platform is FIU registered. It can also copy the name or registration information of a real business. Verify the current information through FIU-IND rather than relying on a badge displayed by the platform.

2. Telegram and WhatsApp Crypto Investment Groups

Telegram and WhatsApp are useful communication tools, but their group structure can be exploited to manufacture social proof.

A typical crypto investment group may contain hundreds of apparently active participants. Members post screenshots showing profits, thank the administrator and discuss upcoming trades. A mentor, professor, analyst or account manager shares daily instructions.

The activity may look spontaneous. In reality, many members may be bots, controlled accounts or participants working with the organisers.

Warning signs of a fraudulent crypto group

Be especially cautious when a group includes several of these signals:

  • You were added without requesting access
  • Members promise fixed or guaranteed returns
  • The administrator claims a near-perfect trading record
  • Users are told to contact a manager privately
  • Deposits are sent to changing bank accounts or wallet addresses
  • The recommended platform is unavailable through normal channels
  • The group prohibits questions about regulation or withdrawals
  • Members are pressured to borrow money
  • A countdown is used to create urgency
  • A “VIP tier” requires a larger deposit
  • Early withdrawals are presented as conclusive proof
  • Support demands more money when a withdrawal is requested

The I4C has warned that fraudulent investment promotions can use sponsored advertisements and deepfake content to redirect users to WhatsApp or Telegram groups. Its advisory also describes fake trading applications, mule bank accounts and early payouts used to establish trust before a larger loss.

The small-withdrawal confidence trick

One of the most persuasive tactics is allowing the victim to withdraw a small amount.

For example, a user deposits ₹5,000 and is allowed to withdraw ₹6,000. The transaction appears to prove that the platform works. The group then persuades the user to deposit ₹1 lakh or more.

The first payout may simply be funded from money collected from other victims. It is a marketing expense for the scam.

A successful small withdrawal does not prove that:

  • Real trading took place
  • The displayed balance is genuine
  • Larger withdrawals will be honoured
  • The application is secure
  • The company is compliant
  • The person running the group is qualified
  • The same bank account will remain available

What to do when you are added to a suspicious group

Do not debate with the organisers. Do not click links to investigate them on the same device that holds your banking or wallet applications.

Instead:

  1. Record the group name and administrator handles if it is safe to do so.
  2. Capture relevant messages without revealing additional personal data.
  3. Leave the group.
  4. Block the contacts.
  5. Use the platform’s reporting function.
  6. Report suspicious identifiers through the official cybercrime portal.
  7. Warn friends privately if their numbers are visible in the group.

Never send funds to a personal wallet controlled by a mentor, account manager or portfolio operator.

3. Exchange Support and Government Impersonation

Impersonation scams exploit authority. The caller does not need to convince you that an investment is profitable. They only need to make you believe that failing to cooperate will cause an account freeze, tax penalty or criminal case.

Common impersonated organisations include:

  • Crypto exchanges
  • Banks and UPI providers
  • FIU-IND
  • The Income Tax Department
  • RBI
  • Police departments
  • Enforcement agencies
  • Telecom providers
  • Courier companies
  • Wallet security teams

A fake exchange agent may claim that your KYC has expired. A supposed tax officer may say that undeclared crypto income has been detected. A caller posing as police may allege that your Aadhaar, SIM card or bank account has been connected to money laundering.

The objective is to create fear before you have time to verify the story.

Digital-arrest and intimidation scams

I4C’s advisory on digital-arrest fraud describes criminals posing as police, CBI, RBI, narcotics or enforcement personnel. Victims may be kept on video calls, shown fake police-station settings and pressured to transfer money. The advisory states that there is no concept of a digital arrest under Indian law and advises people to verify claims directly with the nearest police station.

A crypto-themed version may involve a demand to move assets to:

  • A safe government wallet
  • An investigation account
  • A temporary escrow address
  • A verification wallet
  • A court-supervised address
  • A tax-clearance account

Do not transfer funds to prove that they are legitimate. Do not move crypto to a wallet provided by a caller.

FIU-IND impersonation

FIU-IND carries a prominent warning that it does not seek information from individuals and that fraudulent letters or queries impersonating the organisation should be reported.

This is particularly important because scammers may use FIU terminology to sound credible. They may mention VDA reporting, anti-money-laundering reviews, suspicious transaction reports or registration checks.

Official-sounding language does not make a demand genuine.

How to verify an urgent support message

Do not use the link or telephone number included in the suspicious communication.

Close the message and independently open the exchange’s verified application or bookmarked website. Check for an alert inside the account. Contact support through the help section you opened yourself.

Ask:

  • Is the issue visible inside my account?
  • Does the official support ticket contain the same reference number?
  • Is the sender using an official domain?
  • Why is payment being requested through a private wallet or UPI ID?
  • Why must this be completed immediately?
  • Why am I being asked to install software?
  • Why can the matter not be confirmed through the platform’s normal support channel?

A real organisation should not object to independent verification.

4. Remote-Access and Screen-Sharing Scams

Remote-access software has legitimate uses. The danger begins when an unknown caller persuades you to install it, reveal a connection code or approve control of your device.

CERT-In has warned that screen-sharing applications can be abused by fraudsters posing as company representatives. Once access is granted, the attacker may view activity on the device and capture banking information, UPI PINs or OTPs.

How the scam unfolds

The caller normally starts with a believable problem:

  • Your exchange withdrawal has failed
  • A suspicious login has been detected
  • Your account needs a security update
  • Your KYC documents were rejected
  • A refund must be processed
  • Your bank account has been linked to fraud
  • Your wallet needs to be synchronised

You are instructed to install a remote-support application. The caller may emphasise that the app is available in an official store. That does not make the caller’s request safe. A legitimate tool can still be misused after you approve a remote connection.

The scammer may ask you to:

  • Read a connection number aloud
  • Accept a screen-sharing request
  • Enable accessibility permissions
  • Open your banking application
  • Log in to an exchange
  • Display a wallet recovery phrase
  • Enter an OTP
  • Turn off security warnings
  • Keep the call active while completing a payment

Once you share access, assume that anything displayed on the device may have been seen.

What legitimate support can do without controlling your phone

A genuine support team can normally:

  • Review an account from its own systems
  • Ask for a transaction reference
  • Request non-sensitive screenshots with private information removed
  • Explain standard troubleshooting steps
  • Open a support ticket
  • Ask you to reinstall an official application yourself
  • Direct you to verified documentation

It does not need unrestricted control of your device.

If you installed a remote-access app for a suspicious caller

Take action from a different, trusted device where possible:

  1. Disconnect the affected device from Wi-Fi and mobile data.
  2. End active remote sessions.
  3. Uninstall the remote-access application.
  4. Review accessibility, screen-recording and device-administrator permissions.
  5. Change your email, exchange and banking passwords.
  6. Reset two-factor authentication where compromise is possible.
  7. Contact your bank and exchange through official channels.
  8. Review recent sessions and transactions.
  9. Revoke unrecognised wallet approvals.
  10. Report any financial loss immediately.

A normal uninstall may not remove separate malware downloaded during the session. Where the exposure is serious, obtain professional device-security assistance or consider a secure reset after preserving evidence.

5. Phishing Websites, Fake Apps and Malicious APK Files

Phishing attempts to make you enter sensitive information into a fake interface. The attacker may copy an exchange login page, wallet connection screen, support form or token-claim website.

The page may request:

  • Username and password
  • One-time password
  • Exchange PIN
  • Private key
  • Twelve-word or twenty-four-word recovery phrase
  • Wallet signature
  • QR-code scan
  • Identity documents
  • Debit-card details

A cryptocurrency wallet’s recovery phrase is particularly sensitive. Anyone who obtains it may be able to control the associated wallet. No genuine support agent needs it to investigate an account problem.

Fake login pages

A phishing link can arrive through:

  • Email
  • SMS
  • WhatsApp
  • Telegram
  • Social-media comments
  • Search advertisements
  • Fake support accounts
  • QR codes
  • Calendar invitations
  • Cloud documents
  • Job offers
  • Airdrop promotions

The domain may look correct at a glance. On a mobile screen, the browser may hide part of the address, making a small spelling change harder to notice.

Never log in from a link sent with an urgent message. Open the application or type the verified domain independently.

Fake mobile apps

Fake applications may imitate the appearance and functions of legitimate services. CERT-In notes that fraudulent apps can harvest credentials, intercept sensitive information, track users or install additional malicious software.

Check:

  • Exact developer or publisher name
  • Link from the company’s verified website
  • Number and quality of reviews
  • Requested permissions
  • Application update history
  • Privacy information
  • Whether the name contains subtle spelling changes
  • Whether the download was promoted by an unknown person

Official app stores reduce some risks but do not eliminate them. I4C’s investment-fraud advisory specifically notes that criminals may distribute fake trading applications through app-store links as well as APK files.

Malicious APK downloads

An APK is an Android application installation package. Scammers often distribute APK files directly through messaging apps or websites because this can bypass ordinary store-based discovery and review processes.

A malicious crypto APK may request:

  • SMS access
  • Notification access
  • Accessibility control
  • Screen capture
  • Contact access
  • File access
  • Permission to install other applications
  • Permission to display over other apps

These permissions can be abused to intercept OTPs, copy credentials or create deceptive overlays.

Do not install a financial application merely because a group administrator describes it as:

  • VIP software
  • A beta version
  • An India-only release
  • An institutional trading terminal
  • A faster withdrawal app
  • A tax-compliant upgrade
  • A premium wallet
  • A private mining application

The more exclusive the supposed application, the more carefully it should be verified.

Clipboard address replacement

Some malware monitors copied cryptocurrency addresses and substitutes an attacker-controlled address when the user pastes.

Before approving a transfer:

  1. Compare the beginning and end of the address.
  2. Check several characters in the middle.
  3. Confirm the network.
  4. Verify the destination through a second channel.
  5. Use address-book or allow-list features where available.
  6. Be suspicious if a saved address changes unexpectedly.

For a new destination, a small test transfer can reduce losses caused by an address mistake, but it does not prove that an investment platform is legitimate. Scammers may process small transactions intentionally to build confidence.

6. Wallet-Connection and Token-Approval Scams

Not every crypto theft requires the victim to reveal a password. A malicious website may ask the user to connect a wallet and approve a transaction that grants the attacker permission over certain tokens.

These pages are often presented as:

  • Airdrop claims
  • NFT minting sites
  • Wallet verification tools
  • Staking platforms
  • Token migrations
  • Refund portals
  • Account recovery pages
  • Liquidity rewards
  • Presale registrations

The wallet prompt may not clearly resemble a transfer. It could be a signature or approval request.

Before confirming, read the wallet message. Ask why the site needs approval, which asset is affected and whether the permission is unlimited.

Avoid connecting a wallet containing substantial assets to an unfamiliar website. A separate low-value wallet can limit exposure when interacting with new decentralised applications, but it cannot make a malicious contract safe.

Periodically review token approvals using a trusted blockchain explorer or wallet security feature and revoke permissions that are no longer required.

7. Celebrity Giveaways, Deepfakes and Impersonated Executives

The classic giveaway scam asks a user to send cryptocurrency first and promises to return a larger amount.

The advertisement may use:

  • A celebrity’s photograph
  • A fake livestream
  • A copied company account
  • An AI-generated interview
  • A deepfake video
  • A fabricated news article
  • Comments from fake winners

No legitimate giveaway needs you to send crypto to receive more crypto back.

In 2026, polished video and realistic audio are no longer sufficient proof of identity. CERT-In advises users to verify voice calls, video messages and urgent financial requests through independent channels because AI-generated impersonation can be convincing.

Look for the announcement on the organisation’s official website and verified accounts. Do not rely on a link provided by the advertisement itself.

8. UPI and Peer-to-Peer Crypto Scams

Peer-to-peer crypto trading can create additional risks because payment and asset transfer may occur through separate systems.

Common problems include:

  • Fake payment screenshots
  • Reversed or disputed transfers
  • Payments from third-party bank accounts
  • Requests to communicate outside the platform
  • Fraudulently obtained money sent to a seller
  • Pressure to release crypto before payment is confirmed
  • QR codes that initiate a payment instead of receiving one
  • Overpayment and refund tricks
  • Use of mule accounts

Never rely on a screenshot

A payment screenshot can be edited. Confirm that funds have been credited by checking your bank account directly.

Do not release cryptocurrency because the buyer claims:

  • The transfer is delayed
  • The banking server is slow
  • The payment will appear after release
  • A screenshot is sufficient evidence
  • The platform has confirmed it privately
  • An agent is supervising the trade

Use the platform’s formal dispute process.

Avoid unexplained third-party payments

A buyer may ask a friend, employee or customer to pay on their behalf. That creates uncertainty about the source of funds and can increase the risk of a later dispute.

Where platform rules require the payment name to match the verified user, do not bypass that protection.

Keep:

  • Order identifiers
  • In-platform messages
  • Bank records
  • Payment references
  • Counterparty details
  • Transaction hashes
  • Dispute correspondence

Do not move the conversation to a private messenger merely because the counterparty offers a better rate.

9. Recovery Scams: Fraud After the First Fraud

A recovery scam targets someone who has already lost money.

The victim may post publicly about the theft or search for ways to recover cryptocurrency. A supposed blockchain investigator, lawyer, ethical hacker or recovery agency then makes contact.

The person claims to have:

  • Located the stolen wallet
  • Frozen the scammer’s account
  • Hacked the exchange
  • Obtained a court order
  • Found an insider
  • Recovered part of the funds
  • Identified a private-key vulnerability

Before releasing the supposed recovery, the victim must pay a tracing charge, legal deposit, gas fee, wallet activation fee or tax.

After payment, another charge appears.

Why recovery scams are effective

The victim is no longer motivated by greed or excitement. They are motivated by urgency, embarrassment and hope.

They may also be willing to ignore warning signs because the recovery agent appears to know details of the original fraud. Those details may have been obtained from:

  • Public social-media posts
  • Information submitted to a fake complaint website
  • Data shared between connected scam groups
  • The original fraudsters themselves

Can stolen cryptocurrency ever be recovered?

Sometimes investigations lead to accounts being frozen or assets being traced, particularly where funds pass through identifiable bank accounts or centralised services. That possibility does not mean a private stranger can guarantee recovery.

No genuine professional should promise certainty before examining the evidence and explaining the legal basis, limitations, fees and jurisdiction involved.

Be extremely cautious when someone:

  • Contacts you without being asked
  • Guarantees full recovery
  • Demands payment in cryptocurrency
  • Claims to work secretly with police
  • Refuses to provide a verifiable office or professional registration
  • Asks for your seed phrase
  • Requests access to your wallet
  • Says immediate payment is necessary to stop the funds moving
  • Shows a fake wallet balance as proof of recovery

Report through official channels first. Do not pay a second scammer to solve the first scam.

A 15-Point Crypto Platform Verification Checklist

Before depositing money or connecting a wallet, complete these checks.

1. Verify the exact domain

Inspect every character. Do not rely on the logo or page design.

2. Open the site independently

Avoid links from messages, groups, advertisements and social-media comments.

3. Check the legal entity

Look for a company name, registered address, terms of service, privacy policy and dispute process. Verify the entity independently where possible.

4. Check FIU-related claims

Confirm current information through FIU-IND. Treat reporting-entity registration as one compliance check, not a guarantee of financial safety. FIU’s VDA guidance was updated in January 2026, so older third-party lists may be incomplete.

5. Confirm the official application link

Follow the link from the verified website to the relevant app store. Compare the publisher details.

6. Examine permissions

A trading app should not need unnecessary accessibility, screen-control or contact permissions.

7. Read the withdrawal rules

Look for minimum withdrawals, network fees, KYC requirements, processing periods and account restrictions.

8. Search for the exact URL

Search the full domain with terms such as “scam,” “complaint,” “withdrawal” and “fraud.” Do not search only the brand name.

9. Check the destination of payments

A legitimate service should explain why funds are being sent to a specific account. Constantly changing personal bank accounts are a warning sign.

10. Reject guaranteed returns

Crypto prices and trading outcomes are uncertain. Fixed daily profits are not a normal feature of genuine market activity.

11. Question exclusivity

Institutional access, VIP algorithms, secret mining pools and guaranteed presale allocations are common persuasion devices.

12. Never reveal security secrets

Passwords, OTPs, private keys and seed phrases should not be shared with support personnel.

13. Test support without exposing data

Ask a general question through the official support system. Assess whether responses are documented, consistent and professional.

14. Check the Cybercrime Suspect Repository

The National Cyber Crime Reporting Portal allows citizens to check certain suspected identifiers and report suspicious websites or applications. An identifier not appearing in the repository should not be treated as proof that it is safe.

15. Be willing to walk away

A legitimate opportunity will survive independent verification. Pressure to act before checking is itself a reason to stop.

What to Do Immediately After a Suspected Crypto Scam

The correct response depends on what has already happened.

You clicked a suspicious link but entered nothing

Close the page. Do not download files from it.

Clear the site’s permissions and check whether it installed a browser extension or application. Run the device’s security checks and update the browser and operating system.

If the page requested a wallet connection, confirm that no connection or approval remains active.

You entered an exchange password

Change the password through the official exchange application or bookmarked website.

Then:

  • End other account sessions
  • Change any reused password on other services
  • Enable or reset two-factor authentication
  • Check withdrawal addresses
  • Review API keys
  • Review recent trades and withdrawals
  • Contact official support

Do not use the link from the phishing message to change the password.

You revealed an OTP

Contact the affected bank, exchange or service immediately. An OTP can be time-sensitive, but it may have already authorised an action.

Review the account for:

  • New beneficiaries
  • Password changes
  • Withdrawals
  • Device registrations
  • API creation
  • Changed recovery details

You revealed a wallet seed phrase or private key

Treat the wallet as compromised.

From a clean device, create a new wallet using trusted software or hardware and move remaining assets if it is safe and technically possible. Do not reuse the exposed recovery phrase.

Be aware that an attacker may monitor the compromised wallet and attempt to move incoming assets immediately.

You signed an unknown wallet transaction

Review the transaction through the appropriate blockchain explorer. Check for token approvals, operator permissions or asset transfers.

Revoke dangerous approvals where possible and move remaining assets if the wallet remains exposed.

You installed a suspicious APK or remote-access tool

Disconnect the device from the internet. Use a separate device to secure email, banking and exchange accounts.

Do not immediately delete every item if law enforcement may require evidence, but prioritise stopping continuing access and financial loss.

You sent INR through UPI or a bank transfer

Contact the bank or payment provider immediately using its verified fraud-reporting channel. Provide the transaction reference, beneficiary details, amount and time.

Then call 1930 and submit a report through the National Cyber Crime Reporting Portal. India’s official systems instruct victims to report cyber financial fraud promptly through these channels.

You sent cryptocurrency

Record:

  • Transaction hash
  • Sending address
  • Receiving address
  • Asset and network
  • Date and time
  • Amount
  • Exchange withdrawal record
  • Related chats and account names
  • Website and application details

Notify the exchange from which the funds were withdrawn and any identifiable receiving service. A platform may be able to flag an address or account, but do not assume that a confirmed blockchain transaction can simply be cancelled.

How to Report a Crypto Scam in India

Step 1: Call 1930 for financial cyber fraud

The National Cyber Crime Reporting Portal identifies 1930 as the helpline for immediate cyber financial fraud reporting.

Have the following ready:

  • Your name and contact information
  • Date and approximate time of the incident
  • Amount lost
  • Bank or UPI transaction reference
  • Cryptocurrency transaction hash
  • Beneficiary account or wallet address
  • Phone numbers and usernames used by the scammer
  • Website or application details

Step 2: Submit an online complaint

Use the official National Cyber Crime Reporting Portal and select the relevant financial-fraud or cybercrime category.

The portal supports complaint registration and tracking. It also provides state and Union Territory nodal and grievance-officer information for users who need appropriate escalation.

Step 3: Contact your bank or payment provider

Use the number shown in the official banking application, statement or bank website. Do not use a number found in an advertisement or supplied by the scammer.

RBI directions require regulated payment providers and banks to maintain channels for reporting unauthorised electronic transactions and emphasise prompt notification by customers.

Step 4: Contact the legitimate exchange or wallet provider

Report impersonation, unauthorised access and the destination address through the official support system.

Ask for a case reference. Preserve all replies.

Step 5: Report suspicious identifiers

Even when no money was lost, I4C’s Report Suspect facility accepts information about suspicious website URLs, WhatsApp numbers, Telegram handles, phone numbers, email addresses and social-media URLs.

Step 6: Preserve evidence

Keep original files where possible, including:

  • Full screenshots
  • Chat exports
  • Email headers
  • Audio recordings already lawfully available to you
  • Payment receipts
  • Wallet addresses
  • Transaction hashes
  • Application files or names
  • Advertisement details
  • Support-ticket numbers

Do not edit screenshots in a way that removes dates, usernames or transaction details.

Step 7: Consider a local police complaint

For substantial losses, identity theft, threats or continuing extortion, contact the appropriate police or cybercrime unit. Follow instructions from official authorities regarding additional documentation.

No reporting route guarantees recovery. Reporting remains important because it may help authorities identify connected accounts, warn other users and investigate broader fraud networks.

Crypto Tax Claims Used as a Scam Tactic

Scammers exploit genuine tax rules to make fraudulent demands sound official.

As reflected in Income Tax Department material updated for 2026, income arising from the transfer of virtual digital assets is generally taxed at 30% under Section 115BBH, subject to the applicable statutory rules. The department also states that Section 194S generally provides for 1% TDS on consideration paid to a resident for a VDA transfer, with specified thresholds and conditions.

The Income Tax Department’s Schedule VDA guidance also explains transaction-level reporting of VDA transfers in applicable income-tax returns.

These rules do not mean that a caller, Telegram administrator or fake exchange can demand an immediate crypto payment for:

  • Tax clearance
  • Account unfreezing
  • Release of trading profits
  • A government wallet deposit
  • Withdrawal approval
  • Prevention of arrest

Tax obligations should be handled through official tax processes and, where necessary, with assistance from a qualified chartered accountant.

Do not send cryptocurrency to a private address because someone claims it is required by the Income Tax Department, FIU-IND, RBI or police.

A Simple Zero-Trust Routine for Crypto Users

You do not need to become a cybersecurity specialist. A repeatable routine is more useful than trying to memorise every new scam name.

Before opening a link

Ask who sent it, why it was sent and whether you can reach the same destination independently.

Before installing an app

Verify the publisher through the company’s official website. Review permissions and avoid files distributed through private messages.

Before sending money

Confirm the recipient through a separate channel. Question changing bank accounts, personal UPI IDs and unexplained wallet addresses.

Before approving a wallet request

Read the transaction. Identify the asset, network, amount and permission being granted.

Before accepting support

Initiate the conversation yourself through the official platform. Refuse remote control of your device.

Before trusting profit evidence

Remember that screenshots, dashboards, group messages and small payouts can be manufactured.

Before paying a withdrawal fee

Stop. A request to deposit additional money before releasing a displayed balance is a major scam indicator.

After every important account change

Review active sessions, two-factor authentication, withdrawal addresses and recovery information.

Crypto Scam Red-Flag Table

Red flagWhy it mattersSafer response
Guaranteed daily returnsGenuine markets cannot guarantee fixed profitEnd the conversation
Unsolicited investment groupMembership and testimonials may be fabricatedLeave and report
Seed-phrase requestIt may provide complete wallet controlNever disclose it
Remote-access requestThe caller may view or control your deviceRefuse and disconnect
Upfront withdrawal chargeCommon advance-fee tacticDo not pay
Urgent tax demand by messageFear is being used to prevent verificationCheck through official channels
APK sent through TelegramThe file may contain malwareDo not install
Slightly altered domainMay be a cloned login or exchangeUse a verified bookmark
Personal UPI ID for company paymentRecipient may be a mule or unrelated personVerify independently
Successful small withdrawalMay be a confidence-building paymentDo not treat it as proof
“Send crypto to receive double”Standard giveaway scam structureBlock and report
Guaranteed recovery serviceRecovery cannot be promisedUse official reporting routes

Frequently Asked Questions

What is the easiest way to avoid crypto scams in India?

Do not act directly from an unsolicited message. Independently open the verified exchange, bank, tax or government channel and confirm the claim there. This single habit stops many phishing, impersonation and fake-support attacks.

Is every Telegram crypto group a scam?

No, but unsolicited groups offering guaranteed returns, managed accounts or fixed daily profits should be treated as highly suspicious. Group size and payment screenshots do not prove legitimacy.

Can a fake exchange show live cryptocurrency prices?

Yes. A fraudulent platform can copy public price information while fabricating the user’s balance, trades and profits. A professional dashboard does not prove that the platform holds any assets.

Does a successful withdrawal prove that a crypto platform is legitimate?

No. Some scams permit a small early withdrawal to persuade the victim to make a much larger deposit. Evaluate the company, domain, compliance claims and withdrawal process independently.

Is an FIU-IND-registered exchange completely safe?

No. Reporting-entity registration is a compliance factor, not insurance or a guarantee against hacking, insolvency, fraud, service interruption or market loss. Verify current status directly and perform additional security checks. FIU’s VDA-related AML guidance was updated in January 2026.

Will exchange support ever ask for my seed phrase?

A support agent does not need your recovery phrase to inspect an exchange account or resolve a transaction issue. Anyone who obtains the phrase may be able to take control of the wallet it protects.

Is it safe to install a remote-access app from an official app store?

The software itself may be legitimate, but granting control to an unknown caller is dangerous. CERT-In has documented how fraudsters misuse screen-sharing applications to capture banking and authentication information.

Can police or tax officials ask me to transfer crypto for verification?

Treat such a demand as fraudulent. I4C warns against intimidation scams involving impersonated authorities and says there is no concept of digital arrest under Indian law. FIU-IND also warns that it does not seek information directly from individuals.

What should I do if I downloaded a suspicious crypto APK?

Disconnect the device, stop using it for financial activity and secure your important accounts from another trusted device. Review permissions, remove the application, check for additional malware and report any unauthorised transactions.

Can someone recover cryptocurrency after it has been stolen?

Recovery is uncertain. In some cases, authorities or service providers may trace or freeze assets, but no private recovery agent can guarantee success. Be cautious of anyone demanding an upfront cryptocurrency payment.

Where should I report crypto fraud in India?

For cyber financial fraud, call 1930 promptly and submit a complaint through the National Cyber Crime Reporting Portal. Contact your bank, payment provider and affected exchange through verified channels as well.

What evidence should I save?

Preserve transaction references, wallet addresses, transaction hashes, chat histories, telephone numbers, Telegram handles, website URLs, app information, payment receipts and communications with the platform.

Can a scammer use a real company’s name?

Yes. Fraudsters may copy real company names, addresses, logos and registration information. Verify that the exact domain, application publisher, support channel and payment recipient belong to the genuine company.

Are crypto profits still taxable in India in 2026?

Current Income Tax Department guidance states that income from transfers of VDAs is generally subject to the 30% framework under Section 115BBH, while Section 194S provides for 1% TDS in applicable VDA transfers, subject to statutory conditions and thresholds. Obtain personalised guidance from a qualified chartered accountant.

Should I pay a fee to unlock profits shown on a crypto platform?

Do not make an additional payment until the platform has been independently verified. Repeated demands for tax, AML, security or withdrawal deposits are a common advance-fee fraud pattern.

Final Safety Checklist

Before you send money, connect a wallet or install software, stop and check:

  • Did I initiate this contact?
  • Am I using the exact verified domain?
  • Have I independently confirmed the person’s identity?
  • Is anyone promising guaranteed returns?
  • Am I being rushed?
  • Am I being asked to keep the opportunity secret?
  • Is the payment going to an individual or changing account?
  • Am I being asked for an OTP, password or seed phrase?
  • Am I being asked to install remote-access software?
  • Is an extra payment required before withdrawal?
  • Can I verify the claim through an official application or government portal?
  • Am I prepared to stop rather than risk money I cannot recover?

The central rule is simple: do not allow urgency, authority or apparent profit to replace independent verification.

Crypto scams change names, websites and applications. Their underlying structure changes much less. Someone creates trust, displays proof that cannot be independently verified, demands money, blocks withdrawal and asks for another payment.

Recognising that sequence early is one of the most practical ways to avoid crypto scams in India.


Financial and Legal Disclaimer

This article is provided for general education and fraud awareness. It does not constitute financial, investment, tax, cybersecurity or legal advice. Cryptocurrency and other virtual digital assets can involve market, custody, technology, regulatory and fraud risks, including the possibility of complete loss. Reporting an incident does not guarantee that funds will be recovered. Verify current government, regulatory and tax information through official sources and consult an appropriately qualified professional for advice relating to your circumstances.

How to Avoid Crypto Scams in India in 2026: A Practical Anti-Fraud Guide

Last updated: 2026

Author: EDITORIAL TEAM

Affiliate disclosure: This article may contain affiliate links. We may receive compensation when a reader follows an eligible link or registers with a featured service. Affiliate relationships do not change the security checks, warnings or reporting guidance presented here. No platform should be treated as risk-free merely because it appears on this website.

Crypto scams rarely introduce themselves as scams. They usually arrive disguised as something useful: an exchange support message, an investment opportunity, a tax warning, a profitable Telegram group, a new trading app or an expert offering to recover previously stolen funds.

That disguise is what makes crypto fraud dangerous.

A fake platform can display realistic market prices and fabricated profits. A WhatsApp group can contain hundreds of accounts posting convincing payment screenshots. A caller can know your name, exchange account details or recent complaint. A malicious application can use the logo of a real company. A deepfake video can appear to show a recognisable business leader promoting an investment.

The safest response is not to become better at guessing which stranger looks trustworthy. It is to stop relying on appearances and verify every important claim through an independent channel.

This guide explains how to avoid crypto scams in India by examining where fraud normally begins, what the scammer wants you to do and which checks can interrupt the attack before funds leave your control.

It covers:

  • Fake and cloned cryptocurrency exchanges
  • Telegram and WhatsApp investment groups
  • Exchange, government and celebrity impersonation
  • Remote-access and screen-sharing scams
  • Phishing websites, malicious APKs and fake apps
  • Seed-phrase and wallet-connection traps
  • UPI and peer-to-peer transaction risks
  • Crypto recovery scams
  • Immediate reporting through India’s official cybercrime system

This information is educational. It is not financial, investment, tax or legal advice, and following a checklist cannot eliminate every risk.

Quick Answer: How Can You Avoid Crypto Scams in India?

To avoid most crypto scams in India, apply five rules before sending money, connecting a wallet or sharing account information:

  1. Do not trust financial opportunities received through unsolicited messages.
  2. Open exchanges and wallets only through a previously verified bookmark or official application.
  3. Never reveal your password, OTP, private key or recovery phrase.
  4. Never install a remote-access application for an unsolicited support caller.
  5. Treat every demand for an additional withdrawal, tax, verification or recovery fee as a possible continuation of the fraud.

If money has already been sent through UPI, IMPS, a card or another banking channel, contact your bank immediately and report the incident to the National Cyber Crime Reporting Portal. India’s official portal directs victims of cyber financial fraud to call 1930 for immediate reporting.

Speed matters. Reporting quickly does not guarantee that funds will be recovered, but delaying gives fraudsters more time to move the money through additional bank accounts, exchanges or wallets.

Why Crypto Scams Are Difficult to Recognise

Many people imagine a scam website as a badly designed page full of spelling mistakes. That stereotype is outdated.

Modern fraud operations may use:

  • Professionally designed dashboards
  • Live prices copied from legitimate exchanges
  • Customer-support chat systems
  • Fake KYC procedures
  • Mobile applications with polished interfaces
  • Fabricated withdrawal histories
  • Real company registration details copied from unrelated businesses
  • Paid advertisements
  • Artificially generated reviews
  • Deepfake videos and AI-generated voices
  • Groups populated by bots or coordinated operators

CERT-In warned in 2026 that AI-assisted phishing, impersonation, fake websites and deepfake-based financial requests may appear highly convincing. Its guidance recommends independently verifying urgent calls, videos and messages rather than trusting the quality of the presentation.

The fraudster’s goal is usually to move you through several psychological stages.

The usual scam sequence

StageWhat the victim seesWhat is actually happening
AttentionAn ad, message, call or group invitationThe scammer is identifying possible targets
AuthorityA mentor, support agent, official or public figureTrust is being manufactured
ProofProfit screenshots, reviews or a successful small payoutResistance is being lowered
EscalationA request for a larger depositThe main financial extraction begins
ObstructionWithdrawal pending, KYC failure or tax noticeThe victim is being prepared for another payment
ExtortionUnlock fee, security deposit or recovery chargeThe scam continues after the original loss
DisappearanceAccounts, websites and contacts vanishThe operation changes identity and targets new victims

The most effective moment to stop a scam is before the first transfer. The second-best moment is when the scammer asks for more money to release funds that supposedly already belong to you.

1. Fake and Cloned Crypto Exchanges

A fake crypto exchange is a website or application created to imitate a legitimate trading platform. Some clones copy a real exchange’s logo, colours, menus and sign-in page. Others invent a professional-sounding brand and present themselves as an exclusive institutional trading service.

A fake exchange does not need to execute genuine trades. It only needs to convince the user that trading is happening.

After a victim deposits INR or cryptocurrency, the dashboard may display a growing account balance. The scammers can add fictional bonuses, profitable trades and referral rewards. None of these figures prove that assets are actually held for the user.

How a fake exchange normally works

The journey often begins with one of these routes:

  • A sponsored search advertisement
  • A Telegram or WhatsApp investment group
  • A fake social-media support account
  • A dating or friendship contact recommending a platform
  • A direct message promising access to an exclusive token sale
  • A cloned app promoted as an Indian or VIP version
  • A website address that differs from a known exchange by one character

The user is encouraged to make a modest initial deposit. The platform may then allow a small withdrawal. This is not reliable proof of legitimacy. Processing an early withdrawal can be part of the confidence-building stage.

An I4C advisory about fraudulent investment applications describes the same broader pattern: victims are directed from advertisements and messaging groups to fake trading platforms, early payouts may be used to gain trust, and communication stops after a significant deposit is made.

Once a larger amount is deposited, the account may be frozen. The supposed support department then requests one or more of the following:

  • Withdrawal processing fee
  • GST payment
  • Income-tax clearance
  • Anti-money-laundering deposit
  • Credit-score repair payment
  • Security verification amount
  • Wallet activation charge
  • Cross-border transfer fee
  • Insurance payment
  • Liquidity proof
  • Refundable risk deposit

Paying one charge usually produces another obstacle. The displayed balance may continue to rise, but the user still cannot access it.

How to check a crypto exchange before using it

Start with the domain. Search for differences such as:

  • Additional hyphens
  • Reversed letters
  • Unusual subdomains
  • Misspelled brand names
  • Different domain extensions
  • Words such as “VIP,” “pro,” “India,” “secure” or “official” added to the brand
  • A login page hosted on an unrelated domain

Do not assume that appearing in a paid search advertisement makes a platform legitimate. Open the exchange through a manually verified bookmark rather than searching for it every time.

Check the company’s support documentation, legal identity, fee schedule and withdrawal rules. Search for independent warnings about the exact domain, not only the displayed brand name.

India’s National Cyber Crime Reporting Portal now provides a Suspect Repository through which citizens can check certain mobile numbers, email addresses, account numbers, URLs and other identifiers for possible links to cybercrime. It also allows suspicious websites, applications, WhatsApp numbers and Telegram handles to be reported.

Does FIU-IND registration prove that an exchange is safe?

No.

FIU-IND reporting-entity registration is an important compliance checkpoint for a virtual digital asset service provider operating within the applicable Indian anti-money-laundering framework. FIU-IND published updated AML and counter-terrorist-financing guidelines for VDA service providers in January 2026, along with revised registration material.

However, registration should not be interpreted as:

  • Government insurance for customer deposits
  • A guarantee against hacking
  • Approval of every token listed by the platform
  • Proof that every advertisement is genuine
  • A guarantee that withdrawals will always be available
  • Protection against market losses
  • A substitute for checking the exact website or app

A scammer can falsely claim that a platform is FIU registered. It can also copy the name or registration information of a real business. Verify the current information through FIU-IND rather than relying on a badge displayed by the platform.

2. Telegram and WhatsApp Crypto Investment Groups

Telegram and WhatsApp are useful communication tools, but their group structure can be exploited to manufacture social proof.

A typical crypto investment group may contain hundreds of apparently active participants. Members post screenshots showing profits, thank the administrator and discuss upcoming trades. A mentor, professor, analyst or account manager shares daily instructions.

The activity may look spontaneous. In reality, many members may be bots, controlled accounts or participants working with the organisers.

Warning signs of a fraudulent crypto group

Be especially cautious when a group includes several of these signals:

  • You were added without requesting access
  • Members promise fixed or guaranteed returns
  • The administrator claims a near-perfect trading record
  • Users are told to contact a manager privately
  • Deposits are sent to changing bank accounts or wallet addresses
  • The recommended platform is unavailable through normal channels
  • The group prohibits questions about regulation or withdrawals
  • Members are pressured to borrow money
  • A countdown is used to create urgency
  • A “VIP tier” requires a larger deposit
  • Early withdrawals are presented as conclusive proof
  • Support demands more money when a withdrawal is requested

The I4C has warned that fraudulent investment promotions can use sponsored advertisements and deepfake content to redirect users to WhatsApp or Telegram groups. Its advisory also describes fake trading applications, mule bank accounts and early payouts used to establish trust before a larger loss.

The small-withdrawal confidence trick

One of the most persuasive tactics is allowing the victim to withdraw a small amount.

For example, a user deposits ₹5,000 and is allowed to withdraw ₹6,000. The transaction appears to prove that the platform works. The group then persuades the user to deposit ₹1 lakh or more.

The first payout may simply be funded from money collected from other victims. It is a marketing expense for the scam.

A successful small withdrawal does not prove that:

  • Real trading took place
  • The displayed balance is genuine
  • Larger withdrawals will be honoured
  • The application is secure
  • The company is compliant
  • The person running the group is qualified
  • The same bank account will remain available

What to do when you are added to a suspicious group

Do not debate with the organisers. Do not click links to investigate them on the same device that holds your banking or wallet applications.

Instead:

  1. Record the group name and administrator handles if it is safe to do so.
  2. Capture relevant messages without revealing additional personal data.
  3. Leave the group.
  4. Block the contacts.
  5. Use the platform’s reporting function.
  6. Report suspicious identifiers through the official cybercrime portal.
  7. Warn friends privately if their numbers are visible in the group.

Never send funds to a personal wallet controlled by a mentor, account manager or portfolio operator.

3. Exchange Support and Government Impersonation

Impersonation scams exploit authority. The caller does not need to convince you that an investment is profitable. They only need to make you believe that failing to cooperate will cause an account freeze, tax penalty or criminal case.

Common impersonated organisations include:

  • Crypto exchanges
  • Banks and UPI providers
  • FIU-IND
  • The Income Tax Department
  • RBI
  • Police departments
  • Enforcement agencies
  • Telecom providers
  • Courier companies
  • Wallet security teams

A fake exchange agent may claim that your KYC has expired. A supposed tax officer may say that undeclared crypto income has been detected. A caller posing as police may allege that your Aadhaar, SIM card or bank account has been connected to money laundering.

The objective is to create fear before you have time to verify the story.

Digital-arrest and intimidation scams

I4C’s advisory on digital-arrest fraud describes criminals posing as police, CBI, RBI, narcotics or enforcement personnel. Victims may be kept on video calls, shown fake police-station settings and pressured to transfer money. The advisory states that there is no concept of a digital arrest under Indian law and advises people to verify claims directly with the nearest police station.

A crypto-themed version may involve a demand to move assets to:

  • A safe government wallet
  • An investigation account
  • A temporary escrow address
  • A verification wallet
  • A court-supervised address
  • A tax-clearance account

Do not transfer funds to prove that they are legitimate. Do not move crypto to a wallet provided by a caller.

FIU-IND impersonation

FIU-IND carries a prominent warning that it does not seek information from individuals and that fraudulent letters or queries impersonating the organisation should be reported.

This is particularly important because scammers may use FIU terminology to sound credible. They may mention VDA reporting, anti-money-laundering reviews, suspicious transaction reports or registration checks.

Official-sounding language does not make a demand genuine.

How to verify an urgent support message

Do not use the link or telephone number included in the suspicious communication.

Close the message and independently open the exchange’s verified application or bookmarked website. Check for an alert inside the account. Contact support through the help section you opened yourself.

Ask:

  • Is the issue visible inside my account?
  • Does the official support ticket contain the same reference number?
  • Is the sender using an official domain?
  • Why is payment being requested through a private wallet or UPI ID?
  • Why must this be completed immediately?
  • Why am I being asked to install software?
  • Why can the matter not be confirmed through the platform’s normal support channel?

A real organisation should not object to independent verification.

4. Remote-Access and Screen-Sharing Scams

Remote-access software has legitimate uses. The danger begins when an unknown caller persuades you to install it, reveal a connection code or approve control of your device.

CERT-In has warned that screen-sharing applications can be abused by fraudsters posing as company representatives. Once access is granted, the attacker may view activity on the device and capture banking information, UPI PINs or OTPs.

How the scam unfolds

The caller normally starts with a believable problem:

  • Your exchange withdrawal has failed
  • A suspicious login has been detected
  • Your account needs a security update
  • Your KYC documents were rejected
  • A refund must be processed
  • Your bank account has been linked to fraud
  • Your wallet needs to be synchronised

You are instructed to install a remote-support application. The caller may emphasise that the app is available in an official store. That does not make the caller’s request safe. A legitimate tool can still be misused after you approve a remote connection.

The scammer may ask you to:

  • Read a connection number aloud
  • Accept a screen-sharing request
  • Enable accessibility permissions
  • Open your banking application
  • Log in to an exchange
  • Display a wallet recovery phrase
  • Enter an OTP
  • Turn off security warnings
  • Keep the call active while completing a payment

Once you share access, assume that anything displayed on the device may have been seen.

What legitimate support can do without controlling your phone

A genuine support team can normally:

  • Review an account from its own systems
  • Ask for a transaction reference
  • Request non-sensitive screenshots with private information removed
  • Explain standard troubleshooting steps
  • Open a support ticket
  • Ask you to reinstall an official application yourself
  • Direct you to verified documentation

It does not need unrestricted control of your device.

If you installed a remote-access app for a suspicious caller

Take action from a different, trusted device where possible:

  1. Disconnect the affected device from Wi-Fi and mobile data.
  2. End active remote sessions.
  3. Uninstall the remote-access application.
  4. Review accessibility, screen-recording and device-administrator permissions.
  5. Change your email, exchange and banking passwords.
  6. Reset two-factor authentication where compromise is possible.
  7. Contact your bank and exchange through official channels.
  8. Review recent sessions and transactions.
  9. Revoke unrecognised wallet approvals.
  10. Report any financial loss immediately.

A normal uninstall may not remove separate malware downloaded during the session. Where the exposure is serious, obtain professional device-security assistance or consider a secure reset after preserving evidence.

5. Phishing Websites, Fake Apps and Malicious APK Files

Phishing attempts to make you enter sensitive information into a fake interface. The attacker may copy an exchange login page, wallet connection screen, support form or token-claim website.

The page may request:

  • Username and password
  • One-time password
  • Exchange PIN
  • Private key
  • Twelve-word or twenty-four-word recovery phrase
  • Wallet signature
  • QR-code scan
  • Identity documents
  • Debit-card details

A cryptocurrency wallet’s recovery phrase is particularly sensitive. Anyone who obtains it may be able to control the associated wallet. No genuine support agent needs it to investigate an account problem.

Fake login pages

A phishing link can arrive through:

  • Email
  • SMS
  • WhatsApp
  • Telegram
  • Social-media comments
  • Search advertisements
  • Fake support accounts
  • QR codes
  • Calendar invitations
  • Cloud documents
  • Job offers
  • Airdrop promotions

The domain may look correct at a glance. On a mobile screen, the browser may hide part of the address, making a small spelling change harder to notice.

Never log in from a link sent with an urgent message. Open the application or type the verified domain independently.

Fake mobile apps

Fake applications may imitate the appearance and functions of legitimate services. CERT-In notes that fraudulent apps can harvest credentials, intercept sensitive information, track users or install additional malicious software.

Check:

  • Exact developer or publisher name
  • Link from the company’s verified website
  • Number and quality of reviews
  • Requested permissions
  • Application update history
  • Privacy information
  • Whether the name contains subtle spelling changes
  • Whether the download was promoted by an unknown person

Official app stores reduce some risks but do not eliminate them. I4C’s investment-fraud advisory specifically notes that criminals may distribute fake trading applications through app-store links as well as APK files.

Malicious APK downloads

An APK is an Android application installation package. Scammers often distribute APK files directly through messaging apps or websites because this can bypass ordinary store-based discovery and review processes.

A malicious crypto APK may request:

  • SMS access
  • Notification access
  • Accessibility control
  • Screen capture
  • Contact access
  • File access
  • Permission to install other applications
  • Permission to display over other apps

These permissions can be abused to intercept OTPs, copy credentials or create deceptive overlays.

Do not install a financial application merely because a group administrator describes it as:

  • VIP software
  • A beta version
  • An India-only release
  • An institutional trading terminal
  • A faster withdrawal app
  • A tax-compliant upgrade
  • A premium wallet
  • A private mining application

The more exclusive the supposed application, the more carefully it should be verified.

Clipboard address replacement

Some malware monitors copied cryptocurrency addresses and substitutes an attacker-controlled address when the user pastes.

Before approving a transfer:

  1. Compare the beginning and end of the address.
  2. Check several characters in the middle.
  3. Confirm the network.
  4. Verify the destination through a second channel.
  5. Use address-book or allow-list features where available.
  6. Be suspicious if a saved address changes unexpectedly.

For a new destination, a small test transfer can reduce losses caused by an address mistake, but it does not prove that an investment platform is legitimate. Scammers may process small transactions intentionally to build confidence.

6. Wallet-Connection and Token-Approval Scams

Not every crypto theft requires the victim to reveal a password. A malicious website may ask the user to connect a wallet and approve a transaction that grants the attacker permission over certain tokens.

These pages are often presented as:

  • Airdrop claims
  • NFT minting sites
  • Wallet verification tools
  • Staking platforms
  • Token migrations
  • Refund portals
  • Account recovery pages
  • Liquidity rewards
  • Presale registrations

The wallet prompt may not clearly resemble a transfer. It could be a signature or approval request.

Before confirming, read the wallet message. Ask why the site needs approval, which asset is affected and whether the permission is unlimited.

Avoid connecting a wallet containing substantial assets to an unfamiliar website. A separate low-value wallet can limit exposure when interacting with new decentralised applications, but it cannot make a malicious contract safe.

Periodically review token approvals using a trusted blockchain explorer or wallet security feature and revoke permissions that are no longer required.

7. Celebrity Giveaways, Deepfakes and Impersonated Executives

The classic giveaway scam asks a user to send cryptocurrency first and promises to return a larger amount.

The advertisement may use:

  • A celebrity’s photograph
  • A fake livestream
  • A copied company account
  • An AI-generated interview
  • A deepfake video
  • A fabricated news article
  • Comments from fake winners

No legitimate giveaway needs you to send crypto to receive more crypto back.

In 2026, polished video and realistic audio are no longer sufficient proof of identity. CERT-In advises users to verify voice calls, video messages and urgent financial requests through independent channels because AI-generated impersonation can be convincing.

Look for the announcement on the organisation’s official website and verified accounts. Do not rely on a link provided by the advertisement itself.

8. UPI and Peer-to-Peer Crypto Scams

Peer-to-peer crypto trading can create additional risks because payment and asset transfer may occur through separate systems.

Common problems include:

  • Fake payment screenshots
  • Reversed or disputed transfers
  • Payments from third-party bank accounts
  • Requests to communicate outside the platform
  • Fraudulently obtained money sent to a seller
  • Pressure to release crypto before payment is confirmed
  • QR codes that initiate a payment instead of receiving one
  • Overpayment and refund tricks
  • Use of mule accounts

Never rely on a screenshot

A payment screenshot can be edited. Confirm that funds have been credited by checking your bank account directly.

Do not release cryptocurrency because the buyer claims:

  • The transfer is delayed
  • The banking server is slow
  • The payment will appear after release
  • A screenshot is sufficient evidence
  • The platform has confirmed it privately
  • An agent is supervising the trade

Use the platform’s formal dispute process.

Avoid unexplained third-party payments

A buyer may ask a friend, employee or customer to pay on their behalf. That creates uncertainty about the source of funds and can increase the risk of a later dispute.

Where platform rules require the payment name to match the verified user, do not bypass that protection.

Keep:

  • Order identifiers
  • In-platform messages
  • Bank records
  • Payment references
  • Counterparty details
  • Transaction hashes
  • Dispute correspondence

Do not move the conversation to a private messenger merely because the counterparty offers a better rate.

9. Recovery Scams: Fraud After the First Fraud

A recovery scam targets someone who has already lost money.

The victim may post publicly about the theft or search for ways to recover cryptocurrency. A supposed blockchain investigator, lawyer, ethical hacker or recovery agency then makes contact.

The person claims to have:

  • Located the stolen wallet
  • Frozen the scammer’s account
  • Hacked the exchange
  • Obtained a court order
  • Found an insider
  • Recovered part of the funds
  • Identified a private-key vulnerability

Before releasing the supposed recovery, the victim must pay a tracing charge, legal deposit, gas fee, wallet activation fee or tax.

After payment, another charge appears.

Why recovery scams are effective

The victim is no longer motivated by greed or excitement. They are motivated by urgency, embarrassment and hope.

They may also be willing to ignore warning signs because the recovery agent appears to know details of the original fraud. Those details may have been obtained from:

  • Public social-media posts
  • Information submitted to a fake complaint website
  • Data shared between connected scam groups
  • The original fraudsters themselves

Can stolen cryptocurrency ever be recovered?

Sometimes investigations lead to accounts being frozen or assets being traced, particularly where funds pass through identifiable bank accounts or centralised services. That possibility does not mean a private stranger can guarantee recovery.

No genuine professional should promise certainty before examining the evidence and explaining the legal basis, limitations, fees and jurisdiction involved.

Be extremely cautious when someone:

  • Contacts you without being asked
  • Guarantees full recovery
  • Demands payment in cryptocurrency
  • Claims to work secretly with police
  • Refuses to provide a verifiable office or professional registration
  • Asks for your seed phrase
  • Requests access to your wallet
  • Says immediate payment is necessary to stop the funds moving
  • Shows a fake wallet balance as proof of recovery

Report through official channels first. Do not pay a second scammer to solve the first scam.

A 15-Point Crypto Platform Verification Checklist

Before depositing money or connecting a wallet, complete these checks.

1. Verify the exact domain

Inspect every character. Do not rely on the logo or page design.

2. Open the site independently

Avoid links from messages, groups, advertisements and social-media comments.

3. Check the legal entity

Look for a company name, registered address, terms of service, privacy policy and dispute process. Verify the entity independently where possible.

4. Check FIU-related claims

Confirm current information through FIU-IND. Treat reporting-entity registration as one compliance check, not a guarantee of financial safety. FIU’s VDA guidance was updated in January 2026, so older third-party lists may be incomplete.

5. Confirm the official application link

Follow the link from the verified website to the relevant app store. Compare the publisher details.

6. Examine permissions

A trading app should not need unnecessary accessibility, screen-control or contact permissions.

7. Read the withdrawal rules

Look for minimum withdrawals, network fees, KYC requirements, processing periods and account restrictions.

8. Search for the exact URL

Search the full domain with terms such as “scam,” “complaint,” “withdrawal” and “fraud.” Do not search only the brand name.

9. Check the destination of payments

A legitimate service should explain why funds are being sent to a specific account. Constantly changing personal bank accounts are a warning sign.

10. Reject guaranteed returns

Crypto prices and trading outcomes are uncertain. Fixed daily profits are not a normal feature of genuine market activity.

11. Question exclusivity

Institutional access, VIP algorithms, secret mining pools and guaranteed presale allocations are common persuasion devices.

12. Never reveal security secrets

Passwords, OTPs, private keys and seed phrases should not be shared with support personnel.

13. Test support without exposing data

Ask a general question through the official support system. Assess whether responses are documented, consistent and professional.

14. Check the Cybercrime Suspect Repository

The National Cyber Crime Reporting Portal allows citizens to check certain suspected identifiers and report suspicious websites or applications. An identifier not appearing in the repository should not be treated as proof that it is safe.

15. Be willing to walk away

A legitimate opportunity will survive independent verification. Pressure to act before checking is itself a reason to stop.

What to Do Immediately After a Suspected Crypto Scam

The correct response depends on what has already happened.

You clicked a suspicious link but entered nothing

Close the page. Do not download files from it.

Clear the site’s permissions and check whether it installed a browser extension or application. Run the device’s security checks and update the browser and operating system.

If the page requested a wallet connection, confirm that no connection or approval remains active.

You entered an exchange password

Change the password through the official exchange application or bookmarked website.

Then:

  • End other account sessions
  • Change any reused password on other services
  • Enable or reset two-factor authentication
  • Check withdrawal addresses
  • Review API keys
  • Review recent trades and withdrawals
  • Contact official support

Do not use the link from the phishing message to change the password.

You revealed an OTP

Contact the affected bank, exchange or service immediately. An OTP can be time-sensitive, but it may have already authorised an action.

Review the account for:

  • New beneficiaries
  • Password changes
  • Withdrawals
  • Device registrations
  • API creation
  • Changed recovery details

You revealed a wallet seed phrase or private key

Treat the wallet as compromised.

From a clean device, create a new wallet using trusted software or hardware and move remaining assets if it is safe and technically possible. Do not reuse the exposed recovery phrase.

Be aware that an attacker may monitor the compromised wallet and attempt to move incoming assets immediately.

You signed an unknown wallet transaction

Review the transaction through the appropriate blockchain explorer. Check for token approvals, operator permissions or asset transfers.

Revoke dangerous approvals where possible and move remaining assets if the wallet remains exposed.

You installed a suspicious APK or remote-access tool

Disconnect the device from the internet. Use a separate device to secure email, banking and exchange accounts.

Do not immediately delete every item if law enforcement may require evidence, but prioritise stopping continuing access and financial loss.

You sent INR through UPI or a bank transfer

Contact the bank or payment provider immediately using its verified fraud-reporting channel. Provide the transaction reference, beneficiary details, amount and time.

Then call 1930 and submit a report through the National Cyber Crime Reporting Portal. India’s official systems instruct victims to report cyber financial fraud promptly through these channels.

You sent cryptocurrency

Record:

  • Transaction hash
  • Sending address
  • Receiving address
  • Asset and network
  • Date and time
  • Amount
  • Exchange withdrawal record
  • Related chats and account names
  • Website and application details

Notify the exchange from which the funds were withdrawn and any identifiable receiving service. A platform may be able to flag an address or account, but do not assume that a confirmed blockchain transaction can simply be cancelled.

How to Report a Crypto Scam in India

Step 1: Call 1930 for financial cyber fraud

The National Cyber Crime Reporting Portal identifies 1930 as the helpline for immediate cyber financial fraud reporting.

Have the following ready:

  • Your name and contact information
  • Date and approximate time of the incident
  • Amount lost
  • Bank or UPI transaction reference
  • Cryptocurrency transaction hash
  • Beneficiary account or wallet address
  • Phone numbers and usernames used by the scammer
  • Website or application details

Step 2: Submit an online complaint

Use the official National Cyber Crime Reporting Portal and select the relevant financial-fraud or cybercrime category.

The portal supports complaint registration and tracking. It also provides state and Union Territory nodal and grievance-officer information for users who need appropriate escalation.

Step 3: Contact your bank or payment provider

Use the number shown in the official banking application, statement or bank website. Do not use a number found in an advertisement or supplied by the scammer.

RBI directions require regulated payment providers and banks to maintain channels for reporting unauthorised electronic transactions and emphasise prompt notification by customers.

Step 4: Contact the legitimate exchange or wallet provider

Report impersonation, unauthorised access and the destination address through the official support system.

Ask for a case reference. Preserve all replies.

Step 5: Report suspicious identifiers

Even when no money was lost, I4C’s Report Suspect facility accepts information about suspicious website URLs, WhatsApp numbers, Telegram handles, phone numbers, email addresses and social-media URLs.

Step 6: Preserve evidence

Keep original files where possible, including:

  • Full screenshots
  • Chat exports
  • Email headers
  • Audio recordings already lawfully available to you
  • Payment receipts
  • Wallet addresses
  • Transaction hashes
  • Application files or names
  • Advertisement details
  • Support-ticket numbers

Do not edit screenshots in a way that removes dates, usernames or transaction details.

Step 7: Consider a local police complaint

For substantial losses, identity theft, threats or continuing extortion, contact the appropriate police or cybercrime unit. Follow instructions from official authorities regarding additional documentation.

No reporting route guarantees recovery. Reporting remains important because it may help authorities identify connected accounts, warn other users and investigate broader fraud networks.

Crypto Tax Claims Used as a Scam Tactic

Scammers exploit genuine tax rules to make fraudulent demands sound official.

As reflected in Income Tax Department material updated for 2026, income arising from the transfer of virtual digital assets is generally taxed at 30% under Section 115BBH, subject to the applicable statutory rules. The department also states that Section 194S generally provides for 1% TDS on consideration paid to a resident for a VDA transfer, with specified thresholds and conditions.

The Income Tax Department’s Schedule VDA guidance also explains transaction-level reporting of VDA transfers in applicable income-tax returns.

These rules do not mean that a caller, Telegram administrator or fake exchange can demand an immediate crypto payment for:

  • Tax clearance
  • Account unfreezing
  • Release of trading profits
  • A government wallet deposit
  • Withdrawal approval
  • Prevention of arrest

Tax obligations should be handled through official tax processes and, where necessary, with assistance from a qualified chartered accountant.

Do not send cryptocurrency to a private address because someone claims it is required by the Income Tax Department, FIU-IND, RBI or police.

A Simple Zero-Trust Routine for Crypto Users

You do not need to become a cybersecurity specialist. A repeatable routine is more useful than trying to memorise every new scam name.

Before opening a link

Ask who sent it, why it was sent and whether you can reach the same destination independently.

Before installing an app

Verify the publisher through the company’s official website. Review permissions and avoid files distributed through private messages.

Before sending money

Confirm the recipient through a separate channel. Question changing bank accounts, personal UPI IDs and unexplained wallet addresses.

Before approving a wallet request

Read the transaction. Identify the asset, network, amount and permission being granted.

Before accepting support

Initiate the conversation yourself through the official platform. Refuse remote control of your device.

Before trusting profit evidence

Remember that screenshots, dashboards, group messages and small payouts can be manufactured.

Before paying a withdrawal fee

Stop. A request to deposit additional money before releasing a displayed balance is a major scam indicator.

After every important account change

Review active sessions, two-factor authentication, withdrawal addresses and recovery information.

Crypto Scam Red-Flag Table

Red flagWhy it mattersSafer response
Guaranteed daily returnsGenuine markets cannot guarantee fixed profitEnd the conversation
Unsolicited investment groupMembership and testimonials may be fabricatedLeave and report
Seed-phrase requestIt may provide complete wallet controlNever disclose it
Remote-access requestThe caller may view or control your deviceRefuse and disconnect
Upfront withdrawal chargeCommon advance-fee tacticDo not pay
Urgent tax demand by messageFear is being used to prevent verificationCheck through official channels
APK sent through TelegramThe file may contain malwareDo not install
Slightly altered domainMay be a cloned login or exchangeUse a verified bookmark
Personal UPI ID for company paymentRecipient may be a mule or unrelated personVerify independently
Successful small withdrawalMay be a confidence-building paymentDo not treat it as proof
“Send crypto to receive double”Standard giveaway scam structureBlock and report
Guaranteed recovery serviceRecovery cannot be promisedUse official reporting routes

Frequently Asked Questions

What is the easiest way to avoid crypto scams in India?

Do not act directly from an unsolicited message. Independently open the verified exchange, bank, tax or government channel and confirm the claim there. This single habit stops many phishing, impersonation and fake-support attacks.

Is every Telegram crypto group a scam?

No, but unsolicited groups offering guaranteed returns, managed accounts or fixed daily profits should be treated as highly suspicious. Group size and payment screenshots do not prove legitimacy.

Can a fake exchange show live cryptocurrency prices?

Yes. A fraudulent platform can copy public price information while fabricating the user’s balance, trades and profits. A professional dashboard does not prove that the platform holds any assets.

Does a successful withdrawal prove that a crypto platform is legitimate?

No. Some scams permit a small early withdrawal to persuade the victim to make a much larger deposit. Evaluate the company, domain, compliance claims and withdrawal process independently.

Is an FIU-IND-registered exchange completely safe?

No. Reporting-entity registration is a compliance factor, not insurance or a guarantee against hacking, insolvency, fraud, service interruption or market loss. Verify current status directly and perform additional security checks. FIU’s VDA-related AML guidance was updated in January 2026.

Will exchange support ever ask for my seed phrase?

A support agent does not need your recovery phrase to inspect an exchange account or resolve a transaction issue. Anyone who obtains the phrase may be able to take control of the wallet it protects.

Is it safe to install a remote-access app from an official app store?

The software itself may be legitimate, but granting control to an unknown caller is dangerous. CERT-In has documented how fraudsters misuse screen-sharing applications to capture banking and authentication information.

Can police or tax officials ask me to transfer crypto for verification?

Treat such a demand as fraudulent. I4C warns against intimidation scams involving impersonated authorities and says there is no concept of digital arrest under Indian law. FIU-IND also warns that it does not seek information directly from individuals.

What should I do if I downloaded a suspicious crypto APK?

Disconnect the device, stop using it for financial activity and secure your important accounts from another trusted device. Review permissions, remove the application, check for additional malware and report any unauthorised transactions.

Can someone recover cryptocurrency after it has been stolen?

Recovery is uncertain. In some cases, authorities or service providers may trace or freeze assets, but no private recovery agent can guarantee success. Be cautious of anyone demanding an upfront cryptocurrency payment.

Where should I report crypto fraud in India?

For cyber financial fraud, call 1930 promptly and submit a complaint through the National Cyber Crime Reporting Portal. Contact your bank, payment provider and affected exchange through verified channels as well.

What evidence should I save?

Preserve transaction references, wallet addresses, transaction hashes, chat histories, telephone numbers, Telegram handles, website URLs, app information, payment receipts and communications with the platform.

Can a scammer use a real company’s name?

Yes. Fraudsters may copy real company names, addresses, logos and registration information. Verify that the exact domain, application publisher, support channel and payment recipient belong to the genuine company.

Are crypto profits still taxable in India in 2026?

Current Income Tax Department guidance states that income from transfers of VDAs is generally subject to the 30% framework under Section 115BBH, while Section 194S provides for 1% TDS in applicable VDA transfers, subject to statutory conditions and thresholds. Obtain personalised guidance from a qualified chartered accountant.

Should I pay a fee to unlock profits shown on a crypto platform?

Do not make an additional payment until the platform has been independently verified. Repeated demands for tax, AML, security or withdrawal deposits are a common advance-fee fraud pattern.

Final Safety Checklist

Before you send money, connect a wallet or install software, stop and check:

  • Did I initiate this contact?
  • Am I using the exact verified domain?
  • Have I independently confirmed the person’s identity?
  • Is anyone promising guaranteed returns?
  • Am I being rushed?
  • Am I being asked to keep the opportunity secret?
  • Is the payment going to an individual or changing account?
  • Am I being asked for an OTP, password or seed phrase?
  • Am I being asked to install remote-access software?
  • Is an extra payment required before withdrawal?
  • Can I verify the claim through an official application or government portal?
  • Am I prepared to stop rather than risk money I cannot recover?

The central rule is simple: do not allow urgency, authority or apparent profit to replace independent verification.

Crypto scams change names, websites and applications. Their underlying structure changes much less. Someone creates trust, displays proof that cannot be independently verified, demands money, blocks withdrawal and asks for another payment.

Recognising that sequence early is one of the most practical ways to avoid crypto scams in India.


Financial and Legal Disclaimer

This article is provided for general education and fraud awareness. It does not constitute financial, investment, tax, cybersecurity or legal advice. Cryptocurrency and other virtual digital assets can involve market, custody, technology, regulatory and fraud risks, including the possibility of complete loss. Reporting an incident does not guarantee that funds will be recovered. Verify current government, regulatory and tax information through official sources and consult an appropriately qualified professional for advice relating to your circumstances.