Security12 min read

Crypto Scam Protection Checklist: 8 Checks for the AI-Scam Era

A practical eight-step checklist for spotting AI-powered crypto scams, verifying messages and reducing irreversible mistakes before you act.

Tony Barrett

The best protection against an AI-powered crypto scam is not a better eye for fake videos. It is a verification process that does not depend on the video, voice, email or caller being genuine.

Use this rule as the spine for everything below: trust is not permission to act; verification is. If a message asks for money, credentials, a wallet connection or a transaction, move the decision onto a second channel before you do anything.

That sounds almost insultingly simple. Good. Security systems are supposed to be boring enough to follow when your heart rate is not.

Key takeaway: The more convincing the message, the more important it is to verify the request somewhere the message sender does not control.

Why have AI-powered crypto scams become harder to spot?

Generative AI weakens several warning signs people learned to rely on. Clean grammar is no longer proof. A familiar voice is no longer proof. A recognisable face on a video call is no longer proof.

The FBI has warned that criminals use AI-generated audio and video to impersonate trusted people. In a separate alert, the FBI described a campaign that used AI-generated voice messages while impersonating senior US officials. Its recommended response was not “look harder for rendering glitches.” It was to research the supposed sender independently, find a trusted phone number and verify the identity before responding.

That matters in crypto because many actions are difficult or impossible to reverse. A bank may be able to stop a card. A blockchain transfer usually does not come with a complaints department, a chargeback form or a bloke called Darren who can undo Tuesday.

AI changed the costume. It did not change the defensive principle.

What should be on a crypto scam protection checklist?

A useful checklist has to work across phishing emails, fake support agents, cloned voices, deepfake endorsements, malicious wallet approvals and poisoned addresses. These eight checks cover the decision points where a scam usually needs your cooperation.

1. Did you verify the person through an independent channel?

Never use the phone number, link or contact method supplied inside the suspicious message to verify that same message. That is not verification. That is asking the alleged burglar whether he is meant to be carrying your television.

Find the organisation's official website yourself. Use a saved contact. Call a number you already trust. Never a link, number or address supplied by the person who contacted you. A callback number they provide is part of the production.

For family, agree a code word. One word, agreed in advance, in person, never written down or sent electronically. If someone calls in distress asking for money, they can say it. That is the whole answer to a cloned voice, and it is the FBI's own recommendation: create a secret word or phrase with your family members to verify their identities. It costs one conversation over dinner and it protects the people around you as much as it protects you.

Do not substitute a personal question for the code word. "Something only they would know" is answerable from a data breach, an old post or a public profile. A word nobody has ever written down is not.

The check: Can I confirm the sender without touching anything they sent me?

2. Is the account protected by phishing-resistant authentication?

A password plus SMS code is better than a password alone, but it is not the strongest available setup. Codes can be requested by a fake login page and then relayed to the real service.

There is also the SIM swap. An attacker persuades your mobile provider to move your number onto a SIM they hold, using a little social engineering and a little of your leaked personal data. From that moment every verification text meant for you arrives with them, and the phone in your pocket goes dead in a way you may not notice for hours. This is the awkward part: SMS is the default almost everywhere, and it is the option most people have switched on.

CISA describes FIDO/WebAuthn authentication as the widely available phishing-resistant option. That includes hardware security keys and passkeys supported by the service. Where an exchange, email provider or password manager supports FIDO, use it. Where it does not, an authenticator app is still preferable to relying on SMS alone.

Your email account deserves the same protection as an exchange account. Password-reset links tend to arrive there, which makes the inbox part of the vault whether it looks like one or not.

The check: If someone stole my password today, what would still stop the login?

3. Does crypto have its own email address?

A dedicated address used only for exchanges, wallets and essential account notices reduces the number of places that address can leak. It also makes unsolicited contact easier to classify. If the “exchange support” email arrived at an address you never gave the exchange, the mystery has solved itself.

Do not use that address for newsletters, competitions, Discord accounts or random downloads. Do not publish it. Protect it with a unique password and the strongest multi-factor authentication the provider supports.

This does not make phishing impossible. It removes some of the noise and narrows the attack surface.

The check: Is this sender contacting an address they should legitimately know?

4. Is urgency doing the work that evidence should do?

“Act now.” “Your account will close.” “Only 20 minutes left.” “Connect the wallet immediately.”

Urgency is manufactured, because urgency is what stops you checking. And it is doing that work inside a category that is already disqualifying: no legitimate organisation in this industry will contact you and ask you to move your money. Not your exchange, not your wallet manufacturer, not a support team, not a regulator. There are no exceptions to hunt for, which is exactly what makes it a usable rule. You are not being asked to tell a good approach from a bad one, only to notice that an approach arrived.

Set a cooling-off rule before the message arrives. Routine requests wait long enough for you to verify them. Unusual transfers wait longer. Anything involving a seed phrase gets rejected outright because legitimate support does not need it.

The check: What breaks if I stop for ten minutes and verify this somewhere else?

// Tip

The scammers upgraded. Your operating process can too. Don't Get Rekt is a free five-day email course covering the Four Buckets and Six Defensive Actions, without coin picks or panic.

5. Did you verify the full wallet address on the signing device?

Checking only the first and last few characters is no longer enough. Address-poisoning attackers can create lookalike addresses with familiar beginnings and endings, then place them in your transaction history through a tiny transfer.

MetaMask's current guidance says to pay particular attention to the middle characters, not just the start and end. Better still, use a saved or allowlisted destination that you previously verified, or obtain the address from an independent trusted source.

Confirm the full destination on the hardware-wallet or signing-device screen. For a new or high-value destination, send a small test transaction and confirm receipt before sending the remainder. A test transaction adds cost and time. It is still cheaper than discovering that clipboard history is not a recovery mechanism.

The check: Am I verifying the destination itself, or merely recognising a shortened version of it?

6. Have you kept holdings and account details private?

A public portfolio screenshot gives a scammer three useful things: evidence that you hold crypto, clues about where you hold it, and a rough idea of whether the effort might be worthwhile.

Keep exact holdings, wallet screenshots, exchange names and account details out of public posts and unsolicited direct messages. The same applies to private groups full of people you do not actually know. A Discord avatar and three months of helpful comments do not constitute a background check.

You can discuss principles without publishing an inventory. The goal is not secrecy theatre. It is refusing to hand an attacker the research brief.

The check: Would this information help a stranger target me more precisely?

7. Have you reviewed connected apps and token approvals?

Connecting a wallet and approving token access are different actions. A disconnected website may still have an on-chain allowance that permits its smart contract to spend a token.

MetaMask explains that token approvals allow a decentralised application to access and move tokens on your behalf. Revoking an allowance removes that access, although the revocation itself is an on-chain transaction and normally costs gas.

Review approvals in the wallet's official portfolio tool or the relevant network's block explorer. Remove permissions you no longer need. Read each transaction before signing; disconnecting a site is housekeeping, not a substitute for reviewing allowances.

The structural fix is to keep the wallet that browses separate from the wallet that holds. The one you connect to websites carries walking-around money and nothing else; the one holding your actual position connects to nothing, ever. Then a signature you did not understand costs you a small amount instead of everything, which turns a catastrophe into a lesson.

The check: Which contracts can still move assets from this wallet, and why do they still need that permission?

8. Is there a written cooling-off threshold for unusual transactions?

“Be careful” is not a control. A written threshold is.

Choose an amount or transaction type that automatically triggers a pause, an independent address check and, where appropriate, a second person. The threshold is personal. The mechanism is not: define it while calm, then obey it when a message is pushing you to hurry.

This is Fortress First in miniature. The decision rule exists before the pressure arrives. You do not need to invent judgement while someone is counting down from sixty and calling you “sir” with suspicious enthusiasm.

The check: What pre-written rule governs this transaction, and have I followed it?

What should you do when a crypto message looks suspicious?

Stop interacting with it. Do not click another link, download another file, connect a wallet or send a “small amount to verify.” Preserve the message and note what happened.

Then move to channels you control:

  • Open the official app or type the organisation's known website address yourself.
  • Change compromised credentials from a clean device, starting with email.
  • Revoke suspicious token approvals using an official wallet or block-explorer tool.
  • Contact the relevant exchange, wallet provider, bank or card issuer through its official support channel.
  • If money or personal information was taken, report it promptly. Australians can use Scamwatch and the cybercrime reporting path linked there. US readers can report to the FBI's Internet Crime Complaint Center.

If a seed phrase or private key was exposed, changing a password does not repair that wallet. MetaMask's incident guidance says to act as soon as possible: create a fresh wallet with a new recovery phrase in a separate browser profile or device, move any remaining assets, then retire every account derived from the compromised phrase. If you suspect a sweeper script, do not add gas or improvise a rescue; get qualified, trusted assistance first. Do not accept help from unsolicited replies to a public post about the incident. Scammers monitor those too.

How often should you run this checklist?

Run it once now to fix the infrastructure. Then use the relevant checks at the moment of action.

A quarterly review is a sensible operating cadence for account access, recovery methods, saved destinations, connected apps and token approvals. It is also frequent enough to notice that the backup phone died six months ago or the security key is living in a drawer at the office you left last year.

For the broader setup around wallets, seed phrases, recovery and account security, use the complete crypto security checklist. The scam checklist is the decision layer. The security checklist is the infrastructure underneath it.

Frequently asked questions

Can AI deepfakes be detected by looking for visual glitches?

Sometimes, but that should not be the control you rely on. Visual and audio artefacts change as tools improve. Verify the identity and request through an independent channel even when the media looks convincing.

Will a hardware wallet protect me from every crypto scam?

No. A hardware wallet protects private keys and makes transaction details available for confirmation, but it cannot decide whether the destination or smart-contract approval is legitimate. Read the signing screen and verify the action independently.

Is authenticator-app 2FA enough for a crypto exchange?

It is stronger than SMS-based verification, but CISA identifies FIDO/WebAuthn as the widely available phishing-resistant option. Use a security key or passkey when the service supports it; otherwise use an authenticator app rather than SMS alone.

How can I tell whether a wallet address has been poisoned?

Do not trust transaction history by appearance alone. Compare the full address against a saved or independently obtained destination, including the middle characters, and confirm it on the signing-device screen. A small test transaction adds another check for a new destination.

Should I revoke every token approval?

Not automatically. Some active applications need an allowance to work. Review what each approval permits, remove the ones you no longer need and understand that revocation normally requires an on-chain transaction and gas.

What is the single most important anti-scam rule?

Never let a message verify itself. If it asks for money, credentials, a wallet connection or a transaction, confirm the person and the request through a channel you found independently.

The system is the advantage

AI makes imitation cheaper. It does not make verification obsolete.

The eight checks above all enforce the same spine: trust is not permission to act; verification is. Put the rules in place before the urgent message, cloned voice or convincing video arrives. Then the system can hold when your instincts are being pushed in the wrong direction.

The scammers upgraded. Your process can too. Start the free five-day Don't Get Rekt course →


Crypto Decoded teaches process and systems for managing digital assets. This article is not financial advice and is not a recommendation to buy, sell, or hold any asset, product, or security.

// Free daily email

Want this kind of analysis in your inbox?

A short daily email that decodes the crypto market for people who didn't grow up with it. No hype. No financial advice. Just the signal.

No spam. No financial advice. Unsubscribe anytime.

Tony Barrett
Tony Barrett
Law / MBA / CompSci · 1,500+ Coaching Sessions

Former corporate lawyer and strategy consultant who spent 5 years going deep on crypto so you don't have to. I teach systems, not picks.

Subscribe to the daily email →