Scam classification supports investigation triage; it does not replace evidence validation. Similar symptoms may arise from different attack mechanisms.
Authorization phishing
The victim is induced to sign token approvals, Permit messages or malicious contract calls, after which the attacker transfers assets using delegated authority.
Immediate action: Disconnect the suspicious dApp, review approvals across all chains and move remaining assets to a clean wallet if unauthorized transfers occurred.
Seed phrase or private-key compromise
The attacker can directly sign transactions after obtaining wallet control. Revoking approvals alone usually cannot contain the loss.
Immediate action: Create a clean wallet on a trusted device and move remaining assets. Do not continue using the compromised wallet.
Fake exchange or fraudulent token
A cloned platform, fabricated returns or a token without genuine liquidity is used to induce deposits and repeated payments.
Immediate action: Stop sending funds and preserve platform pages, chats, deposit addresses and transaction hashes.
Pig-butchering and investment fraud
Trust is built over time before the victim is directed to controlled wallets or platforms. Withdrawal is then blocked by demands for tax, margin or verification fees.
Immediate action: Stop paying, export the full communication and fund timeline, and prioritize custodial or identity-bearing touchpoints.