The greatest threats in 2025 were not entirely new types of scams. Instead, investment fraud, account takeovers, and fake customer support schemes expanded through more convincing websites, compromised accounts, and cross-border infrastructure.

The FBI's 2025 annual report recorded 61,559 complaints involving cryptocurrency investment fraud, with reported losses of approximately $7.228 billion. Other cryptocurrency-related complaints involved account takeovers, payments through ATMs or kiosks, and recovery scams.
These figures come from complaints submitted to the U.S. Internet Crime Complaint Center (IC3). They do not represent every case worldwide and cannot be used to calculate the risk of a particular country or platform directly. They do, however, show that long-term relationship investment scams and secondary recovery scams remained significant threats.
First, fake investment platforms used batches of domains and professional hosting infrastructure. In May 2025, the FBI disclosed a domain-management network associated with numerous cryptocurrency investment scam websites, showing how quickly criminal groups could migrate after an individual fake site was shut down.
Second, compromised social media accounts were used to promote fraudulent investments. An old account belonging to a real friend or KOL might suddenly post profit screenshots and limited-time opportunities, turning an existing social connection into an entry point for misplaced trust.
Third, fake customer support was combined with account takeover tactics. Scammers first impersonated a platform or financial institution and fabricated an account problem, then induced victims to provide login details, approve a verification request, or transfer assets.
Fourth, recovery scams increased. Fake lawyers, fake government representatives, and supposed on-chain experts obtained information about a victim's losses, then demanded upfront fees or collected more identity and account information under the pretext of recovering the funds.

This record should be updated only when verifiable first-party alerts or annual data become available. It should not invent a "new scam" for every month. Each update should record the publication date, issuing organization, affected channel, attack action, and recommended response.
| Time | Confirmed alert | Direct implication for users |
|---|---|---|
| February 2025 | Relationship investment scams continued to use dating and social platforms | Independently verify any platform promoted through a new personal relationship |
| May 2025 | Compromised social accounts were used to publish investment scams | Confirm even a real friend's account through another channel |
| May 2025 | Large numbers of fake investment domains shared infrastructure | A changed domain or polished website does not prove legitimacy |
| Full year 2025 | Crypto investment fraud, account takeovers, ATM schemes, and recovery scams remained prevalent | Set different loss-limiting actions based on permissions and the path of funds |
This article is a record of threats observed in 2025 and should not be treated as a real-time blacklist. Domains, wallets, and accounts change rapidly, so any current action still requires checking the latest official security notices.
Scammers may adopt new narratives, but their core actions remain relatively stable: demanding secrecy and urgency, moving the conversation into private messages, directing users to a designated entry point, requesting credentials or signatures, and asking for payment to an address that cannot be independently verified.
If you have been scammed, read the Emergency Loss Mitigation and Reporting Guide. For a complete overview of scam types, return to the Complete Guide to Cryptocurrency Scams.
No. Synthetic content made impersonation more convincing, but large losses were still commonly caused by long-term manipulation, fake platforms, and victims actively transferring funds.
No. Criminal groups can change domains quickly. Blocklists should be combined with browser protection, trusted bookmarks, account permission controls, and manual verification.
No. The figures only reflect reports received and classified by the relevant organization. They are affected by unreported cases, duplicate reports, geographic coverage, and differences in reporting methodology.
Because this article records official information and trends from 2025. A new year should have a new, verifiable record rather than overwriting the historical scope of this article.


