Blog / Security

Monero scams and how to avoid them

Monero's cryptography has never been the weak point. Almost every loss comes from a person being persuaded to hand something over, or from software that was not what it claimed to be.

·9 min read
SecurityScamsPhishingSeeds

Monero has strong cryptography and an irreversible ledger. Those two facts together produce a specific security reality: nobody is going to break your keys, and nobody can undo a transaction once it is made. There is no chargeback, no support line with a reversal button, and no protocol-level recovery.

Which means every successful attack is really a social or software attack. Here are the ones that actually work, roughly in order of how much they cost people, with the habit that defeats each.

The one rule

Before anything else:

Your seed phrase is your money. Anyone who has it owns your funds, immediately and permanently. No legitimate person, service, developer, moderator, exchange, wallet, or support agent will ever need it. There is no exception, no verification process, no migration, no airdrop and no security check that requires it. Every single request for a seed phrase is theft in progress, without exception.

If you internalise nothing else, internalise that. It defeats the majority of what follows.

Fake wallets and lookalike sites

The highest-volume attack. Someone builds a wallet that works exactly as advertised — pleasant interface, correct addresses, real balances — and quietly sends every seed it generates or imports to the attacker. Funds may sit untouched for months before being swept, so "it worked fine for a while" proves nothing.

Distribution is through search results (including paid ads that outrank the real project), app stores, forum posts, and domains one character away from the real thing.

How to defend:

  • Type the domain yourself, or use a bookmark you created from a source you trust. Never reach a wallet through a search ad. Attackers buy ads for exactly these terms because they convert extremely well.
  • Check the domain character by character before entering anything. Substituted letters, added hyphens, different suffixes, and lookalike Unicode characters are all in use.
  • On app stores, look for signals a scammer cannot fake cheaply: long publishing history, large install counts, a developer name matching the project, and an official link from the project's own site to the store listing.
  • Prefer open-source wallets whose code you or others can inspect. Open source is not a guarantee — plenty of malicious code is public — but a closed wallet asking for your seed offers you nothing at all.
  • Test with a small amount first whenever you use anything new.

Seed phishing

The direct approach, dressed up in whatever story is most plausible today:

  • "Validate your wallet to continue using it."
  • "Your wallet is affected by a vulnerability — migrate now."
  • "Connect your wallet to claim your airdrop."
  • "Complete verification to unlock your withdrawal."
  • A support agent in a chat who needs to "check your seed against our records."

Some are crude. Some are excellent — pixel-perfect clones of a real interface, with a convincing pretext and a countdown timer.

How to defend: apply the one rule above without thinking about it. The moment anything asks for your seed, the interaction is over. Do not evaluate the story, do not reply, do not try to work out whether this particular case is legitimate. It never is.

Note the specific danger of urgency: legitimate software does not create time pressure about your keys. A countdown, a threatened deadline, or a warning that your funds are "at risk unless you act now" is a manipulation technique, and recognising it is often faster than analysing the content.

"Recovery services"

A cruel one, because it targets people who have already lost money.

You post about a lost wallet, a forgotten passphrase, a scam. Within hours you receive messages from accounts offering recovery — hackers with special tools, forensic specialists, a "blockchain recovery team". They ask for an upfront fee, or your seed, or both.

These are always fraudulent. Not usually — always. Monero's keys cannot be brute-forced; if a partial seed were recoverable it would be recoverable by you with public tools. The people contacting you found you by monitoring public posts from victims, which is exactly why they arrive so fast.

How to defend: treat any unsolicited offer of recovery as a second attempt on you. Never post publicly that you have lost funds if you can avoid it, and never pay anyone up front to recover crypto.

Giveaways and doublers

"Send 1 XMR, receive 2 back." Impersonated exchanges, fake project accounts, hijacked social media profiles, live-streamed videos with a QR code overlaid.

The variant that catches more sophisticated people is the impersonated support account. You post a question in a public channel. Within minutes someone with the project's name and logo direct-messages you offering help, then walks you toward a "validation" site or asks for your seed.

How to defend: nobody gives away free money. Real project staff do not initiate direct messages about support. Verify anything unexpected through the project's official site, not through a link the message provided.

Clipboard hijacking

Malware sits on your machine watching for anything that looks like a cryptocurrency address. When you copy one, it silently substitutes the attacker's address. You paste, glance at the first few characters — which some variants even match — and send your funds to a stranger.

This is malware, not persuasion, and it hits people who would never fall for a phishing message.

How to defend:

  • Always verify the pasted address against the source, checking the beginning and the end, not just the start.
  • Use a QR code where possible; hijacking a camera scan is much harder.
  • Send a small test amount first for any large or first-time transfer. Two transactions of a few cents in fees is cheap insurance.
  • Keep your operating system clean. If you suspect infection, do not transact on that machine at all.

Malicious remote nodes

Specific to Monero, and underappreciated.

If your wallet connects to someone else's node, that node operator sees your IP address and every transaction you broadcast through it. A hostile node cannot steal your funds or read your balance — the cryptography holds — but it can build a picture of your activity, and it can misreport network state in ways that are inconvenient or misleading.

How to defend:

  • Run your own node if you can. It is the only complete answer. Our self-hosting guide covers doing so alongside a light wallet server.
  • If you use a remote node, use one run by someone you have reason to trust, and route through Tor so the operator does not also learn your IP.
  • Understand what a light wallet server sees. If you use a light wallet, some party holds your view key and can see everything you receive. That is a deliberate trade-off, not a scam — but it must be an informed choice. We explain exactly what it means here.

Malicious mining software

Mining attracts a particular kind of attack, because the people downloading miners have hardware worth hijacking and often disable antivirus to get the software running.

Fake builds of popular miners are widespread, distributed through search results and download aggregators. They mine — for the attacker — and frequently bundle credential stealers that go looking for wallet files.

How to defend: download mining software only from the project's official repository, verify the published hashes, and be sceptical of any build that is not the official one. More detail in our mining guide.

Supply chain compromise

The most sophisticated category, and it has happened to Monero directly: in 2019 the official Monero website was compromised and served a tampered binary for a period. It was caught quickly because a user checked the hash and found it did not match, but some people were affected.

The lesson is not that the project is untrustworthy. It is that downloading from the right website is necessary but not sufficient.

How to defend: verify what you downloaded. The project publishes hashes and GPG signatures for its binaries, and checking them takes under a minute. Almost nobody does it, which is exactly why the attack is worth attempting. If you are downloading software that will hold your money, check the hash.

This is also a real argument for browser-based tooling that has nothing to install: there is no binary to tamper with, and you can inspect what runs. It comes with its own trade-offs — you are trusting the page you loaded — but the attack surface is a different shape.

Fake exchanges and pressure to move funds

Two related patterns.

Fake exchanges look completely functional. Deposits work, the interface shows profits, small withdrawals may even succeed to build confidence. Then large withdrawals require a fee, a tax payment, or an identity check that never resolves.

Investment schemes — often the long-form romance or friendship variety — build trust over weeks before introducing a platform with guaranteed returns. These are patient, well-scripted, and devastating.

How to defend: guaranteed returns do not exist. An unsolicited introduction to a trading opportunity is a script. And a platform requiring you to deposit more money to release your existing funds is confirming it is fake — no legitimate service ever works that way.

The red flag checklist

If any of these appear, stop:

  • Anyone asks for your seed phrase, ever, for any reason.
  • Anyone asks for your private spend key.
  • Urgency — a countdown, a deadline, a warning that funds are at risk unless you act now.
  • An unsolicited direct message offering support, recovery or an opportunity.
  • A guaranteed return, or free money for sending money.
  • A link you did not seek out, particularly from a search ad.
  • A demand to pay a fee to release funds you already own.
  • Software downloaded from anywhere other than the official source.
  • A request to disable antivirus or grant unusual permissions.

Habits that make you hard to rob

Rather than a list of things to fear, a short list of things to do:

  • Bookmark the real sites and use only those bookmarks.
  • Verify addresses in full, at both ends, before every send.
  • Send a test transaction for anything new or large.
  • Check hashes and signatures on downloaded software.
  • Keep the seed offline, on paper or metal, never photographed, never typed anywhere except the wallet you are deliberately restoring.
  • Separate your funds: a small hot wallet for spending, the bulk somewhere you touch rarely.
  • Slow down when something feels urgent. Urgency is manufactured almost every time it appears.

The short version

Monero itself is not the risk. The seed is the whole system, and every meaningful loss traces back to it being handed over, or to software that was not what it claimed to be.

If you never share your seed, only install software you verified from its official source, and check addresses before you send, you have eliminated nearly the entire attack surface — and the small remainder is mostly patience: the willingness to stop for thirty seconds when something is urgent, unsolicited, or too good to be true.

Our wallet is open source and fully self-hostable precisely so you never have to take our word for what it does. That is the standard worth demanding from anything that touches your keys — including us.

Open your Monero wallet in the browser

Free, open source, non-custodial. BIP-39, MyMonero 13-word, Polyseed and 25-word seeds. Nothing to install.

Open Wallet →