Orca Crypto
Attacks

Attacks and scams

Thirteen ways people actually lose crypto, and what each one needs from you to work.

13Attacks covered
4Moves they share
1Habit that stops most
0Reversals
Loading live prices
Every way this actually goes wrong

Thirteen attacks, and what each one needs from you

Almost nobody loses crypto to cryptography. They lose it because they were persuaded to sign something, or told somebody a phrase, or trusted a face on a screen.

Impersonation

Phishing emails and messages

A message that looks like it came from a service you use, built to get a click.

How it works
Extortion

Sextortion phishing

An email claiming to have recorded you, demanding payment in crypto. It is a bluff.

How it works
Malware

Ransomware

Software that encrypts your files and demands crypto to release them.

How it works
Surveillance and bait

Wallet dusting

Tiny unrequested amounts sent to your wallet so somebody can follow what you do next.

How it works
Long con

Pig butchering and romance scams

A relationship built over weeks, then an investment platform that is entirely fake.

How it works
Impersonation

Fake support and impersonation

Somebody posing as help, reaching you first, after you asked a question in public.

How it works
Impersonation

Giveaway and doubling scams

Send one and get two back. Nobody has ever got two back.

How it works
Account takeover

SIM swap attacks

Somebody moves your phone number to their SIM, then resets everything that trusts your number.

How it works
Drainer

Malicious airdrops and claim sites

A free token you did not ask for, and a claim page built to empty the wallet.

How it works
Malware

Clipboard hijacking

Malware that swaps the address you copied for one belonging to somebody else.

How it works
Impersonation

Counterfeit wallets and extensions

A wallet app or browser extension that is a working copy, plus a copy of your keys.

How it works
Real world

Physical safety and operational security

The attack that does not need any code: somebody who knows you hold crypto.

How it works
Impersonation

Deepfakes and AI impersonation

Video and voice of somebody real, saying something they never said.

How it works
The shape they all share

Four moves, in the same order, every time

  1. Contact you did not start

    An email, a message, a reply, a search advert, a wrong number. Almost every loss begins with something that arrived rather than something you went looking for.

  2. A reason to feel something

    Urgency, fear, greed or affection. The emotion is not a side effect, it is the mechanism. It is there to stop you doing the boring check that would end the whole thing.

  3. One irreversible action

    A signature, a seed phrase, a transfer, an install. Every attack narrows to a single moment where you do something that cannot be undone.

  4. Silence afterward

    By the time anything looks wrong the transaction has confirmed. There is no chargeback, no fraud department, and no reversal.

The one habit
If you learn one habit from this whole section, make it this: anything that arrives unrequested and wants an action from you is hostile until you have verified it through a channel you already trusted. That single rule defeats most of the thirteen pages above.
Sorted by how it reaches you

The same list, grouped

AttackTypeWhat it wants
Phishing emails and messagesImpersonationA message that looks like it came from a service you use, built to get a click.
Sextortion phishingExtortionAn email claiming to have recorded you, demanding payment in crypto. It is a bluff.
RansomwareMalwareSoftware that encrypts your files and demands crypto to release them.
Wallet dustingSurveillance and baitTiny unrequested amounts sent to your wallet so somebody can follow what you do next.
Pig butchering and romance scamsLong conA relationship built over weeks, then an investment platform that is entirely fake.
Fake support and impersonationImpersonationSomebody posing as help, reaching you first, after you asked a question in public.
Giveaway and doubling scamsImpersonationSend one and get two back. Nobody has ever got two back.
SIM swap attacksAccount takeoverSomebody moves your phone number to their SIM, then resets everything that trusts your number.
Malicious airdrops and claim sitesDrainerA free token you did not ask for, and a claim page built to empty the wallet.
Clipboard hijackingMalwareMalware that swaps the address you copied for one belonging to somebody else.
Counterfeit wallets and extensionsImpersonationA wallet app or browser extension that is a working copy, plus a copy of your keys.
Physical safety and operational securityReal worldThe attack that does not need any code: somebody who knows you hold crypto.
Deepfakes and AI impersonationImpersonationVideo and voice of somebody real, saying something they never said.
What actually protects you

Six things, in order of how much they help

The seed phrase never leaves paper

No photo, no cloud, no file, no support agent, no validation page. This one rule alone prevents most total losses.

A hardware wallet for anything meaningful

It puts a second screen between a malicious site and your keys, and that screen cannot be faked by a website.

Authenticator app, never SMS

SMS two factor is only as strong as the support desk at your mobile carrier, and that has repeatedly not been strong enough.

Bookmarks instead of search

Most drainer traffic arrives through paid adverts sitting above the real site. Never search for a crypto site you already use.

A burner wallet for anything new

Claims, mints, unfamiliar apps. Fund it with gas and nothing else, and a bad signature costs you nothing.

A pause before anything irreversible

Every one of these attacks needs you to act now. Waiting ten minutes and checking independently breaks almost all of them.

Go through your own setup with somebody

We look at what you actually hold and how it is stored, check approvals, fix the weak points, and set up a recovery plan. You keep control of everything and we never ask for keys.