How to Spot NFT Scams: A Collector's Field Guide
The most common NFT scams are fake mint sites, impersonation of official accounts, seed-phrase phishing, pump-and-dump groups, and counterfeit marketplaces. Almost all of them depend on tricking you into signing a wallet transaction or revealing a seed phrase. Licensed platforms with custodial wallets, like VeVe, remove those attack surfaces because there is no seed phrase to steal and no external contract to approve.

Every hobby has its pickpockets. Stamp collecting had forgers, sports cards had trimmed corners and fake grades, and digital collectibles have a whole taxonomy of scams that evolved at internet speed. The good news: nearly every NFT scam relies on the same handful of tricks, and once you can name them, they stop working on you.
This is the field guide. Learn the species, memorize the red flags, and you’ll walk through this hobby with your wallet intact.
What are the most common NFT scams?
Fake mints and copycat drops
A “mint” is the moment a new digital collectible is created and sold for the first time. Scammers love this moment because buyers are excited, rushed, and expecting to send money to a site they’ve never used before. The scam: a lookalike website announces a surprise drop from a popular project, often minutes after a real announcement, and collects payments for collectibles that never existed. The site is usually one letter off from the real domain, or a fresh domain registered that same week.
The tell: real projects announce drops in advance through their established channels. A “stealth mint” with a countdown clock pressuring you to act in the next ten minutes is a fireworks display of red flags.
Impersonation
The oldest con in a new costume. Scammers clone the profile picture, name, and posting style of an official project account or a well-known collector, then slide into replies and DMs offering “support,” whitelist spots, or exclusive deals. Discord is a favorite hunting ground: a fake “admin” messages you first, which real admins almost never do.
The tell: check the account’s age, follower history, and whether it’s the handle you’ve always known. And burn this into memory - legitimate support never contacts you first, and never via DM.
Seed-phrase phishing
If you use a self-custody crypto wallet, your seed phrase (the 12 or 24 recovery words) is the master key to everything in it. Phishers build fake “wallet validation” pages, fake support forms, and fake airdrop claims - all designed to get you to type in those words. The moment you do, everything in the wallet is gone, usually within minutes.
The tell is simple because the rule is absolute: no legitimate service, ever, for any reason, needs your seed phrase. Anyone asking for it is robbing you. There is no exception.
Pump groups and manufactured hype
Some scams don’t steal your login - they steal your judgment. Coordinated groups buy into an obscure project, flood social media with manufactured excitement and screenshots of “gains,” wait for outsiders to pile in, then dump everything and vanish. The project’s socials go quiet, and latecomers hold collectibles nobody wants.
The tell: hype with no substance underneath. No license, no named team, no actual product - just vibes, rocket emojis, and urgency. Real collecting communities talk about the art, the characters, and the chase. Pump groups only talk about the price going up.
Fake marketplaces
Counterfeit storefronts list collectibles they don’t control, or clone a real marketplace’s design down to the pixel and harvest your payment details or wallet approvals. Some even display real collectibles scraped from legitimate platforms to look convincing.
The tell: you arrived via a link from a DM, a reply, or an ad rather than typing the address yourself. Bookmark the real sites you use and only enter through the front door.
Why do custodial platforms sidestep most of this?
Here’s the structural insight most guides skip: the majority of NFT scams attack the wallet layer - the seed phrases, the transaction signatures, the token approvals that self-custody requires. Take that layer away and most of the scam taxonomy has nothing to grab.
That’s the model VeVe uses. It’s a licensed platform - Marvel, DC, Star Wars, Disney, and dozens more sign actual contracts with it - and it holds collectibles in a custodial wallet inside the app. Practically, that means:
- No seed phrase exists for you to be phished out of. Your account works like any modern app login, with standard account security instead of 24 words on a sticky note.
- No external contracts to approve. You can’t be tricked into signing a malicious transaction because you never sign transactions at all.
- No fake mints of licensed characters. A random website cannot legitimately sell you an official Marvel collectible, because the license lives with the platform. If it’s not in the app, it’s not real.
- Purchases run through the app store payment rails and the platform’s gems system, not through crypto transfers to a stranger’s address.
Custodial isn’t a magic forcefield - you still need a strong password and you should still ignore fake “VeVe support” DMs - but it deletes the single biggest attack surface in the hobby. We dig into the platform’s overall safety record in is the VeVe app safe? and tackle the skeptic’s question head-on in is VeVe a scam?
What’s the red-flag checklist?
Screenshot this, or just let it live rent-free in your head:
- Anyone asking for your seed phrase. Automatic scam, zero exceptions.
- “Support” that DMs you first. Real support waits for your ticket.
- Urgency as a sales tactic. Countdown pressure, “only 5 left,” “mint closes in 10 minutes” from a source you don’t know.
- Links from DMs, replies, or ads. Type addresses yourself or use your own bookmarks.
- Domains that are almost right. One swapped letter, an extra hyphen, a weird ending.
- Guaranteed profits. Nobody can guarantee that, and digital collectibles are a hobby, not an income plan. Anyone promising returns is selling you something rotten.
- No license, no team, no product. If you can’t find out who runs it and what rights they actually hold, walk away.
- Requests to move the conversation somewhere private. Scammers hate witnesses.
One red flag means slow down. Two means close the tab.
What should you do if you’re targeted?
First: getting targeted is not embarrassing. These operations are industrialized, and the messages go out to thousands of people at once. What matters is what you do next.
- Don’t engage. Don’t reply to argue, don’t click “just to see.” Block and report the account on the platform where it contacted you.
- If you clicked a link, don’t enter anything. Close the tab. If you entered a password, change it immediately, everywhere you reuse it (and stop reusing it - a password manager fixes this permanently).
- If you revealed a seed phrase, assume that wallet is compromised right now. Move anything salvageable to a fresh wallet immediately.
- If money left your account, contact your payment provider - card issuers and app stores have dispute processes that crypto transfers don’t.
- Report it. Platforms do act on reports, and in the US the FTC and IC3 (the FBI’s internet crime center) both take scam reports. You probably won’t get a personal follow-up, but the data takes down operations.
- Warn the community. One post in the right Discord saves the next ten people. Collecting communities protect their own - it’s one of the genuinely great things about this hobby. Our glossary can help you name exactly what you saw.
Scams thrive in the dark and die in the daylight. The more collectors who can spot the patterns, the smaller the pond the scammers have to fish in.
Start collecting - the safe way
If you want to enjoy digital collectibles without ever touching a seed phrase, VeVe is the walled garden built for exactly that. New collectors get US$10 in free credit to start - no card required - which means your first collectible can cost you nothing but the fun of choosing it.