General legal information, published for everyone. It does not apply the law to anyone’s particular situation and is not legal advice. Laws change and differ by place; check the primary sources below.
Quick summary
- Crypto scams can involve stolen funds, compromised accounts, lost private keys, impersonation, or false claims made about a person or business.
- Blockchain transactions are often difficult or impossible to reverse, but reporting, preserving evidence, securing accounts, and contacting relevant platforms may improve the chances of recovery.
- Public accusations about an alleged scammer can also create privacy, harassment, or defamation risks.
What it means
Crypto scams can involve stolen funds, compromised accounts, lost private keys, impersonation, or false claims made about a person or business. Blockchain transactions are often difficult or impossible to reverse, but reporting, preserving evidence, securing accounts, and contacting relevant platforms may improve the chances of recovery. Public accusations about an alleged scammer can also create privacy, harassment, or defamation risks.
How the law works
How the law usually works
If someone faces an immediate threat, stalking, or violence, emergency services should be contacted first. Crypto disputes commonly involve several legal issues at once:
- Fraud or theft: A scammer may have committed a criminal offense by obtaining crypto through deception, unauthorized access, impersonation, or theft. Criminal investigations are handled by law enforcement, not by private victims.
- Civil recovery: A victim may sometimes sue a known person or business for fraud, breach of contract, conversion, or unjust enrichment. A court may order repayment or allow steps to identify or preserve assets, but a judgment is useful only if the defendant or assets can be found.
- Blockchain tracing: Public blockchains may show wallet addresses and transfers, but a wallet address does not automatically identify its owner. Investigators may use exchanges, subpoenas, court orders, and specialist tracing services.
- Exchange and platform action: An exchange may be able to freeze an account or flag suspicious funds if contacted quickly. It usually cannot reverse a completed transaction without cooperation from the recipient, another intermediary, or legal authority.
- Lost access: If crypto was sent to the wrong address, the private key was lost, or a wallet was destroyed, there may be no practical legal remedy. A custodian may have different recovery procedures if it held the assets.
- Privacy and reputation: Publishing a name, photograph, wallet address, phone number, or home address can expose personal data and may encourage harassment. Calling someone a “criminal” or “scammer” as a fact, especially before a court finding, may create defamation risk.
A recovery service that guarantees results, demands an upfront crypto payment, or claims to be working with government officials may be a second scam.
Common processes
- Secure accounts and devices. People commonly change passwords from a clean device, enable multifactor authentication, revoke suspicious wallet permissions, move remaining assets to a secure wallet, and contact their mobile carrier if a SIM-swap is suspected. They avoid sharing seed phrases, private keys, authentication codes, or remote-access credentials.
- Preserve evidence. Useful material can include wallet addresses, transaction IDs, dates and times, blockchain network, amounts, screenshots, emails, chat messages, website addresses, phone numbers, payment records, and promises made by the promoter. Original files and message headers can be more useful than edited screenshots.
- Contact the exchange or wallet provider. People commonly use the provider’s official website—not a link supplied by the suspected scammer—to report unauthorized activity. They ask whether an account can be frozen, whether a recipient exchange can be notified, and what information is needed for a law-enforcement request.
- Report the conduct. Reports may be made to local police, national fraud-reporting services, financial regulators, and cybercrime agencies. A report may not produce immediate recovery, but it can connect related complaints and preserve an investigative record.
- Notify payment providers. If fiat currency, a bank transfer, card payment, wire, or money-transfer service was involved, people commonly contact that provider’s fraud department promptly. The possible remedy depends on the payment method and whether the transfer was authorized.
- Consider a civil investigation. Where the loss is substantial and a likely defendant or exchange can be identified, a lawyer may assess tracing, preservation orders, subpoenas, or a lawsuit. These proceedings can be expensive and may not succeed if the funds have been moved through mixers, converted, or spent.
- Handle public statements carefully. People commonly describe verifiable events—such as “this wallet received these funds on this date”—rather than making unsupported accusations. They avoid publishing private addresses, family information, or personal contact details and report threatening replies to the platform and police.
- Request account or personal-data action. Depending on the jurisdiction, a person may ask a platform to remove hacked content, correct inaccurate account information, disclose certain personal data, or explain how data is being used. These rights have exceptions and do not necessarily reveal an anonymous user.
Deadlines and time limits
Deadlines depend heavily on the claim, location, defendant, and type of transaction. Sources commonly provide limitation periods ranging from about one to several years for fraud, contract, property, or other civil claims, with special rules for discovering concealed wrongdoing.
Platform complaints, bank recalls, and fraud reports often have much shorter practical windows—sometimes days or weeks—because funds can be moved quickly. Defamation claims also commonly have relatively short limitation periods, particularly in England and Wales and in some Australian jurisdictions.
Data-access, correction, and removal requests usually have response periods set by the applicable privacy law or platform terms. Criminal investigations generally do not operate on the same limitation period as a private lawsuit, though offenses can have different rules. You should confirm the applicable deadline with the relevant court, regulator, platform, or a licensed attorney where you live.
Documents that usually matter
- Wallet addresses, transaction hashes, network names, and block-explorer records
- Exchange statements, account records, deposit and withdrawal histories
- Bank, card, wire, or payment-service records
- Emails, direct messages, text messages, call logs, and website captures
- Investment agreements, invoices, terms of service, and promotional material
- Identity information connected to the suspected person or business
- Police, regulator, platform, and insurance reports
- Evidence of account compromise, including password-reset notices and login alerts
- Records of public posts, threats, doxxing, impersonation, or requests for removal
Keeping evidence in its original form and recording when it was collected can help establish authenticity.
How it differs by jurisdiction
- United States: Fraud and unauthorized-access laws can be federal or state-based. The FBI’s Internet Crime Complaint Center, the Federal Trade Commission, state regulators, and relevant financial regulators may receive reports. Defamation, privacy, limitation periods, and civil procedure vary by state. Section 230 of the Communications Decency Act may protect some online platforms from liability for user content, but it does not generally prevent action against the original speaker and does not resolve every privacy issue.
- England and Wales: The Fraud Act 2006 covers several forms of fraud. The Defamation Act 2013 includes a serious-harm threshold and defenses such as truth and honest opinion, but online accusations can still create risk. The UK GDPR and Data Protection Act 2018 govern many personal-data rights and exemptions. The Financial Conduct Authority and Action Fraud commonly receive relevant reports.
- Canada: Criminal fraud and unauthorized-use provisions are federal, while civil claims, limitation periods, defamation, and procedure are largely provincial or territorial. The federal Personal Information Protection and Electronic Documents Act applies to many private-sector organizations, but provincial privacy laws can also apply. The Canadian Anti-Fraud Centre commonly receives scam reports.
- Australia: The Corporations Act 2001 and financial-services rules may apply to certain crypto businesses and promotions, while state and territory laws govern much civil procedure, defamation, and some privacy matters. The Privacy Act 1988 applies to covered organizations. Scamwatch, ReportCyber, and ASIC may be relevant reporting channels.
When people consult a lawyer
Legal advice is especially worth considering when the loss is substantial, a known person or company can be identified, funds reached a regulated exchange, an employer or business account was involved, or a limitation deadline may be approaching. A lawyer can assess jurisdiction, preservation or disclosure orders, tracing options, insurance, tax issues, and the risks of public accusations.
Advice may also help when you received crypto from someone else, your account was used as a “mule,” you are accused publicly of a scam, or a platform has suspended your account. Avoid paying a recovery service before independently checking its identity, terms, licensing, and fee arrangement.
Primary sources
- Official sourceFederal Bureau of Investigation, Internet Crime Complaint Center (IC3), United StatesUnited States (federal)official reporting guidance
- Official sourceFederal Trade Commission, “ReportFraud,” United StatesUnited States (federal)official consumer-fraud reporting information
- Official sourceU.S. Securities and Exchange Commission, Investor.gov crypto and investment-scam alerts, United StatesUnited States (federal)official investor guidance
- StatuteFraud Act 2006, United KingdomEngland & Walesprimary legislation
- StatuteDefamation Act 2013, United KingdomEngland & Walesprimary legislation
- Official sourceUK Information Commissioner’s Office, data-protection rights and criminal-fraud guidance, England and WalesEngland & Walesofficial guidance
- Official sourceCanadian Anti-Fraud Centre, Government of CanadaCanadaofficial reporting guidance
- StatutePersonal Information Protection and Electronic Documents Act, CanadaCanadaprimary legislation
- Official sourceAustralian Securities and Investments Commission, crypto-asset and investment-scam guidance, AustraliaAustraliaofficial guidance
- Official sourceScamwatch and ReportCyber, Australian GovernmentAustraliaofficial reporting guidance
- StatutePrivacy Act 1988, AustraliaAustraliaprimary legislation
Links go to official or widely used free sources. Check that a source is current before relying on it. Browse all sources →
- Last updated
- Sep 26, 2026
- Jurisdiction
- General — United States, England & Wales, Canada, Australia
- Written by
- House Legal editorial (AI-generated, earlier format)