This is the first GACS State of Crypto Scams report. Every number below is drawn directly from the live Risk & Recon engine — not a survey, not a third-party feed, just the entities our triage pipeline has independently verified and promoted onto the public blacklist. Treat it as a snapshot of the threat surface as of 25 May 2026, not a forecast.
Headline numbers
- 228 active entities on the blacklist, plus 2 still in pending review.
- 164 rated critical, 64 rated high — every entity in this report has cleared multi-source verification.
- 88 phishing websites, 74 fake brokers, 34 fraudulent tokens, 16 drainer wallets, 13 social-impersonation accounts, 2 memecoin rugs, 1 scam phone number.
- 228 of 228 were added or refreshed inside the last 14 days; the engine moved from 100 entities on 20 May to 228 by 23 May — a 128% lift in three days as the latest wallet-drainer cluster came online.
Where crypto scams actually live in 2026
If you only looked at the news cycle you'd think the threat is "AI deepfakes" and "memecoin rugs". The data says otherwise: 38% of every verified threat is a phishing website, 32% is an unlicensed broker, and just 0.9% is a memecoin. Memecoin rugs are loud; phishing front-ends are everything.
“38% of every verified crypto scam is a phishing website. Just 0.9% is a memecoin.”
### By category (active blacklist)
- Phishing websites — 88 (38.6%)
- Fake brokers / cloned exchanges — 74 (32.5%)
- Fraudulent tokens — 34 (14.9%)
- Drainer wallets — 16 (7.0%)
- Social-impersonation accounts — 13 (5.7%)
- Memecoin rugs — 2 (0.9%)
- Scam phone numbers — 1 (0.4%)
The takeaway: a 4-second Safe Scanner check on the URL stops over 70% of incidents before any money moves. Wallet-level forensics — what most "recovery experts" sell after the fact — applies to only 7% of cases.
The chain breakdown
When a wallet *is* involved, where does the money actually land? Of the 53 chain-tagged entities (16 wallets + 37 tokens), the breakdown is:
- BSC — 17 entities (32%). Low fees, lax KYC on bridge endpoints, dominant for fake-token deployments.
- Ethereum (incl. L2-tagged "ethereum" aliases) — 21 entities (40%). Drainer wallets and the bulk of phishing-front siphons.
- Arbitrum / Base — 3 entities each. Fake "airdrop claim" pages favour L2s where users have lower transaction-sign anxiety.
- Bitcoin — 2 wallets (4%). Almost exclusively long-form romance-investment victims pushed to "mining pools".
- Solana — 2 entities (4%). Mostly memecoin rugs and clones of legitimate launchpads.
- Optimism / Tron — 2 each. Tron's share is small in count but disproportionate in laundered USD value via USDT-TRC20.
- zkSync — 1 entity. Bleeding-edge L2s lag the scam wave by 6–12 months; expect this number to grow.
If you operate on BSC or Ethereum mainnet, you are statistically in the blast radius. If you operate purely on Solana or Bitcoin, the threat surface is narrower but the per-incident loss is larger.
How GACS triages an entity
A scam doesn't get a public blacklist page just because someone reported it. Each entity is sourced, deduplicated, scored, and only then promoted. The 228 active entities trace back to:
- Curated public records — 124 entities (54%). Cross-referenced regulator notices, court filings, and chain-analysis sources.
- GACS analyst triage — 41 entities (18%). Manual investigation when automated signals are ambiguous.
- URLhaus feed — 24 entities (11%). Live phishing-URL feed, intersected against our own crypto-domain pattern matcher.
- FCA warnings — 24 entities (11%). UK Financial Conduct Authority unauthorised-firm alerts.
- SEC litigation releases — 5 entities.
- Community reports — 3 entities promoted from public victim reports that crossed the 3-report critical threshold.
- DOJ press releases — 3 entities.
- CryptoScamDB / CFTC / ASIC — 4 entities combined.
Every entity has a permanent /scam/<slug> URL with the source chain visible. There's no "trust us" — read the scoring methodology for the exact rules.
Three patterns that stand out
### 1. Phishing now imitates the wallet, not the exchange
Six years ago the dominant scam page was a cloned Binance or Kraken login. In our 2026 data set, the majority of phishing websites imitate the wallet — MetaMask, Ledger, Phantom — using "support", "recovery", "claim", or "update" subdomains. The reason is simple: signing a malicious approval drains every token in the wallet in one transaction, while a cloned exchange only gets one set of credentials.
### 2. Brokers and tokens are converging
74 fake brokers and 34 fraudulent tokens are tracked separately, but increasingly the same operation runs both: a "broker" platform that pushes victims into a custom ERC-20 the operator minted, then disables withdrawals when the price chart suits them. If a "broker" insists you trade only their in-house token, you're in a single-operator rug, not on a market.
### 3. The drainer-wallet ring is small and reused
There are 16 drainer wallets — across 88 phishing sites and dozens of front-end campaigns. The wallet:site ratio is 1:5.5. This is the single most actionable insight in the data: blocking those 16 addresses neutralises the back-end of the entire visible campaign. We've published the full mapped wallet list in our pig butchering data investigation.
What to do with this report
- Run a [free Safe Scanner](/safe-scanner) check on any platform you're considering. 70%+ of incidents in this data set would have been blocked at the URL stage.
- For higher-stakes flows, use the Risk & Recon report — full forensic pass against all 228 entities plus the broader 250k-row historical archive.
- Embed the warnings. Every
/scam/<slug>page can be embedded as a warning widget on your own site, forum, or community thread. - Add what we don't have yet. Three independent reports auto-promote a new entity to critical. Report a scam in 60 seconds.
Methodology and disclosure
This report is descriptive, not predictive. Counts reflect the GACS active blacklist as of 25 May 2026 (timezone UTC). Categories use the GACS taxonomy defined in our scoring methodology. Severity tiers (critical / high) reflect cross-source verification, not the dollar magnitude of any individual loss. "Active blacklist" excludes entities still under review (status: pending). Chain attribution is based on the on-chain network of the wallet or token contract; entities without a chain tag are excluded from chain-share percentages. GACS is advisory-only — we do not execute trades, move funds, or guarantee recovery. To request a correction, use the feedback form.
We will refresh this report monthly. If you want the next edition delivered to your inbox, join the GACS weekly digest.
