What Are NFTs? 5 Common NFT Scams & 9 Safety Tips 2021

Header

Author: Trend Micro

December 16, 2021

This article is from Trend Micro.

It seems that everyone is talking about NFTs lately. Have you caught on to the trend? They’ve exploded and redefined the art market A LOT recently with tons of people getting super excited about them, but scammers have also been getting excited — about the prospect of scamming lots of people with NFT-related scams!

In this post, we introduce some of the most common NFT scams and share some tips to avoid them. Check it out!

What are NFTs?

Non-fungible tokens (NFTs) are artworks (physical or digital) with digital signatures that represent their ownership. They can be viewed as digital assets and can be used as real money, like cryptocurrencies (Bitcoin, Ethereum, etc.). What’s different is that each NFT is UNIQUE and can’t be replaced or reproduced, and that’s why they’re now popular among art enthusiasts, gamers, and those involved in real estate.

5 common NFT scams

#1 — Fake NFT websites

If you’re interested in investing in NFTs, the first thing is to find out WHERE you can buy and sell NFTs. When searching online, you’ll be flooded with millions of search results, but there are many fake NFT trading websites among them. It can be hard to tell these scam websites apart from genuine ones as they often look extremely alike.

First of all, there are no legitimate NFTs on scam sites, so if you purchase one, you are just throwing your money away. What’s worse, scammers can record all the credentials you submit on the sites. Normally you only have to provide your MetaMask wallet address to make transactions, but scammers may request for the seed phrase of your Ethereum wallet (the master key to your cryptocurrency wallet) and use it to hack into your wallet and steal all your cryptocurrency.

Choose legitimate NFT trading websites

The easiest way to stay safe is to choose legitimate NFT trading websites. There are lots of different types of NFTs — there are ones relating to sports, video games, real estate, and lots more. Besides the most famous NFT trading platform OpenSea, here are some other legitimate NFT marketplaces/NFT collectible websites:

NFTs for art

Super Rare
Foundation
Nifty Gateway
Rarible
Zora
Mintable

NFTs for sports

NBA Top Shot
Sorare

NFTs for gaming

Axie Infinity
Street Fighter
Myth.Market
Treasureland

NFTs for digital real estate

Decentraland

NFTs for Tweets

Valuables

#2 — Fake offers

Impersonating famous NFT trading platforms, scammers send you fake emails claiming that someone has made an offer for your NFT. They prompt you to click on an embedded button:

Like all the other phishing scams we’ve reported on before, the button leads to a phishing website. The fake page will ask you to link your wallet and submit your seed phrase/recovery phrase. Scammers can record the credentials and hack into your wallet and steal everything you’ve got!

#3 — Fake technical support

Besides fake offer email notifications, fake customer service/technical support is also a common scam tactic.

Via Discord

Imagine encountering some technical problems and seeking help on Discord. Someone who claims to be from OpenSea then comes to your rescue.

The fake support agent (the scammer) may ask you to share your screen to check what’s going on, making you inadvertently reveal your cryptocurrency wallet’s credentials. When you do so, they can take screenshots of your seed phrase (the recovery key to your wallet) or the QR code linked to it. Or, the scammer could redirect you to a website that looks like the official OpenSea website and coerce you into entering detailed personal information there. You know what will happen next. Don’t fall for it!

Via email

In some other cases, scammers send you fake security alerts about your OpenSea account/NFT collection. Again, they try to prompt you into clicking on the embedded phishing link. Don’t get tricked!

#4 — Fake giveaways

Posing as employees from famous NFT trading platforms, scammers contact you via social media (e.g. Discord or Telegram), saying they are holding giveaway campaigns. They promise you free NFTs as long as you spread the giveaway messages and sign up for the campaigns — through scam/phishing NFT websites! When you try to link your MetaMask wallet, your credentials will be stolen.

#5 — Fake NFT projects (rug pull scams) 

Many new NFT projects appear every day, for example, Squid — a new digital token for the world-famous Netflix series Squid Game. However, after its price reached its peak, it turned out to be a “rug pull” scam — the creation of an NFT that can’t be circulated. Owners can’t re-sell the tokens, making their prices plummet in a short time. In such schemes, the only ones who profit are the creators of the digital tokens.

In other cases, such scams are committed by romance scammers. Romance catfishers try to lure you into investing in some NFT projects. They might send you links to fake NFT websites, or ask you to wire them money. Be careful!

9 tips to protect yourself from NFT scams

1. Check the price. If the offer of an NFT on a site is much lower than that on legitimate websites like OpenSea, it’s probably a scam.

2. Check verification marks. Most legitimate NFT sellers will have a blue checkmark beside their usernames, and the properties of the collection will be listed clearly.

3. Check the contact address. It should specify where the NFT was minted. You can check the creator’s website to make sure the information is genuine.

4. Turn to the official customer service of the NFT trading sites for help instead of someone who contacted you via social media.

5. Be smart with your wallet credentials and NEVER share your seed phrase (recovery phrase).

6. Use legitimate wallet apps and browser extensions to avoid phishing. There are lots of malicious apps impersonating official ones.

7. Use strong passwords and enable two-factor authentication (2FA) to protect your accounts. Try Trend Micro™ ID Security to monitor your personal information with ease.

8. Never click on links or attachments from unknown sources. Use Trend Micro Check to check if a website is secure (It’s free!)

1. After you’ve pinned the Trend Micro Check browser extension, it will block dangerous sites for you automatically:

2. Send suspicious links to Trend Micro Check on WhatsApp for immediate scam detection.

9. Add an extra layer of protection to your device with Trend Micro Maximum Security. It includes Web Threat Protection, Ransomware Protection, Anti-phishing, and Anti-spam Protection to help you combat scams and cyberattacks.

Click the button below to give it a try:

If you found this article helpful or interesting, please SHARE it to help protect your friends and family!

Report a Scam!

Have you fallen for a hoax, bought a fake product? Report the site and warn others!

Help & Info

Top Safety Picks

Your Go-To Tools for Online Safety
Disclaimer: Some of the links here are affiliate links. If you click them and make a purchase, we may earn a commission at no extra cost to you.

  1. ScamAdviser App - iOS : Your personal scam detector, on the go! Check website safety, report scams, and get instant alerts. Available on iOS
  2. ScamAdviser App - Android : Your personal scam detector, on the go! Check website safety, report scams, and get instant alerts. Available on Android.
  3. NordVPN : NordVPN keeps your connection private and secure whether you are at home, traveling, or streaming from another country. It protects your data, blocks unwanted ads and trackers, and helps you access your paid subscriptions anywhere. Try it Today!
  4. Incogni : Incogni automatically removes your personal data from data brokers that trade in personal information online, helping reduce scam and identity theft risks without the hassle of manual opt-outs. Reclaim your privacy now!

Popular Stories

As the influence of the internet rises, so does the prevalence of online scams. There are fraudsters making all kinds of claims to trap victims online - from fake investment opportunities to online stores - and the internet allows them to operate from any part of the world with anonymity. The ability to spot online scams is an important skill to have as the virtual world is increasingly becoming a part of every facet of our lives. The below tips will help you identify the signs which can indicate that a website could be a scam. Common Sense: Too Good To Be True When looking for goods online, a great deal can be very enticing. A Gucci bag or a new iPhone for half the price? Who wouldn’t want to grab such a deal? Scammers know this too and try to take advantage of the fact. If an online deal looks too good to be true, think twice and double-check things. The easiest way to do this is to simply check out the same product at competing websites (that you trust). If the difference in prices is huge, it might be better to double-check the rest of the website. Check Out the Social Media Links Social media is a core part of ecommerce businesses these days and consumers often expect online shops to have a social media presence. Scammers know this and often insert logos of social media sites on their websites. Scratching beneath the surface often reveals this fu

How do I recover my crypto after it’s stolen? What happens if your crypto wallet is compromised? Can stolen crypto be traced, and can police actually recover crypto in 2026? These are the questions most people ask within minutes of realizing their wallet has been drained. Crypto theft is fast, quiet, and unforgiving. By the time most victims notice something is wrong, the funds are already moving across the blockchain. Once seen as a problem for exchanges and whales, crypto theft now heavily affects everyday investors. Phishing links, fake support chats, wallet approval scams, SIM swaps, and malware attacks have become common. Knowing what recovery realistically looks like—and what it doesn’t—can prevent panic, bad decisions, and costly follow-up scams. In a Nutshell Crypto recovery is possible, but only in limited situations Blockchain transactions are irreversible, but stolen crypto can still be traced Speed and documentation matter more than optimism Police and exchanges play a bigger role than private recovery services Guaranteed recovery offers are almost always scams Is it Actually Possible to Recover Stolen Crypto? Yes, crypto recovery is possible, but only under specific conditions and rarely through direct action by the victim. Blockchain transactions are final by design. Once crypto is sent and confirmed, it cannot be reversed. There is no central authority, no chargeback process, and no technical “undo” button, even if the transaction was clearly fraudulent. This is where many people ask whether stolen crypto can be traced. In most cases, it can. Every transaction