If sanctions and darknet are the "heavy artillery" of risk, then scams and phishing are the most widespread, "grassroots" threat that almost every crypto holder faces. What is especially insidious here is that the victim often becomes a carrier of suspicious activity themselves: scam tokens and traces of interaction with fraudulent contracts settle in their wallet. Let's examine the types of scam, the phenomenon of "dust", the mechanics of drainers and approval phishing, and understand why databases of scam addresses are always lagging behind.
One of the most underrated topics. The blockchain lets anyone create a token with any name and send it to any addresses — without the recipient's consent. Fraudsters exploit this.

A wallet's Token transfers tab. Numerous unsolicited tokens with "come-on" names — the typical picture of a scam giveaway and "dust".
Let's go through what is visible on the screenshot and why it matters:
A drainer is a malicious service that empties a victim's wallet. The key to understanding it is the mechanics of approval on blockchains like Ethereum.
approve transaction — permission for the contract to dispose of your tokens. Legitimate applications request limited access. A drainer, however, disguised as "connect wallet" or "activate airdrop", asks you to sign an approval for an unlimited amount (unlimited approval) in favour of the fraudster's contract. After that, the attacker can withdraw all the approved tokens at any moment — without the victim's renewed consent.
It might seem: "There are blacklists of scam addresses — check against them and you're done." In practice this method is fundamentally behind the curve, and here is why.
Practical hygiene for the client (and for you). 1) Do not interact with unsolicited tokens. 2) Regularly revoke old approvals through dedicated services. 3) Check the application's domain letter by letter. 4) Use a separate "hot" wallet with a small balance for risky interactions. 5) Never enter your seed phrase for anyone — a legitimate service will not ask for it.
In the closing lesson of this section we will examine the "grey zone" — high-risk exchanges without KYC, nested exchanges, casinos and P2P: why this is a moderate rather than maximum risk, and how to correctly interpret scores of 30–50.
This material is for educational purposes only and does not constitute legal advice.