Skip to content
CP Health
← All articles

Trust & Ownership

Staying Safe — Common Scams, Lost Keys, and How People Actually Lose Funds

How funds actually disappear when you hold your own crypto, the lines scammers use, and the habits that stop most of it.

Fletcher Watson, MN, RN, CNL9 min read
A hand writes on a sheet of paper beside a closed laptop at a plain wooden desk, in warm lamplight.

An ounce of prevention is worth a pound of cure.

Benjamin Franklin, Poor Richard's Almanack

Telling someone to "be careful" does very little. Naming the specific danger, and the specific thing to do about it, does more.

This is not unique to one network. Any time people hold value in a new system — especially one without a bank window and a password-reset desk — thieves try the same moves. They impersonate help. They invent urgency. They ask you to hand over the one thing that controls the money. The details change. The pattern does not.

You hold the keys

If you keep crypto in your own wallet, a secret key is what signs and spends. A recovery phrase — a list of words — is the backup that can rebuild that key. You hold both. There is no bank to call and no "forgot my password" button. That is the design. It is also the main risk.

People lose funds in four ways.

  1. They lose the recovery phrase. If the phrase is gone and the phone or computer is gone, the coins are gone for good. There is no department that can get them back. This is the most common way coins disappear for good. Often it is not a theft. Someone tidied a drawer, or the paper got wet.
  2. They give the phrase away. Usually because a message looked official — a text, an email, a webpage, a phone call. This is where most scams live. The four lines below cover it.
  3. The price falls. Crypto prices move a lot. They can drop. Nothing on this page prevents that. Only use money you can stand to see fall.
  4. The wallet software itself is flawed. This is rare. It is not your mistake and not a scam. In June 2026, for example, a Cardano wallet called SecondFi — built by EMURGO — had a bug in how it created wallets. Attackers could rebuild private keys from information already visible on the network. About 16 million ADA was stolen from 374 wallets. A larger amount was moved to safety in time. The wallet has been shut down.[1] There were warning signs months earlier. We notified known CarPool delegators about those concerns and recommended they avoid that wallet and move funds if they were a user. We do not know of any CarPool delegator who was harmed.

A wallet you control cannot be frozen the way an exchange account can. You still depend on the software that created those keys. Use a well-known wallet. Read notes from the people who make it. Do not assume the wallet you picked years ago is finished changing.

If a wallet changes its name, its owner, or its default settings, read that email. Settings can change in the switch. Several of those signs showed up with SecondFi.

Four lines that mean stop

Almost every crypto scam needs you to do one of these. If you hear them, stop.

  1. "Enter your recovery phrase to verify / restore / claim." No real service needs that phrase. Not a wallet company, not support, not a website, not us. We will never ask for it — not by email, not on a phone call, not ever. The only time you type it is when you are restoring your wallet on a screen you opened yourself.
  2. "I'm from support — let me help." Real support does not message you first. Fake helpers show up on social media, chat apps, and comment threads, usually when you are already stuck.
  3. "Connect your wallet to claim X." Free tokens, airdrops, "migrate now," "security upgrade." Connecting a wallet can be normal. Approving a transaction you do not understand is how assets get drained. Only connect to sites you already trust. Read the approval screen. If it is not what you meant to do, close it.
  4. "Guaranteed returns." Nobody can promise a fixed return on staking or on "just send us your coins." Rewards change. We will never promise, forecast, or guarantee an amount.

What has been showing up

This list will go out of date. The four lines above will not. Snapshot: September 2026.

  • Fake apps in the real app stores. In April 2026, Lace warned that fake Lace apps were on the Apple App Store and Google Play, listed under a made-up developer name.[2] You do not have to avoid phone wallets. You do have to check the developer name. The real Lace app is published by Input Output HK Limited. The same trick is used against MetaMask, Ledger, Trust Wallet, and others.[3] The safe path on any chain: go to the wallet's own website, then use the store link on that site. Do not install from an ad or a search result.
  • Fake update emails and websites. Lace also flagged a fake site and emails about a "Lace Desktop 2.0" upgrade.[2] Real updates come from the browser's extension store or from inside the wallet. Not from a link in email.
  • Fake sites for wallets people actually use. Copied sites and apps are common. Cardano's scam page lists Vespr, Eternl, and Typhon among wallets often copied here.[4] If you use a wallet from our guide, the safest step is to type the address yourself. You can use our link too — then check the address in the browser when you arrive. Do not click an ad.

Habits that stop most of this

  • Write the recovery phrase on paper, stamp it in steel, or keep it in a reputable password manager. Not a photo. Not a note in the cloud. Not an email to yourself.
  • Store that backup the way you would store a passport. Fire, flood, and spring cleaning lose more phrases than burglars do.
  • Type web addresses yourself. Do not tap links in messages or ads.
  • If a message says you must act in the next hour, pause. Nothing legitimate requires that speed.
  • If you are moving money for the first time, start with a small amount.

If something already went wrong

If you typed your recovery phrase into a site or a chat, create a new wallet right away and move what is left to it. The old phrase cannot be made safe again.

If you are not sure a message is real, do not reply. Contact us through this website.

If the scam involved Cardano or ADA, report it so it can be taken down for other people:

No one can get stolen coins back. A stranger offering to recover them is the next scam. That pattern is common after a loss, in every part of this industry.

Related pages

Use any of these. They do not assume what you already know.

References

  1. 1.

    SecondFi (EMURGO) wallet exploit, June 2026: a flaw in SecondFi's proprietary wallet-generation software, at the address level, allowed private keys to be reconstructed from public on-chain data; the risk materialised when an affected user signed a transaction. About 16 million ADA (≈$2.4 m) was stolen from 374 wallets between 21 and 23 June 2026, and roughly 129 million ADA was moved to safety through emergency containment before attackers reached it. EMURGO stated SecondFi would not resume operations and wound it down in July 2026. See CoinDesk (24 June 2026), The Defiant (June 2026), and EMURGO's incident report of 25 June 2026. Included as a software-defect risk, not a scam.

  2. 2.

    Lace (Cardano light wallet) security alerts, 2026: a counterfeit site and "Lace Desktop 2.0" phishing emails flagged 24 March 2026; counterfeit Lace mobile apps on both the Apple App Store and Google Play under a fabricated developer name, flagged 21 April 2026. Lace states it will never ask for a recovery phrase or private keys. The official Lace Wallet app is published by Input Output HK Limited (App Store id6743856101; Google Play io.lace.mobilewallet) and linked from lace.io — the counterfeits were distinguishable by developer name, not by existing at all.

  3. 3.

    Kaspersky, "FakeWallet cryptostealer propagating via iOS App Store applications" (Securelist, April 2026): 26 counterfeit wallet apps on the Apple App Store harvesting recovery phrases, impersonating MetaMask, Ledger Live, Trust Wallet, Coinbase, TokenPocket, imToken and Bitpie — not Cardano wallets. Concentrated in the Chinese App Store; Android variants spread via malicious pages, with no evidence of Google Play distribution. Cited for the technique, with its actual scope stated.

  4. 4.

    cardano.org/common-scams names Typhon, VESPR and Eternl among wallets mimicked by phishing sites and apps, and states that no Cardano organisation will ever ask you to send ADA. Reporting channels, from separate official pages: report@cardano.org, per the Cardano Forum's scam-reporting guidance (put the platform in the subject line); and the Cardano Fraud Detection Bureau via the "Report fraud" link on the IOHK Support Portal (support article "How to report fraud").

This page is education, not financial advice. Nothing here is a recommendation to buy, sell, or delegate any asset.