TLDR
- Crypto job scams cost US victims $197 million across 6,533 complaints in 2024 (FBI IC3)
- No legit employer asks you to pay, deposit crypto or run unknown code
- Verify every recruiter through the company's official site, not the DM
- Real web3 salaries run roughly $50k to $250k+ depending on role and seniority
- Report scams at ic3.gov
Crypto job scams follow a handful of predictable patterns: unsolicited DMs from "recruiters", offers that pay suspiciously well for vague work, requests to deposit money to "activate" your account and interviews that ask you to download software or run code. If any of those show up, walk away. The FBI's Internet Crime Complaint Center logged 6,533 crypto-related employment scam complaints in 2024, with losses of about $197 million.
The good news is that once you know the patterns, these scams are easy to spot. This guide covers the red flags, the interview tricks, the difference between a scam and a merely bad employer and what real web3 jobs actually pay. If you want to skip the sketchy Telegram offers entirely, browse web3 jobs on vetted listings instead.

Why are crypto job scams so common?
Web3 is the perfect hunting ground for employment fraud. Jobs are remote by default, hiring often happens over Discord or Telegram, payments in crypto are irreversible and candidates are used to unconventional setups like anonymous founders and token-based pay. Scammers exploit every one of those norms.
The scale is real. Crypto-related fraud overall cost Americans $9.3 billion in 2024 according to the FBI, rising past $11 billion in 2025. Employment scams are a small slice of that, but the average IC3 fraud loss was $19,372 per incident in 2024. That's a brutal hit for someone who thought they were starting a new job.
It's not just petty criminals either. The FBI has warned that North Korean state hackers actively target web3 workers with fake job offers. The 2022 Ronin bridge hack, which drained roughly $625 million from Axie Infinity's ecosystem, started when a senior engineer opened a fake job offer PDF sent through LinkedIn.
What are the most common fake crypto jobs?
Fake crypto jobs cluster into four formats. Learn these and you'll recognize 90% of what lands in your inbox.
Task and "app optimization" scams
You're offered $100 to $500 a day to complete simple tasks like clicking links, boosting apps or rating products. Early payouts arrive to build trust. Then you're told you need to deposit crypto to "unlock" higher-paying task sets or withdraw your earnings. The deposit disappears. This is the single most reported employment scam format in IC3 data.
Money mule roles
Titles like "payment processor", "regional agent" or "treasury assistant" where your job is receiving funds and forwarding them on, keeping a cut. You're not an employee. You're laundering stolen money, and that carries real criminal liability even if you didn't know.
Malware interviews
A recruiter, often impersonating a real company, moves you quickly to a technical interview. Then comes the trap: run this coding challenge from GitHub, install this "video call" app or paste this command to fix your camera. The code is an infostealer that drains connected wallets and steals credentials. Security researchers have tracked North Korean campaigns doing exactly this at scale since 2023.
Pay-to-start jobs
You got the job! You just need to pay for equipment, training, a background check or a "refundable" security deposit first. Real employers pay you, never the reverse. This rule has no exceptions.

How do you spot crypto job scams before applying?
Run every offer through this comparison. Scam offers usually fail three or more rows at once.

A few checks take five minutes and kill most scams. Look up the recruiter on the company's official team page or LinkedIn, then message them through that channel to confirm. Check the email domain character by character since scammers register lookalikes like "binancé" or "coinbase-careers.net". Search the company name plus "scam" and check the domain age on a WHOIS tool. Anything under six months old claiming to be established is a problem.
How do web3 job scams play out during interviews?
Even when the listing looks fine, the interview stage is where sophisticated web3 job scams strike. The pattern is consistent: build legitimacy first, then introduce one small technical request.
Common versions include a "skills assessment" hosted in a private GitHub repo containing obfuscated malicious dependencies, a request to install a niche video conferencing app because "Zoom is having issues" and a fake error during the call that requires pasting a terminal command to fix your camera or microphone. All three install malware.
Protect yourself with two habits. First, do interview coding challenges in a sandbox, a virtual machine or at minimum a machine with no wallet extensions or private keys on it. Second, refuse to install anything that isn't a mainstream tool. A real employer will happily switch to Google Meet. A scammer will pressure you, and pressure itself is the tell.
One more rule that covers everything: no legitimate company will ever ask for your seed phrase, ask you to send a "verification" transaction or ask you to connect your wallet to an unknown site during hiring. Not for KYC, not for payroll setup, not for anything.
What separates a bad web3 employer from a scam?
Not every red flag means fraud. Some companies are real but will still waste a year of your career. These are the bad-employer warnings worth taking seriously.
Compensation paid mostly or entirely in the project's own token is the big one. If the token hasn't launched, you're working for lottery tickets. If it has, check the liquidity, because a $150k package in an illiquid token can be worth a fraction of that when you're actually able to sell. A reasonable structure is a livable fiat or stablecoin base with tokens as upside, plus a clear vesting schedule in writing.
Other patterns to probe in interviews: founders who won't say how much runway the company has, fully anonymous leadership on a project handling user funds, "we'll formalize your contract after the token launch" and heavy turnover you can spot by checking how many ex-employees lasted under a year on LinkedIn. Ask directly about runway, treasury management and how the last funding round was structured. Evasiveness is your answer.

What do real web3 jobs actually pay?
Salary sanity checks catch scams fast, because fake offers are almost always priced wrong for the work. Exact figures vary a lot by region, company stage and whether pay is remote-global or US-benchmarked, but these are realistic 2025-2026 ranges for full-time roles:
- Smart contract / Solidity engineers: roughly $120k to $250k+, with senior security-focused roles going higher
- Backend and full-stack engineers at crypto companies: roughly $90k to $200k
- Product managers: roughly $100k to $200k
- Community and social managers: roughly $50k to $90k
- Marketing and growth roles: roughly $60k to $150k
- Entry-level and internship roles: roughly $40k to $70k
So when a Telegram stranger offers $500 a day for "liking posts" with no interview, the math alone exposes it. That's a six-figure annual rate for work that requires no skill. Nobody pays that. Equally, an offer far below these ranges from a supposedly funded company signals an employer to avoid.
What should you do if you spot or fall for a crypto job scam?
If you spot one, report the account on the platform it contacted you from and file a complaint at ic3.gov even if you lost nothing, since reports help investigators map networks. Warn the community if the scam impersonated a real company, because their team usually wants to know.
If you already engaged, act fast. Stop all contact and don't pay any "release fee" to recover funds, as that's a second scam. If you ran any software from them, disconnect the machine, move funds from any wallet that touched it to a fresh wallet from a clean device and revoke token approvals using a tool like Revoke.cash. Change passwords and rotate any exposed credentials, then file with IC3 and your local police. Recovery of sent crypto is rare, but freezes do happen when reports come in quickly.
Also ignore anyone who contacts you afterwards claiming they can recover your funds for a fee. The FBI logged over 10,500 complaints about these recovery scams in 2025, worth an estimated $1.4 billion in losses.
The bottom line
Every crypto job scam depends on you skipping one verification step because the offer feels exciting or urgent. Slow down, confirm the recruiter through official channels, never pay or deposit anything and keep interview code away from your real machine. Bad employers take a little more digging, but runway, token-pay structure and employee turnover tell you most of what you need.
The safest move is starting from listings that are already vetted. Browse web3 jobs on CoinTerminal and apply knowing the company on the other side is real.
FAQ
Are jobs that pay in crypto automatically scams?
No. Plenty of legitimate companies pay in stablecoins like USDC, especially for remote international teams. The red flags are being paid only in an illiquid project token, being asked to deposit crypto yourself or payroll that requires sharing wallet credentials.
How do I verify a web3 recruiter is real?
Find the company's official website independently, not through the recruiter's link. Check the team page or LinkedIn for the recruiter's name, then contact them through that verified channel to confirm the conversation. Also verify the email domain matches the official one exactly.
Is a paid test task ever legitimate?
Yes, and it's actually a good sign when a company pays for trial work. The direction of money is what matters. They pay you for the task. If you're asked to pay for materials, access or a deposit to receive the task, it's a scam.
Can I get my money back after a crypto job scam?
Sometimes, but only if you move fast. Report to ic3.gov and your exchange immediately, since funds can occasionally be frozen before they're laundered. Never pay a "recovery service" that contacts you promising to retrieve funds. Those are scams targeting scam victims.
