Signature phishing losses jumped 207% in a single month this year. The attacks aren't getting more technical — they're getting more targeted. Here's what's actually happening and how to not be next.
Chainalysis estimates scammers stole roughly $17 billion through crypto scams and fraud in 2025, and early 2026 data suggests this year may exceed it. But the more useful story isn't the total — it's how the attacks have changed. Fewer victims are losing far more money each, and the tools behind these attacks have gotten dramatically cheaper to deploy.
In January 2026, signature phishing losses jumped 207% compared to December — while the actual number of victims fell 11%. That divergence is the headline: scammers are deliberately moving away from mass campaigns targeting thousands of small wallets, toward fewer, wealthier targets. Just two victims accounted for 65% of all January phishing losses that month. Security researchers call this pattern "whale hunting," and it shows up starkly in address poisoning cases: one investor lost $12.25 million in January 2026 after copying a fraudulent address from their own transaction history; a month earlier, another lost $50 million the same way.
Most people picture phishing as an obviously fake email. In crypto, the actual mechanism is usually different and harder to spot: you connect your wallet to what looks like a routine dApp, airdrop claim, or NFT mint, and approve what appears to be a normal transaction. What you're often actually approving is a smart contract permission that grants indefinite access to move a specific token from your wallet — no further clicks needed. This is what's called "blind signing": approving a transaction without your wallet showing you, in plain language, what it actually does. Most wallets still display raw hexadecimal data instead of a human-readable summary, which is precisely the gap attackers exploit with spoofed interfaces.
Wallet drainer losses actually fell 83% in 2025 — from about $494 million in 2024 down to roughly $84 million — after major drainer-as-a-service operations like Inferno Drainer were shut down. That's genuine progress, but the attack pattern hasn't disappeared, and the fall in one category has coincided with a rise in others, like signature phishing and AI-assisted impersonation scams.
The technical exploits get the headlines, but most 2026 losses trace back to social engineering, not code. Impersonation scams — fake "customer support" agents contacting users with alarming claims about account access, then walking them through moving funds to a "secure" wallet — have become common enough that a documented federal case in 2026 centered on exactly this pattern, run against Coinbase users. Separately, the FBI recorded $333.5 million in crypto ATM scam losses between January and November 2025 alone, with more than 85% of victims over age 60 — largely impersonation of government agencies or tech support pressuring victims into depositing cash at crypto kiosks.
AI has lowered the cost of running these operations dramatically. Voice cloning, synthetic video, and generated personas now make "romance scam into investment opportunity" (so-called pig-butchering) schemes and impersonation calls far more convincing at a fraction of the previous cost — while the psychological mechanics (urgency, authority, fear of missing out) remain exactly what confidence scams have always relied on.