BlockBeats News, June 1st, according to Chainalysis research, social engineering attacks have become the primary source of financial losses in the cryptocurrency industry. AMLBot data shows that about 65% of the cryptocurrency theft cases investigated in 2025 involved social engineering methods; Chainalysis estimates that the total global cryptocurrency fraud loss in 2025 reached approximately $17 billion.
Attackers mainly exploit user trust, fear, and a sense of urgency to carry out scams, rather than directly attacking the underlying blockchain technology. The report summarizes the six most common current attack methods, including phishing attacks, identity fraud scams, SIM card hijacking, rug pulls (investment/romance scams), AI-driven scams, as well as airdrop and giveaway scams.
Hacken data shows that in the first quarter of 2026, the Web3 sector suffered approximately $306 million in losses due to phishing attacks; Chainalysis data shows that identity fraud scam clusters saw a year-on-year growth of about 1400%; CoinLaw estimates that SIM card hijacking attacks caused approximately $410 million in losses in 2025; while "rug pulls" and other investment scams accounted for around $7.2 billion in losses, making it the largest fraud category.
Furthermore, Chainalysis points out that the average profit from a single AI-powered scam is approximately $3.2 million, about four times the profit of traditional scam operations. FBI statistics in the United States indicate that in 2025, a total of 22,364 complaints related to AI-assisted cryptocurrency scams were received, involving losses of around $893 million.
As attack methods continue to evolve, users should avoid using SMS verification codes as the primary security verification method, verify customer service identities through official channels, and regularly check and revoke wallet authorizations to reduce the risk of asset theft.

