How do you spot a crypto trading bot scam?
Check three things before anything else: whether the product holds your funds, whether it asks for withdrawal permission on your API key, and how old its domain is. All three are verifiable on pages the operator does not control, and any one of them settles the question. The remaining six flags matter, but these three are decisive.
That distinction is the whole method, and it is not how most scam checklists are organised. Below, the nine flags are grouped by how much trust each check requires from you: three you can verify independently, three that live in what the product claims, and three that only appear in how it behaves over time.
The nine flags at a glance
| Red flag | How to verify | Time |
|---|---|---|
| You deposit funds to them | Does money leave your exchange? | 10 sec |
| Withdrawal permission requested | Exchange API permission page | 30 sec |
| Team or domain history does not check out | ICANN lookup, reverse image search | 2 min |
| Returns guaranteed or fixed | Ask for the max drawdown figure | 1 min |
| No way to watch before paying | Look for a demo on live data | 1 min |
| Track record is a backtest screenshot | Ask: historical or forward? | 1 min |
| Unsolicited contact plus urgency | Notice how they found you | ongoing |
| Recruitment pays better than the product | Read the affiliate terms | 5 min |
| Withdrawals develop problems | Try a small withdrawal early | varies |
Group 1: Flags you can verify without trusting anyone
These three checks run on infrastructure the scammer does not control. That makes them qualitatively different from everything else on the list, because no amount of marketing polish can change what your exchange's permission page says.
1. It asks you to deposit funds to them
A real automation product trades on your own exchange account. Your money never moves.
A scam asks you to send crypto to their wallet, their platform balance, or their "trading account", usually with a minimum entry amount. Once funds sit in someone else's custody, every other safeguard becomes decoration.
The US Commodity Futures Trading Commission documents this exact pattern in the Mirror Trading International case. Entry cost as little as $100 in bitcoin, no trading experience was required, and the promise was at least 10% monthly. Very little was actually traded. It ran as a Ponzi scheme, and its CEO was ordered to pay over $3.4 billion.
The test: if the product needs to hold your money, it is custody, not automation.
2. The setup guide tells you to enable withdrawal permission
Connecting a bot to an exchange means generating an API key. Read, trade, and withdraw are separate switches, and you choose them.
No trading strategy needs withdrawal permission. Not a simple one, not a sophisticated one, not ever. Opening and closing positions is entirely covered by read plus trade. A product requesting withdrawal access has announced what it plans to do with it.
The inverse is a genuine trust signal. A product that tells you to leave withdrawal off, and shows you which boxes to tick, has built your protection into its architecture instead of asking you to believe its intentions.
The test: open your exchange's API management page. Read on, trade on, withdrawal off. If the setup guide says otherwise, stop there.
3. The team or the domain does not survive a lookup
Anonymous teams are not automatically fraudulent. Crypto has cultural reasons for pseudonymity. But anonymity combined with custody and guaranteed returns is a complete scam profile.
The CFTC advisory recommends two checks most people skip:
- Reverse image search the founders. Stock photos and stolen headshots are common.
- Check the domain registration date at lookup.icann.org.
A claimed five-year track record on a domain registered four months ago is a fact, not an interpretation. Thirty seconds settles it.
One search technique worth adopting: search the brand name alongside "withdrawal" and "scam" before you search it alongside "review". Review pages in this category are frequently affiliate-driven, and they rank well precisely because someone is paid when you click through.
Group 2: Flags in what the product claims
These require judgment rather than lookup, because you are assessing statements the operator wrote themselves.
4. Returns are guaranteed, fixed, or suspiciously clean
Real strategies produce variable, sometimes negative results. Scams produce tidy numbers, because the numbers are the product.
Disqualifying language:
- Guaranteed daily or monthly percentages
- "Risk-free", "no-loss", or "passive income" framing
- Win rates at or near 100%
- Any return figure with no drawdown figure beside it
The CFTC names enormous return claims and 100% win rates directly as fraud markers, and states plainly that the technology cannot predict the future or sudden market moves.
Here is the counterintuitive part: a modest guarantee is more dangerous than an absurd one. "Just 3% a week, guaranteed" filters out nobody, because it sounds achievable. Absurd promises repel cautious people. Modest ones are engineered to attract them.
The test: ask for the maximum drawdown. Honest products publish it. Scams change the subject, because stating a drawdown admits that losses happen.
5. There is no way to watch it work before paying
This flag is underweighted, and it is one of the most reliable.
A product confident in its strategy can afford to let you observe it running on live market data with demo funds. That costs the operator almost nothing and proves nearly everything. A product that requires payment first has built its funnel around collecting money from people who will be disappointed later.
Note the difference between a free trial and actual proof. A trial that unlocks a dashboard shows you an interface. A demo that runs the strategy on live data shows you behaviour. Only the second one is evidence.
The test: can you see the strategy trade before any money or exchange connection is involved? If not, ask why not, and listen to the shape of the answer.
6. The track record is a backtest, not a forward run
Beautiful equity curve screenshots are the cheapest asset in crypto marketing.
A backtest runs a strategy against historical data. Because the past is known, a backtest can be tuned until it looks flawless, a practice called curve fitting. It demonstrates that a strategy would have worked on the data it was built against, which is close to circular.
A forward run happens on data nobody has seen yet. It cannot be curve fit, because the future was unavailable at design time.
Evidence, ranked from weakest to strongest:
- A backtest screenshot
- An independently audited backtest
- A forward run on demo funds that you watched form in real time
- A verifiable live track record
The test: ask whether the numbers are historical or forward. Then ask whether you can start a run today and watch it. Vagueness here is itself the answer.
Group 3: Flags that only appear in behaviour
These emerge over time, which is exactly why the first six matter more. Reaching flag nine usually means the money is already gone.
7. It found you, and it is in a hurry
Large crypto fraud categories share a distribution pattern: unsolicited contact, a relationship built over days or weeks, then a time-limited opportunity.
The FBI describes crypto investment scams as typically beginning through social media, messaging, adverts, or dating platforms, with the fraudster presenting as a knowledgeable insider.
Urgency is not incidental to these schemes. It exists specifically to prevent the checks in this article.
The test: urgency and verification are opposites. Any product that loses value if you spend a week researching it was never worth buying. Take the week.
8. Recruitment pays better than the product
If the affiliate scheme has multiple levels, or referral earnings feature more prominently than the strategy itself, then recruitment is the actual product. That is the mechanical shape of a Ponzi: returns funded by later entrants rather than by trading.
A normal affiliate programme pays one level and sits in the footer. A pyramid pays for downlines and puts the earnings chart on the homepage.
The test: look at where the marketing spends its space. If it is on what you could earn by referring others rather than on how the strategy behaves, you have found the business model.
9. Deposits are instant, withdrawals develop problems
The pattern is consistent enough to be predictable.
Deposits clear immediately. An early small withdrawal succeeds, which builds confidence and often prompts a larger deposit. Then the larger withdrawal triggers a new requirement: a tax payment, an unlock fee, a compliance deposit, a liquidity verification.
Every one of those requests is fraudulent. No legitimate platform requires an additional payment to release funds you already hold. Paying it never works, and it marks you as responsive.
There is a second wave worth knowing about. The FBI's 2025 report recorded over 10,500 complaints about recovery scams, with roughly $1.4 billion in losses, in which fake law firms and impersonated officials approach earlier victims offering to retrieve their money. In one scheme, the fraudsters impersonated IC3 staff.
The test: if a withdrawal requires a payment, it is a scam. And whoever offers to recover it for you afterwards is likely running the sequel.
What the numbers actually show
The scale is documented rather than anecdotal.
In its 2025 Internet Crime Report, the FBI's Internet Crime Complaint Center logged 181,565 cryptocurrency-related complaints totalling roughly $11.4 billion in reported losses, a 22% increase year over year. Crypto investment fraud accounted for about $7.2 billion of that.
One figure is worth sitting with: where crypto was involved, the average reported loss was $62,604, against roughly $20,700 across all reported cybercrime. These are not small, recoverable amounts.
The regulators have also named this specific product category. The CFTC published a customer advisory titled "AI Won't Turn Trading Bots into Money Machines", warning that fraudsters promote automated trading algorithms, signal services, and crypto arbitrage schemes on promises of unreasonably high or guaranteed returns. It is short, free, and written by the agency that prosecutes these cases.
The two-minute API key audit
If you have connected any tool to an exchange before, do this today rather than next time:
- Open your exchange's API management page, usually under account or security settings
- Review every active key and the permissions attached to it
- Delete any key with withdrawal enabled unless you can immediately say why it is there
- Delete keys belonging to products you no longer use
- Enable IP whitelisting where your exchange supports it, so a leaked key only works from approved servers
An abandoned key from a product you stopped using is the most common self-inflicted risk in this space. Closing it costs nothing.
What a legitimate setup looks like
For contrast, the inverse profile:
- Funds stay on your own exchange account throughout
- The connection uses a trade-only API key, and the product states this plainly
- You can observe the strategy before committing money
- Risk appears in specifics: expected drawdowns, explicit loss language, no return promises
- You can revoke access yourself, instantly, without contacting anyone
None of this guarantees a strategy will make money. It guarantees that the failure mode is a trading loss you can see and stop, rather than a disappearance you cannot.
FAQ
Are all crypto trading bots scams? No. Automated execution is a legitimate category and several established platforms operate openly. The distinguishing factors are custody and permissions: whether your funds stay on your own exchange, and whether the connection is able to withdraw them.
Can a trading bot steal my crypto? Only within the permissions you granted. A key with withdrawal enabled can move funds. A trade-only key cannot, because the exchange rejects withdrawal requests from keys that lack the permission.
What is the fastest way to check if a trading bot is legit? Two questions. Does it require you to deposit funds to them? Does it ask for withdrawal permission on the API key? A yes to either is disqualifying, and both take seconds to answer.
Where do I report a crypto trading bot scam? In the US, report to the FBI's Internet Crime Complaint Center at ic3.gov and to the CFTC. Elsewhere, report to your national financial regulator and to the exchange involved, which may be able to flag the receiving addresses.
Is a free trial enough proof that a product is real? Not by itself. A trial that unlocks a dashboard proves nothing. A trial that runs a strategy on live market data before any payment or exchange connection is meaningful evidence of behaviour.







