Lost my crypto after connecting to a fake UniSwap site for 'liquidity mining' – what now?

asked 8d ago1 views39 answers
0

Hey everyone, feeling pretty sick about this. I was browsing Twitter like an idiot and saw an ad for a new UniSwap v4 liquidity mining pool, offering some crazy APY. It looked legit, even had the UniSwap logo and everything. I clicked through, connected my MetaMask wallet, and approved a transaction thinking I was getting into some high-yield farming.

Instantly, my wallet was drained. Like, gone. All my USDC, a good chunk of ETH, disappeared in seconds. I'm talking low five figures. I quickly disconnected everything and revoked permissions but it was too late. I've checked Etherscan and can see the transaction, where my funds went to some random address.

Is there literally anything at all I can do? I'm heartbroken. I reported it to my local police but they just looked blank. Did I just lose everything? Has anyone ever gotten funds back in a situation like this?

Mentioned in this discussion
Etherscan· neutralMetaMask· neutral

39 Answers

42

Yeah, I went through something similar, though thankfully for a much smaller amount. Clicked a fake ad for a 'new token launch' on like, Pancakeswap or something, and my Bnb was gone in a flash. The shock was real. I tracked it on BscScan and it went right to a known scammer address. I reported it to the exchange it landed at (Kucoin, I think?), but nothing came of it. It's a brutal lesson. What I learned was to literally triple-check URLs and only trust links from official project discords or Twitter accounts, never sponsored ads. And if it's too good to be true, it absolutely is. I hope you get some closure, man.

Mohammed Khan · Ajman, UAEanswered 8d ago
45

Ugh, Jack, I'm really sorry to hear this. It's a classic wallet drainer scam, targeting folks looking for high yield in DeFi. They replicate legitimate sites perfectly. The tough truth is, once those funds are approved and moved out of your wallet on-chain, especially to a scammer's address, it becomes incredibly difficult to recover them. This isn't like a bank transfer where you can call your bank and have them recall funds.

However, 'difficult' isn't 'impossible'. Your first step is to trace the funds on Etherscan. You mentioned you did that – good. Now, you need to use that transaction hash to see where those funds moved. Did they go to a CEX (centralized exchange) like Kraken or Binance? If so, immediately report it to that exchange's compliance/security team with your transaction details. They *might* freeze the funds if they haven't been cashed out yet, especially if it's a large amount.

If the funds moved around a lot to other addresses, it gets even harder. At that point, you'd be looking at professional blockchain tracing services like Chainalysis or TRM Labs, but those are usually engaged by law enforcement or larger organizations, not typically individuals directly due to cost. For individuals, your best bet is reporting to local authorities (which you did) and any relevant national cybercrime units. Keep all screenshots, transaction hashes, and the scam site URL. Every little detail helps, even if the police acted clueless. FWIW, sometimes these addresses get flagged by services like ChainAbuse too, which helps others avoid them. Sorry man, this sucks.

Daniel Davis · Portland, USAanswered 8d ago
21

Oh man, that's absolutely gutting, Jack. I can only imagine how you're feeling right now. It's so easy to fall for these sophisticated scams because they really do look incredibly professional, especially with the fake v4 hype. You're not alone in this; so many people have been caught by similar tactics. The instant drain is the worst part, feels like a punch to the gut.

Like Daniel said, chasing funds through centralized exchanges is your best bet, but it's a long shot. Don't beat yourself up for it. The scammer's goal is to make you *feel* stupid and embarrassed so you don't talk about it, but sharing your story helps others. Keep all records, every single detail, even if it seems minor. Sending positive thoughts your way, hope you find some path to recovery.

Hao Chan · Singapore, Singaporeanswered 8d ago
32

This happened because you gave a smart contract *permission* to move your tokens. When you "approved a transaction," you likely approved an 'unlimited allowance' or granted a 'spender' permission to a malicious contract to take your tokens directly from your wallet.

This is a critical red flag for anyone reading this: NEVER approve unlimited spending limits on any token for any contract you don't 100% trust. Always approve specific amounts if possible, or revoke permissions immediately after a transaction, especially on new or unfamiliar DApps. Often the prompt looks innocent, like just a gas fee, but it's actually giving away control of your assets. The scam wasn't just connecting your wallet; it was that final approval. Learning to read those smart contract prompts *before* clicking 'confirm' on MetaMask is vital.

Ahmed Al Nahyan · Sharjah, UAEanswered 8d ago
41

Jack, I'm truly sorry for your loss. When funds are drained this way, it's usually because you signed a malicious 'approve' function giving the scammer's contract control over your tokens. This is often disguised as a standard interaction. As Ahmed mentioned, an 'unlimited allowance' is the common culprit. Always check what you're approving – often it's buried in the details of the MetaMask popup.

While direct recovery is very tough, your primary focus should be on prevention for any remaining assets and reporting. If you have other wallets or assets connected to similar dApps, immediately go to sites like Revoke.cash or Etherscan's Token Approvals page for your address. Revoke every single approval for tokens you don't actively use or trust. This is a crucial step to prevent future drains from existing permissions you might have unknowingly granted. Also, screenshot everything: the ad, the fake website URL, the transaction on Etherscan. These details are vital for any potential future investigations by authorities or specialized firms. The trail on the blockchain can be followed, it's getting law enforcement to act that's the challenge.

Aisha Al Marri · Dubai, UAEanswered 8d ago
17

Oh no, Jack, my heart goes out to you. That instant sinking feeling when your balance zeroes out is just horrible. These scammers are really good at what they do, making everything look so official, especially with hyped projects like UniSwap v4 not even being out yet creates a perfect storm for fakes.

Don't let the police's initial reaction get you down too much. Sometimes they need more specific information or prodding, or they pass it to a specialized unit. Keep pushing, or at least keep documentation in case something comes up later. For now, focus on securing any other assets you have and educating yourself on how to spot these tactics. It's a painful lesson, but an important one for staying safe in crypto. Sending you strength.

Tess van den Berg · Tilburg, Netherlandsanswered 8d ago
36

Mate, this is rough, but it's exactly why you *must* always, always, always verify the URL of any DeFi project, exchange, or wallet interface you interact with. Scammers use homoglyphs, typos, and subdomains to fool you. Before connecting your wallet or approving *anything*, take an extra 30 seconds to confirm you're on the *official* site. Bookmark the real ones. And if an APY sounds too good to be true, it absolutely is. This 'liquidity mining' scam is a classic and targets the greedy. You're not alone, but this red flag is flashing bright for everyone reading this.

Daniel Williams · Portland, USAanswered 8d ago
12

Jack, I'm so incredibly sorry to hear this happened to you. It's an awful experience. The feeling of helplessness is truly debilitating when your funds just vanish like that. Remember, it's not your fault for being trusting; it's the scammers who are maliciously exploiting that trust. You've done the right thing by reporting it, even if it feels like nothing happened. Keep every piece of evidence. Sometimes, these addresses get linked to other scams and investigations, and your report could become part of a larger case. Hang in there.

Yusuf Al Nahyan · Ajman, UAEanswered 8d ago
29

This whole 'liquidity mining' and 'yield farming' space is ripe for these kinds of sophisticated phishing attacks, Jack. The promise of high returns blinds people to the risks. Always be suspicious of *any* site asking for an approval that allows unlimited spending, especially if it's for liquidity providing or staking that seems brand new or too profitable. These scammers are quick; they launch the fake site, run their ads, drain wallets for a few days, then disappear and move the funds through mixers or to CEXs before anyone can react. It's a high-speed game of cat and mouse where the scammer always has the initial advantage. Prevention really is your only strong defense here.

Amelia Harris · Sydney, Australiaanswered 8d ago
15

Jack, I wanted to echo what others have said about not blaming yourself. These scams are designed to be convincing and prey on the natural desire for good returns. The feeling of having your funds just disappear like that is truly awful, and you're absolutely right to feel heartbroken. While direct recovery is often a long shot in these specific wallet drainer cases, the most important thing now is to shore up your defenses if you have any other crypto. Learn from this painful experience, and share it with others. Your story could very well prevent someone else from falling victim to the exact same trap. Take care of yourself.

Anna Fischer · Berlin, Germanyanswered 8d ago
3

That sounds brutal, mate. And yeah, the local police are *not* equipped for crypto stuff, bless 'em. They looked blank at me when my mate lost a bundle on a fake NFT presale. The key thing here is that the scammer got you to *approve* a transaction, not just connect your wallet. That's the immediate red flag for any 'super high APY' farm that pops up out of nowhere, especially from a Twitter ad. Always, always go to the official site directly from a bookmark or a known link, never click through ads or DMs.

Mia Smith · Canberra, Australiaanswered 8d ago
5

I feel this so deeply. I made a similar mistake last year. Mine was a fake staking site, looked exactly like the real thing. Connected my Trust Wallet, approved a gas fee, and boom – gone. ~10k worth of SOL. I was sick for weeks. Spent nights trawling forums. The police were useless, said it was 'online gambling'. My bank? Even worse. One thing I learned is that these scammers are *fast*. By the time you realise, they've already moved it through mixers. Don't beat yourself up too much, these are sophisticated scams. My only silver lining was that they didn't get *all* my funds. Stay safe out there.

Noah Meijer · Eindhoven, Netherlandsanswered 8d ago
2

This is precisely how they operate. The fake UniSwap site is a classic phishing technique. They mimic official interfaces to lull you into a false sense of security. The ad on Twitter is designed to target eager investors looking for quick gains. The crazy APY is the bait. Once you connect MetaMask and approve *any* transaction, it's game over. It bypasses the need for your private key. Always double-check the URL, even if the logo looks right. A single typo can mean the difference between profit and loss. Report this to ChainAbuse too, they track these scams.

Hugo Laurent · Nice, Franceanswered 8d ago
2

Oh no, that's absolutely devastating. I'm so sorry you're going through this. It takes a lot of courage to share your story. It's easy to fall prey to these schemes, especially when the promises are so enticing. Don't blame yourself too harshly. The good news is that by reporting it to your local police, you've taken a step. Even if they can't act directly, such reports can sometimes help build a case or identify patterns. Keep your head up, and try to focus on what you *can* control going forward. Maybe look into a hardware wallet for future holdings?

Steven Miller · Houston, USAanswered 8d ago
3

From a technical standpoint, this aligns with common 'drainer' vulnerabilities. These malicious smart contracts are designed to interact with your wallet upon approval. The attackers often deploy these contracts on the same blockchain or networks that UniSwap operates on. The initial 'ad' is the social engineering layer. The critical failure here was authorising a transaction to an unknown, untrusted contract. Always review the *specific* function being called and the target contract address before approving anything in MetaMask, no matter how legitimate the website appears. Tools like Revoke.cash for managing approvals are essential.

Noor Iqbal · Ajman, UAEanswered 8d ago
4

This is exactly the kind of scam that gives real DeFi a bad name. They prey on people's FOMO and greed. That 'crazy APY' was the immediate red flag. No legitimate platform is going to offer life-changing returns overnight through a random Twitter ad. Always verify the source. If it seems too good to be true, it almost certainly is. I’ve seen too many friends get burned by these same tactics. Report it to the CFTC as well if you're in the US, they monitor crypto fraud. It might not get your money back, but it adds to the data.

Sophie Hall · Leeds, United Kingdomanswered 7d ago
3

This is a textbook example of a 'phishing drainer' attack, common in the crypto space. The website you visited was likely a sophisticated frontend designed to mimic UniSwap v4, but it hosted a malicious script. When you connected your MetaMask and approved a transaction, you weren't interacting with UniSwap, but with a smart contract controlled by the scammers. This contract was pre-programmed to sweep your wallet of specified tokens (USDC, ETH in your case) to their address. It's a harsh lesson, but a crucial one: never trust unsolicited links or deals, no matter how professional they look.

Joshua Wong · Singapore, Singaporeanswered 7d ago
3

I’ve seen this exact scenario play out multiple times. The attackers essentially trick you into signing a malicious transaction disguised as something benign. The high APY is just the lure. The fact that it was a Twitter ad is particularly insidious, as Twitter is a major platform for crypto news and discovery. For future reference, always use a hardware wallet like Ledger or Trezor for significant holdings. They require physical confirmation on the device for transactions, making it much harder for remote attacks like this to succeed. Also, ensure your Etherscan analysis is thorough – sometimes patterns emerge.

Rachel Ong · Singapore, Singaporeanswered 7d ago
3

This is so painful to read. I also lost funds recently, though not as much as you. It was a fakeirdrop I thought I was claiming. Connected my wallet, approved a small fee. Within minutes, my altcoins were gone. I felt so stupid and ashamed. I haven't told many people. I looked into Nethertrace.co, heard they might have some success tracking certain types of illicit funds. Might be worth a shot, but don't expect miracles. The feeling of violation is the worst part, isn't it? We're all just trying to make a buck.

Samuel Ng · Singapore, Singaporeanswered 7d ago
4

The fundamental problem is the transactional nature of most blockchain interactions combined with human trust. You trusted the visual mimicry and the promise of high returns. The attacker manipulated this trust. Think of it like this: you handed over the keys (wallet connection) and signed a blank cheque (transaction approval) to a stranger pretending to be a bank. Recovering funds after they've been moved to an exchange or laundered through mixers is exceedingly difficult, bordering on impossible for individuals. Reporting to organizations like Chainalysis or TRM Labs can aid in broader investigations, but direct recovery is unlikely.

Raphael Simon · Paris, Franceanswered 7d ago
3

I'm so sorry. Reading your story brought back memories of when my own funds were stolen via a fake lottery on Telegram. It was about $7k. I was so excited about the potential payout. I connected my MetaMask, approved some transaction, and poof. It was gone. I felt like such an idiot. My husband kept saying, 'How could you be so careless?' I was devastated. The police just shrugged. I tried to contact some recovery services, but they all wanted upfront fees and sounded dodgy. It's a lonely hell.

Layla Al Nahyan · Abu Dhabi, UAEanswered 7d ago
4

This is incredibly tough, and I truly empathize. The psychological impact of such a loss is immense. The key takeaway for everyone reading this is the danger of approving tokens or contracts without rigorous verification. The fraudsters exploit the complexity and the desire for quick profit. When you connect your wallet, you grant permissions. Approving a transaction to a *new, unknown contract*, especially one promising unrealistic gains, is the critical point of vulnerability. Always scrutinize the contract address and the permissions granted. If unsure, *do not proceed*. For tracking, consider blockchain forensics firms, though their services are costly.

Lea Hoffmann · Hamburg, Germanyanswered 7d ago
4

Ah, the classic UniSwap drainer. Happens way too often. The trick is they make it look *identical* to the real site. I saw one last week that was so convincing, even the ENS name looked right at first glance. My partner caught it as I was about to connect – she noticed the specific function called in MetaMask was transferFrom or something similar, not the usual approve for staking. That’s your biggest clue: always, *always* check the transaction details in your wallet before signing. What exactly is it asking for? If it's sending tokens *out* to an unknown address, red alert.

Ava Thompson · Hobart, Australiaanswered 7d ago
3

This sounds like a malicious frontend exploit. The website itself isn't UniSwap; it's a fake designed to catfish users. When you connect your wallet and approve transactions, you're authorizing a smart contract — likely deployed recently by the scammers — to move your assets. They often use services that allow them to analyze popular DeFi protocols and then create convincing clones. The high APY is the bait. A vital safety measure is to always bookmark your essential DeFi sites and access them directly, instead of clicking links from social media or ads. Never input your seed phrase anywhere, obviously, but approvals are just as dangerous.

Eva Janssen · Amsterdam, Netherlandsanswered 7d ago
3

Ugh, I hate these stories. It’s the Wild West out there. The sad reality is that these scams are incredibly sophisticated and built to exploit the trust people place in official-looking interfaces. The Twitter ad is a HUGE red flag. Real projects don't generally advertise massive APYs on platforms like that; they have established channels. Did you check the actual URL very carefully? Sometimes a subtle difference can give it away. The fact that you lost funds immediately after approving a transaction means you likely interacted with a contract designed to drain your wallet. This is why even though my bank is useless for crypto, I'd still report it to the police.

Tess van den Berg · Utrecht, Netherlandsanswered 7d ago
4

Another one. It’s relentless. They get smarter every day. That UniSwap v4 bait is new, but the method is old. Fake site, fake promise, wallet connect, transaction approval = gone. My cousin lost a pile like this last year. He was looking for a new NFT project, clicked a 'verify your wallet' link. Boom. Low five figures gone. He was devastated. We looked into Nethertrace.co, but honestly, the chances of getting funds back once they hit tumblers are slim to none. The best defense is just extreme caution. If it's not from a primary source you REALLY trust, don't click it.

Sem de Groot · Nijmegen, Netherlandsanswered 7d ago
3

I'm really sorry this happened to you. It's a horrifying experience. These fake sites are incredibly well-made these days. The key is that they *don't need* your private key – just your permission to move funds. When you connected MetaMask and approved that transaction, you essentially gave them the green light to take specific assets. Going forward, if you're ever tempted by an insane APY, pause. Take a breath. Go to CoinMarketCap or CoinGecko, find the *real* project link there, and navigate to their official site from there. Never click ads or DMs promising riches.

Amelia Bouchard · Montreal, Canadaanswered 7d ago
3

This is incredibly painful to read, and I completely understand your desperation. The scenario you described – fake site, wallet connection, draining – is unfortunately very common. The scammers leverage the trust associated with big names like UniSwap. The crucial point is the transaction approval. Always scrutinize what you're approving. Does it make sense? Is it sending tokens to a contract you don't recognize? If you're unsure, abort. Sadly, direct recovery of funds is rare. Your best bet is reporting it widely so authorities can track the addresses. Consider reporting to the CFTC if you are in the US.

Thomas Anderson · Sydney, Australiaanswered 7d ago
3

I feel you. I lost about 3 ETH on a fake staking pool last month. It was supposed to be a new platform and the returns looked amazing (like yours!). I connected my wallet, signed the transaction... felt a knot in my stomach but it was too late. Gone in seconds. My bank said 'crypto is a risk'. Police were like '¯\_(ツ)_/¯'. I was so angry and ashamed. I've been using MetaMask vault and setting up multiple approvals for bigger transactions. It's slow, but better than losing everything again. Stay strong man.

Saar Bos · Tilburg, Netherlandsanswered 7d ago
3

This is devastating, and I'm really sorry you went through this. It's a brutal reminder of how risky the crypto space can be, especially with brand new shiny things like 'UniSwap v4 liquidity mining' offering crazy APYs. The scammers are *so* good at making fake sites look legitimate. The moment you clicked through from a Twitter ad and connected your wallet, you entered dangerous territory. For future protection, always double-check the URL *very* carefully, even if logos are correct. A single wrong character can lead to disaster. Reporting it to ChainAbuse is a good step for tracking.

Sarah Hall · San Antonio, USAanswered 7d ago
5

Ugh, I am so sorry. This is a textbook example of a phishing scam targeting crypto users. Those insane APY offers are almost always a red flag. The scammers create fake websites that mirror legitimate ones to trick you into connecting your wallet and signing transactions that drain your funds. Unfortunately, once a transaction is confirmed on the blockchain, it's irreversible. The police not knowing what to do makes sense; it's outside their usual jurisdiction. Have you tried reporting it to ChainAbuse? They track these scams and their findings can sometimes be useful, even if recovery isn't possible.

Saoirse O'Neill · Waterford, Irelandanswered 7d ago
8

Heartbroken is the word. I fell for something similar last year, but thankfully it was only a few hundred bucks. Saw a 'limited time offer' on some random crypto news site. Connected my Trust Wallet and bam – gone. I was devastated and angry at myself for days. What I learned, the hard way, is that if it looks too good to be true, it *definitely* is. Especially in crypto. No legitimate project gives away free money like that. The police won't do much, if anything. Focus on securing what you have left. Change passwords, use a hardware wallet from now on, and never click on suspicious links, no matter how convincing they look.

Ethan Naidoo · Pretoria, South Africaanswered 7d ago
3

This is exactly why people need to be so careful. Twitter ads are wild west right now. UniSwap itself would *never* advertise like that for a v4 pool, especially not on a third-party social media platform with a pop-up 'crazy APY'. They'd announce it on their official channels. The *only* thing you can do is be more vigilant next time. A huge red flag is any site asking you to connect your wallet and sign a transaction for 'yield farming' or 'airdrop rewards' that weren't explicitly claimed through official means. Always go directly to the source website, and use a bookmark for safety.

Ryan Young · Phoenix, USAanswered 7d ago
4

Oh no, that sounds absolutely awful. I can only imagine how you must be feeling right now, that's a devastating loss. It's so easy to get caught up in the hype, especially when the returns seem so high. Don't beat yourself up too much; these scammers are incredibly sophisticated. It's good that you're asking questions now and trying to learn from it. Focusing on future security is the best path forward. Maybe take a break from trading and Twitter for a bit to clear your head?

Mia Gagnon · Toronto, Canadaanswered 7d ago
7

My condolences. What you've experienced is a common Vector for wallet drainers. They prey on the desire for high yields. The key indicators here were: unsolicited ad on Twitter (outside of official UniSwap channels), unusually high APY, and directing you to a non-official-looking domain, even with a familiar logo.

Actionable Advice:

  • Verify URLs: Always double-check the domain name. Scammers use subtle variations like uniswap-v4.com instead of uniswap.org.
  • Transaction Scrutiny: Never approve transactions without understanding exactly what they do. Look for any token transfers *out* of your wallet, not just *into*.
  • Revoke Permissions: You did this part correctly. Use sites like Revoke.cash periodically to manage DApp approvals linked to your MetaMask.

While recovery is unlikely, consider thoroughly documenting the scam and reporting it to relevant crypto watchdog organizations. Nethertrace might be able to assist with tracing the flow of funds for your records.

Maryam Al Suwaidi · Ras Al Khaimah, UAEanswered 7d ago
2

That's rough, man. Really sorry to hear that. It's happened to others, and unfortunately, it sounds like you ran into one of those slick phishing sites. The crypto space can be pretty unforgiving if you make one mistake. I’d suggest taking a deep breath and not letting this one loss stop you from crypto altogether, but definitely stepping up your security game. Hardware wallets and double-checking every single link and transaction are non-negotiable from here on out. Maybe start with smaller amounts on platforms you've thoroughly vetted.

Christopher Miller · Denver, USAanswered 7d ago
6

Je suis désolé for you. It's a nightmare scenario, I know. I lost about half of what you did a few months ago to a similar scam. Was trying to swap on a fake PancakeSwap site. Waited three days to even tell my wife. The police were useless here too, just shrugged. The blockchain is unforgiving. There is no 'undo' button. What I did was spend weeks learning about smart contract security, how these drainers work, and how to spot them. I started using a hardware wallet for everything and never connect it unless I'm 1000% sure the site is legitimate. It's a brutal lesson.

Alice Leroy · Bordeaux, Franceanswered 7d ago
4

Wait, you connected directly on Twitter? That's the first mistake. Any legitimate crypto project, esp UniSwap, would *never* run a direct 'connect wallet' ad on social media. They'd link to their official site. If it looks too juicy, it's bait. Police can't help with blockchain issues, sadly. And getting funds back from a scammer's wallet address? Forget it. They'll just move it through mixers or swap it instantly. You're unlikely to see that money again. Best you can do is report it to places like ChainAbuse and maybe Nethertrace to help warn others.

Aoife Byrne · Waterford, Irelandanswered 7d ago
5

My friend, I feel this. I lost a chunk of my savings a while back to a 'support' scam. Someone messaged me on Discord pretending to be from a project I was invested in, said my account was flagged and I needed to connect my MetaMask to a 'secure portal' to fix it. Did it, and boom. Less than my neighbour's car. I was sick for weeks. The key takeaway is: *never* trust unsolicited DMs or ads, no matter how official they seem or how much they promise. Always go to the project's *official* website yourself. If you have to connect your wallet for something, verify the URL three times. It’s a harsh learning curve, but it has to be done.

Faisal Ahmed · Al Ain, UAEanswered 7d ago

Your answer

You'll be asked to sign in to post.