Scope: What This Guide Covers
This page is deliberately narrow. It covers where and how to file a formal report after a crypto scam, the government agencies and platforms that accept reports, and the specific information each one needs to actually act on a case. It does not cover the immediate incident-response sequence: disconnecting a compromised wallet or device, moving surviving funds to a clean wallet, and revoking malicious token approvals. That broader containment process is covered in full in Swoopr's companion guide, What to Do After a Crypto Scam, Wallet Hack, or Unauthorized Transfer, and it generally belongs first, within the first hour, before turning to the reporting steps described here. If a wallet is still connected to a malicious site or an approval is still active, that guide's contain-protect-revoke sequence takes priority over anything on this page.
Direct answer: In the US, report a crypto scam to the FBI's Internet Crime Complaint Center at IC3.gov for federal law-enforcement records, to the FTC at ReportFraud.ftc.gov for consumer-fraud tracking, and to your state attorney general's consumer protection office for state-level action, then separately notify any exchange the funds passed through and the social media platform where the scam originated, if either applies. Reporting rarely returns funds directly, but it feeds the databases used to flag wallets, connect related cases, and occasionally support larger law-enforcement action against an operation running the same scam on many victims.
Key Takeaways
- Formal reporting is distinct from incident containment; do the contain-protect-revoke sequence first, then come back to this page.
- IC3.gov, ReportFraud.ftc.gov, and a state attorney general's office each serve a different purpose; filing with more than one is normal, not redundant.
- Platform reports to an exchange or social media company move faster than government channels and are the only path with any chance of freezing funds in time.
- Reports that lead with structured identifiers, hashes, addresses, dates, and amounts, are processed faster than a narrative alone.
- Recovering the specific funds lost is genuinely unlikely; reporting still matters for pattern detection, potential larger cases, and documentation.
- Different scam types map to different best-first channels; the table below covers every category in this sub-group.
Primary US Reporting Channels
Three channels form the backbone of formal crypto scam reporting in the United States, each serving a different institutional purpose. None substitutes for the others, and filing with more than one is the normal, expected path rather than an inefficiency.
FBI Internet Crime Complaint Center (IC3.gov)
IC3 is the FBI's centralized intake system for internet-enabled crime, including cryptocurrency fraud, and it's generally the first stop for a US-based crypto scam report of any meaningful size. A submitted report is reviewed and, where the details support it, referred to the appropriate FBI field office or another law-enforcement partner. IC3 also aggregates report data across victims, which is how a wallet address, domain, or phone number tied to a scam operation gets flagged as a recognized pattern rather than treated as an isolated incident. Expect an automated confirmation with a reference number, and in most cases no further individual follow-up unless the case is selected for active investigation, typically ones with substantial losses or a traceable pattern; silence isn't a sign the report was ignored.
Common mistake
Expecting a personal case update and treating silence as proof the report didn't matter. IC3's value is largely aggregate and referral-based; keep the reference number because a platform or later report may ask for it.
FTC ReportFraud.ftc.gov
The FTC's consumer fraud reporting portal, ReportFraud.ftc.gov, serves the same general purpose as IC3 from a consumer-protection angle rather than a criminal-investigation one. Reports feed the FTC's Consumer Sentinel Network, a database shared with thousands of law enforcement agencies at the federal, state, and local level, including many state attorneys general. The FTC doesn't investigate individual complaints itself, but Consumer Sentinel data drives its enforcement priorities and litigation against large-scale fraud operations, and it also publishes aggregate fraud-loss data broken out by category, including cryptocurrency. As with IC3, expect a confirmation and reference number rather than ongoing individual follow-up.
Common mistake
Treating an IC3 report and an FTC report as duplicates and skipping one. They reach different databases used by different investigators and regulators; filing both takes largely the same evidence twice, not double the effort.
State Attorney General Consumer Protection Offices
Every US state has a consumer protection division within its attorney general's office, and many states also house their state securities regulator within or adjacent to it. A state-level report matters most with a plausible local angle: an operator registered in the state, a scheme resembling unregistered securities activity such as certain Ponzi structures or copy-trading arrangements, or a pattern affecting multiple state residents. Some state AG offices coordinate multi-state actions against fraud operations federal agencies haven't prioritized. Processes vary by state, from online forms with status updates to slower mail-in intake.
Common mistake
Skipping the state AG entirely because a scam feels purely federal or international. Even an anonymous, overseas scammer leaves a report that contributes to that state's fraud-pattern data and can matter if a related, more traceable party is ever identified.
Platform-Level Reporting
Government channels build the record that supports law enforcement and pattern detection over time, but they rarely move fast enough to affect funds still in transit. Two platform-level reports fill that gap and are worth filing alongside, not instead of, the government channels above.
Reporting to the Exchange Involved
If stolen funds passed through, or landed in, a centralized exchange, contact that exchange's dedicated fraud or security channel directly, not general support. Some exchanges can freeze an account holding flagged funds before a withdrawal or conversion completes, but only within a narrow window; once funds are withdrawn, swapped, or mixed, the opportunity closes. Lead with the transaction hash, addresses, and timestamp rather than a narrative. This applies both to the exchange a victim's funds left from and to the destination exchange the scammer's wallet sent funds to; the destination platform is often the only party able to freeze anything, and it's the one people forget to contact.
Common mistake
Contacting only the exchange the funds left from, when the destination exchange is usually the only party positioned to act before the funds move again.
Reporting to the Social Media Platform
If the scam was encountered or amplified through a specific account, post, or ad, most major platforms have a dedicated fraud or impersonation reporting flow, distinct from a general content-violation report. This won't affect funds already lost, but it can get a fraudulent account or post taken down faster than any government process, directly protecting other potential victims. This matters most for giveaway scams, fake celebrity endorsements, and impersonated support accounts, where the fraud lives entirely on the platform.
Common mistake
Treating a platform report as pointless because it won't recover funds. Its value is takedown speed and protecting the next victim, not this incident's outcome.
What Information to Gather and Include
Every reporting channel above works faster and more effectively with the same core set of information. Gathering it once, before starting any specific report, saves having to reconstruct the same details repeatedly across multiple forms.
- Transaction hashes and IDs. The single most useful identifier; a hash lets an investigator pull the sending address, receiving address, amount, and timestamp directly from the blockchain, independent of what the victim remembers.
- Wallet addresses, both yours and the scammer's, if known. Your own address establishes the funds left your control; the destination address, if identifiable, is what gets flagged and watched, and what later reports link back to if it resurfaces.
- Screenshots of all relevant communications. Full-page screenshots, not crops, preserve exact wording and context that disappear once an account is deleted or a phishing site is taken down. Keep unedited originals alongside any cropped versions.
- Platform and website URLs involved. The exact domain of any phishing site, the exchange or app used, and the social handle or profile URL help investigators connect a report to others describing the same infrastructure.
- Dates, times, and amounts. The exact date and time, with timezone, funds left your control, and the USD value at the time, are fields nearly every form asks for; blockchain timestamps are typically UTC.
- Identifying details about the scammer's claimed identity or channel. Any name, company, phone number, email, or handle used, even if obviously fake, helps connect a report to others describing the same persona or script.
Common mistake
The common mistake is waiting for every field to be complete before filing anything. An incomplete report filed promptly is more useful than a complete one filed weeks later, after a phishing site has gone offline or a chat history has expired. Most forms allow amending information later; they don't allow recovering evidence that's already gone.
Worked Example: Filing an IC3 Report for a Phishing-Drainer Scam
Hypothetical scenario — for education only.
Assume a reader clicked a link in a reply under a legitimate project's social media post, connected their wallet to what looked like an official claim page, and signed a transaction that turned out to be an unlimited token approval to a malicious contract. Within minutes, several tokens were drained from the wallet and swapped through a decentralized exchange, with the proceeds eventually routed to a wallet that, per a block explorer, sent a portion of the funds on to a known centralized exchange. The reader has already worked through Swoopr's crypto-scam-recovery guide: remaining approvals were revoked, and no further funds are at risk. This example walks through what would go into an IC3.gov report for that incident.
Complainant information
The reader's own contact information: name, address, phone number, and email. IC3 uses this only to route and potentially follow up on the complaint; it isn't shared publicly.
Financial transaction information
This section matters most and is where the evidence gathered earlier gets used directly: the exact date and time the malicious transaction was signed (with timezone), the transaction hash for the approval and the subsequent draining transaction, the reader's own wallet address, the malicious contract address that received the approval, the destination wallet the funds were swept to, the tokens and quantities lost, and their approximate USD value. Where funds moved on to a centralized exchange, naming that exchange and its transaction hash is valuable, since IC3 can sometimes coordinate directly with exchanges on active cases.
Subject information
Whatever is known about the party behind the scam, which in a phishing-drainer case is often little beyond technical identifiers. That's normal to report as-is: the malicious contract address, the fake claim site's domain, and the social handle that posted the malicious reply link are all appropriate here even without a name attached.
Description of incident
The narrative belongs last, as a short, factual sequence rather than a detailed account: what was clicked, what was signed, what happened, and what was done afterward. A concise line like "connected wallet to fake claim page linked from a reply under [project]'s official post; signed what appeared to be a claim transaction; wallet was drained via an unlimited approval to [contract address] within minutes" gives an investigator the mechanism at a glance.
After submission, the reader receives a confirmation with a reference number, logged alongside the evidence folder, ready to reference in a subsequent FTC report or exchange fraud inquiry.
Scam Type to Reporting Channel Map
Every scam category Swoopr covers across the Common Crypto Scams sub-group, along with the pillar page's own categories, maps to a best-first reporting channel based on how that scam typically operates. Use this table to skip straight to the most relevant channel for a specific incident rather than filing everywhere at once; the channel descriptions above still apply once you get there.
| Scam Type | Best First Channel | Why |
|---|---|---|
| Pig-Butchering Scams | IC3.gov | Sustained losses through a fabricated trading platform are the financial-crime pattern IC3 is built to log; file with the FTC too given the romance-adjacent social engineering. |
| Rug Pull Anatomy | IC3.gov | A hidden mint, blacklist, or liquidity-drain function built into a contract is engineered fraud; IC3's pattern data can support a broader case against a repeat offender. |
| Pump-and-Dump Schemes | State AG consumer protection office | Coordinated price manipulation touches state securities law, the channel a state AG's office is purpose-built for. |
| Fake Token Presales | IC3.gov | An unregistered presale that collects contributor funds and disappears is investment fraud at a scale IC3's intake is designed to capture. |
| Ponzi and High-Yield Scams | FTC ReportFraud.ftc.gov | Guaranteed or fixed-return schemes are a core FTC fraud category feeding the Consumer Sentinel Network shared with state and federal partners. |
| Giveaway and Airdrop Scams | Social media platform report | These scams live and spread entirely on the platform they're posted on; a takedown report stops the post or account faster than any government channel. |
| Romance and Social-Engineering Scams | FTC ReportFraud.ftc.gov | The FTC maintains a dedicated romance-scam reporting category and publishes aggregate loss data tracking this exact pattern. |
| Fake Celebrity Endorsement Scams | Social media platform report | A platform takedown request stops the specific fraudulent post fastest; also file with the FTC, since impersonation-based deceptive advertising is an imposter-scam category. |
| Honeypot Tokens Explained | IC3.gov | A token engineered to block or tax selling is deliberate technical fraud; the deployer wallet and contract address are exactly what IC3's transaction fields ask for. |
| Exit Scams Explained | IC3.gov | A team disappearing with custodial or pooled funds fits federal financial-crime reporting, especially with multiple victims and a traceable wallet. |
| Fake Mining and Staking Scams | FTC ReportFraud.ftc.gov | Fabricated returns from a cloud-mining or staking contract are a deceptive-investment pattern within the FTC's consumer-fraud scope. |
| Copy-Trading Scam Signals | State AG consumer protection office | An unlicensed party mirroring trades or managing funds can cross into unlicensed investment-adviser activity, which state securities regulators are positioned to evaluate. |
| Impersonation Scams | Social media platform report | Impersonation exploits a specific fake account or post; the fastest mitigation is a takedown report to the platform hosting it. |
| Phishing and Wallet Drainers | Exchange fraud team | Drained funds often move through an exchange before cashing out; a fast fraud report to the destination exchange is the only channel that can still freeze them in time. |
| Investment and Giveaway Fraud | FTC ReportFraud.ftc.gov | Doubling schemes and fake investment dashboards fall squarely within the FTC's consumer-fraud scope. |
| Rug Pulls and Exit Scams (overview) | IC3.gov | Same reasoning as the dedicated rug-pull and exit-scam pages above: engineered contract fraud is federal financial-crime territory. |
| Fake Tokens and Contracts | IC3.gov | Counterfeit tokens and spoofed contract addresses used to steal funds are reportable fraud with concrete, traceable on-chain identifiers. |
| Recovery Scams | FTC ReportFraud.ftc.gov | A second scam targeting an existing victim is the imposter and advance-fee fraud pattern the FTC tracks; also worth an IC3 report referencing the original case. |
| Relationship Scams | FTC ReportFraud.ftc.gov | Identical path to romance and social-engineering scams above; the FTC's dedicated romance-scam category applies directly. |
IC3 is the best-first channel most often here, reflecting how much of this sub-group involves engineered technical fraud and traceable on-chain transactions. Where a scam's mechanism lives primarily on a social platform, a takedown report belongs alongside the government channel, since it's the only one that can stop the post from reaching more people today.
Setting Realistic Expectations
Crypto's pseudonymous, cross-border nature genuinely makes fund recovery difficult, and it would be dishonest to suggest otherwise. A scammer's wallet may never be tied to a real identity, funds routed through a mixer or across several chains become extremely hard to trace, and cross-border law enforcement cooperation, while real, is slow. Filing a report doesn't obligate any agency to recover a specific victim's funds, and most individual crypto scam losses are never returned to the person who reported them.
That's a genuinely disappointing outcome, worth naming directly rather than around. But it doesn't make reporting pointless, for three reasons that don't depend on your case being the one that gets solved. Pattern detection: a wallet address that shows up in one report looks like noise, but the same identifier across dozens of reports is the signal that gets a case opened or an account flagged. Case-building: a handful of large crypto fraud investigations succeeded specifically because enough individual reports accumulated to justify a serious, cross-agency effort. Documentation: a dated reference number and a paper trail of what was lost can matter later, whether for a tax-loss conversation, a related report, or a record if the same operation resurfaces.
Misconceptions Versus Reality
| Misconception | Reality |
|---|---|
| Reporting a scam is pointless since I'll never get my money back | Partially true about individual recovery, but overstated as a reason to skip reporting: pattern detection across victims, potential case-building against an operation, and dated documentation are all real value that doesn't depend on this report recovering these funds. |
| Filing with IC3 and the FTC is redundant, so one is enough | The two feed different databases used by different investigators and regulators; filing both takes roughly the same evidence twice, not twice the effort. |
| Only large losses are worth formally reporting | Smaller reports still contribute to the pattern data that eventually flags a wallet or operation; a scam running thousands of small losses can be more damaging in total than one large one. |
| Nothing can be done once a transaction is confirmed on-chain | A confirmed transaction can't be reversed, but funds sitting in an identifiable destination wallet can sometimes still be frozen before they move again; reporting to that platform quickly is the only channel where speed matters. |
| A police report and an IC3 report are the same thing | Different systems serving different purposes; some exchanges and insurers specifically require a local police report number, which IC3 doesn't provide. |
| Reporting requires proof of exactly who the scammer is | Reports are routinely filed, and useful, with only technical identifiers such as a wallet or contract address and no confirmed real-world identity attached at all. |
Risks, Limitations, and Exceptions
- No reporting channel described here can reverse a confirmed blockchain transaction or guarantee any specific outcome, including fund recovery.
- IC3 and FTC reports are primarily aggregate and referral-based from an individual filer's perspective; expect a confirmation and reference number, not an ongoing case update.
- An exchange freeze only works within a narrow window before funds are withdrawn, converted, or mixed, and only if the destination platform cooperates.
- State-level reporting processes and outcomes vary significantly by state.
- This guide focuses on US-based channels; readers outside the US should use their own country's equivalent reporting body in addition to, or instead of, the channels described here.
- Reports should stick to what the evidence supports; overstating the certainty of who was responsible can create problems for a later investigation.
- None of the channels here substitute for the incident-containment steps in Swoopr's crypto-scam-recovery guide; complete that process first if any exposure is still active.
Practical Implementation Checklist
- Confirm the immediate containment steps in Swoopr's crypto-scam-recovery guide are complete before starting any report.
- Gather transaction hashes, wallet addresses, screenshots, URLs, dates, amounts, and any identifying details about the scammer first.
- Identify the scam type and check the mapping table above for the best-first reporting channel.
- File with the FBI's Internet Crime Complaint Center at IC3.gov, leading with the structured financial-transaction fields.
- File a separate report with the FTC at ReportFraud.ftc.gov using the same evidence.
- Contact your state attorney general's consumer protection office if a state-specific or securities-related angle applies.
- If funds passed through a centralized exchange, contact its dedicated fraud team directly, not general support, as quickly as possible.
- If the scam spread through social media, file a fraud or impersonation report with that platform separately.
- Keep every report's reference number, dated, in the same evidence folder used for the incident.
- Set realistic expectations and continue with normal account and wallet security rather than pausing everything to wait on a resolution.
Tool Opportunity
A dedicated Swoopr tool should convert this guide's evidence-gathering and channel-mapping logic into a guided reporting assistant.
Recommended inputs: the scam type, whether exchange funds were involved, state of residence, and evidence already collected (hashes, addresses, screenshots, URLs, dates, amounts).
Expected outputs: a prioritized list of channels to file with, a pre-filled summary formatted for IC3 and FTC intake fields, and links to the relevant exchange or platform report flow.
Validation requirements: never claim a specific outcome or timeline, never request a seed phrase or private key, distinguish confirmed on-chain data from user-supplied claims, and surface the crypto-scam-recovery guide first if containment steps look incomplete.
Frequently Asked Questions
Do I still need to report a crypto scam if I know I won't get my money back?
Yes. Individual fund recovery is genuinely unlikely once crypto has moved to a scammer's wallet, but a report isn't only about your own outcome. It adds to the pattern data law enforcement uses to flag wallets and connect related cases, it can support a larger investigation against an operation running the same scam on many victims, and it creates a dated, official record that can matter later for tax-loss documentation or if the same address resurfaces in a future case.
Should I report to IC3 or the FTC first?
File with both; they serve different purposes and neither substitutes for the other. IC3.gov routes reports into the FBI's cybercrime investigation pipeline. ReportFraud.ftc.gov feeds the FTC's Consumer Sentinel Network, a shared database that state attorneys general and other agencies also draw on. Filing both takes roughly the same evidence twice, not twice the effort.
What if the scam originated outside the United States or I'm not a US resident?
IC3 accepts reports regardless of where the scammer is believed to be located, since crypto scams routinely cross borders. If you're not a US resident, your own country typically has an equivalent national cybercrime or consumer-fraud reporting body, and filing there in addition to, or instead of, IC3 is worthwhile if the platform or funds touched US-based services.
Can reporting to an exchange actually get my stolen funds frozen?
Sometimes, but only within a narrow window. If the destination exchange still holds the funds and hasn't yet allowed a withdrawal or conversion, a fast, well-documented fraud report can prompt an account freeze while the exchange investigates. Once funds are withdrawn, converted, or mixed, that window closes. This is why platform reporting belongs alongside government reporting, and why speed matters more here than with IC3 or FTC filings.
What if I only have a transaction hash and not the scammer's wallet address?
A transaction hash alone is still useful and worth submitting; it lets an investigator pull the sending and receiving addresses directly from the blockchain, along with the exact time and amount. Include whatever you have rather than waiting to gather every field, since an incomplete report filed promptly is more useful than a complete one filed weeks later after evidence has disappeared.
How is this page different from Swoopr's crypto-scam-recovery guide?
That guide covers the first hours after discovering a scam or wallet compromise: disconnecting from the malicious site, moving surviving funds, revoking approvals, and avoiding secondary recovery scams. This page picks up after that containment work is done and focuses specifically on the formal reporting step, which agencies and platforms to file with, what information to include, and how to map a specific scam type to the channel most likely to be useful.
Sources and Methodology
This guide describes publicly available reporting channels and intake processes as of mid-2026. Key sources include:
- FBI Internet Crime Complaint Center (IC3.gov): the official federal intake portal for internet-enabled crime, including cryptocurrency fraud, cited here as this guide's primary reporting channel, along with its published annual Internet Crime Report summarizing aggregate cryptocurrency fraud trends.
- Federal Trade Commission, ReportFraud.ftc.gov: the official federal consumer-fraud reporting portal, cited here as this guide's primary consumer-protection channel, feeding the FTC's Consumer Sentinel Network shared with law-enforcement and regulatory partners.
- State attorney general consumer protection offices: the state-level reporting channel referenced throughout this guide; specific filing processes vary by state and are best confirmed through each state's official attorney general website.
The worked IC3 report example in this guide is a hypothetical, illustrative scenario constructed for educational purposes and does not describe a real incident, victim, or account.
This content was reviewed by the Swoopr Editorial Team in August 2026 and reflects publicly available information at that time. Reporting portals and agency processes can change; treat this guide as a durable framework rather than a permanently current list of every form field.
Conclusion
Reporting a crypto scam is a distinct step from containing one, and it deserves its own deliberate process rather than an afterthought tacked onto the end of a stressful day. File with IC3.gov for the federal record, ReportFraud.ftc.gov for the consumer-fraud database, and a state attorney general's office when a state-specific angle applies, then move quickly on platform-level reports to any exchange or social media company involved, since those are the only channels where speed can still change the outcome. Lead every report with structured identifiers, hashes, addresses, dates, and amounts, rather than a narrative alone. None of this guarantees recovering what was lost, and it would be dishonest to suggest otherwise, but it builds the pattern data, case-building potential, and documentation that make reporting worthwhile even when direct recovery isn't.
Related Reading
- Crypto Security and Scam Center — the top-level hub for every scam and security topic Swoopr covers.
- Common Crypto Scams — the parent pillar page for this reporting guide.
- What to Do After a Crypto Scam, Wallet Hack, or Unauthorized Transfer — the companion incident-response guide; work through this first if any exposure is still active.
- Pig-Butchering Scams — long-con investment fraud built on a fabricated relationship.
- Rug Pull Anatomy — a hidden contract function or drained liquidity pool that ends a token overnight.
- Pump-and-Dump Schemes — coordinated price manipulation before a sell-off.
- Fake Token Presales — presale contributions collected for a token that never launches.
- Ponzi and High-Yield Scams — guaranteed returns paid from new deposits rather than real gains.
- Giveaway and Airdrop Scams — send-to-receive-more schemes spread through hijacked accounts.
- Romance and Social-Engineering Scams — trust built over time before an investment ask.
- Fake Celebrity Endorsement Scams — deepfaked or edited clips lending false credibility.
- Honeypot Tokens Explained — tokens that can be bought but not sold.
- Exit Scams Explained — a team disappearing with pooled or custodial funds.
- Fake Mining and Staking Scams — fabricated yield from cloud-mining or staking contracts that don't exist.
- Copy-Trading Scam Signals — warning signs behind unlicensed trade-mirroring schemes.
- How to Verify a Legitimate Crypto Site or Service — the prevention checklist that closes the gap most of these scams rely on.