Cryptocurrency scams in Hong Kong range from fake exchanges and investment platforms to wallet drainers and rug pulls. The SFC's VASP licensing regime provides a verification pathway — but only works if investors use it.
Hong Kong's position as a major regional financial centre and the introduction of the SFC's Virtual Asset Service Provider (VASP) licensing regime have made it both a legitimate hub for cryptocurrency activity and a significant target for cryptocurrency fraud. The VASP regime requires crypto exchanges operating in Hong Kong to obtain SFC licences, maintain client asset segregation, and meet anti-money laundering standards — but compliance is only among licensed entities. Fraudulent platforms operating without licences actively target Hong Kong investors, often by cloning the branding and interface of legitimate licensed exchanges to appear authorised when they are not.
The scale of cryptocurrency fraud in Hong Kong reflects the broader regional pattern. SFC enforcement actions and HKPF investigations have identified numerous unlicensed virtual asset trading platforms and fraudulent investment schemes Hong Kong Bank Customers">targeting Hong Kong retail investors. The HKPF's financial crime statistics consistently show cryptocurrency-related fraud among the highest-loss fraud categories, with individual losses ranging from tens of thousands to multiple millions of HK dollars. The irreversibility of cryptocurrency transactions — once funds leave a legitimate wallet to a fraudulent address, recovery is practically impossible — makes crypto scams particularly severe in their financial impact compared to bank transfer fraud where some interception may be possible.
Several distinct crypto fraud typologies operate in Hong Kong. Fake exchange scams present fraudulent platforms as licensed exchanges — victims deposit HK dollars which are credited on the platform dashboard but never actually converted to cryptocurrency; the funds are simply stolen. Pig butchering investment scams use cryptocurrency as the medium for their fake trading platform, exploiting crypto's apparent complexity to make the fabricated returns seem more plausible. NFT and DeFi (decentralised finance) scams exploit the lower regulatory oversight of these newer markets. Wallet drainers — malicious smart contracts or apps that request wallet connection permissions and then drain all assets — target active crypto users through phishing sites and social media advertising.
Rug pulls are a form of fraud endemic to decentralised finance (DeFi) and the token creation ecosystem. A project team creates a new cryptocurrency token, promotes it heavily on social media to drive investment and inflate the price, then abruptly sells all their holdings (or removes liquidity from a DeFi pool), causing the token's value to collapse to near zero while early team members exit with investor funds. The promotion phase uses manufactured social proof — Telegram groups with thousands of apparent members, Twitter/X follower counts inflated with bots, claimed partnerships with established projects, and endorsements from apparent crypto influencers. Rug pulls have affected retail investors globally including in Hong Kong, with total losses estimated in billions of dollars across the sector annually.
NFT (Non-Fungible Token) fraud takes several forms. Wash trading — where the same tokens are traded between wallets controlled by the same party to artificially inflate apparent transaction volume and price — creates a misleading market activity picture to attract genuine external buyers. Counterfeit NFT projects copy the visual style and branding of established collections to deceive buyers who believe they are purchasing genuine items. Phishing sites specifically targeting NFT holders are common — fraudulent "exclusive minting" sites, fake OpenSea or other marketplace login pages, and social media impersonations of NFT project teams all aim to steal wallet credentials or obtain transaction signatures that drain assets. The NFT market's nascent regulatory status in Hong Kong means investor protections are significantly weaker than for licensed securities.
Fake crypto airdrop and token distribution scams exploit the practice of legitimate projects distributing free tokens to existing wallet holders. Phishing emails and social media posts claiming that a victim's wallet is eligible for a valuable airdrop direct them to a fraudulent site that requests wallet connection through a "claim" interface. The connection request grants the fraudulent smart contract permission to transfer assets from the wallet — once granted, this permission can be exercised immediately to drain all tokens. Always verify airdrop announcements through the project's official website and official social media channels found through your own navigation, never through links in emails or unsolicited social media messages.
The SFC's VASP licensing register is the first and most important verification step for any cryptocurrency platform that accepts deposits from Hong Kong retail investors. The register is publicly accessible at sfc.hk and lists all currently licensed virtual asset service providers. If a platform is not on this register and is accepting deposits from Hong Kong residents, it is operating without a licence and is outside the consumer protection framework. The SFC also maintains an Investor Alert List of specifically identified suspicious or unlicensed platforms — checking both the licensed register and the Alert List before engaging with any crypto investment platform is a five-minute process that provides significant fraud protection.
Beyond regulatory registration, additional verification steps help assess platform legitimacy. Check when the platform's domain was registered (via WHOIS lookup) — legitimate exchanges that have been operating for years will have older domain registrations, while fraudulent platforms typically use recently registered domains. Search for independent user reviews on forums like BitcoinTalk, Reddit (particularly r/CryptoCurrency and r/Scams), and Hong Kong-focused finance communities. Verify that the platform's social media presence predates the current promotional push — scam platforms often have sudden surges in follower counts or posting activity coinciding with a fundraising or token sale phase. Look for verifiable team members: platforms whose teams are entirely anonymous or whose team members cannot be found on LinkedIn are higher risk.
For smart contract interactions in DeFi, use contract verification tools before approving any transaction. Etherscan (for Ethereum) and equivalent block explorers for other chains allow you to inspect the source code and transaction history of smart contracts — verified contracts with substantial legitimate transaction history are significantly lower risk than unverified contracts or contracts deployed days before a promotion. Tools like Revoke.Cash allow you to review and revoke existing smart contract approvals granted by your wallet, enabling you to limit the ongoing exposure from previously granted permissions. Hardware wallets (Ledger, Trezor) provide an additional layer of protection by requiring physical confirmation of transactions and preventing remote wallet compromise even if a connected device is phished.
If you have transferred cryptocurrency to a fraudulent platform or wallet, act immediately even though the prognosis for direct fund recovery is poor. Report to HKPF at 182 388 and file a formal police report with all transaction details — including the wallet addresses you sent funds to, the amounts, and the dates. While cryptocurrency transactions are irreversible at the protocol level, law enforcement and cryptocurrency intelligence firms can trace blockchain transactions to identify exchange accounts where stolen funds may have been deposited. In some cases, exchanges have frozen accounts containing fraud proceeds when provided with appropriate documentation by law enforcement.
Report to the SFC if the fraud involved an unlicensed virtual asset service provider — this can be done through the SFC's online complaints form at sfc.hk/complaint. The SFC can take enforcement action against platforms operating in Hong Kong without a licence, and reports of specific unlicensed platforms contribute to the intelligence basis for enforcement. If you connected your wallet to a fraudulent site, immediately revoke all smart contract approvals using a tool like Revoke.Cash or MetaMask's built-in approval management, and consider moving remaining assets to a new wallet address — while revoking approvals prevents future drain of the original wallet, a new wallet provides a clean security state. Do not use any wallet that connected to a fraudulent site for any further transactions until you have revoked all approvals.
Be specifically alert to cryptocurrency recovery scam services that will contact crypto fraud victims following reports to law enforcement or victim communities. These services claim specialist capabilities to trace and recover cryptocurrency, charge significant upfront fees, and then disappear. Recovery of cryptocurrency from completed fraudulent transactions is practically impossible for private entities — blockchain forensics firms work with law enforcement, not with individual victims for upfront fees. Any service offering crypto recovery for payment should be reported to HKPF as a suspected secondary fraud. Official resources — HKPF, SFC, HKCERT — do not charge fees for assistance with fraud reports or investigations.