Common RuneScape scams and how to avoid them
Spot every common RuneScape scam: doubling and trust trades, account phishing, fake Jagex mods, and gold-buying traps, with the defence for each.
Every RuneScape scam belongs to one of three families
Scams in OSRS and RS3 look endlessly varied, but every one of them is after exactly one of three things: your in-game gold, your account, or your real money. Learn the shape of each family once and the individual tricks stop being surprising, because a new scam is almost always an old scam wearing a new coat.
This guide catalogues all three families, pairing each scam with its tell (the red flag) and its counter (the defence). The in-game and phishing sections are built on what Jagex and the game's own documentation actually say. The gold-buying section is our home turf: we run a price-comparison site for this market and have watched it since 2017, so that family is written from what we see happening, not from theory.
One fact frames everything else, and it is worth absorbing before the catalogue. Jagex's support policy is explicit that scammed items are never returned, even when the scammer is punished, and Old School has no general lost-item service at all. There is no compensation step, no restitution form. Against RuneScape scams, prevention is the entire game.
Family one: in-game trade scams
Money doubling and trust trades
The oldest con in Gielinor. A player advertises that they are "doubling money". They genuinely double your first, small trade, usually something like 20,000 to 50,000 coins, sometimes a couple of times in a row. Trust established, you hand over the real amount, and they log out or block you. Crews run accomplice accounts alongside, shouting that their money really was doubled, so the "proof" you see in chat is part of the act. Jagex classifies this whole family as trust trading: any arrangement where you give gold or items on a promise that more will come back.
Red flag: anyone offering to multiply your money, hold your items "for a bonus", or asking you to prove your trust by paying first. The small successful payout is not a counter-signal; it is the bait, priced into the scam.
Defence: never hand over wealth on a promise of return, full stop. There is no legitimate doubling, holding, or bonus service in RuneScape, and there never has been.
The trade-window switch
You agree a trade, everything looks right, and the scammer cancels at the last moment with an excuse: lag, a misclick, "let me add more". The trade re-opens and an item you already checked has been quietly replaced with a lookalike worth a fraction as much, a cheap crossbow standing in for an expensive one, or platinum tokens dressed up as a bigger number than they represent. Jagex calls the family misuse of trade windows, and it works because people confirm the second trade on memory instead of re-reading it.
Red flag: any cancelled and re-opened trade, however plausible the excuse. The in-game warning that flashes when an item is removed only protects you within a single trade session; declining and re-opening resets it, which is precisely why scammers do it.
Defence: treat every re-opened trade as a brand new trade. Re-read the items and the value on both confirmation screens every single time, and slow down; the scam needs your hurry to work.
Street gambling, dicing and giveaway cons
Hosted games of chance, dice duels, flower poker and "trust me" giveaways share one property: the host controls the game, the payout, or both. Some simply never pay winners; others rig the outcome and let you win small before you lose big, the doubling con with a costume on. Drop-party and giveaway bait works the same way in reverse, gathering a crowd so that a few planted "winners" make the con look real.
Red flag: any wager or giveaway where a stranger holds the stakes, decides the outcome, or asks for a payment to unlock a prize.
Defence: treat all street gambling as a donation. If you would not hand the host your money for nothing, do not hand it to them for a coin flip they control.
Family two: account-takeover scams (phishing)
Fake login pages and fake Jagex emails
The classic vector: an email or link that looks like Jagex, panics you about your account ("action required", "ban appeal", "unusual login"), and lands you on a login page that harvests your password. The test is mechanical, and Jagex publishes it: legitimate RuneScape and Jagex web and email addresses always end in one of exactly four domains, *.runescape.com, *.jagex.com, *.runescape.zendesk.com, or *.jagexsupport.zendesk.com. Anything else asking for RuneScape credentials is a phishing page, no matter how perfect it looks.
Red flag: any RuneScape-related login or email on a domain outside those four. Careful with the reverse, though: a sender address that looks official is not proof of legitimacy, because email headers can be forged. Off-domain proves fake; on-domain proves nothing.
Defence: never log in from a link you did not type or bookmark yourself. Jagex states plainly that it will never ask for your password or verification codes by email or message, so any such request is by definition fraud.
Fake Jagex mods and fake giveaways
Jagex's own phishing guidance names these directly: messages from someone impersonating a Jagex Mod, and unofficial competitions that require you to share personal information or log in through a third-party site. In the wild this is the Discord DM from a "moderator" about your account, the stream giveaway that needs your login to "deliver the prize", the competition form that wants your email password. The impersonation is the scam; there is no prize.
Red flag: any moderator contact that arrives as a private message with a link, and any giveaway that needs credentials or personal information to enter or collect.
Defence: real account matters happen through the official site, reached by typing the address. Verify any competition on RuneScape's own news channels before touching it, and treat DM "mods" as scammers by default.
Fake P-Mod forms and counterfeit game clients
In June 2026 Jagex published a warning after reports of players phished through two newer mechanics: fake Player-Moderator application forms that harvest login details, and counterfeit Jagex Launcher downloads hosted on non-Jagex websites. The categorical answers came in the same post. There is no P-Mod application form at all; P-Mods are invited in game, so every "apply here" form is fraudulent by definition. And downloads are only safe from Jagex's or RuneScape's own domains. The same logic covers fake copies of popular third-party clients: reach the approved ones only through the links on the official OSRS site, never from an ad or a forum link.
Red flag: any P-Mod application form anywhere, and any RuneScape download offered outside official channels, especially via ads or DMs.
Defence: download the game and launcher from the official site only, keep an authenticator on both your account and its email, and use a password you use nowhere else. That combination survives most phishing even when a password leaks.
Family three: gold-buying scams
This family is the reason PixelRates exists, so a note on sourcing: unlike the sections above, almost none of this is documented by Jagex or any official body. It is practitioner knowledge, what we and the sellers we track see in this market continuously. Buying gold is a market of small, urgent, hard-to-reverse payments to strangers, which is close to a perfect environment for fraud. Almost every scam below is a variation on one trick: getting you to send money, or credentials, to something impersonating a real seller.
Fake and cloned seller sites
A scammer copies a well-known seller's storefront pixel for pixel and hosts it on a near-identical domain: an extra word, a swapped letter, a different ending such as .shop. The clone takes your payment and disappears. Some clones buy search ads on the real seller's own brand name, so the fake ranks above the site it is impersonating.
Red flag: you arrived via an ad or a chat link rather than typing the address; the domain is subtly off; the site is weeks old with no independent review history anywhere.
Defence: reach sellers through a source that verifies the real storefront. Every outbound link on our tracked-seller list goes to the exact domain we independently source prices from, so a clone never enters the funnel.
Phishing checkouts and the friends-and-family trap
Two payment-step cons. The first routes you to a fake processor page that harvests your card or PayPal login; a legitimate seller hands you to a named processor at a URL you can verify, and never collects card details on its own page. The second is subtler: the "seller" insists you pay by PayPal friends and family, often sweetened with a discount. PayPal's own terms make personal payments, including friends-and-family, categorically ineligible for Purchase Protection. That is not a side effect; it is the reason scammers demand it. The moment the payment sends, your buyer protection is zero by design.
Red flag: a payment page whose address is not the processor's real domain; any request to pay friends-and-family, "to avoid fees", for a discount, or otherwise.
Defence: read the address bar at the exact moment you enter payment details, and refuse friends-and-family outright. A seller who asks for it is telling you they plan to keep the money.
No-delivery after payment
You pay, the confirmation says the gold is "on its way", and it never arrives. Support stalls until any dispute window feels hopeless. This is the most common outcome with fly-by-night sellers, and it is exactly the failure a trust signal is supposed to price in.
Red flag: no verifiable track record; reviews that are all five-star, all recent, and all worded alike; support that pushes an irreversible payment method for a "discount" while dodging delivery questions.
Defence: buy from sellers with a long, independently visible history, and start with a small test order. Our PixelScore and scam radar exist for this: a spike in proof-backed no-delivery reports de-ranks a seller automatically, even when its price is the lowest on the board.
"Verification" that asks for your login
Mid-purchase, a popup or "support agent" asks you to log in through their form or run a "sync tool" to "verify ownership" or "unlock delivery". Gold is delivered by a simple in-game trade; no legitimate step touches your credentials, ever. Every such request is account theft in progress, and a stolen account is often worth more than the order.
Red flag: any prompt for your game password, authenticator code, bank password, or email password, at any point, for any stated reason.
Defence: treat every credential request as an immediate stop. Delivery happens face to face in game and needs nothing but your character at a meeting spot.
Recovery scams and middleman impersonation
Two cons that target people mid-deal or post-loss. In the first, a "seller" delivers, then later claws the payment back through a fraudulent reversal, or a "recovery service" contacts a recent scam victim promising to get their money back for an upfront fee, stealing twice from the same person. In the second, you agree a deal on a forum or Discord and a "trusted middleman", or an account one character off the real seller's name, DMs you to move payment somewhere new. The real seller never sent that message.
Red flag: unsolicited DMs about your trade or your loss; requests to move off-platform, to a new payment address, or to a "faster" method; anyone who contacts a scam victim offering recovery.
Defence: keep the entire transaction on the seller's own verified storefront, pay nobody who messages you first, and know that legitimate fund recovery services for this market do not exist.
If you have been scammed: what actually works
What happens next depends on which family got you, so here is the honest map.
Scammed in game: report the player through the in-game report system with as much evidence as you can attach; Jagex reviews reports and punishes scammers with mutes or bans. What reporting will not do is bring anything back: the lost-items policy explicitly rules out returns for scam and hijack victims. If credentials were involved, change your password, check your registered email, and add an authenticator before anything else; hijacked accounts are recoverable even though their contents are not.
Phished: secure the account and its email first, then report the phishing site to your browser's safe-browsing report and the fake email to your email provider, so the same page burns fewer people after you.
Scammed out of real money: move fast and pick your lane deliberately. A PayPal item-not-received dispute must open within 180 days of the payment; if something arrived but was wrong, the window can be as short as 30 days from delivery. And under PayPal's terms you must choose between a PayPal claim and a card-issuer chargeback: going to your card first permanently closes the PayPal route, while card chargeback rights are often broader. Friends-and-family payments have no purchase protection at all, and crypto is irreversible by design, which is why both are scam-seller favourites. One line you must never cross in the other direction: filing a chargeback after gold was actually delivered is payment fraud, not a refund, and it gets your details blacklisted across sellers.
The uncomfortable part for buyers: buying gold is against Jagex's rules, which define real-world trading as buying or selling anything relating to a Jagex account for real money. In September 2025 Jagex announced the end of its historic leniency toward buyers: bans, temporary or permanent, even for first offences, plus confiscation. No policy says whether a scammed buyer who reports gets any amnesty, so assume reporting an RMT scam to Jagex identifies you as a participant. Weigh that before you attach payment receipts to an in-game report. Protecting your money runs through your payment provider; protecting your account runs through never having shared credentials in the first place.
Red flags at a glance
If two or more of these are true, walk away and re-check before spending a coin or a coin's worth of trust:
- Anyone offering to double, hold, or multiply your money, or a game of chance where the host controls the stakes.
- A cancelled trade that re-opens, however good the excuse.
- A RuneScape login page or email on a domain that is not runescape.com, jagex.com, or their two Zendesk support domains.
- A "Jagex Mod" who contacts you by DM, a giveaway that needs your login, or any P-Mod application form (none exist).
- A game or launcher download from anywhere but the official site.
- A seller domain that is subtly wrong, brand-new, or reached through an ad or chat link.
- Any request for your game, email, or bank password or authenticator code, from anyone, for any reason.
- A request to pay by PayPal friends-and-family, or pressure toward an irreversible method to unlock a "discount".
- An all-in price far below every established seller for the same quantity.
- An unsolicited DM offering a deal, a middleman, or recovery of money you already lost.
The short list of rules that beats all of them
- Never hand over gold, items, or money on a promise of more back. No doubling, no holding, no trust trades.
- Re-read both trade screens on every trade, and treat every re-opened trade as new.
- Log in only at addresses you typed yourself; download only from the official site; share your password and codes with no one, ever.
- Reach gold sellers through verified storefronts, never ads, DMs, or "middlemen", and check the domain again at the payment step.
- Pay with buyer protection intact: goods-and-services, never friends-and-family, and start new sellers with a small test order.
Worth stating plainly: buying in-game currency is against the game's rules and carries account risk no guide can remove; since late 2025 that explicitly includes buyers, not just sellers. Avoiding scammers protects your money. It does not make the purchase itself safe, and nobody honest will tell you otherwise.
How PixelRates reduces the risk
A comparison site is only useful against fraud if it removes the seller's ability to lie to you. Three parts of how we work do exactly that.
Independent sourcing. We scrape every price from the seller's live storefront ourselves and spot-check it against a real checkout. Sellers cannot submit their own numbers or their own links, so a cloned lookalike domain or a fabricated "best price" never gets into our data. When you click through from our OSRS gold board or the RS3 board, you land on the exact storefront we vetted.
PixelScore. Each seller carries a single score built from reviews aggregated across the web (Trustpilot, Reviews.io, marketplace ratings) plus our own verified-buyer reviews, each source weighted by how many reviews it represents. It is the fast answer to "does this seller actually deliver", and it is deliberately hard to fake because it draws on sources the seller does not control.
The scam and ban-risk radar. Buyers submit proof-backed reports (proof of purchase plus proof of a non-delivery or a ban), and a spike in verified delivery-failure reports automatically de-ranks a seller, even when it is the cheapest on the page. No other comparison site tracks this. You can read the full weighting on our methodology page, and browse the vetted storefronts on the seller directory.
To be clear about what we are: PixelRates is independent, is not affiliated with, endorsed by, or sponsored by Jagex or any game publisher, and does not sell gold or process payments. We compare sellers and link you to the real ones. The rest of avoiding RuneScape scams is the short list above, applied every single time.