How to avoid cryptocurrency phishing
Once cryptoassets leave your wallet, you cannot simply reverse the transfer. Attackers therefore try to trick users into handing over keys or signatures instead of predicting prices or moving markets. This article covers common phishing tactics and practical defenses. It provides security information, not investment recommendations.
Why phishing is especially dangerous in crypto
Bank transfers can sometimes be stopped or refunded, but a blockchain transaction cannot be canceled once confirmed. Control over assets rests with the private key and seed phrase rather than merely a password. Exposing them even once can lead directly to theft of the entire balance. This makes phishing a much more immediate threat than a mistaken price forecast or chart reading.
Fake websites and direct messages
The most common tactics use lookalike websites and impersonation messages.
- Fake websites: Attackers use prominent search advertisements or similarly spelled domains, exploiting confusion between 0 and O or l and 1.
- Impersonation DMs: Messages on Telegram, Discord or X claim to be from administrators, announce an airdrop prize or demand wallet verification.
- Urgency: Threats such as “Verify within 10 minutes or your assets will be frozen” pressure you into poor judgment.
Actions to avoid
| Action | Why it is dangerous |
|---|---|
| Entering your seed phrase or private key | It can expose all your assets immediately. No legitimate service asks you to disclose it. |
| Connecting a wallet through a received link | A fake website can solicit a malicious signature. |
| Clicking unknown tokens or NFTs | Unsolicited bait assets may direct you to malicious websites. |
| Allowing screen sharing or remote control | Attackers can target your entire wallet under the pretext of technical support. |
Watch for wallet-drainer signatures
A particularly deceptive tactic obtains a malicious wallet-drainer signature without asking for the seed. If you casually agree to Approve or setApprovalForAll in a prompt after connecting a wallet, an attacker can gain permission to move your tokens. This explains how assets can disappear even when you never reveal the seed. Always read what you are authorizing when signing with a Web3 wallet.
- Be suspicious when a signature request grants an unlimited spending amount.
- Reject signatures you do not understand and verify the site's identity first.
- Regularly review existing permissions with a token-approval revocation tool.
A practical defense checklist
- Bookmark URLs yourself: Access exchanges and wallets through saved bookmarks rather than search or DM links.
- Keep the seed offline: Do not leave it on screens, in photos, in the cloud or in messages. See the seed-management material for details.
- Separate large holdings: Keep larger amounts in a wallet you rarely use or a hardware wallet to reduce exposure; see wallet types.
- Use app-based 2FA (OTP) rather than text messages.
- Pause: When a message emphasizes urgency, prizes or free offers, stop and verify it through official channels.
Phishing is deception aimed at human psychology, rather than simply a technical hack. Two principles—legitimate services do not ask you to disclose your seed, and signatures must be read—can prevent much of the damage. This article provides security information, not investment recommendations.
Choose your language in the bot, then join the shared chat group and channel.
Start in the bot