Phishing
Deception used to steal secrets or obtain harmful authorization.
Phishing is a deceptive attempt to make a person reveal sensitive information or authorize an action that benefits an attacker. In crypto, the target may be a recovery phrase, private key, exchange password, token approval, or wallet signature. The message or website often impersonates a trusted company, project, colleague, or support representative.
Traditional phishing pages copy a login screen and capture credentials. Crypto phishing can be more subtle because a user does not need to reveal a secret to lose assets. A malicious site may prepare an approval that lets a contract transfer tokens later, request a signature for a fraudulent marketplace order, or disguise a transfer as a routine wallet connection.
Attackers create urgency through fake security alerts, limited airdrops, token migrations, job offers, tax notices, or support cases. They use lookalike domains, paid search results, compromised social accounts, QR codes, and direct messages. A correct logo or verified-looking profile is not proof of authenticity. Legitimate support staff do not need a recovery phrase to troubleshoot a public transaction.
Phishing matters because blockchain transactions are often irreversible and attackers can move stolen assets within seconds. Hardware wallets protect keys from direct extraction but cannot prevent users from approving harmful transactions. Clear-signing support helps by displaying human-readable details, yet unfamiliar contract calls may still appear as opaque data. Separating valuable assets from everyday dapp activity limits potential damage.
Prevention relies on repeatable habits. Open important services from bookmarks, verify announcements through more than one official channel, check the full domain, and read recipient, amount, network, permissions, and expiration on the signing device. Use limited allowances instead of unlimited approvals. Protect email, cloud storage, and mobile accounts because attackers use them to reset exchange access or find backups.
After suspected phishing, preserve transaction hashes and messages, revoke permissions, rotate affected passwords, and contact the genuine platform through a known channel. Report malicious domains and accounts to the relevant providers when safe. Move funds only after confirming the destination wallet is clean. If a seed phrase or private key was exposed, no password change can repair it. Create a new wallet from fresh keys and transfer assets before the attacker does.
Frequently asked questions
- Common attacks include lookalike websites, fake wallet updates, search advertisements, support impersonators, urgent direct messages, fraudulent airdrops, QR codes, and malicious calendar invitations. Some requests steal recovery phrases, while others ask for token approvals or signatures that transfer assets. Treat unexpected urgency, guaranteed rewards, secrecy, and requests to move funds for “verification” as warning signs.
- Bookmark important sites, verify domains and contract addresses through independent official sources, and inspect every transaction on a hardware wallet screen. Never share a recovery phrase or private key. Use separate wallets for valuable holdings and routine dapp activity, limit token approvals, enable strong account security, and distrust links sent through direct messages, even from a familiar compromised account.
- Disconnecting the wallet is not enough. Identify the signed message or transaction, revoke relevant token and NFT approvals through a trusted tool, and move unaffected assets to a newly secured wallet if the key may be exposed. Act quickly but verify every recovery step. If a recovery phrase was entered anywhere, treat all accounts derived from it as permanently compromised.
