Skip to content

Crypto phishing

Crypto phishing uses impersonation and urgency to trick people into revealing wallet secrets, sending assets, or approving malicious transactions and signatures. Learn the attack chain, warning signs, preventive controls, and immediate response steps.

Updated

For educational purposes only; not investment advice. Investing may result in loss.

Direct answer

Crypto phishing is social engineering aimed at cryptocurrency users. An attacker impersonates a wallet, exchange, project, or support agent and pressures the victim to reveal a recovery phrase or password, install malicious software, send assets, or approve a transaction or signature that benefits the attacker.

Merely viewing a token or connecting a wallet does not normally authorize a transfer. The decisive event is what the user reveals, sends, signs, or approves. A request described as “verify,” “sync,” “claim,” or “secure” can still grant token spending rights or create an off-chain signature that the attacker uses later.

Common lures include:

  • Lookalike domains, sponsored search results, fake browser extensions, and cloned wallet apps.
  • Unsolicited support messages, account warnings, and recovery offers.
  • Fake airdrops, mints, refunds, migrations, and investment giveaways.
  • QR codes, attachments, or links that lead to a malicious transaction or credential form.
Crypto phishing
0 / 5
0 items reviewed; 5 items still unresolved

Completing this review does not prove an asset, transaction, or system is safe.

How it works

The attack usually has three stages. First, the lure borrows trust and creates urgency. Second, the capture step asks for a secret or wallet action. A disclosed recovery phrase or private key gives control of every account derived from it; stolen exchange credentials can enable account takeover; an on-chain approval can leave a persistent token allowance; and an off-chain signature may be submitted later if its terms permit.

Finally, the attacker transfers assets directly or exercises the permission that was granted. The theft may be immediate, but a delayed signature or allowance can make a harmless-looking first interaction misleading. Confirmed blockchain transactions generally cannot be reversed by a wallet provider or network operator.

Disconnecting a site from a wallet is not the same as revoking an on-chain token approval. A revocation is itself an on-chain transaction on the relevant network and normally costs a network fee.

Example

A social-media post advertises an airdrop and links to a domain that differs from the project’s real domain by one character. The page asks the user to connect a wallet and press “Claim.” The wallet prompt actually grants a contract a large token allowance or requests an off-chain signature that can authorize a later transfer. Nothing may disappear immediately, but the attacker can use that authority while it remains valid.

The safe check is to compare the requested action with the intended action: verify the domain through an independent official channel, then inspect the network, contract or spender, asset, amount or scope, and any deadline. Reject the request if the wallet cannot explain it clearly or if it asks for more authority than the action requires.

Risks and controls

  • Never enter a recovery phrase or private key into a website or share it with a support agent. Legitimate support does not need it.
  • Open frequently used services from a verified bookmark or independently confirmed official channel, not from an ad or unsolicited message.
  • Read every wallet prompt. A gas-free message can still carry authority, and a hardware wallet cannot protect assets if its owner confirms a malicious request.
  • Limit token allowances, review them periodically, and separate long-term holdings from a wallet used for unfamiliar applications.
  • Use unique passwords and multi-factor authentication for custodial accounts, keep wallet software updated, and do not ignore wallet security warnings.

If you may have interacted with a phish

  • If a recovery phrase or private key was exposed, treat the wallet as compromised and move remaining assets to a new wallet created from a new secret. Do not reuse the exposed phrase.
  • If you approved a suspicious contract or signature, use a trusted block explorer or verified approval-management tool on the correct network to revoke relevant permissions; move at-risk assets if necessary.
  • Change affected exchange and email passwords, enable multi-factor authentication, and end unknown sessions.
  • Preserve URLs, messages, addresses, transaction hashes, and screenshots; report them to the impersonated service and appropriate authorities. Be wary of anyone promising guaranteed recovery for an upfront fee.

Common misconceptions

Does connecting a wallet let a site drain it?

Connection usually exposes the selected public address and lets the site propose requests; it does not by itself approve every transfer. The danger begins when a secret is disclosed or a harmful transaction, approval, or signature is confirmed.

Does disconnecting the site cancel its token allowance?

No. Disconnecting the interface and revoking an on-chain allowance are different actions. Check active approvals on the correct network and submit a revocation when needed.

Does a hardware wallet eliminate phishing risk?

No. It helps isolate private keys and requires physical confirmation, but it cannot determine the user’s intent. Verify the details shown on the trusted device and reject any request that does not match the intended action.

Sources

Navigation

Search the wiki...