Crypto Phishing: Fake Sites and Messages That Drain Wallets
Crypto Phishing: Fake Sites and Messages That Drain Wallets
Key takeaways:
- Crypto phishing attacks use fake sites, messages, and links to steal private keys or trick you into a malicious transaction.
- Always check the exact domain name in the address bar before entering any data or connecting your wallet.
- Review the transaction signature in your wallet before confirming; if you see an unknown call or suspicious address, cancel.
- Fake airdrops and fake support messages often demand urgent action or sensitive data; be wary of pressure.
- Use a hardware wallet and verify the address on the device screen before final confirmation of a transaction.
Crypto phishing is one of the most common ways attackers try to drain the wallets of everyday users. Instead of breaking encryption, they target people: with fake sites, messages that look official, and links that lead to copies of well-known platforms. In this article, we will show you how to recognize the most common attack channels and what steps to take before you click on anything.
Security in the crypto world is not absolute, but with proper verification of domains and transaction signatures, you can significantly reduce the risk. The goal is to understand attack patterns, not to be afraid.
Fake Airdrop: How the Bait Leads You to a Dangerous Transaction
A fake airdrop is one of the most widespread forms of crypto phishing attacks. Attackers send messages on social media, email, or even Telegram, promising free tokens if you connect your wallet or send a small amount of cryptocurrency to ‘cover gas fees’. In reality, the goal is to trick you into signing a transaction that gives the attacker permission to spend your funds.
- Recognize the signs: messages with exaggerated promises, urgent deadlines, and a request to connect your wallet on an unknown site.
- Never enter your private key or seed phrase on a site that came from a message; official projects never ask for that.
- If an airdrop seems too good to be true, it probably is. Check the project’s official channels before doing anything.
Fake Support: When ‘Help’ Becomes a Threat
Attackers often use fake customer support to get to your funds. They pose as representatives of an exchange or wallet, contact you via social media or even by phone, and offer a solution to a ‘problem’ with your account. Then they ask you to confirm a transaction or reveal sensitive data.
- Remember: real support never asks for your seed phrase or private key.
- If someone contacts you first, be suspicious; end the communication and reach out to the official support channel from a site you opened yourself.
- Check the domain: fake support sites often have a similar name but with a typo or an addition (e.g., ‘support-exchange.com’).
Poisoned Search Links: How Cloned Pages Appear at the Top
Crypto phishing attacks often use fake sites that appear in search results, especially when users search for popular platforms. Attackers create a copy of a well-known site and use SEO techniques to rank it high. When you click the link, you land on a page where you enter data or connect your wallet to a malicious app.
- Before clicking, check the URL in the address bar: the exact domain name, without extra words or substituted letters (e.g., ‘binancee.com’ instead of ‘binance.com’).
- Use bookmarks for frequently visited sites instead of searching for them every time.
- If a site asks you to connect your wallet, first verify that the domain is truly official; fake sites often have a certificate, so that is not a reliable sign.
How to Check a Domain Before Clicking: Practical Steps
Domain verification is the first line of defense against crypto phishing attacks. It does not require technical knowledge, just a little attention.
- Always type the site address manually into your browser instead of clicking a link from a message or email.
- Look at the exact domain name, including the extension (e.g., ‘.com’, ‘.rs’). Fake sites often use similar extensions like ‘.net’ or ‘.io’.
- A certificate is not proof of legitimacy; check the exact domain in the address bar and compare it with the project’s official site.
- Compare the contract address from the project’s official site with the address on a block explorer (e.g., Etherscan) before interacting.
Checking the Transaction Signature: What to Look For Before You Confirm
When you connect your wallet and the site requests a transaction, the signature is your last defense. Many users confirm transactions without looking at the details, which attackers exploit.
- In your wallet, before confirming, review all details: recipient address, amount, network, and call type.
- If you see a call you do not recognize (e.g., ‘approve’ or ‘setApprovalForAll’), it could be an attempt to grant access to your tokens.
- Use a hardware wallet that displays transaction details on the device screen; this reduces the risk of a fake display on your computer.
- If anything looks suspicious, cancel the transaction and verify the information on official channels.
How to Protect Yourself: Habits That Reduce Risk
Protection against crypto phishing attacks is not a one-time action, but a set of habits that become automatic.
- Use a hardware wallet for larger amounts; it keeps private keys isolated on the device itself, out of reach of your computer and the internet, reducing the risk of malware.
- Always check the domain and transaction signature before every click and confirmation, without exception.
- Be skeptical of messages that demand urgent action or personal data; legitimate platforms do not pressure you.
- Regularly check the official blogs and announcements of the projects you use, so you know which addresses are real.
- If you suspect that your seed phrase or key may be compromised, immediately move your funds to a new wallet and revoke all token approvals (e.g., via revoke.cash or the Etherscan Token Approval tool). Changing your password does not protect your funds if the key has leaked.
On this blog, we regularly cover current threats; for external resources, see the official documentation of your wallet.
Related Articles
Frequently Asked Questions
What is crypto phishing?
Crypto phishing is a type of attack where scammers use fake sites, messages, or links to trick you into revealing private keys or signing a malicious transaction.
How do I recognize a fake airdrop?
A fake airdrop usually promises free tokens with a request to connect your wallet or send a small amount of cryptocurrency. If it seems too good to be true, it probably is.
Is https a sufficient sign that a site is safe?
No. Fake sites can have a certificate, so https is not a guarantee of legitimacy. Always check the exact domain name and be cautious.
What should I check before confirming a transaction?
Check the recipient address, amount, network, and call type. If you see an unknown call or suspicious address, cancel.
How can I verify that a domain is official?
Type the address manually into your browser, compare the exact domain name with the project’s official site, and use bookmarks for frequently visited pages.
What should I do if I suspect I am a victim of a phishing attack?
Immediately stop the interaction, move your funds to a new wallet if possible, revoke all token approvals, and report the attack to the relevant authorities.