How to avoid crypto phishing scams
Lesson 48 · practical guide
Phishing copies exchanges, wallets or support teams to steal credentials, recovery phrases or transaction approvals. The strongest defence is verifying the route before clicking and limiting what a compromised account can do.
What you will learn
Stop phishing by verifying the destination, the request and the transaction before responding.
Key terms
- Phishing — a fake message or site designed to steal credentials or approvals.
- Spoofed domain — an address made to resemble a legitimate website.
- One-time code — a temporary authentication secret that should never be given to support.
Follow these steps
- Open the service from a saved bookmark or typed address, not from an unexpected message.
- Check the full domain, sender address, spelling and requested action.
- Reject requests for seed phrases, passwords, remote access or urgent transfers.
- Use hardware or app-based two-factor authentication and report the attempt.
Practical advice
Support staff do not need your seed phrase or one-time code. Before signing, read the network, recipient, amount and permissions on the wallet device itself.
Long-form explainer
The full guide
Read this lesson as a chapter: understand the mechanism, test the assumptions and apply the idea with a clear risk limit.
Phishing attacks target decisions, not only passwords
A fake message may imitate an exchange, wallet, support team or colleague and ask you to click, sign, pay or reveal a code. A spoofed domain can differ from the real address by one character or use a convincing subdomain. The request often creates urgency so the recipient skips verification.
A one-time code is still secret. Legitimate support should not need your password, seed phrase, private key or authentication code. A wallet signature can authorise an action without looking like a transfer, so read the request and destination instead of approving every prompt.
Use an independent route every time
Do not open financial links from unsolicited messages. Open a saved official address or verified application, then compare the request there. Check the domain, certificate, network, contract, recipient and amount on a trusted device. If the message says you must pay to unlock a withdrawal or recover funds, pause and verify through a separate channel.
Keep devices updated, use a password manager and enable strong multi-factor authentication. If you clicked or approved something suspicious, disconnect when appropriate, revoke permissions, move remaining assets to a clean wallet and contact official support. Preserve evidence for reporting rather than negotiating with the attacker.
What usually goes wrong
The first mistake is judging a message by how professional it looks. Phishing operations copy branding precisely, register convincing domains and buy advertising so their fake site appears above the real one in search results. The second error is following links at all. Typing the address yourself or using a saved bookmark removes almost the entire attack surface, and it costs a few seconds.
People also respond to urgency, which is the point of it. A message saying an account will be locked, a withdrawal is pending or a wallet is compromised is engineered to make you act before thinking. A further failure is reading transaction details on the website that requested them rather than on the wallet or hardware device, which is the only display an attacker cannot control. The final mistake is assuming the danger has passed once a fake site is closed. If a signature was approved, the permission may still be live, so check and revoke approvals and move assets from a clean device rather than assuming nothing happened.
How it works
Avoid links from unsolicited messages, search ads, fake support accounts and urgent pop-ups. Type the domain or use a trusted bookmark, inspect spelling and check that the action matches your intent. Legitimate support does not request a seed phrase.
Use passkeys or strong two-factor authentication, separate email security, withdrawal alerts and allowlists. If a wallet is compromised, stop signing, preserve evidence and move assets from a clean device if possible.
Worked example
Numbers make an idea concrete. Here is a small, illustrative one — not a forecast.
A fake site can show the correct logo. Visual similarity is not verification; the safe test is a trusted route and an independent confirmation of the request.
Before you act
Run through these questions before you commit any money or make a decision based on this lesson:
- Did I use a trusted bookmark or typed domain?
- Is the sender asking for a secret or urgency?
- What will this signature approve?
- What is my response plan after exposure?
Practice this lesson
Reading is a start; doing the exercise is what makes the idea stick.
Inspect three messages without clicking. Identify sender, domain, request, urgency and independent verification. Report or delete failures.
Further reading
Educational content only: This guide is not personal financial, legal or tax advice. Markets involve risk, including the possible loss of capital. Verify current rules, fees and product availability in your country.